Single-Server Install

One command runs NocoDB with Postgres + Redis. It also sets up Traefik with automatic Let's Encrypt SSL and gives you a working HTTPS endpoint.

All parts run on one server: app, database, cache and proxy. For a managed database, multiple app replicas or Kubernetes, refer to Custom infrastructure.

Before you begin

You need Docker with the Compose v2 plugin, on a host where ports 80 and 443 are reachable. For production, we recommend a Linux server. macOS and Windows (Git Bash or WSL) also work. If you use a real domain, point its DNS A record at the public IP of this host before you run the installer.

If you only want to try NocoDB locally on Mac or Windows, the Quickstart is simpler. This installer also runs there. But its HTTPS setup needs a host that is reachable at your domain on ports 80 and 443.

1. Run

curl -fsSL https://install.nocodb.com/noco.sh | bash

2. Answer 3–4 prompts

PromptWhat to enterNotes
Domainnocodb.example.comMust resolve to this server. Blank or localhost gives local mode (port 8080). A bare IP serves plaintext HTTP on port 80. Both skip SSL.
Postgres1 (Bundled) or 2 (Existing)Bundled is the usual choice. Select Existing to use a managed database (RDS, Cloud SQL and others).
Redis1 (Bundled) or 2 (Existing)The same as Postgres.
Let's Encrypt emailops@example.comThe installer asks for it only if you entered a real domain. Let's Encrypt uses it for SSL certificate renewal notifications.

After you confirm the summary, the installer writes all files into nocodb/. Then it pulls the images and starts the stack. The first run can take a few minutes.

3. Open NocoDB

  1. Open https://your-domain.
  2. Sign up with an email and password. The first user becomes super admin.

What the script generates

./nocodb/
├── docker-compose.yml      # Service orchestration
├── docker.env              # Environment variables
├── .gitignore              # Keeps secrets and runtime data out of version control
├── nocodb/
│   └── db.json             # Database connection (knex format, supports custom CA)
├── update.sh               # docker compose pull && up -d && image prune
└── letsencrypt/            # Traefik ACME storage (production with a real domain)

Docker keeps the Postgres, Redis and NocoDB application data (with attachments) in named volumes, not in this directory. To see them, run docker volume ls. The volumes stay after docker compose down.

Reviewing the script before running

To read the script before you pipe it to bash:

curl -fsSL https://install.nocodb.com/noco.sh -o noco.sh
less noco.sh
bash noco.sh

The script source is in the nocodb/nocodb GitHub repo.

Non-interactive install

Use this for automation (CI, IaC, configuration management):

curl -fsSL https://install.nocodb.com/noco.sh | bash -s -- \
  --domain=nocodb.example.com \
  --acme-email=ops@example.com \
  --pg=bundled --redis=bundled

This is the full flag list:

FlagValuesNotes
--quickBundled Postgres + Redis, local mode (port 8080). For production HTTPS, add --domain=.
--domain=hostname or IPBlank or localhost gives local mode (port 8080). A bare IP serves plaintext HTTP on port 80 (no SSL).
--acme-email=emailRequired for production with a valid domain.
--image-tag=image tagPin nocodb/nocodb to a version. Default: latest.
--pg=bundled or external
--pg-host=, --pg-port=, --pg-database=, --pg-user=, --pg-password=When --pg=external.
--pg-ssl=managed, none, or /path/to/ca.pemWhen --pg=external.
--redis=bundled or external
--redis-url=redis://...When --redis=external.

For the official list, run bash noco.sh --help.

Updating

cd nocodb
./update.sh

This script pulls the latest images, restarts the containers and removes old image layers.

Common operations

cd nocodb

# Tail logs
docker compose logs -f nocodb

# Restart NocoDB only (keeps DB and Redis up)
docker compose restart nocodb worker

# Stop everything
docker compose down

# Reconfigure: re-run the wizard (overwrites docker-compose.yml after confirmation, then restarts)
curl -fsSL https://install.nocodb.com/noco.sh | bash

If the stack does not start, or you cannot reach NocoDB, refer to Troubleshooting.

Bringing your own reverse proxy or SSL

If you already have nginx, Caddy or a load balancer in front:

  1. Run the installer with a blank domain (local mode). NocoDB then listens on port 8080.
  2. Forward the X-Forwarded-Proto and Host headers from your proxy. NocoDB needs them to make correct callback URLs.

For more control, refer to Custom infrastructure.

Production hardening checklist

When the stack runs and you can sign in, do this checklist before you open it to real traffic:

  • Firewall. Allow only the ports that you need (22 for SSH, 80+443 for HTTPS). On Ubuntu/Debian: sudo ufw allow OpenSSH && sudo ufw allow 80,443/tcp && sudo ufw enable. On RHEL family: firewall-cmd --add-service=ssh --add-service=http --add-service=https --permanent && firewall-cmd --reload.
  • Verify secret-file permissions. The installer already sets docker.env and nocodb/db.json to 600. If you copied or edited them by hand, set the permissions again:
    cd nocodb
    chmod 600 docker.env nocodb/db.json
  • SELinux (RHEL, Rocky, Alma, Fedora). Docker relabels named volumes automatically, so the data volumes need no action. The other bind mounts are the config files and the letsencrypt/ directory. If SELinux is in Enforcing mode (getenforce) and it denies these mounts, add the :Z suffix to their entries in docker-compose.yml (for example, ./letsencrypt:/letsencrypt:Z).
  • License activation outbound. NocoDB calls https://app.nocodb.com/api/v1/on-premise/agent over TCP 443 every 6 hours. If you filter egress by host or path, allowlist exactly that URL. For fully offline servers, refer to Airgapped license.
  • Log rotation. By default, the Docker json-file log driver has no size limit. Add a global limit in /etc/docker/daemon.json:
    {
      "log-driver": "json-file",
      "log-opts": { "max-size": "10m", "max-file": "5" }
    }
    To apply the change, restart Docker (sudo systemctl restart docker).
  • systemd unit (optional but recommended). The default Compose stack restarts the containers when the Docker daemon restarts. A systemd unit also makes the deployment a managed service. Create /etc/systemd/system/nocodb.service:
    [Unit]
    Description=NocoDB
    Requires=docker.service
    After=docker.service network-online.target
    
    [Service]
    Type=oneshot
    RemainAfterExit=yes
    WorkingDirectory=/path/to/nocodb
    ExecStart=/usr/bin/docker compose up -d
    ExecStop=/usr/bin/docker compose down
    
    [Install]
    WantedBy=multi-user.target
    To enable it, run sudo systemctl daemon-reload && sudo systemctl enable --now nocodb.service.
  • Healthcheck endpoint. NocoDB exposes GET /api/v1/health. Connect it to your monitoring system.
  • Pin your image tags for production. Do not track latest. Refer to Pinning to a specific version.
  • Schedule backups. Refer to Backups. At minimum, make a daily pg_dump and an attachment tarball.

Activating an enterprise license

When NocoDB runs:

  1. Sign up as the first user.
  2. Go to Admin Panel → License.
  3. Paste your key.

For the full procedure, refer to Purchase a license and License activation.

Last updated on

Latest product updates?See Changelog
Stay in the loop? Follow us onLinkedInLinkedInYouTubeYouTubeXX