Ploydok is an open-source, security-first, self-hosted PaaS for deploying web applications, APIs, background services and databases on your own VPS. It is designed as a pragmatic alternative to Dokploy, Coolify, CapRover, Heroku, Railway, Render and Vercel for teams that want Git-based deploys, Docker runtime control, blue/green rollouts, framework guardrails and clear operations without running Kubernetes.
Ploydok focuses on the daily production workflow: connect a repository, deploy an app, attach domains and databases, scale replicas, inspect logs, monitor runtime health, recover safely, and keep the host clean over time.
- Why Ploydok
- Features
- Supported Stacks
- Install on a VPS
- Zero-Downtime Updates
- Local Development
- Architecture
- Security Model
- SEO Keywords
- Contributing
Ploydok is built for operators who want a small, inspectable deployment platform instead of a large cluster stack.
| Need | Ploydok approach |
|---|---|
| Deploy from GitHub or GitLab | Repository import, branch tracking, webhook deploys and preview flows |
| Run many frameworks | Dockerfile, Nixpacks and framework-specific env guardrails |
| Scale apps over time | Docker Swarm services, replicas, service updates and runtime monitoring |
| Avoid downtime on deploy | Blue/green runtime model and Swarm start-first updates |
| Keep storage under control | Runtime image cleanup, registry garbage collection and build cache hygiene |
| Operate from a VPS | One-line installer, systemd supervision, Caddy ingress, Postgres and Redis |
| Keep accounts secure | Password login, TOTP, backup codes, passkeys on HTTPS origins and session controls |
Use Ploydok if you want a self-hosted PaaS for a single server or small fleet, with practical production defaults and no Kubernetes dependency.
- Deploy web apps, APIs and services from Git repositories.
- Dockerfile and Nixpacks build paths.
- Framework detection from repository files and manifests.
- Runtime env and secret handling for build-time and runtime phases.
- Production deployments and preview deployments.
- GitHub/GitLab provider integration and webhook-driven auto-deploy.
- Docker Swarm runtime mode for long-lived application services.
- Replica scaling per application.
- Blue/green deployment model.
start-firstupdates for cleaner reloads.- Healthcheck-aware deployment status.
- Runtime reconciliation so stale DB state follows real running services.
Ploydok adds framework-aware defaults before deploy so common 502s are caught or repaired early.
- Laravel:
APP_KEY, safe cache/session defaults when no external store exists. - Symfony:
APP_SECRET,APP_ENV=prod,APP_DEBUG=0. - PHP: runtime port and web-root handling.
- Next.js: Node runtime defaults and container host binding.
- Hono and Node APIs: host/port/runtime guardrails.
- Python: Django, Flask and FastAPI process defaults.
- Rails and Phoenix: secret key checks.
- Provisioned databases managed as runtime resources.
- Connection reveal and database env injection.
- Adminer integration for database inspection.
- Runtime monitoring for app and database containers.
- Workspace dashboard with application status, service health and deploy history.
- Monitoring page for runtime status, CPU, memory, uptime, restarts and images.
- Runtime logs and live status updates.
- Health pings and stale/offline agent states.
- Password login, TOTP, backup codes and passkey enrollment.
- WebAuthn passkeys on trusted HTTPS origins.
- HttpOnly access and refresh cookies.
- mTLS between API and agent in production TCP mode.
- Image signature verification in installer flows.
- Host CLI for upgrade, uninstall and recovery operations.
Ploydok is framework-friendly rather than framework-locked. It can deploy any containerized workload and has extra guardrails for popular stacks.
| Ecosystem | Examples |
|---|---|
| JavaScript and TypeScript | Next.js, Hono, Node.js APIs, React frontends |
| PHP | Laravel, Symfony, generic PHP apps |
| Python | FastAPI, Flask, Django |
| Ruby | Rails |
| Elixir | Phoenix |
| JVM | Spring Boot through Dockerfile or build tooling |
| Custom | Any app with a Dockerfile or compatible Nixpacks build |
Install Ploydok on a Debian or Ubuntu VPS with one command:
curl -fsSL https://raw.githubusercontent.com/dev-toolings/ploydok/main/installer/bootstrap.sh | sudo bashInstall in coexist mode when another proxy already owns ports 80 and 443:
curl -fsSL https://raw.githubusercontent.com/dev-toolings/ploydok/main/installer/bootstrap.sh \
| sudo bash -s -- --mode=coexist --yesThe installer deploys the production control plane as a single-node Docker
Swarm stack by default. Docker Compose remains available only for explicit
local and test workflows (--runtime=compose).
The installer:
- clones the installer into
/opt/ploydok-installer; - installs Docker when missing, unless
--skip-docker-installis provided; - creates the
ploydoksystem user; - writes runtime descriptors under
/opt/ploydok; - stores mutable data under
/var/lib/ploydok; - generates platform secrets and mTLS material;
- pulls and verifies platform images;
- renders Docker Compose and systemd units;
- starts the platform and waits for health checks;
- installs
ploydok-clion the host.
| Mode | Use when |
|---|---|
takeover |
Ploydok should own ports 80 and 443. Existing nginx/apache config is backed up. |
coexist |
Another edge proxy keeps TLS and forwards to Ploydok on local ports. |
bootstrap-http |
Temporary first setup over HTTP from a controlled VPS security group. |
abort |
Preflight only. Prints what would happen and exits. |
Useful flags:
--unattended
--manage-firewall
--public-host=example.com
--public-scheme=https
--public-port=443
--http-port=8080
--https-port=8443
--install-dir=/opt/ploydok
--data-dir=/var/lib/ploydok
--version=<tag>
--image-registry=<registry>For production, use a real HTTPS domain. Browser passkeys require a secure WebAuthn-compatible origin. Raw HTTP on an IP address is only suitable for temporary bootstrap access.
Run upgrades from the host with the installed CLI:
sudo ploydok-cli upgrade --version=1.2.3Default upgrades roll the control plane and keep the data plane stable.
| Component | During upgrade |
Notes |
|---|---|---|
ploydok-api, ploydok-web, ploydok-agent, ploydok-adminer |
restarted | New images are pulled and applied. |
ploydok-caddy |
not restarted by default | Use --include-data-plane for ingress releases. |
postgres, redis |
not restarted unless image tags change | Patch releases usually leave them alone. |
| User apps | not touched | Runtime app containers keep serving traffic. |
| User databases | not touched | Provisioned databases keep running. |
Safety checks:
- control-plane database snapshot before upgrade;
- compose file backup before upgrade;
- image signature verification;
- readiness check after upgrade;
- rollback to the previous compose file if readiness fails.
Uninstall while preserving data as a tarball:
sudo ploydok-cli uninstall --yesRestore a previous nginx/apache edge proxy as part of uninstall:
sudo ploydok-cli uninstall --yes --restore-previous-proxyRequirements:
- Bun 1.3 or newer
- Node.js 22 or newer for tooling
- Docker
- Rust stable for the agent and host CLI
Install everything in one step (dependencies + secrets + local infra + migrations):
make installOr run the steps individually:
bun install # workspace dependencies
make infra-up # postgres + redis + caddy + buildkitd + registry + agent
make db-migrate # apply database migrationsRun the development servers:
make devLocal ports:
| Service | URL |
|---|---|
| Web | http://localhost:5173 |
| API | http://localhost:3335 |
| Caddy admin | http://127.0.0.1:2020/config/ |
| Local registry | http://127.0.0.1:5000/v2/ |
| Postgres | 127.0.0.1:5434 |
| Redis | 127.0.0.1:6381 |
Useful commands:
bun test
bun run typecheck
bun run lint
bun run check:spdx
bun run db:migrate
bun run db:generateAgent and host CLI:
cd agent
cargo test
cargo build --releaseploydok/
├── apps/
│ ├── web/ # React 19, TanStack Start, TanStack Router
│ └── api/ # Bun, Hono, queues, auth, providers
├── packages/
│ ├── db/ # Drizzle schema and migrations
│ ├── shared/ # shared Zod schemas and domain types
│ ├── ui/ # shared UI components
│ └── agent-proto/ # gRPC contract and generated client types
├── agent/ # Rust agent and host CLI
├── installer/ # VPS installer, systemd and host templates
├── infra/ # local Postgres, Redis, Caddy, registry, BuildKit
└── scripts/ # validation and maintenance scripts
Runtime overview:
Browser
-> Ploydok web
-> Ploydok API
-> Rust agent over mTLS
-> Docker / Docker Swarm
-> App containers, database containers and Caddy routes
Ploydok is designed for production self-hosting, not only local demos.
- Access token: 10 minutes.
- Refresh token: 7 days, rotating.
- Cookies:
HttpOnly,SameSite=Lax,Securewhen public origin is HTTPS. - TOTP and backup codes for second-factor and recovery.
- Passkeys through WebAuthn on secure origins.
- Agent communication protected with mTLS in production TCP mode.
- Secrets encrypted at rest with the configured master key.
- SPDX
AGPL-3.0-onlyheaders enforced in CI. - Responsible disclosure: see SECURITY.md.
Ploydok is relevant for searches around:
- self-hosted PaaS
- open-source PaaS
- Docker PaaS
- Docker Swarm PaaS
- Dokploy alternative
- Coolify alternative
- CapRover alternative
- Heroku alternative
- Railway alternative
- Render alternative
- Vercel alternative
- self-hosted deployment platform
- Git-based deployments
- blue/green deployments
- zero-downtime deploys
- Laravel hosting panel
- Symfony hosting panel
- Next.js self-hosting
- Hono deployment
- VPS app hosting
- Docker app hosting
- self-hosted CI/CD deployment platform
See CONTRIBUTING.md. DCO sign-off is required:
git commit -sPloydok is licensed under AGPL-3.0-only.