Docker lets you run applications in containers: self-contained packages that include everything the app needs. It's the easiest way to run many popular self-hosted apps, and it keeps each app separate from the rest of your server. Docker Compose lets you describe an app and its services (for example, a website and its database) in a single file and start them with one command.
This guide installs Docker from Docker's official repository, which gives you the latest version and keeps it updated with the rest of your system. It works on every operating system we offer: Ubuntu 22.04, 24.04 and 26.04, Debian 12 and 13, AlmaLinux 8, 9 and 10, and Rocky Linux 9 and 10.
Before you start
- Any VPS size will run Docker. What you need depends on the apps you run in it.
- SSH access as root or as a user with sudo rights. If you're logged in as root, you can leave
sudooff the commands. - Don't install Docker on a server running cPanel. The two aren't designed to run together.
Step 1: Update the server
Ubuntu/Debian
sudo apt update && sudo apt upgrade -y
AlmaLinux/Rocky
sudo dnf upgrade -y
Step 2: Install Docker
Ubuntu 22.04, 24.04, 26.04 and Debian 12, 13
First, remove any unofficial Docker packages your system may have installed. It's fine if apt says none are installed.
sudo apt remove -y docker.io docker-compose docker-doc podman-docker containerd runc
Then add Docker's repository and install:
sudo apt update
sudo apt install -y ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
. /etc/os-release
sudo curl -fsSL https://download.docker.com/linux/$ID/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc
sudo tee /etc/apt/sources.list.d/docker.sources <<EOF
Types: deb
URIs: https://download.docker.com/linux/$ID
Suites: ${UBUNTU_CODENAME:-$VERSION_CODENAME}
Components: stable
Signed-By: /etc/apt/keyrings/docker.asc
EOF
sudo apt update
sudo apt install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
AlmaLinux 8, 9, 10 and Rocky Linux 9, 10
These systems ship with Podman, which conflicts with Docker, so remove it first. It's fine if dnf says nothing is installed.
sudo dnf remove -y podman runc buildah
sudo dnf install -y dnf-plugins-core
sudo dnf config-manager --add-repo https://download.docker.com/linux/rhel/docker-ce.repo
sudo dnf install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
Step 3: Start Docker and check it works
sudo systemctl enable --now docker
sudo docker run --rm hello-world
If you see Hello from Docker!, Docker is working. Check that Docker Compose is installed too:
docker compose version
Step 4 (optional): Run Docker without sudo
If you log in as a normal user rather than root, you can add yourself to the docker group so you don't need to type sudo before every Docker command:
sudo usermod -aG docker $USER
Log out and back in for this to take effect. Be aware that members of the docker group effectively have root access to the server, so only add users you trust.
Step 5 (recommended): Limit container log sizes
By default, Docker keeps container logs forever, and they can slowly fill your disk. This setting caps each container's logs at about 30 MB:
sudo tee /etc/docker/daemon.json <<EOF
{
"log-driver": "json-file",
"log-opts": {
"max-size": "10m",
"max-file": "3"
}
}
EOF
sudo systemctl restart docker
The new limit applies to containers created after the change.
Try it: your first Docker Compose app
This example runs a simple Nginx web server on port 8080, so you can see how Compose works.
mkdir -p ~/hello-compose
cd ~/hello-compose
nano compose.yaml
Paste in the following, then press Ctrl+O and Enter to save and Ctrl+X to exit:
services:
web:
image: nginx:latest
ports:
- "8080:80"
restart: unless-stopped
Start it:
sudo docker compose up -d
Open http://YOUR_SERVER_IP:8080 in your browser and you'll see the Nginx welcome page. When you're done, stop and remove it with sudo docker compose down.
Useful Docker commands
docker ps: list running containersdocker ps -a: list all containers, including stopped onesdocker logs -f NAME: follow a container's logsdocker compose up -d: start the app in the current folder in the backgrounddocker compose down: stop and remove the app in the current folderdocker compose pull && docker compose up -d: update the app to the latest imagesdocker system df: show how much disk Docker is usingdocker system prune: remove stopped containers, unused networks and dangling images to free up space
A note on firewalls
Docker manages its own firewall rules. Ports published by a container (the ports: lines in a Compose file) can be reachable from the internet even if UFW or firewalld would normally block them. Don't rely on your firewall to hide a Docker port. If a service should only be reachable from the server itself, publish it on 127.0.0.1, for example "127.0.0.1:8080:80".
What to run next
Once Docker is installed, you can follow any of these guides:
- Install Nextcloud, your own private cloud storage
- Set up your own VPN with WireGuard
- Install Uptime Kuma to monitor your websites
- Install n8n for workflow automation
Keeping Docker up to date
Docker updates along with the rest of your system: sudo apt update && sudo apt upgrade on Ubuntu/Debian, or sudo dnf upgrade on AlmaLinux/Rocky. Your apps' container images are updated separately, with docker compose pull and docker compose up -d in each app's folder.
Troubleshooting
- "permission denied while trying to connect to the Docker daemon socket": run the command with
sudo, or add your user to thedockergroup (Step 4) and log in again. - "Cannot connect to the Docker daemon": Docker isn't running. Start it with
sudo systemctl start docker, and check for errors withsudo systemctl status docker. - Package conflicts on AlmaLinux/Rocky: make sure Podman and Buildah were removed in Step 2, then try the install again. Adding
--allowerasingto the install command can also resolve conflicts. - Disk filling up: check usage with
docker system df, and clean up withdocker system prune. Set up the log limits in Step 5 if you haven't already.
Need help?
Our Cloud VPS plans are self-managed, so you're responsible for installing, securing and maintaining the software on your server. If something on our side isn't working, such as the network, or your VPS won't boot, open a support ticket. New to your VPS? Start with our Cloud VPS Getting Started Guide.







