Home
Web Hosting
Domains FAQ
Resources
About Contact Client Portal
Self-Hosting ยท ยท 14 min read

Docker Hosting: Where to Run Containers and How to Do It Safely

ยท 14 min read

Docker hosting is any server or platform where your containers run around the clock. For most projects that means a VPS with Docker Engine installed. You get a fixed monthly price, root access and a server in the country you choose, and every new app is one more entry in a compose file. The other routes, container platforms and managed Kubernetes, trade that control for convenience.

This guide covers the options, how much server you need, a safe setup from a blank VPS to a working HTTPS app, the mistakes that leave servers exposed, and what Docker hosting means for your privacy.

The short version

For a handful of containers, rent a VPS that is a full virtual machine, install Docker Engine from Docker's own repository, turn on log rotation, and put a reverse proxy such as Caddy in front for HTTPS. Publish no other ports: published ports listen on every network interface by default, and Docker routes their traffic around UFW, so every port you publish is open to the internet whatever UFW says.

What Docker hosting means

Docker packages an app with everything it needs into an image, and runs that image as a container. Docker hosting is simply where those containers live. There are four common ways to do it, and they differ mostly in who looks after the machine underneath.

Option You look after Billing Best for
VPS with Docker Engine The operating system, Docker, updates and backups Fixed monthly price A handful of services with steady traffic, full control, a location you choose
Container platform Your image and its settings; the platform runs the servers Usage-based Apps with spiky traffic, teams that never want to touch a server
Managed Kubernetes Cluster configuration and workloads; the provider runs the control plane Nodes plus extras, usage-based Many services across many machines, teams with Kubernetes skills
Dedicated server Everything, on hardware no one else shares Fixed monthly price Heavy workloads or many stacks on one machine

Container platforms are the most hands-off kind of Docker hosting, but the bill moves with usage, and the servers belong to the platform or to the cloud it runs on. Many are built on the large US clouds, which brings their jurisdiction with them; our guide to hosting outside the US explains why the provider matters more than the server's location. If you are weighing a VPS against a whole machine, see VPS hosting vs dedicated hosting.

When a VPS is the best Docker hosting option

A VPS fits when you want

  • One to a dozen services with fairly steady traffic
  • A predictable monthly bill
  • Root access and free choice of software
  • Your data stored in a jurisdiction you picked

Look elsewhere when

  • Traffic swings from nothing to thousands of requests and you only want to pay for what you use
  • You need containers spread across several machines with automatic failover
  • Nobody on the team wants to apply updates or check backups

Not sure what to run yet? Our list of things you can host on a VPS has ideas, and most of them ship as Docker images.

What to look for in a Docker hosting plan

  • A full virtual machine. Docker needs control of kernel features such as namespaces and cgroups. A full virtual machine with its own kernel gives you that. Some budget VPS are themselves containers (OpenVZ or LXC), where Docker may not run at all or needs settings only the provider can change.
  • Root or sudo access. The standard Docker Engine installation in this guide needs it, and it is also why conventional shared hosting cannot run Docker.
  • Enough memory. Memory runs out long before processor power on a small Docker host. The next section has sizes.
  • Disk space for images. Every image you pull stays on disk until you remove it, and old versions pile up after updates.
  • A public IPv4 address. Caddy can get certificates over IPv6 alone, but visitors on IPv4-only networks could not reach you, so a dedicated IPv4 address is still the practical choice for anything public.
  • An acceptable use policy that allows your workload. The rules apply to what runs inside your containers exactly as they would on the host.

How much server you need

Docker Engine itself adds little overhead. What decides your Docker hosting plan is the sum of what you run in it, and databases are usually the hungriest part. Once you are up, docker stats shows each container's live memory use, so you can see how much room is left.

What you run Packetra plan that fits Price per month
A reverse proxy plus one or two light apps, such as an uptime monitor, a static site or a bot Cloud VPS #1: 2 vCPU, 1.5 GB RAM, 25 GB EUR 9.90 Finland, EUR 13.90 Switzerland
A web app with its own database, such as PostgreSQL or MariaDB Cloud VPS #2: 3 vCPU, 3 GB RAM, 40 GB EUR 15.90 Finland, EUR 22.90 Switzerland
Several stacks side by side Cloud VPS #3: 4 vCPU, 4 GB RAM, 60 GB EUR 22.90 Finland, EUR 32.90 Switzerland
Memory-heavy stacks, such as a full mail server like mailcow, which asks for 6 GB plus swap Cloud VPS #4: 5 vCPU, 7 GB RAM, 80 GB EUR 32.90 Finland, EUR 45.90 Switzerland

Start one size smaller if you are unsure and watch docker stats for a week. A small swap file is cheap insurance on the 1.5 GB plan, and our guide to running an email server on a VPS covers the mail stacks in detail.

Setting up Docker hosting on a VPS, step by step

This example takes a fresh Debian VPS to a working app on its own domain with HTTPS. The app is Uptime Kuma, a self-hosted uptime monitor, but the same pattern covers most Docker hosting setups: the app gets no public port, and Caddy, the only container that faces the internet, handles HTTPS in front of it.

1Prepare the server

Log in with SSH keys, apply updates, and turn on the firewall for SSH. UFW still protects services on the host itself, such as SSH, even though it does not police Docker's published ports.

sudo apt update && sudo apt upgrade -y
sudo apt install ufw
sudo ufw allow 22/tcp
sudo ufw enable

2Install Docker Engine from Docker's repository

Use Docker's own repository rather than the distribution's docker.io package, which Docker asks you to remove first if it is installed. These are Docker's commands for Debian 12 and 13; on Ubuntu, follow Docker's Ubuntu page, where only the repository lines differ. Docker's convenience script is meant for testing, not production.

sudo apt install ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/debian/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc

sudo tee /etc/apt/sources.list.d/docker.sources <<EOF
Types: deb
URIs: https://download.docker.com/linux/debian
Suites: $(. /etc/os-release && echo "$VERSION_CODENAME")
Components: stable
Architectures: $(dpkg --print-architecture)
Signed-By: /etc/apt/keyrings/docker.asc
EOF

sudo apt update
sudo apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
sudo docker run hello-world

If the last command prints "Hello from Docker!", the engine works. Docker starts automatically at boot.

3Turn on log rotation before you run anything

Docker's default log driver keeps everything a container prints, with no rotation, which is how small servers run out of disk. The local driver rotates logs automatically and keeps about 100 MB per container. The setting only applies to containers created after the change, so do it now.

echo '{ "log-driver": "local" }' | sudo tee /etc/docker/daemon.json
sudo systemctl restart docker

4Point your domain at the server

Create an A record, and an AAAA record if you use IPv6, for the hostname you want, such as status.example.com, pointing to your VPS. Caddy needs it in place to get a certificate.

5Write the compose file

Create a project folder with mkdir -p ~/status/conf && cd ~/status, then save this as compose.yaml. Only Caddy publishes ports. Uptime Kuma has none, so nothing reaches it except through Caddy.

services:
  caddy:
    image: caddy:2
    restart: unless-stopped
    ports:
      - "80:80"
      - "443:443"
      - "443:443/udp"
    volumes:
      - ./conf:/etc/caddy
      - caddy_data:/data
      - caddy_config:/config

  uptime-kuma:
    image: louislam/uptime-kuma:2
    restart: unless-stopped
    volumes:
      - ./data:/app/data

volumes:
  caddy_data:
  caddy_config:

6Tell Caddy where to send traffic

Save this as conf/Caddyfile, with your own hostname. Containers in the same compose file reach each other by service name, so Caddy finds the app at uptime-kuma:3001.

status.example.com {
	reverse_proxy uptime-kuma:3001
}

7Start it and check

sudo docker compose up -d
sudo docker compose ps
sudo docker compose logs caddy

Once your DNS record resolves to the server and ports 80 and 443 are reachable, Caddy gets a certificate on its own and https://status.example.com loads. The unless-stopped restart policy brings both containers back after a crash or a reboot, unless you stopped them yourself.

8Keep it updated

Run this in the project folder every week or two. It pulls newer images, recreates only the containers that changed, and removes the old untagged images left behind. Your regular apt upgrade keeps Docker Engine itself current.

sudo docker compose pull
sudo docker compose up -d
sudo docker image prune -f

9Back up the project folder

Because Uptime Kuma's data lives in ./data, one archive of the folder holds the app's data, the compose file and the Caddyfile together. Caddy's certificates sit in the caddy_data volume and are not included, which is fine: after a restore, Caddy requests new ones. Stop the stack briefly so nothing is written mid-copy, then copy the archive off the server. For a database container, use the database's own dump tool instead of copying its files while it runs.

cd ~/status
sudo docker compose stop
sudo tar czf ~/status-backup-$(date +%F).tar.gz -C ~ status
sudo docker compose start

Five Docker hosting mistakes that expose your server

1. Trusting UFW to block Docker-published ports

Docker's installation guide says it plainly: if you use ufw or firewalld, ports you publish bypass your firewall rules, because Docker routes container traffic before those rules are checked. Published ports also listen on every interface by default, and plenty of example compose files publish an admin port such as "3001:3001". Publish only your reverse proxy, and bind anything else to the server itself with "127.0.0.1:3001:3001".

2. Treating the docker group as harmless

Adding your user to the docker group saves typing sudo, but Docker's own docs warn that the group grants root-level privileges. Anyone who can control the Docker daemon can mount the host's files into a container. If you want Docker without root, use rootless mode instead.

3. Opening the Docker API to the network

By default the daemon listens only on a local socket. To manage the server from your laptop, use SSH, which the Docker CLI supports directly, for example docker context create --docker host=ssh://user@your-server myvps. Never expose the API port to the internet.

4. Letting logs and images fill the disk

Without log rotation, a chatty container can fill a 25 GB disk on its own, and old images pile up after every update. Set the local log driver on day one, prune images after updates, and check usage with docker system df.

5. Keeping data inside the container

Anything written inside a container disappears when the container is removed, and an update removes it. Keep every piece of data you care about in a volume or a mounted folder, and test a restore before you need one.

Docker hosting and privacy

Containers do not change who can reach your data. Your volumes sit on the host's disks, so the provider's jurisdiction and the server's location decide which legal demands can reach them. Our Hosting Jurisdiction Index compares 14 countries on exactly that, and Finland vs Switzerland goes deeper on the two we host in. A few Docker-specific points are worth knowing too:

  • The registry sees your server. Docker Hub counts anonymous pulls per IP address, 100 every 6 hours for each IPv4 address or IPv6 /64, and ties pulls to your account once you log in, where free accounts get 200.
  • Images are other people's code. Prefer official images and those published by the project itself, and pin major versions such as caddy:2 so an update cannot jump to a new major release unannounced.
  • Secrets live on disk. Passwords in a compose file or an .env file are readable by anyone with root on the server. Keep the project folder private and never bake secrets into an image.
  • Backups leave the server. Encrypt archives before they go to another provider, so the backup host holds nothing readable.

Docker hosting at Packetra

Our Cloud VPS plans are full KVM virtual machines with their own kernel and full root access, the same as on a dedicated server. Our own BTCPay Server runs in Docker on this platform, and Docker Engine installs and runs exactly as in the guide above, from Docker's own repository, with you in control of the version. Every plan has a dedicated IPv4 address, optional IPv6, DDoS protection on IPv4, a 1 Gbit/s unmetered connection (or 10 Gbit/s with a monthly traffic allowance on the 10G plans) and 24/7 support from the team that runs the servers. You choose Finland or Switzerland, sign up with just an email address, and can pay with Bitcoin or Monero.

Three things to know before you deploy. Outbound port 25 is closed by default, so an app that sends email should use a mail provider's SMTP server, or ask us to open the port on Cloud VPS #2 and above, or on #1 with a longer billing cycle. Our acceptable use policy applies to what runs inside your containers: torrent clients, for example, are not permitted on Finland servers, while Switzerland allows them. And this is self-managed Docker hosting: we look after the hardware and network, and you look after the containers.

FAQ

What is Docker hosting?

A server or platform that runs your Docker containers continuously. It can be a VPS or dedicated server where you install Docker yourself, a container platform that runs your images for you, or a managed Kubernetes cluster.

Is Docker free to use on a server?

Yes. Docker Engine, which is what runs on a Linux server, is open source under the Apache 2.0 licence. Docker Desktop is a separate product for Windows, macOS and Linux desktops. It is free for personal use, education, non-commercial open source projects and small businesses with fewer than 250 employees and under USD 10 million in annual revenue; larger organisations and government entities need a paid subscription.

Can I run Docker on shared hosting?

Not on conventional shared hosting. Running Docker means installing and controlling your own Docker daemon, which shared hosting does not allow. For Docker hosting you need a VPS that is a full virtual machine, a dedicated server, or a platform built to run containers.

How much RAM do I need for Docker?

Docker itself uses little. Add up what your containers need: 1.5 GB handles a reverse proxy and a couple of light apps, 3 GB suits an app with a database, and memory-heavy stacks such as mailcow need 6 GB or more.

Do I need Kubernetes?

Not for a handful of services on one server. Docker Compose runs a multi-container app from a single file. Kubernetes earns its complexity when you run many services across many machines and need automatic scheduling and failover.

Why can people reach a container port I blocked in UFW?

Because Docker routes published ports before UFW's rules apply. Remove the port from the compose file, or bind it to 127.0.0.1, and put a reverse proxy in front for anything that should be public.

Sources

Last reviewed: 7 October 2026

Research note: Commands are taken from Docker's official installation guide for Debian at the time of review. The compose file and Caddyfile were checked with docker compose config and caddy validate. Docker Hub limits and Docker Desktop licence terms change from time to time, so check the linked pages for current figures.

Need Reliable Hosting?

Privacy-focused, anonymous, and built for people who value their data.