Skip to content

Deployer

Deployer turns "I want this Docker app on its own subdomain, behind single sign-on, with HTTPS" into one guided form. Pick a name and an image, adjust the Docker Compose file and the nginx site if you want, choose who may open the app, and deploy. Deployer creates the DNS record, the stack folder, the containers, the nginx site, the Let's Encrypt certificate and the Authentik application, checks that everything answers, and undoes every step it made if anything fails.

It is a single Go binary with an embedded SvelteKit interface, made for one self-hosted Linux server that already runs Docker, nginx, certbot and (optionally) Authentik.

What it does

Area What you get
Apps A curated catalog (about 30 tested apps), Docker Hub search with stars, pulls, tags and architectures, or any image reference.
Docker Compose A generated, conventional compose file. Edit it in a simple form or in a full code editor; switch between both at any time. Every file is linted against server rules (no host network, no public ports, no Docker socket without confirmation…).
nginx A generated site with HTTPS, HSTS, websockets, upload size, timeouts, buffering. Simple form or raw editor; every candidate is tested with an isolated nginx -t before it touches the live configuration.
DNS + HTTPS The A record is created through the DNS provider API, propagation is awaited on the authoritative name server, then certbot issues the certificate.
Access Authentik SSO with a smart group picker, the app's own login, or public.
Account in the app The best single sign-on each image supports: OpenID Connect, SAML, a trusted username header, login turned off, HTTP Basic injection or auto-login with a shared account, chosen from evidence (tested recipes, documentation, Authentik's integration guides, the image itself).
Safety Every operation is a run with a live log; each step registers its undo; failures roll back. Updates back up the previous files and restore them if the app does not come back healthy.
Operations Start, stop, restart, logs, file view, run history, change groups, change the account method, update compose or nginx, delete with fine-grained options (keep or remove data, DNS, certificate, images, archives).
People Local accounts with Argon2id passwords and TOTP, or sign-in to Deployer itself with OIDC; roles admin, editor, viewer; full audit log.

How it fits on a server

flowchart LR
    U[Browser] -->|HTTPS| N[nginx]
    N -->|127.0.0.1:8150| D[Deployer<br/>Go + embedded UI]
    D --> P[(PostgreSQL<br/>deployer-db)]
    D -->|docker compose| S[/srv/stacks/&lt;app&gt;/]
    D -->|vhosts, nginx -t, reload| N
    D -->|certbot| C[Let's Encrypt]
    D -->|REST| DNS[DNS provider API]
    D -->|REST| A[Authentik]
    N -->|forward auth| A
    N -->|127.0.0.1:port| APP[App containers]

Deployer runs on the host (it needs to write nginx sites, run docker compose, nginx -t and certbot), listens on loopback only and is published by nginx like any other app.

Where to go next