Back to all templates
ZITADEL logo

ZITADEL

Development512MB+ RAM

Cloud-native identity management platform

authidentitycloud-native

Deploy ZITADEL in 3 Steps

1

Connect Your VPS

Add your server credentials to Server Compass

2

Select ZITADEL

Choose from our template library

3

Deploy & Configure

Fill in settings and click Deploy

No Docker knowledge required
Step-by-step deployment guide

Deploy ZITADEL on a VPS with Server Compass

Use the ZITADEL template in Server Compass to deploy a self-hosted identity and access management server with Postgres on your VPS, then verify the ZITADEL web UI in a browser.

About 7 minutesBrowser verified
1
Step 1

Open the server Apps tab

Select your VPS, open the Apps tab, and start a new app deployment. Keep sensitive server details hidden before capturing or sharing screenshots.

Server Compass Apps tab before creating a ZITADEL app
2
Step 2

Choose an app template

Click New App and choose the template deployment path so Server Compass can load the built-in catalog.

Choosing to deploy an app from a Server Compass template
3
Step 3

Search for ZITADEL

Use the template picker search to find ZITADEL in the Server Compass template catalog.

Searching for ZITADEL in the Server Compass template picker
4
Step 4

Select the ZITADEL template

Choose the ZITADEL template. Server Compass fills the ZITADEL web service, external URL settings, master key, initial admin password, and Postgres password.

ZITADEL template selected in Server Compass
5
Step 5

Review the ZITADEL settings

Confirm the app name and compose services. In this run, the app was named zitadel-demo and used host port 8080.

Reviewing ZITADEL project settings and compose services
6
Step 6

Deploy ZITADEL

Review the generated environment values, confirm the external domain and port match the public URL, and click Deploy Now.

Reviewing ZITADEL environment variables and port before deployment
7
Step 7

Watch the deployment progress

Keep the deployment modal open while Server Compass uploads the compose file, pulls the ZITADEL image, starts the container, and verifies the stack.

Server Compass deploying the ZITADEL template on the VPS
8
Step 8

Confirm ZITADEL is running

After deployment finishes, return to the Apps tab and confirm the ZITADEL app is marked Running with its application URL available.

ZITADEL template running in the Server Compass Apps tab
9
Step 9

Open ZITADEL in the browser

Open the application URL in a browser. The ZITADEL web UI confirms the stack is reachable.

The deployed ZITADEL web UI loaded in a browser

After ZITADEL Opens

  • Sign in with the initial admin account and rotate the password before production use.
  • Configure HTTPS, organizations, projects, applications, identity providers, SMTP, and production mode before exposing ZITADEL to users.
  • Add a domain and HTTPS before exposing ZITADEL to users.
  • Back up the ZITADEL Postgres volume before relying on it for production identity data.

Verified Result

The ZITADEL web UI loaded successfully in a browser.

ZITADEL deployment questions

What does the ZITADEL template deploy?

It deploys ZITADEL with a Postgres database service.

Which port did the tutorial use?

The tutorial verified ZITADEL on host port 8080, which maps to the ZITADEL web service on container port 8080.

Why does the guide stop at the first-run web UI?

The tutorial verifies the clean ZITADEL web UI because organizations, projects, applications, users, and identity providers depend on the production server.

Should this become a blog post?

No. The deployment guide should live on the ZITADEL template detail page and be linked from the reusable template deployment docs page.

DIY Deployment

Self-Host ZITADEL with Docker

Take the DIY route and deploy ZITADEL on your own server using Docker.

1

Connect to Your VPS via SSH

Fire up your terminal application and establish a connection to your remote server.

terminal
# Access your VPS
ssh root@YOUR_SERVER_IP

# With SSH key authentication
ssh -i ~/.ssh/your-private-key root@YOUR_SERVER_IP

First time? Ensure Docker is installed first: curl -fsSL https://get.docker.com | sh

2

Initialize Project Folder

Create a folder to house your Docker Compose configuration.

terminal
# Create and navigate to project directory
mkdir -p ~/apps/zitadel
cd ~/apps/zitadel
3

Create Docker Configuration

Define your services in a docker-compose.yml file:

docker-compose.yml
services:
  zitadel:
    image: ghcr.io/zitadel/zitadel:latest
    command: start-from-init --masterkeyFromEnv --tlsMode disabled
    ports:
      - "8080:8080"
    environment:
      - ZITADEL_MASTERKEY=<your-master-key>
      - ZITADEL_DATABASE_POSTGRES_HOST=db
      - ZITADEL_DATABASE_POSTGRES_PORT=5432
      - ZITADEL_DATABASE_POSTGRES_DATABASE=postgres
      - ZITADEL_DATABASE_POSTGRES_USER_USERNAME=postgres
      - ZITADEL_DATABASE_POSTGRES_USER_PASSWORD=<your-db-password>
      - ZITADEL_DATABASE_POSTGRES_ADMIN_USERNAME=postgres
      - ZITADEL_DATABASE_POSTGRES_ADMIN_PASSWORD=<your-db-password>
      - ZITADEL_DATABASE_POSTGRES_USER_SSL_MODE=disable
      - ZITADEL_EXTERNALSECURE=false
      - ZITADEL_FIRSTINSTANCE_ORG_HUMAN_USERNAME=admin
      - ZITADEL_FIRSTINSTANCE_ORG_HUMAN_PASSWORD=<your-admin-password>
    restart: unless-stopped
    depends_on:
      db:
        condition: service_healthy

  db:
    image: postgres:16-alpine
    environment:
      - POSTGRES_USER=postgres
      - POSTGRES_PASSWORD=<your-db-password>
      - POSTGRES_DB=postgres
    volumes:
      - postgres_data:/var/lib/postgresql/data
    restart: unless-stopped
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U postgres"]
      interval: 10s
      timeout: 5s
      retries: 5

volumes:
  postgres_data:
Configurable Options
PORTHost port(default: 8080)
MASTER_KEYMaster key
ADMIN_PASSWORDAdmin password
DB_PASSWORDDB password
4

Execute the Deployment

Start your containers and verify they're running correctly.

terminal
# Launch the stack
docker compose up -d

# Verify container status
docker compose ps

# Follow the logs
docker compose logs --follow
5

Allow Network Access

Update UFW rules to allow traffic on the application port.

terminal
# Allow the application port through firewall
sudo ufw allow 8080/tcp
sudo ufw reload

# Access your app at:
# http://your-server-ip:8080
Skip the Terminal

Don't want to type commands? We've got you.

Forget SSH and YAML files. Deploy ZITADEL visually with Server Compass in just a few clicks.

  • No terminal required
  • Point-and-click setup
  • Auto SSL certificates
  • Rolling deployments
  • Health monitoring
  • Instant rollbacks
Download Server Compass$29 one-time • Lifetime license

After Deployment

After deploying ZITADEL with Server Compass, complete these steps to finish setup

1

Login with admin credentials

2

Create organization

3

Configure identity providers

Need help? Check out our documentation for detailed guides.

ZITADEL FAQ

Common questions about self-hosting ZITADEL

How do I deploy ZITADEL with Server Compass?

Simply download Server Compass, connect to your VPS, and select ZITADEL from the templates list. Fill in the required configuration and click Deploy. The entire process takes under 3 minutes.

What are the system requirements for ZITADEL?

ZITADEL requires a minimum of 512MB RAM. We recommend a VPS with at least 1024MB RAM for optimal performance. Any modern Linux server with Docker support will work.

Can I migrate my existing ZITADEL data?

Yes! Server Compass provides volume mapping that allows you to import existing data. You can also use standard ZITADEL backup and restore procedures.

How do I update ZITADEL to the latest version?

Server Compass makes updates easy. Simply click the Update button in your deployment dashboard, and the latest ZITADEL image will be pulled and deployed with zero downtime.

Is ZITADEL free to self-host?

ZITADEL is open-source software. You only pay for your VPS hosting (typically $5-20/month) and optionally Server Compass ($29 one-time). No subscription fees or per-seat pricing.

Ready to Self-Host ZITADEL?

Download Server Compass and deploy ZITADEL to your VPS in under 3 minutes. No Docker expertise required.

Download Server Compass