Self-host Firefly III with Docker Compose
Self-hosted personal finance manager to track income, expenses, and budgets.
firefly-iii
postgres
postgres:18.3-alpine3.23
postgres-postgres-data-init
busybox
postgres-postgres-socket-init
busybox
The steps below take a few minutes end to end.
Requirements
You'll need these installed on the machine you're deploying to:
Docker
Packages Firefly III and everything it depends on into an isolated container, so it runs the same way on your machine as it does everywhere else.
Install guideDocker Compose
Reads docker-compose.ymland starts everything in it together. Ships with Docker Desktop. On Linux servers it's usually a separate install.
Install guide1. Docker compose setup and file
Create a folder for Firefly III and save the file below into it as docker-compose.yml. It describes every container the stack needs — Firefly IIIitself and any supporting services, such as its database — along with the ports, volumes and environment variables each one uses. You'll also need an empty .env file in the same folder; Docker Compose reads it automatically and uses it to fill in the ${VARIABLE}references you'll see in the file below.
docker-compose.yml
version: "3.9"
services:
firefly-iii:
image: fireflyiii/core:latest
restart: unless-stopped
ports:
- 8080:8080
environment:
APP_ENV: production
APP_KEY: base64:${RANDOM_APP_KEY_RAW}
APP_KEY_RAW: ${RANDOM_APP_KEY_RAW}
APP_URL: http://localhost
DB_CONNECTION: pgsql
DB_DATABASE: app
DB_HOST: localhost
DB_PASSWORD: ${RANDOM_PG_PASSWORD}
DB_PORT: "5432"
DB_USERNAME: app
TRUSTED_PROXIES: '**'
volumes:
- upload:/var/www/html/storage/upload
- storage:/var/www/html/storage
- run:/run
- nginx-log:/var/log/nginx
- nginx-cache:/var/cache/nginx
- nginx-config:/etc/nginx
healthcheck:
test:
- CMD
- curl
- -f
- http://localhost:8080/login
interval: 10s
timeout: 5s
retries: 5
postgres:
image: postgres:18.3-alpine3.23
restart: unless-stopped
network_mode: service:firefly-iii
environment:
PGDATA: /var/lib/postgresql/data
POSTGRES_PASSWORD: ${RANDOM_PG_PASSWORD}
POSTGRES_USER: app
volumes:
- postgres-data:/var/lib/postgresql/data
- postgres-socket:/var/run/postgresql
depends_on:
postgres-postgres-data-init:
condition: service_completed_successfully
postgres-postgres-socket-init:
condition: service_completed_successfully
postgres-postgres-data-init:
image: busybox
volumes:
- postgres-data:/var/lib/postgresql/data
command:
- chown
- 70:70
- /var/lib/postgresql/data
postgres-postgres-socket-init:
image: busybox
volumes:
- postgres-socket:/var/run/postgresql
command:
- chown
- 70:70
- /var/run/postgresql
volumes:
nginx-cache: null
nginx-config: null
nginx-log: null
postgres-data: null
postgres-socket: null
run: null
storage: null
upload: null
Volumes
Firefly III stores its data in named Docker volumes, so it survives container restarts and updates:
- upload mounted at /var/www/html/storage/upload: Firefly III's user uploads: the file attachments users add to transactions and other records.
- storage mounted at /var/www/html/storage: Firefly III's runtime storage: application logs, framework cache/session/view files, and the generated Passport OAuth signing keypair, all written into the tree the image ships here.
- run mounted at /run: Runtime state (process-manager sockets and pid files) the app writes on startup.
- nginx-log mounted at /var/log/nginx: Nginx's access and error logs, which it opens for writing on startup.
- nginx-cache mounted at /var/cache/nginx: Nginx's temporary caches (client_temp, proxy_temp, and similar), which it creates while serving requests.
- nginx-config mounted at /etc/nginx: Nginx configuration, which Firefly III regenerates from its bundled .template sources inside this directory on each start.
2. Secret generation
Firefly III needs a few randomly generated secrets — for example, database passwords or an internal session key — before it can start. These are referenced from docker-compose.ymlabove but don't live in it, so they need to end up in your .env file. Pick one of the two options below.
Generating secrets…
3. Start Firefly III with Docker Compose
From the folder with docker-compose.yml and .env, run:
Terminal
Start Firefly III and all its supporting services in the background.
docker compose up -dThe -d flag runs the stack in the background so it keeps running after you close the terminal. Docker will pull the images the first time, which can take a minute or two.
To check on it afterwards: docker compose ps shows whether containers are healthy, and docker compose logs -f follows their logs if something looks wrong. Once it's running, open http://localhost:8080 in your browser.