# Single-Server Install

> Part of the NocoDB documentation (Self-hosting > Installation). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/self-hosting/installation/single-server
Last updated: 2026-10-03

Deploy NocoDB on a single server with Docker, Traefik and automatic HTTPS.

One command runs NocoDB with Postgres + Redis. It also sets up Traefik with automatic Let's Encrypt SSL and gives you a working HTTPS endpoint.

All parts run on one server: app, database, cache and proxy. For a managed database, multiple app replicas or Kubernetes, refer to [Custom infrastructure](/docs/self-hosting/installation/custom-infrastructure).

## Before you begin

You need [Docker](https://docs.docker.com/get-docker/) with the Compose v2 plugin, on a host where ports **80** and **443** are reachable. For production, we recommend a Linux server. macOS and Windows (Git Bash or WSL) also work. If you use a real domain, point its DNS A record at the public IP of this host before you run the installer.

If you only want to try NocoDB locally on Mac or Windows, the [Quickstart](/docs/self-hosting/installation/quickstart) is simpler. This installer also runs there. But its HTTPS setup needs a host that is reachable at your domain on ports **80** and **443**.

## 1. Run

```bash
curl -fsSL https://install.nocodb.com/noco.sh | bash
```

## 2. Answer 3–4 prompts

| Prompt                  | What to enter                   | Notes                                                                                                                                      |
| ----------------------- | ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| **Domain**              | `nocodb.example.com`            | Must resolve to this server. Blank or `localhost` gives local mode (port 8080). A bare IP serves plaintext HTTP on port 80. Both skip SSL. |
| **Postgres**            | `1` (Bundled) or `2` (Existing) | Bundled is the usual choice. Select Existing to use a managed database (RDS, Cloud SQL and others).                                        |
| **Redis**               | `1` (Bundled) or `2` (Existing) | The same as **Postgres**.                                                                                                                  |
| **Let's Encrypt email** | `ops@example.com`               | The installer asks for it only if you entered a real domain. Let's Encrypt uses it for SSL certificate renewal notifications.              |

After you confirm the summary, the installer writes all files into `nocodb/`. Then it pulls the images and starts the stack. The first run can take a few minutes.

## 3. Open NocoDB

1. Open `https://your-domain`.
2. Sign up with an email and password. The first user becomes super admin.

## What the script generates

```
./nocodb/
├── docker-compose.yml      # Service orchestration
├── docker.env              # Environment variables
├── .gitignore              # Keeps secrets and runtime data out of version control
├── nocodb/
│   └── db.json             # Database connection (knex format, supports custom CA)
├── update.sh               # docker compose pull && up -d && image prune
└── letsencrypt/            # Traefik ACME storage (production with a real domain)
```

Docker keeps the Postgres, Redis and NocoDB application data (with attachments) in **named volumes**, not in this directory. To see them, run `docker volume ls`. The volumes stay after `docker compose down`.

## Reviewing the script before running

To read the script before you pipe it to bash:

```bash
curl -fsSL https://install.nocodb.com/noco.sh -o noco.sh
less noco.sh
bash noco.sh
```

The script source is in the [nocodb/nocodb GitHub repo](https://github.com/nocodb/nocodb/blob/develop/docker-compose/1_Auto_Upstall/noco.sh).

## Non-interactive install

Use this for automation (CI, IaC, configuration management):

```bash
curl -fsSL https://install.nocodb.com/noco.sh | bash -s -- \
  --domain=nocodb.example.com \
  --acme-email=ops@example.com \
  --pg=bundled --redis=bundled
```

This is the full flag list:

| Flag                                                                         | Values                                  | Notes                                                                                                   |
| ---------------------------------------------------------------------------- | --------------------------------------- | ------------------------------------------------------------------------------------------------------- |
| `--quick`                                                                    |                                         | Bundled Postgres + Redis, local mode (port 8080). For production HTTPS, add `--domain=`.                |
| `--domain=`                                                                  | hostname or IP                          | Blank or `localhost` gives local mode (port 8080). A bare IP serves plaintext HTTP on port 80 (no SSL). |
| `--acme-email=`                                                              | email                                   | Required for production with a valid domain.                                                            |
| `--image-tag=`                                                               | image tag                               | Pin `nocodb/nocodb` to a version. Default: `latest`.                                                    |
| `--pg=`                                                                      | `bundled` or `external`                 |                                                                                                         |
| `--pg-host=`, `--pg-port=`, `--pg-database=`, `--pg-user=`, `--pg-password=` |                                         | When `--pg=external`.                                                                                   |
| `--pg-ssl=`                                                                  | `managed`, `none`, or `/path/to/ca.pem` | When `--pg=external`.                                                                                   |
| `--redis=`                                                                   | `bundled` or `external`                 |                                                                                                         |
| `--redis-url=`                                                               | `redis://...`                           | When `--redis=external`.                                                                                |

For the official list, run `bash noco.sh --help`.

## Updating

```bash
cd nocodb
./update.sh
```

This script pulls the latest images, restarts the containers and removes old image layers.

## Common operations

```bash
cd nocodb

# Tail logs
docker compose logs -f nocodb

# Restart NocoDB only (keeps DB and Redis up)
docker compose restart nocodb worker

# Stop everything
docker compose down

# Reconfigure: re-run the wizard (overwrites docker-compose.yml after confirmation, then restarts)
curl -fsSL https://install.nocodb.com/noco.sh | bash
```

If the stack does not start, or you cannot reach NocoDB, refer to [Troubleshooting](/docs/self-hosting/troubleshooting).

## Bringing your own reverse proxy or SSL

If you already have nginx, Caddy or a load balancer in front:

1. Run the installer with a blank domain (local mode). NocoDB then listens on port 8080.
2. Forward the `X-Forwarded-Proto` and `Host` headers from your proxy. NocoDB needs them to make correct callback URLs.

For more control, refer to [Custom infrastructure](/docs/self-hosting/installation/custom-infrastructure).

## Production hardening checklist

When the stack runs and you can sign in, do this checklist before you open it to real traffic:

* **Firewall.** Allow only the ports that you need (`22` for SSH, `80`+`443` for HTTPS). On Ubuntu/Debian: `sudo ufw allow OpenSSH && sudo ufw allow 80,443/tcp && sudo ufw enable`. On RHEL family: `firewall-cmd --add-service=ssh --add-service=http --add-service=https --permanent && firewall-cmd --reload`.
* **Verify secret-file permissions.** The installer already sets `docker.env` and `nocodb/db.json` to `600`. If you copied or edited them by hand, set the permissions again:
  ```bash
  cd nocodb
  chmod 600 docker.env nocodb/db.json
  ```
* **SELinux (RHEL, Rocky, Alma, Fedora).** Docker relabels named volumes automatically, so the data volumes need no action. The other bind mounts are the config files and the `letsencrypt/` directory. If SELinux is in `Enforcing` mode (`getenforce`) and it denies these mounts, add the `:Z` suffix to their entries in `docker-compose.yml` (for example, `./letsencrypt:/letsencrypt:Z`).
* **License activation outbound.** NocoDB calls `https://app.nocodb.com/api/v1/on-premise/agent` over TCP 443 every 6 hours. If you filter egress by host or path, allowlist exactly that URL. For fully offline servers, refer to [Airgapped license](/docs/self-hosting/license-activation#airgapped-license).
* **Log rotation.** By default, the Docker `json-file` log driver has no size limit. Add a global limit in `/etc/docker/daemon.json`:
  ```json
  {
    "log-driver": "json-file",
    "log-opts": { "max-size": "10m", "max-file": "5" }
  }
  ```
  To apply the change, restart Docker (`sudo systemctl restart docker`).
* **systemd unit (optional but recommended).** The default Compose stack restarts the containers when the Docker daemon restarts. A systemd unit also makes the deployment a managed service. Create `/etc/systemd/system/nocodb.service`:
  ```ini
  [Unit]
  Description=NocoDB
  Requires=docker.service
  After=docker.service network-online.target

  [Service]
  Type=oneshot
  RemainAfterExit=yes
  WorkingDirectory=/path/to/nocodb
  ExecStart=/usr/bin/docker compose up -d
  ExecStop=/usr/bin/docker compose down

  [Install]
  WantedBy=multi-user.target
  ```
  To enable it, run `sudo systemctl daemon-reload && sudo systemctl enable --now nocodb.service`.
* **Healthcheck endpoint.** NocoDB exposes `GET /api/v1/health`. Connect it to your monitoring system.
* **Pin your image tags** for production. Do not track `latest`. Refer to [Pinning to a specific version](/docs/self-hosting/maintenance/upgrading#pinning-to-a-specific-version).
* **Schedule backups.** Refer to [Backups](/docs/self-hosting/maintenance/backups). At minimum, make a daily `pg_dump` and an attachment tarball.

## Activating an enterprise license

When NocoDB runs:

1. Sign up as the first user.
2. Go to **Admin Panel → License**.
3. Paste your key.

For the full procedure, refer to [Purchase a license](/docs/self-hosting/purchase-license) and [License activation](/docs/self-hosting/license-activation).

---

## Related pages

- [Quickstart](https://nocodb.com/docs/self-hosting/installation/quickstart.md): Run NocoDB locally in 60 seconds on Mac, Windows or Linux with one Docker Compose command.
- [Custom Infrastructure](https://nocodb.com/docs/self-hosting/installation/custom-infrastructure.md): Run self-hosted NocoDB with a managed database, external Redis, custom SSL, a private CA or your own reverse proxy.
- [Community Methods](https://nocodb.com/docs/self-hosting/installation/community-methods.md): Install NocoDB with platform-specific methods that the community or platform vendors maintain.
