Why deploy with Dokploy on your VPS?
Managed PaaS providers popularized a compelling model: push code, get a URL. But that convenience has a price. As traffic grows or databases scale, monthly bills can spiral. Dokploy reverses the equation: install it once on a fixed-resource VPS and get the same deployment experience at a predictable cost starting from 99 DH/month.
The platform is built entirely on Docker. Each application runs in a container or Compose stack; Dokploy orchestrates networking, volumes, the Traefik reverse proxy, and Let's Encrypt certificates. The web interface lets you manage everything without opening a terminal — though the terminal remains available for advanced operations.
Dokploy's key strengths
- Deploy from Git (GitHub, GitLab, Bitbucket) or a Docker Hub image
- Built-in Traefik reverse proxy with automatic Let's Encrypt SSL
- Native Docker Compose support — deploy multi-service stacks in one click
- Encrypted environment variables managed directly in the interface
- Scheduled backups to S3, Backblaze B2, or any compatible storage
- Managed databases (PostgreSQL, MySQL, MongoDB, Redis) provisioned locally
- Real-time logs and per-service CPU/RAM metrics
- Open source, no forced telemetry, self-hosted on your infrastructure
Dokploy vs Coolify vs Caprover — which one to choose?
Scroll the table
| Criterion | Dokploy | Coolify | Caprover |
|---|---|---|---|
| License | Apache 2.0 | Apache 2.0 | Apache 2.0 |
| Built-in proxy | Traefik | Traefik / Caddy | NGINX |
| Native Docker Compose | Yes | Yes | Partial |
| Managed databases | Yes (5 engines) | Yes (many) | Not native |
| Built-in backups | Yes (S3/B2) | Yes | No |
| User interface | Modern, clear | Very complete | Functional |
| Learning curve | Low | Medium | Medium |
| Maturity (mid-2026) | Active — v0.15.x | Mature — v4.x | Stable — v1.x |
Prerequisites
Before installing Dokploy, make sure you have the following:
- A VPS running Ubuntu 22.04 LTS or Debian 12 (recommended), with at least 2 vCPUs and 2 GB of RAM. For complex stacks (Supabase, n8n with workers), plan for 4 GB.
- SSH access as root or a user with sudo privileges.
- A domain name pointing to your VPS IP — or at minimum the IP address for initial testing.
- Ports 80 and 443 open in your firewall. Dokploy also uses port 3000 for its interface during installation; you can restrict it afterward.
- Docker Engine absent from the server at installation time (Dokploy's script installs the correct version itself).
Install and deploy with Dokploy
Connect to your VPS via SSH
Open a terminal and connect:
ssh root@your-ip. If using a non-root user, prefix the following commands withsudo.Run the official installation script
A single command installs Docker, Traefik, and the Dokploy panel:
curl -sSL https://dokploy.com/install.sh | sh. The script detects your distribution, installs dependencies, and starts services. The operation takes two to five minutes depending on your server's connection.Access the interface and create your admin account
Once installation is complete, open
http://your-ip:3000in your browser. The first visit displays an admin account creation form. Choose a strong password — this is the only account with full access to all resources. You can invite other users with restricted roles from the settings.Connect your Git repository
In the menu Settings → Git Providers, add a personal access token for GitHub, GitLab, or Bitbucket. Dokploy uses it to clone and monitor your repositories. For GitHub, a token with
repoandread:userscopes is sufficient.Create your first project and service
Click New Project, give it a name, then add a Service. Choose the type: *Application* (Docker image or Git repository), *Docker Compose*, or *Database*. For a Git application, select the repository and branch to track. Dokploy builds the image automatically on each push if you enable the webhook.
Configure the domain and SSL
In the Domains tab of your service, add your domain (e.g.
app.yourdomain.com). Dokploy automatically creates a Traefik rule and requests a Let's Encrypt certificate via the HTTP-01 challenge. Propagation takes less than a minute if your DNS already points to the server. Enable forced HTTPS redirection from the same tab.Inject your environment variables
Go to the Environment tab of the service. Enter each variable as
KEY=value. Values are stored encrypted and never exposed in logs. You can also import an existing.envfile using the dedicated button. After modification, a redeployment is triggered automatically if the option is enabled.Trigger the first deployment
Click Deploy. Dokploy pulls the image or clones the repository, builds if necessary, creates the container, and connects it to the proxy. Follow the progress in the Deployment Logs tab in real time. A green indicator confirms the service is
Running.Enable webhooks for continuous deployment
Copy the webhook URL shown in the General tab of the service, then paste it into your Git repository's webhook settings (event:
pushon the chosen branch). From now on, everygit pushwill trigger an automatic redeployment without manual action.Check service health and metrics
The Monitoring tab shows live CPU, RAM, and network usage for the container. If you have configured a health check in your
Dockerfile(theHEALTHCHECKinstruction), Dokploy honors it and automatically restarts the container after a prolonged failure.
Deploy a complete Docker Compose stack — n8n example
Dokploy's true power shows with multi-service stacks. Here is how to deploy n8n (workflow automation) with its PostgreSQL database.
In Dokploy, create a new Docker Compose service and paste your docker-compose.yml directly. A minimal example includes the n8n service with image: n8nio/n8n, environment variables like DB_TYPE=postgresdb and DB_POSTGRESDB_HOST=postgres, and a postgres service with a persistent volume.
Dokploy creates an isolated internal Docker network for your stack. Services communicate by name (postgres, n8n) without exposing internal ports. Only n8n's interface port (default 5678) is declared as an entry point, and Traefik handles HTTPS routing to it.
For Supabase, the approach is identical: the official supabase/supabase repository provides a ready-to-use docker-compose.yml. Import it, adjust environment variables in the dedicated tab, and deploy. Dokploy orchestrates all fifteen services in the stack without further intervention.
Configure domains, SSL, and environment variables
Dokploy supports multiple domains per service — useful for exposing an API and a dashboard under separate subdomains from the same container. Each domain has its own Traefik routing rule and independent SSL certificate.
For a wildcard (*.yourdomain.com), Traefik requires a DNS-01 challenge rather than HTTP-01. Dokploy exposes advanced Traefik configuration options under Settings → Proxy; you can inject custom TOML configuration files there.
Environment variables deserve special attention: never store secrets in your versioned docker-compose.yml. Always use Dokploy's Environment tab, which encrypts values at rest. For secrets shared across multiple services in the same stack (encryption key, API token), define them once at the project level and reference them in each service.
Backups and managed databases
Dokploy can provision PostgreSQL, MySQL, MongoDB, Redis, and MariaDB instances directly on your VPS, without manually writing Docker Compose files. Under New Service → Database, choose the engine, set the name, user, and password — Dokploy creates the container, persistent volume, and exposes it only on the internal network.
For backups, go to the Backups tab of the database service. Configure an S3 destination (AWS, Scaleway Object Storage, Backblaze B2 — any S3-compatible provider). Set a cron schedule (0 3 * * * for nightly at 3 AM), a retention period in days, and Dokploy dumps the database, compresses it, and uploads it to object storage.
For application volumes (uploaded files, generated assets), the same logic applies: Dokploy archives the volume contents and sends them to the same destination. Test restoration regularly — an untested backup is not a backup.
Troubleshooting — 4 common errors
Here are the most common error messages and how to resolve them.
1. Error response from daemon: pull access denied — The Docker image is private or the name is incorrect. Check the exact image name spelling and, if private, add your Docker Hub credentials under Settings → Docker Registries.
2. Certificate not found for domain — Let's Encrypt's HTTP-01 challenge failed. Common causes: DNS not yet pointing to the server (wait for propagation), or port 80 is blocked by the VPS firewall. Verify with curl -I http://your-domain from an external machine.
3. Container exited with code 1 at startup — The application crashes immediately. Open the service's Logs tab to read the container's stderr. The cause is almost always a missing environment variable or a refused database connection (wrong hostname, port, or credentials).
4. bind: address already in use — Another process is occupying the port your service is trying to open. On the server, ss -tlnp | grep :PORT identifies the offending process. If it is another Dokploy service, check that internal ports are not declared identically across two different services.
Security tip — restrict access to the admin interface
By default, Dokploy's port 3000 is accessible from any IP. In production, restrict it at the firewall level: ufw allow from YOUR_FIXED_IP to any port 3000, then ufw delete allow 3000. Also place the interface behind your VPN if your team uses one. Enable two-factor authentication under Settings → Account. Finally, create accounts with limited roles for team members who do not need access to system settings.
Version note
This guide is written in line with features available around Dokploy's v0.15.x branch (mid-2026). The project evolves quickly; check the GitHub changelog for recent updates.
Official documentation
Dokploy's complete documentation is available at docs.dokploy.com. There you will find CI/CD integration guides (GitHub Actions, GitLab CI), the REST API reference, and advanced Traefik configuration examples.