One command runs NocoDB with Postgres + Redis. It also sets up Traefik with automatic Let's Encrypt SSL and gives you a working HTTPS endpoint.
All parts run on one server: app, database, cache and proxy. For a managed database, multiple app replicas or Kubernetes, refer to Custom infrastructure.
You need Docker with the Compose v2 plugin, on a host where ports 80 and 443 are reachable. For production, we recommend a Linux server. macOS and Windows (Git Bash or WSL) also work. If you use a real domain, point its DNS A record at the public IP of this host before you run the installer.
If you only want to try NocoDB locally on Mac or Windows, the Quickstart is simpler. This installer also runs there. But its HTTPS setup needs a host that is reachable at your domain on ports 80 and 443.
Must resolve to this server. Blank or localhost gives local mode (port 8080). A bare IP serves plaintext HTTP on port 80. Both skip SSL.
Postgres
1 (Bundled) or 2 (Existing)
Bundled is the usual choice. Select Existing to use a managed database (RDS, Cloud SQL and others).
Redis
1 (Bundled) or 2 (Existing)
The same as Postgres.
Let's Encrypt email
ops@example.com
The installer asks for it only if you entered a real domain. Let's Encrypt uses it for SSL certificate renewal notifications.
After you confirm the summary, the installer writes all files into nocodb/. Then it pulls the images and starts the stack. The first run can take a few minutes.
./nocodb/├── docker-compose.yml # Service orchestration├── docker.env # Environment variables├── .gitignore # Keeps secrets and runtime data out of version control├── nocodb/│ └── db.json # Database connection (knex format, supports custom CA)├── update.sh # docker compose pull && up -d && image prune└── letsencrypt/ # Traefik ACME storage (production with a real domain)
Docker keeps the Postgres, Redis and NocoDB application data (with attachments) in named volumes, not in this directory. To see them, run docker volume ls. The volumes stay after docker compose down.
When the stack runs and you can sign in, do this checklist before you open it to real traffic:
Firewall. Allow only the ports that you need (22 for SSH, 80+443 for HTTPS). On Ubuntu/Debian: sudo ufw allow OpenSSH && sudo ufw allow 80,443/tcp && sudo ufw enable. On RHEL family: firewall-cmd --add-service=ssh --add-service=http --add-service=https --permanent && firewall-cmd --reload.
Verify secret-file permissions. The installer already sets docker.env and nocodb/db.json to 600. If you copied or edited them by hand, set the permissions again:
cd nocodbchmod 600 docker.env nocodb/db.json
SELinux (RHEL, Rocky, Alma, Fedora). Docker relabels named volumes automatically, so the data volumes need no action. The other bind mounts are the config files and the letsencrypt/ directory. If SELinux is in Enforcing mode (getenforce) and it denies these mounts, add the :Z suffix to their entries in docker-compose.yml (for example, ./letsencrypt:/letsencrypt:Z).
License activation outbound. NocoDB calls https://app.nocodb.com/api/v1/on-premise/agent over TCP 443 every 6 hours. If you filter egress by host or path, allowlist exactly that URL. For fully offline servers, refer to Airgapped license.
Log rotation. By default, the Docker json-file log driver has no size limit. Add a global limit in /etc/docker/daemon.json:
To apply the change, restart Docker (sudo systemctl restart docker).
systemd unit (optional but recommended). The default Compose stack restarts the containers when the Docker daemon restarts. A systemd unit also makes the deployment a managed service. Create /etc/systemd/system/nocodb.service:
[Unit]Description=NocoDBRequires=docker.serviceAfter=docker.service network-online.target[Service]Type=oneshotRemainAfterExit=yesWorkingDirectory=/path/to/nocodbExecStart=/usr/bin/docker compose up -dExecStop=/usr/bin/docker compose down[Install]WantedBy=multi-user.target
To enable it, run sudo systemctl daemon-reload && sudo systemctl enable --now nocodb.service.
Healthcheck endpoint. NocoDB exposes GET /api/v1/health. Connect it to your monitoring system.