Why self-host Mattermost on a VPS
SaaS messaging tools charge per active user and store your message history on their servers. Mattermost reverses that logic: a self-hosted instance on a VPS can serve entire teams with no per-seat cost on the Team edition, with full message history and file storage you control. For an agency or company with confidentiality constraints, hosting your own messaging means that messages, shared files and metadata never pass through a third party. Mattermost also integrates natively with Git forges, CI/CD tools and inbound/outbound webhooks, making it a central communication hub for technical teams.
Unlike Slack, which imposes its infrastructure and tiered pricing, a Mattermost instance gives you complete control over message retention, archiving policies, audit logs and integrations. This is especially important for teams subject to sector-specific regulations — healthcare, finance, defense — where data cannot leave a defined perimeter.
Concrete benefits of a self-hosted Mattermost
- Full message history on the Team edition — the free Entry edition caps viewable history at 10,000 messages since version 11 (see dedicated section).
- File storage on your VPS or an S3 bucket you control.
- Inbound/outbound webhooks and slash commands to connect CI, monitoring and alerts.
- Enterprise authentication: LDAP/AD, SAML and OAuth depending on the edition.
- Official desktop and mobile apps pointing to your own domain.
- Data compliance and sovereignty: no conversation leaves your infrastructure.
- Integrated Boards plugin (v10+) for Kanban/dashboard project management directly in messaging.
- HD audio/video calls via the Calls plugin — conferences without a third-party tool.
Hardware and software requirements
Mattermost is more demanding than a Git forge because it maintains persistent WebSocket connections. Plan for a VPS with 2 vCPU and 4 GB RAM for a team of up to 50 active users; aim for 8 GB beyond that or if you enable advanced search (Elasticsearch). For organizations of 100 to 500 users, or if you activate HD video calls via the Calls plugin, plan for 16 GB RAM and 4 vCPU. PostgreSQL is the recommended database since v10 — MySQL is still supported but PostgreSQL delivers better performance for large volumes and full-text search. Provision at least 30 GB SSD, more if you store many files locally.
On the software side: Docker Engine 24+ and Docker Compose v2, a subdomain chat.yourdomain.com with an A record, and a reverse proxy that can correctly relay WebSocket connections (Upgrade/Connection). A valid TLS certificate is required — mobile clients refuse HTTP connections. Also open port 8443 if you enable video calls (Calls/RTCD plugin) and configure a TURN server for connections behind NAT.
Deploy Mattermost with Docker and SSL
Prepare the VPS
Install Docker and Compose, then clone the official
mattermost-dockerrepo or create/opt/mattermost. Increasevm.max_map_countand open file limits if needed — Mattermost opens many simultaneous connections:sysctl -w vm.max_map_count=262144echo 'vm.max_map_count=262144' >> /etc/sysctl.confConfigure PostgreSQL and volumes
In
docker-compose.yml, declare apostgresservice with a strong password and persistent volumes for/var/lib/postgresql/data. For Mattermost, mount dedicated volumes forconfig,data,logsandpluginsto keep everything outside the container.Start the Mattermost stack
Set
MM_SQLSETTINGS_DATASOURCEandMM_SERVICESETTINGS_SITEURL(in HTTPS), then rundocker compose up -d. Followdocker compose logs -funtil the message indicating the server is listening on port 8065.Configure the HTTPS reverse proxy with WebSocket
With Nginx, proxy to
http://127.0.0.1:8065and add the mandatory WebSocket headers:proxy_set_header Upgrade $http_upgrade;proxy_set_header Connection "upgrade";proxy_read_timeout 86400;
Without these lines, real-time messaging will not work. With Caddy,reverse_proxy localhost:8065handles WebSocket automatically.Enable the SSL certificate (Let's Encrypt)
Get the certificate with
certbot --nginx -d chat.yourdomain.comor let Caddy provision it automatically. Verify thatSiteURLis set tohttps://in the configuration, otherwise mobile clients will refuse to connect.Create the team and harden the instance
Open
https://chat.yourdomain.com, create the system administrator account and your first team. Disable open registration (allow email invitations only), configure SMTP for notification emails, and restrict team creation to administrators.First login
Open the URL as soon as the installation is complete: Mattermost shows an account creation screen, and the VERY FIRST account created automatically receives the system administrator role. Create it immediately.
Mattermost v10: key new features
Mattermost v10 (released late 2024, Extended Support branch active through 2026) introduced several significant improvements for self-hosted instances:
Boards integrated in GA — the Boards plugin (Kanban/dashboard) is now pre-packaged and enabled by default. Your teams manage projects directly from Mattermost without an external tool.
HD Calls (Calls plugin v0.x) — HD audio and video conferences directly in channels, with screen sharing. The Docker installation includes the plugin; simply enable MM_PLUGINSETTINGS_ENABLE=true.
SAML AES-256-GCM — enhanced encryption of SAML assertions for Enterprise environments.
Connected Workspaces in GA — shared channels between multiple Mattermost instances move from beta to general availability, enabling federated workspaces.
End of E10/E20 support — if migrating from an old license, check your plan before upgrading.
Integrations: webhooks, Gitea, Jira and Zoom
Mattermost excels as a centralized hub for technical teams. The most common integrations in self-hosted deployments:
Inbound webhooks — each channel has a webhook URL. Your CI sends a JSON POST when a deployment succeeds or fails; Mattermost displays it in #ci-alerts. Configure under Integrations → Incoming Webhooks.
Outbound webhooks — Mattermost sends an HTTP request when a message contains a defined keyword. Useful for triggering pipelines from a conversation.
Gitea and GitLab — the official Mattermost plugin for GitLab (compatible with Gitea via JSON webhooks) notifies pushes, merge requests and issues in your repository channels.
Jira — the Jira plugin lets you create tickets directly from a Mattermost message and receive status updates in channels.
Zoom — the Zoom plugin generates a meeting link with the /zoom slash command in any channel. Alternative: use the native Calls plugin for fully on-premise meetings.
Backups: database and files
A Mattermost instance relies on two components to back up regularly: the PostgreSQL database and the data folder.
PostgreSQL backup with pg_dump (from the host, with the container running):docker exec mattermost-postgres pg_dump -U mmuser mattermost | gzip > /backups/mm-$(date +%Y%m%d).sql.gz
Data folder backup — mount the mattermost/data volume externally and archive it:tar czf /backups/mm-data-$(date +%Y%m%d).tar.gz /opt/mattermost/data
Restore — to restore: stop the containers, import the SQL dump into a fresh Postgres container, replace the data folder, then docker compose up -d.
Remember to test the restore at least once: an untested backup is not a backup.
What the free edition limits since version 11
From Mattermost 11 onward, the free self-hosted edition — called Entry — caps viewable history at 10,000 messages, across all channels and for the entire server. The important point is often misunderstood: older messages are not deleted. They remain in your database, on your machine — they simply stop being displayable and searchable from the app. The change was poorly received by the community, precisely because it restricts data that the user hosts themselves. Two options exist: upgrade to a paid edition to lift the cap, or choose a tool whose free edition does not limit history. If your use case is long-term team messaging, measure your monthly volume before committing: 10,000 messages are consumed quickly among several people. There is a third option, often overlooked: the Team edition, also free, does NOT cap history — but it does not support SSO and is limited to 250 users. The choice is therefore between a history cap (Entry) and a user cap without SSO (Team).
Mattermost vs Slack vs Rocket.Chat
Scroll the table
| Criterion | Mattermost (Team) | Slack (free) | Rocket.Chat (CE) |
|---|---|---|---|
| Self-hosted | Yes | No (SaaS) | Yes |
| Message history | Full history | 90 days | Full history |
| Cost per seat | Free up to 250 users | Free / $7.25/u/mo Pro | Free (open source) |
| Native video calls | Calls plugin (HD) | Huddles integration | Jitsi plugin |
| Boards / PM built-in | Boards plugin (GA v10) | No (Canvases) | No |
| LDAP/SAML | Paid editions | No (SAML Enterprise+) | Yes (included CE) |
| API & webhooks | Yes (in/outbound) | Yes | Yes |
| Mobile (iOS/Android) | Official apps | Official apps | Official apps |
Troubleshooting: common errors
WebSocket SSL not establishing — verify your Nginx block includes proxy_set_header Upgrade $http_upgrade; and proxy_set_header Connection "upgrade";. If the proxy is behind Cloudflare, enable WebSocket mode in the Cloudflare dashboard (Network → WebSockets).
Database connection error — check that MM_SQLSETTINGS_DATASOURCE points to the postgres Compose service (postgres://mmuser:password@db:5432/mattermost). The Mattermost container must be on the same Docker network as postgres.
Upgrading between major versions — do not skip major versions. From v9 to v11: go through v10 first, wait for the schema migration to complete (check logs), then upgrade to v11. Consult the official CHANGELOG.md for breaking changes before each jump.
Mobile clients refusing to connect — SiteURL must be https:// and the certificate valid. A self-signed certificate is rejected by iOS/Android apps without MDM configuration.
For shared files, do not store everything on the VPS disk long-term: configure Mattermost with S3-compatible object storage. This decouples your data volume from the VPS size, radically simplifies backups (the bucket is versioned independently) and facilitates potential horizontal scaling. Also consider enabling data retention to automatically purge old messages and control PostgreSQL growth.
Official documentation
For advanced configuration and tool-specific options, refer to the official Mattermost documentation. This guide covers VPS deployment; the publisher's docs remain the reference for fine-tuning, major upgrades and specific use cases.