Installing Caprover - Self Hosted deployment & web server manager

A current CapRover install guide: the terms flag that older tutorials omit, wildcard DNS, firewall rules and the CLI server setup.

Share

CapRover is a straightforward app and database deployment manager that doubles as a web server manager. It is a FOSS alternative to Cloudron, and as of this update the current release is v1.15.4. Similar products include YunoHost and Yacht. It is quick to get running and it hides real infrastructure: Docker, nginx, Let's Encrypt and Netdata all sit underneath a single interface.

There are several ways to deploy CapRover. Upstream, the recommended route is the one-click app on DigitalOcean. You can use the following link to sign up for a 60-day, $200 credit.

DigitalOcean Referral Badge

However, in this tutorial I will demonstrate how to install CapRover on any server, regardless of whether it is a VPS on a different cloud or a home server in your home lab. If you are starting from a fresh VPS, the first 24 hours on a new VPS covers the account, SSH and firewall groundwork this guide assumes. Once CapRover is running it is a natural host for the rest of a self-hosted stack, and it is one of the ways to run Uptime Kuma in one click.

Prerequisites

Before deploying CapRover, you will need to have at least the following:

  1. Domain Name: you can get domains as cheap as $1 on any domain name provider. My preference is Namecheap
  2. Server: this is of course where the application will sit, preferable one with a public IP. You can however choose to install CapRover locally on your laptop on a private network which is behind NAT (your router). But if you want to enable HTTPS and/or access the apps from outside your private network, it requires some special setup, like port forwarding. Be sure to follow their documentation to achieve this

Server specs

Published CapRover images target AMD64 (x86-64) and ARM64. The 32-bit ARMv7 image is no longer published, so a Raspberry Pi running a 32-bit OS will not work. The upstream documentation tests against Ubuntu 24.04 LTS and Docker 25 or newer, and that is the combination this guide assumes. The older recommendation of Ubuntu 20.04 with Docker 19.03 dates from 2019 and is no longer supported. 20.04 LTS reaches standard end of life in 2027, and Docker 19.03 has been out of support for years.

A recommended RAM of at least 1GB is suitable to make sure the build process runs successfully.

Install docker using the official installation instructions. Avoid using snaps.

Make sure the required ports are opened/allowed on your firewall or security groups on whichever cloud provider you are using.

ufw allow 80/tcp                # web
ufw allow 443/tcp               # web-TLS
ufw allow 443/udp               # web-TLS over QUIC (HTTP/3)
ufw allow 3000/tcp              # admin dashboard

Those four are the single-node set. 443/udp is easy to forget and it is not optional if you want HTTP/3 to work. If you are running a multi-node Swarm, the swarm control and overlay ports have to be open as well:

ufw allow 2377/tcp              # swarm control
ufw allow 7946/tcp              # swarm gossip
ufw allow 7946/udp              # swarm gossip
ufw allow 4789/udp              # overlay networking

Port 3000 is the admin dashboard. Leaving it open to the world is convenient but not ideal; restrict it to your own address once you are finished setting up.

CapRover Installation

The steps below install CapRover on a server you already control. The whole process is: run the container, point a wildcard DNS record at the server, install the CLI and run the server setup. Take them in order. CapRover validates the DNS record during setup, so creating the record first saves a failed attempt.

Step 1: Installation

Installing CapRover is as simple as running the following command:

docker run -p 80:80 -p 443:443 -p 3000:3000 \
  -e ACCEPTED_TERMS=true \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v /captain:/captain \
  caprover/caprover

The -e ACCEPTED_TERMS=true flag is not optional. CapRover will not start without it, and the container will exit with a message telling you to accept the terms. Older guides, including an earlier version of this one, omit it, which is why the command sometimes appears to do nothing.

The three container ports (80, 443 and 3000) are fixed and should be left alone, since CapRover binds to those internally. If they clash with something already on the host you can remap the host side instead, using CAPTAIN_HOST_HTTP_PORT, CAPTAIN_HOST_HTTPS_PORT and CAPTAIN_HOST_ADMIN_PORT. Changing the left-hand side of the -p flags alone will not work.

Once CapRover has initialised, visit http://YOUR_SERVER_IP:3000 and log in with the default password captain42. Change that password before you do anything else. The default is public knowledge, and port 3000 is reachable by anyone who finds it. Better still, once setup is complete, restrict port 3000 to your own IP in the firewall.

Do not configure anything through the dashboard at this point. Server setup happens from the command line; the dashboard is for managing apps once the server is configured.

Step 2: Connect Root Domain

Add an A record to your domain registrar that maps a wildcard subdomain (*.something.com) to the IP address of your CapRover server.

Steps:

  1. Access your domain registrar's DNS config.
  2. Create an A record:
  • HOST: *.something
  • POINTS TO: IP of CapRover server
  • TTL: ~1 hour

On Cloudflare the record looks like this. Note the wildcard host, and that the proxy must be switched off (grey cloud). CapRover needs to terminate TLS itself, as explained below.

TypeNameContentProxy statusTTL
A*your CapRover server IPDNS only (grey)1 hour
Acaptainyour CapRover server IPDNS only (grey)1 hour

Notes:

  • DNS changes can take up to 24 hours to propagate.
  • A TTL of ~1 hour is recommended.
  • CapRover requires A Record to be pointing to CapRover's IP Address. If you use proxy services, such as Cloudflare, you may face difficulties. CapRover does not officially support such use cases.

Step 3: Install CapRover CLI

The caprover CLI runs on NPM. The recommended way of installing NPM is via a package manage. There is a detailed guide on how to install Node.js $ NPM on the GitHub page.

On Ubuntu 24.04, install the current LTS release of Node.js from NodeSource. Node 18, which older versions of this guide recommended, reached end of life in April 2025 and no longer receives security updates.

curl -fsSL https://deb.nodesource.com/setup_24.x | sudo -E bash -
sudo apt-get install -y nodejs

With Node installed, install the CLI globally:

npm install -g caprover

Then start the server setup:

caprover serversetup

It will ask for the IP address of your server, the root domain you configured above, and an email address for Let's Encrypt. It will then ask you to confirm the existing password or set a new one, and enable HTTPS. This is the step that actually provisions the server, which is why the dashboard is left alone beforehand.

One catch: caprover serversetup cannot complete if HTTPS has already been forced on the instance. If you enabled and forced HTTPS through the dashboard first, the setup command will not run. In that case log in with caprover login instead and change the password from the settings menu.

Once it finishes, CapRover is reachable at https://captain.YOUR-DOMAIN.com. From that point the workflow is to create apps in the dashboard, then deploy to them with caprover deploy from your project directory.

Step 4: (Optional) Set up Swap file

In some cases, you may run into problems due to not having enough physical RAM, particularly during image builds on a 1 GB instance. A swap file is the standard workaround, and following these instructions on How To Create A Linux Swap File will get you there. It is worth adding up front on a small VPS rather than waiting for a build to fail.

## Convertkit Newsletter