Skip to content

TutorialsGit & DevOps

How to install Dokploy with Docker Swarm, Traefik and HTTPS

Install Dokploy with its official script, create the admin account, move the panel to HTTPS on your domain, close port 3000, then set up backups and updates.

  • Intermediate
  • 30 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Debian 12

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Prerequisites
  2. Step 1 — Prepare the firewall
  3. Step 2 — Download and review the installer
  4. Step 3 — Run the installer
  5. Step 4 — Create the administrator account
  6. Step 5 — Put the panel on your domain with HTTPS
  7. Step 6 — Close port 3000
  8. Back up and restore
  9. Update Dokploy
  10. Troubleshooting
  11. The installer stops because port 80, 443 or 3000 is in use
  12. Swarm initialisation fails or the panel shows the wrong IP address
  13. The panel does not load after a reboot
  14. Let's Encrypt does not issue a certificate
  15. The disk fills up with images and build cache
  16. You forgot the administrator password
  17. Next steps

Dokploy is an open-source, self-hostable deployment platform. It builds and runs applications from Git repositories, Dockerfiles and Docker Compose files, provisions databases, and routes your domains through Traefik with automatic Let's Encrypt certificates. Under the hood it turns your server into a Docker Swarm manager, which also lets it manage more servers later.

This guide installs Dokploy with the official install script after you download and read it, creates the administrator, moves the panel to your own domain with HTTPS, removes the public port 3000, and sets up Dokploy's S3 backups for the instance, databases and volumes. It finishes with the update procedure and fixes for common problems.

Prerequisites

  • A fresh server running Ubuntu 24.04 LTS or Debian 12. Dokploy's tested list also includes older releases (Ubuntu 22.04, 20.04, Debian 11 and others), Fedora 40 and CentOS 9 and 8. Ubuntu 26.04 and Debian 13 are not on the tested list in October 2026, so this guide does not cover them.
  • Root access through sudo, with a non-root admin user and SSH key login as in Secure a new Linux server and Set up SSH keys. The installer itself must run as root.
  • Ports 80, 443 and 3000 free. The installer stops if anything listens on them, so do not install Caddy, Nginx or Apache first.
  • Docker is optional: if it is missing, the installer installs it. Do not join the server to an existing Swarm.
  • A domain such as dokploy.example.com with an A record pointing at the server, for the panel's HTTPS address.
ResourceMinimum (official)Suggested starting point
CPUNot published2 vCPU, 4 vCPU if you build images here
Memory2 GB4 GB
Disk30 GB60 GB SSD

The memory and disk minimums come from Dokploy's installation page; Dokploy does not publish a CPU minimum. The right-hand column is a conservative starting point, not an official or benchmarked figure. Builds, databases and logs grow quickly, so leave room.

Step 1 — Prepare the firewall

Allow SSH, HTTP, HTTPS and, for the first setup only, the panel port 3000:

Bash
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 3000/tcp
sudo ufw enable
sudo ufw status verbose

Two caveats. First, Dokploy publishes port 3000 and Traefik publishes 80 and 443 through Docker, and Docker's documentation explains that packets for published ports are routed before ufw's rules apply. ufw therefore cannot close port 3000; Step 6 removes it instead, and a provider network firewall adds a second layer. Second, the installer creates a Docker Swarm, which listens on 2377/tcp, 7946/tcp and udp, and 4789/udp. Keep these closed to the internet: Docker's Swarm documentation says the VXLAN port 4789 must never be exposed to untrusted networks. ufw's default deny policy already blocks them; open them only between your own nodes if you add servers later.

Step 2 — Download and review the installer

Download the official script and read it before you run it as root:

Bash
curl -sSL https://dokploy.com/install.sh -o dokploy-install.sh
less dokploy-install.sh

In October 2026 the script:

  • selects the latest stable Dokploy release from GitHub (or DOKPLOY_VERSION if set);
  • exits unless it runs as root, on macOS or inside a container, and exits if ports 80, 443 or 3000 are in use;
  • installs Docker if it is missing, using Docker's convenience script pinned to Docker 28.5.0, and on apt-based systems puts docker-ce, docker-ce-cli and docker-ce-rootless-extras on hold;
  • runs docker swarm leave --force, then docker swarm init with an advertise address: the first private IPv4 address, otherwise the public IP it looks up through ifconfig.io or icanhazip.com;
  • creates the attachable overlay network dokploy-network and the folder /etc/dokploy;
  • generates the PostgreSQL password and an auth secret and stores them as Docker secrets, so they are never printed;
  • starts the Swarm services dokploy-postgres (PostgreSQL 16) and dokploy (the panel, published on port 3000), and the container dokploy-traefik (Traefik v3 on ports 80 and 443).

Dokploy no longer uses Redis for self-hosted installations since version 0.29.9.

Step 3 — Run the installer

Run the reviewed script as root:

Bash
sudo sh dokploy-install.sh

If the server has several addresses, or the script cannot determine one, set the address Swarm should advertise yourself:

Bash
sudo ADVERTISE_ADDR=203.0.113.10 sh dokploy-install.sh

The script ends by printing http://your-server-ip:3000 and asks you to wait about 15 seconds. Check the services and the Traefik container:

Bash
sudo docker service ls
sudo docker ps

dokploy and dokploy-postgres should show 1/1 replicas, and dokploy-traefik should be Up.

Step 4 — Create the administrator account

Open http://your-server-ip:3000 right away. The first visit shows the setup page where you create the administrator account: enter your name, email address and a long, unique password. Anyone who reaches this page before you can claim the instance, so do not leave it waiting.

After you sign in:

  1. Turn on two-factor authentication in your profile.
  2. Invite other people under Settings, Users, and give them only the roles they need instead of sharing the admin login.

Step 5 — Put the panel on your domain with HTTPS

Dokploy's docs stress that DNS must point at the server before you add a domain; otherwise the certificate is not generated. Confirm that dokploy.example.com resolves to your server, then:

  1. Open Settings, then Web Server, which holds the domain, certificate and maintenance settings of the panel itself.
  2. Enter dokploy.example.com as the host, switch HTTPS on, choose Let's Encrypt as the certificate type and enter an email address for Let's Encrypt notices.
  3. Save. Traefik requests the certificate.

Check from your computer:

Bash
curl -I https://dokploy.example.com

You should get a response over HTTPS with a valid certificate. Sign in through the new address before you continue.

Step 6 — Close port 3000

Once the panel works on HTTPS, remove the published port 3000 with the command from Dokploy's documentation, and drop the temporary ufw rule:

Bash
sudo docker service update --publish-rm "published=3000,target=3000,mode=host" dokploy
sudo ufw delete allow 3000/tcp

From another machine, nc -vz your-server-ip 3000 should now be refused or time out, while https://dokploy.example.com still loads. If you ever need direct access again, publish the port temporarily with --publish-add and the same specification.

Back up and restore

Dokploy's backups all go to S3-compatible storage, so start by adding a destination: open Settings, then S3 Destinations, and enter the access key, secret key, bucket, region and endpoint of your storage provider.

Instance backup. Under Web Server, open Backups, select Create Backup, choose the destination and, optionally, a cron schedule such as 0 3 * * *. Each run packs the dokploy-postgres database and the /etc/dokploy folder (including Traefik's configuration) into one compressed .zip file and uploads it.

Database backups. For every database you create in Dokploy, open its Backup tab, choose the destination and fill in Database Name, Schedule Cron and Prefix. Leave Enabled on and select Test to send a first backup to the bucket.

Volume backups. For named Docker volumes of applications and Compose services, use Volume Backups: give the job a name, pick the service and volume, set a schedule and keep Turn off Container selected so that files are consistent. Bind mounts are not supported; switch them to named volumes first.

A local copy of the configuration folder is a useful extra, for example before you change Traefik settings:

Bash
sudo mkdir -p /opt/backups
sudo tar czf /opt/backups/dokploy-etc-$(date +%F).tar.gz /etc/dokploy

Restore. To restore the instance, open Web Server, then Backups, select Restore Backup, pick the destination and file, and review the summary. The restore replaces /etc/dokploy, drops and rebuilds the dokploy-postgres database and disconnects current sessions, so sign in again afterwards and restart Traefik if routes misbehave. On a new server, install Dokploy first, add the same S3 destination, restore, then use Update IP under the server settings, update your DNS records and reconfigure Git providers that used IP addresses. Databases restore from their Backup tab with Restore; volumes restore with Restore Volume into a volume name that does not exist yet, with its containers stopped.

Update Dokploy

Read the release notes on Dokploy's GitHub releases page (0.30.8 was the latest release in early October 2026) and run an instance backup first. Then download the script again and run its update command:

Bash
curl -sSL https://dokploy.com/install.sh -o dokploy-install.sh
sudo sh dokploy-install.sh update
sudo docker service ls

The official one-line form is curl -sSL https://dokploy.com/install.sh | sh -s update. The update command pulls the new dokploy/dokploy image and updates the dokploy service only; it does not touch PostgreSQL or Traefik, which Dokploy's manual installation page covers separately. If the installer installed Docker for you, the Docker packages are on hold at the version it pinned, so apt upgrade leaves Docker alone. Check Dokploy's documentation before you lift that hold with apt-mark unhold.

Troubleshooting

The installer stops because port 80, 443 or 3000 is in use

Something already listens on one of Dokploy's ports. Find it with sudo ss -tulnp | grep -E ':(80|443|3000) ', then stop and disable that service (often Apache, Nginx or Caddy) and run the installer again.

Swarm initialisation fails or the panel shows the wrong IP address

The script could not detect a usable address, or picked a private one you do not want. Run it again with ADVERTISE_ADDR set to the server's public IP, as shown in Step 3.

The panel does not load after a reboot

The containers may have started in the wrong order, so Dokploy came up before PostgreSQL was ready. Read the logs, then restart the panel service:

Bash
sudo docker service logs dokploy --tail 50
sudo docker service logs dokploy-postgres --tail 50
sudo docker logs dokploy-traefik --tail 50
sudo docker service scale dokploy=0
sudo docker service scale dokploy=1

A full disk can also push the Dokploy database into recovery mode; check free space with df -h.

Let's Encrypt does not issue a certificate

The domain was probably added before its DNS record pointed at the server. Fix the record, then recreate the domain in Dokploy or restart Traefik with sudo docker restart dokploy-traefik. Make sure ports 80 and 443 are open in your provider's firewall too.

The disk fills up with images and build cache

Dokploy's troubleshooting page uses Docker's prune commands, for example sudo docker builder prune -a for the build cache and sudo docker image prune -a for unused images. Check what is using space with sudo docker system df first; prune -a removes every image that no container currently uses.

You forgot the administrator password

Find the container of the dokploy service (its image is dokploy/dokploy) and run Dokploy's reset command inside it:

Bash
sudo docker ps --filter name=dokploy
sudo docker exec -it CONTAINER_ID bash -c "pnpm run reset-password"

Replace CONTAINER_ID with the ID from the first command. For two-factor authentication, pnpm run reset-2fa works the same way.

Next steps

Frequently asked questions

Which operating systems does Dokploy support?

Dokploy lists Ubuntu 24.04, 23.10, 22.04, 20.04 and 18.04, Debian 12, 11 and 10, Fedora 40 and CentOS 9 and 8 as tested. Ubuntu 26.04 and Debian 13 are not on that list in October 2026, so this guide uses Ubuntu 24.04 or Debian 12.

Why does Dokploy use Docker Swarm?

The installer turns the server into a single-node Docker Swarm manager. Dokploy runs its panel and PostgreSQL database as Swarm services on an overlay network called dokploy-network, and Traefik routes your domains to the apps you deploy.

Do I need to keep port 3000 open?

No. Port 3000 is only needed until the panel works on your own domain with HTTPS. Dokploy’s documentation then shows a docker service update command that removes the published port.

Can I run Dokploy behind my own Caddy or Nginx on the same server?

Not without changing the installation. The installer refuses to run when ports 80, 443 or 3000 are in use, because Dokploy’s own Traefik container serves every domain on 80 and 443 and requests the certificates.

Does Dokploy back up my apps automatically?

No. You first add an S3-compatible destination, then schedule backups for the Dokploy instance, for each database and for named volumes. The instance backup only covers Dokploy’s own database and the /etc/dokploy folder.

Sources

Сгенерировать пароль

Please confirm