Self-hosting Penpot: a Docker Compose guide for design teams
A new guide details how to deploy the open-source design platform Penpot using Docker Compose, Traefik, and PostgreSQL on a Linux server.
Sanskriti Harmukh and Aashish Chaurasiya published a detailed deployment guide for Penpot on September 30, 2026. The article outlines how to run this open-source design and prototyping platform on a private Linux server using Docker Compose, providing an alternative to cloud-based design tools.
What happened
The guide provides a step-by-step procedure for setting up Penpot in a self-hosted environment. It relies on a stack of six containerized services that work together to deliver the full application experience. The architecture includes a frontend for the user interface, a backend for application logic, an exporter for rendering assets, a PostgreSQL database for persistent storage, a Valkey instance for transient state, and Traefik for handling reverse proxying and TLS termination.
The authors emphasize the use of open web standards, noting that Penpot stores files in SVG format to keep design and code in sync. The deployment process is designed to be reproducible, using a docker-compose.yml file to define the services. The guide also covers post-deployment configuration, such as creating the first administrative account and verifying that the HTTPS certificate has been provisioned correctly by Let's Encrypt.
Key details
- The deployment uses PostgreSQL 15 for data storage and Valkey 8.1 for websocket notifications and transient state management.
- Traefik handles reverse proxying and automatically provisions Let's Encrypt certificates over ports 80 and 443.
- The
penpot-exporterservice is responsible for rendering design boards and files into PNG, SVG, and PDF formats. - Email verification is disabled in the default configuration, allowing the first account to become active immediately after registration.
- Team invitations require SMTP configuration; without it, invitation emails are not sent to collaborators.
- The guide validates the setup by walking through an end-to-end workflow, including creating teams, designing screens, and linking prototypes.
Background
Penpot is an open-source alternative to proprietary design tools like Figma or Sketch. It is built for designers, developers, and product teams who want to maintain control over their design data. By running entirely in the browser and using SVG as its native file format, it aims to reduce the friction between design and development phases. Self-hosting such a platform allows organizations to keep sensitive design intellectual property on their own infrastructure rather than relying on third-party cloud providers.
Docker Compose is a tool for defining and running multi-container Docker applications. In this context, it orchestrates the various microservices that make up Penpot. Traefik is a modern HTTP reverse proxy and load balancer that makes deploying microservices easy. It integrates with existing infrastructure components and configures itself dynamically and automatically. Valkey is an open-source, high-performance key-value store, often used as a drop-in replacement for Redis, handling real-time updates and session data in this stack.
Why it matters
For IT leads and DevOps engineers at small and mid-sized companies, this guide offers a clear path to internalizing design tooling. Many organizations are increasingly cautious about storing proprietary product designs on external SaaS platforms due to compliance requirements or data sovereignty concerns. By providing a tested Docker Compose configuration, the authors lower the barrier to entry for teams that want to migrate away from subscription-based cloud design tools.
The use of standard components like PostgreSQL and Traefik means that sysadmins can leverage existing monitoring and backup strategies. Since the database is exposed as a standard PostgreSQL 15 instance, it can be backed up using familiar tools. The separation of concerns between the frontend, backend, and exporter also allows for easier troubleshooting and potential scaling of specific components if the design team grows.
However, self-hosting introduces operational responsibilities. The guide notes that SMTP configuration is necessary for collaborative features like team invitations. Without a properly configured mail server, the administrative overhead increases as admins must manually manage user access. Additionally, managing TLS certificates and ensuring the health of the Valkey and PostgreSQL containers requires ongoing attention from the infrastructure team.
What you can do
- Review the Docker Compose file to understand the resource requirements for each of the six services before provisioning your server.
- Configure a reliable SMTP provider in the environment variables to enable email invitations and password resets for your team.
- Set up automated backups for the PostgreSQL volume and the
penpot_assetsvolume to prevent data loss. - Test the end-to-end workflow by creating a test team, importing a simple SVG, and verifying that the exporter generates PDFs correctly.
- Monitor the health checks for
penpot-postgresandpenpot-valkeyto ensure the backend starts only when dependencies are ready. - Consider integrating Penpot with your existing identity provider if you need more robust access control than the built-in email authentication.



