1. Docker Compose on a VPS
A virtual machine from any provider, with Docker installed and ports 80 and 443 open. Postgres, the server and Caddy run as three containers; Caddy gets a certificate from Let's Encrypt on its own once the domain points at the machine. One small VM (1 vCPU, 1 GB of memory) is enough to start.
services:
db:
image: postgres:17
environment:
POSTGRES_USER: identity
POSTGRES_PASSWORD: CHANGE_ME
POSTGRES_DB: identity
volumes:
- pgdata:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U identity"]
interval: 5s
retries: 10
identity:
build: .
depends_on:
db:
condition: service_healthy
volumes:
- ./config.yml:/config.yml:ro
environment:
IDENTITY_CONFIG: /config.yml
restart: unless-stopped
caddy:
image: caddy:2
ports:
- "80:80"
- "443:443"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile:ro
- caddy_data:/data
restart: unless-stopped
volumes:
pgdata:
caddy_data:id.example.com {
reverse_proxy identity:8080
}# config.yml: host=db user=identity password=CHANGE_ME
# dbname=identity sslmode=disable
docker compose up -d --build
docker compose logs identity | grep -E "Encryption Key|Server Application Token"The database is on the Compose network, so the connection string uses host=db and sslmode=disable; nothing leaves the machine unencrypted because nothing leaves the machine. Back up the pgdata volume and config.yml.