Open the server Apps tab
Select your VPS, open the Apps tab, and start a new app deployment. Keep sensitive server details hidden before capturing or sharing screenshots.


Modern identity provider with advanced features
Add your server credentials to Server Compass
Choose from our template library
Fill in settings and click Deploy
Use the Authentik template in Server Compass to deploy a self-hosted identity and access management server with Postgres on your VPS, then verify the Authentik web UI in a browser.
Select your VPS, open the Apps tab, and start a new app deployment. Keep sensitive server details hidden before capturing or sharing screenshots.

Click New App and choose the template deployment path so Server Compass can load the built-in catalog.

Use the template picker search to find Authentik in the Server Compass template catalog.

Choose the Authentik template. Server Compass fills the Authentik web service, HTTPS port, secret key, and Postgres password.

Confirm the app name and compose services. In this run, the app was named authentik-demo and used host port 9000.

Review the generated environment values, confirm the port is available, and click Deploy Now.

Keep the deployment modal open while Server Compass uploads the compose file, pulls the Authentik image, starts the container, and verifies the stack.

After deployment finishes, return to the Apps tab and confirm the Authentik app is marked Running with its application URL available.

Open the application URL in a browser. The Authentik web UI confirms the stack is reachable.

It deploys Authentik with a Postgres database service.
The tutorial verified Authentik on host port 9000, which maps to the Authentik web service on container port 9000.
The tutorial verifies the clean Authentik initial setup web UI because applications, providers, users, groups, and outposts depend on the production server.
No. The deployment guide should live on the Authentik template detail page and be linked from the reusable template deployment docs page.
Get your hands dirty: manual Authentik deployment guide for developers.
Fire up your terminal application and establish a connection to your remote server.
# Access your VPS
ssh root@YOUR_SERVER_IP
# With SSH key authentication
ssh -i ~/.ssh/your-private-key root@YOUR_SERVER_IPFirst time? Ensure Docker is installed first: curl -fsSL https://get.docker.com | sh
Create a folder to house your Docker Compose configuration.
# Create and navigate to project directory
mkdir -p ~/apps/authentik
cd ~/apps/authentikDefine your services in a docker-compose.yml file:
services:
authentik:
image: ghcr.io/goauthentik/server:latest
ports:
- "9000:9000"
- "9443:9443"
environment:
- AUTHENTIK_SECRET_KEY=<your-secret-key>
- AUTHENTIK_REDIS__HOST=redis
- AUTHENTIK_POSTGRESQL__HOST=db
- AUTHENTIK_POSTGRESQL__USER=authentik
- AUTHENTIK_POSTGRESQL__NAME=authentik
- AUTHENTIK_POSTGRESQL__PASSWORD=<your-db-password>
command: server
volumes:
- authentik_media:/media
- authentik_templates:/templates
restart: unless-stopped
depends_on:
- db
- redis
worker:
image: ghcr.io/goauthentik/server:latest
command: worker
environment:
- AUTHENTIK_SECRET_KEY=<your-secret-key>
- AUTHENTIK_REDIS__HOST=redis
- AUTHENTIK_POSTGRESQL__HOST=db
- AUTHENTIK_POSTGRESQL__USER=authentik
- AUTHENTIK_POSTGRESQL__NAME=authentik
- AUTHENTIK_POSTGRESQL__PASSWORD=<your-db-password>
volumes:
- authentik_media:/media
- authentik_templates:/templates
restart: unless-stopped
depends_on:
- db
- redis
db:
image: postgres:16-alpine
environment:
- POSTGRES_USER=authentik
- POSTGRES_PASSWORD=<your-db-password>
- POSTGRES_DB=authentik
volumes:
- postgres_data:/var/lib/postgresql/data
restart: unless-stopped
redis:
image: redis:7-alpine
restart: unless-stopped
volumes:
authentik_media:
authentik_templates:
postgres_data:
PORTHTTP port(default: 9000)HTTPS_PORTHTTPS port(default: 9443)SECRET_KEYSecret keyDB_PASSWORDDB passwordStart your containers and verify they're running correctly.
# Launch the stack
docker compose up -d
# Verify container status
docker compose ps
# Follow the logs
docker compose logs --followUpdate UFW rules to allow traffic on the application port.
# Allow the application port through firewall
sudo ufw allow 9000/tcp
sudo ufw reload
# Access your app at:
# http://your-server-ip:9000Why type commands when you can click? Deploy Authentik the easy way with Server Compass.
After deploying Authentik with Server Compass, complete these steps to finish setup
Complete initial setup wizard
Create applications and providers
Need help? Check out our documentation for detailed guides.
Common questions about self-hosting Authentik
Simply download Server Compass, connect to your VPS, and select Authentik from the templates list. Fill in the required configuration and click Deploy. The entire process takes under 3 minutes.
Authentik requires a minimum of 1024MB RAM. We recommend a VPS with at least 2048MB RAM for optimal performance. Any modern Linux server with Docker support will work.
Yes! Server Compass provides volume mapping that allows you to import existing data. You can also use standard Authentik backup and restore procedures.
Server Compass makes updates easy. Simply click the Update button in your deployment dashboard, and the latest Authentik image will be pulled and deployed with zero downtime.
Authentik is open-source software. You only pay for your VPS hosting (typically $5-20/month) and optionally Server Compass ($29 one-time). No subscription fees or per-seat pricing.

Open-source backend in a single file with realtime database, auth, and file storage

Open-source backend-as-a-service - self-hosted Firebase alternative

Open-source backend framework with dashboard

Full Supabase self-hosted with Kong, GoTrue Auth, Realtime, and Studio
Download Server Compass and deploy Authentik to your VPS in under 3 minutes. No Docker expertise required.
Download Server Compass