What you will set up
Dokploy is a platform for your own apps: point it at a Git repository, and it builds the app, runs it in a container, gives it a certificate and restarts it when it stops. It also runs databases next to your apps.
Like Coolify, Dokploy installs Docker, takes over ports 80 and 443 for its own proxy, Traefik, and runs as root, so it needs a server of its own, freshly installed. Dokploy runs everything as Docker Swarm services, which also lets it spread apps over several servers later.
Every step below was run on a fresh Melonslab VC-P Alloy (2 vCPU, 8 GB) with Debian 13, which Dokploy's docs do not list yet:
- Dokploy 0.30.7 installed in about 3 minutes, and its dashboard got a Let's Encrypt certificate for its own name.
- A Go app was built from a public Git repository in about 2 minutes, got its certificate, and redirected HTTP to HTTPS. Over IPv4, apps saw each visitor's real address.
- A PostgreSQL database was reachable from Dokploy's own network, but not from the internet.
- The setup page was never reachable from the internet, and everything came back by itself after a reboot.
With two apps and a database, the server used about 1.4 GB of memory.
Before you start
You need:
- a fresh Melonslab server with Debian 13 and nothing else installed, with at least 2 GB of memory, which is Dokploy's minimum. Building apps on the server takes more: Dokploy recommends 4 GB or more for that;
- a name for the dashboard, such as
dokploy.example.com, and one for each app, such asapp.example.com, with A and AAAA records pointing at the server.
Set up SSH keys and automatic security updates as in steps 1 to 3 of the security guide, and skip its step 4: Docker opens container ports past ufw, so step 2 here closes the port that should not be public instead.
The examples use dokploy.example.com for the dashboard and app.example.com for an app. Replace them with your own throughout.
1. Install Dokploy
As root:
apt update
apt install -y curl
curl -sSL https://dokploy.com/install.sh -o dokploy-install.sh
bash dokploy-install.sh
The installer sets up Docker, Docker Swarm, Traefik and Dokploy's own database, and finishes with Congratulations, Dokploy is installed! and an address with port 3000. Do not open that address yet. It shows a page where anyone who arrives first creates the admin account, with control of the server. Do step 2 straight away.
2. Close port 3000
Docker opens container ports past ufw, so close port 3000 in Docker's own chain, with a service that adds the rule again after every restart. Create /etc/systemd/system/dokploy-ports.service:
[Unit]
Description=Keep the Dokploy dashboard port off the internet
After=docker.service
Requires=docker.service
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/bin/sh -c "for t in iptables ip6tables; do $t -C DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport 3000 -j DROP 2>/dev/null || $t -I DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport 3000 -j DROP; done"
[Install]
WantedBy=multi-user.target
Then start it:
systemctl daemon-reload
systemctl enable --now dokploy-ports.service
Port 3000 is now closed to the internet over IPv4 and IPv6, but still open on the server itself.
3. Create the admin account
Reach the setup page through SSH instead. On your own computer, open a tunnel:
ssh -L 3000:127.0.0.1:3000 root@203.0.113.10
Keep it open, and go to http://localhost:3000. Under Setup the server, enter a name, your email address and a password, and choose Register. Once the account exists, the page no longer lets anyone else register.
Dokploy then shows a few first steps. Skip all leaves them.
4. Give the dashboard its own name
Open Settings and Web Server. Under Server Domain, enter dokploy.example.com as the Domain and your address as the Let's Encrypt Email, turn on HTTPS, and choose Save. Within a minute, the dashboard answers at https://dokploy.example.com with a Let's Encrypt certificate. From now on, log in there, and close the tunnel.
5. Deploy an app
Point app.example.com at the server first, with an A and an AAAA record. Then open Projects, create a project, and inside it choose Create Service and Application. Give it a name, and choose Create. On the application's General tab:
- Under Provider, choose Git, and enter the Repository URL, the Branch and the Build Path, then Save. For a first test, Dokploy's own examples work:
https://github.com/Dokploy/examples.git, branchmain, with/go-fiberas the build path. - Under Build Type, Nixpacks is chosen by default, which detects the language by itself. A repository with a
Dockerfilecan use Dockerfile instead. - On the Domains tab, choose Add Domain. Enter
app.example.comas the host, the port the app listens on,3000for the example, turn on HTTPS, and pick Let's Encrypt as the certificate. - Choose Deploy. The Deployments tab shows the build log, and the app answers at
https://app.example.comwhen it is done. Visitors on plain HTTP are redirected to HTTPS.
The other providers, such as GitHub and GitLab, connect an account for private repositories and deploys on every push. Autodeploy turns that on for the app.
Apps behind Dokploy's proxy see the visitor's address in the X-Forwarded-For and X-Real-Ip headers. Over IPv6, they see the address of Docker's own network instead, 172.18.0.1, because Dokploy's network has no IPv6. The sites still answer over IPv6.
6. Add a database
In the project, choose Create Service and Database, and pick PostgreSQL or another database. Dokploy starts it with the name, user and password you set. It is not reachable from the internet, and your apps reach it by its App Name on Dokploy's network.
7. Back up
Dokploy backs up databases and volumes to S3-compatible storage only, not to the server itself. Add a bucket under Settings and S3 Destinations, then schedule backups from the database's page, and for files your apps store, under Volume Backups on the application. We did not test a backup, because it needs an S3 bucket.
Your apps are rebuilt from Git, so the database backups and any files your apps store are what you need to keep.
8. Updates
Dokploy does not update itself. Under Settings and Web Server, Check for updates looks for a new version. Debian's own packages are covered by the automatic security updates from the security guide.
We found no telemetry in Dokploy. It asks Docker Hub for new versions when you check for updates, and contacts its licence server only when you enter a paid licence key.
Troubleshooting
Someone else registered first. The setup page was reachable before step 2. Reinstall the server, and do step 2 before you open the page.
An app has no certificate. Its A and AAAA records do not point at the server yet. Validate DNS on the Domains tab checks them. Traefik requests the certificate once they do.
A build is slow or stops. Building takes memory and CPU on the server itself. Dokploy recommends 4 GB or more for builds, and our 8 GB server built the example in about 2 minutes.