Custom Infrastructure

Use this page for NocoDB deployments that the single-server installation wizard does not cover. These include managed databases, custom SSL certificates, private CAs, your own reverse proxy, multi-replica setups and Kubernetes.

Before you begin

NocoDB works with all actively maintained PostgreSQL releases (12 and later). Use the version that your managed provider offers. We recommend a current major version.

When to use this page

Use this page if one of these is true:

  • You use a managed Postgres (RDS, Azure, Cloud SQL) with public CA SSL.
  • You use a self-managed Postgres with a private or internal CA.
  • You already have a TLS certificate and want to pin it through Traefik.
  • You have nginx, Caddy or a load balancer in front, and want NocoDB on port 8080.
  • You deploy to Kubernetes and want a reference compose file to translate.

Option A: Clone the repo and run the wizard interactively

git clone https://github.com/nocodb/nocodb.git
cd nocodb/docker-compose
./setup.sh

setup.sh runs the same installation wizard as the Single-server install one-liner. It writes its output into the current working directory. Use this option to edit the generated files before you start the stack.

Option B: Copy a pre-built example

The docker-compose/examples/ directory contains a set of selected configurations.

ExamplePostgresRedisProxyBest for
quickstart-demoBundledBundledNone (port 8080)Local eval / "show me NocoDB"
managed-postgresExternal managed (RDS/Azure/Cloud SQL)ExternalNone (port 8080)Production behind your own LB
external-postgres-and-redisExternal self-managedExternalNone (port 8080)Minimal Docker footprint
traefik-custom-sslExternal managedExternalTraefik + custom TLS certProduction with your own SSL cert
postgres-private-caExternal (private CA)ExternalTraefik + Let's EncryptOn-prem / private cloud DB

To start quickly with an example:

git clone --depth 1 https://github.com/nocodb/nocodb.git
cp -r nocodb/docker-compose/examples/managed-postgres ./my-deployment
cd my-deployment
# Edit docker-compose.yml, docker.env, and nocodb/db.json: replace placeholders
docker compose up -d

Configuring SSL for an external Postgres with a private CA

SSL for an external Postgres with a private CA is the most complex external database setup. NocoDB reads its database connection from nocodb/db.json (knex format). In this file, you can put a CA certificate inline:

{
  "client": "pg",
  "connection": {
    "host": "your-private-db-host.internal",
    "port": "5432",
    "user": "nocodb",
    "password": "your-password",
    "database": "nocodb",
    "ssl": {
      "rejectUnauthorized": true,
      "ca": "-----BEGIN CERTIFICATE-----\nMIID...\n-----END CERTIFICATE-----"
    }
  }
}

The CA must be one string, with newlines escaped as \n. The postgres-private-ca example shows the full layout, with a Traefik proxy.

To change a multi-line PEM into the single-line JSON form, run:

awk 'NF {sub(/\r/, ""); printf "%s\\n", $0}' your-ca.pem

Multi-replica / scaling

NocoDB scales horizontally when you configure Redis. Redis is necessary for distributed coordination:

# In docker-compose.yml
nocodb:
  deploy:
    mode: replicated
    replicas: 3

For more than a few replicas, run NocoDB in Kubernetes. Translate one of the examples into a Deployment + Service + Ingress. Point the same env vars at managed Postgres and Redis.

Bringing your own reverse proxy

The managed-postgres and external-postgres-and-redis examples expose NocoDB on host port 8080, without Traefik.

  1. Put your own nginx, Caddy or load balancer in front.
  2. Forward HTTP traffic to port 8080.
  3. Forward the X-Forwarded-Proto and Host headers. NocoDB needs them to make correct callback URLs.

Last updated on

Latest product updates?See Changelog
Stay in the loop? Follow us onLinkedInLinkedInYouTubeYouTubeXX