Bitflake logo

Self-host OpenProject with Docker Compose

Powerful classic, agile or hybrid project management in a secure environment.

open-project

postgres

postgres:18.3-alpine3.23

The steps below take a few minutes end to end.

  1. Docker compose setup and file
    save the generated compose and env files.
  2. Secret generation
    create the random passwords OpenProject needs.
  3. Start OpenProject with Docker Compose
    bring the stack up and check it's healthy.

Requirements

You'll need these installed on the machine you're deploying to:

Docker

Packages OpenProject and everything it depends on into an isolated container, so it runs the same way on your machine as it does everywhere else.

Install guide

Docker Compose

Reads docker-compose.ymland starts everything in it together. Ships with Docker Desktop. On Linux servers it's usually a separate install.

Install guide

1. Docker compose setup and file

Create a folder for OpenProject and save the file below into it as docker-compose.yml. It describes every container the stack needs — OpenProjectitself and any supporting services, such as its database — along with the ports, volumes and environment variables each one uses. You'll also need an empty .env file in the same folder; Docker Compose reads it automatically and uses it to fill in the ${VARIABLE}references you'll see in the file below.

docker-compose.yml

version: "3.9"
services:
  open-project:
    image: openproject/openproject:17-slim
    restart: unless-stopped
    ports:
      - 8080:8080
    environment:
      DATABASE_URL: postgresql://app:${RANDOM_PG_PASSWORD}@localhost:5432/app
      OPENPROJECT_DEFAULT__LANGUAGE: en
      OPENPROJECT_HOST__NAME: localhost
      OPENPROJECT_HTTPS: "true"
      OPENPROJECT_SEED__ADMIN__USER__PASSWORD: Admin123
      RAILS_ENV: production
      RANDOM_PG_PASSWORD: ${RANDOM_PG_PASSWORD}
      SECRET_KEY_BASE: ${RANDOM_SECRET_KEY_BASE}
      TMPDIR: /tmp/openproject
    volumes:
      - assets:/var/openproject/assets
      - tmp:/tmp
      - app-tmp:/app/tmp
      - app-log:/app/log
    command:
      - /bin/bash
      - -c
      - mkdir -p -m 700 "$$TMPDIR" && ./docker/prod/seeder && exec ./docker/prod/web
    healthcheck:
      test:
        - CMD
        - curl
        - -f
        - http://localhost:8080/
      interval: 10s
      timeout: 5s
      retries: 5
  postgres:
    image: postgres:18.3-alpine3.23
    restart: unless-stopped
    network_mode: service:open-project
    environment:
      POSTGRES_PASSWORD: ${RANDOM_PG_PASSWORD}
      POSTGRES_USER: app
volumes:
  app-log: null
  app-tmp: null
  assets: null
  tmp: null

Volumes

OpenProject stores its data in named Docker volumes, so it survives container restarts and updates:

  • assets mounted at /var/openproject/assets: Uploaded files and attachments
  • tmp mounted at /tmp: System temp dir. The Rails seeder/migration (and Ruby's Dir.tmpdir) need a writable temporary directory; on the read-only root filesystem neither /tmp nor the app dir is writable, so the boot fails with "could not find a temporary directory" unless /tmp is a volume.
  • app-tmp mounted at /app/tmp: Rails runtime tmp dir (cache, pids, sockets) under the app root, written on every boot and not writable on the read-only root filesystem.
  • app-log mounted at /app/log: Rails log dir under the app root, written on every boot and not writable on the read-only root filesystem.

2. Secret generation

OpenProject needs a few randomly generated secrets — for example, database passwords or an internal session key — before it can start. These are referenced from docker-compose.ymlabove but don't live in it, so they need to end up in your .env file. Pick one of the two options below.

Generating secrets…

3. Start OpenProject with Docker Compose

From the folder with docker-compose.yml and .env, run:

Terminal

Start OpenProject and all its supporting services in the background.

docker compose up -d

The -d flag runs the stack in the background so it keeps running after you close the terminal. Docker will pull the images the first time, which can take a minute or two.

To check on it afterwards: docker compose ps shows whether containers are healthy, and docker compose logs -f follows their logs if something looks wrong. Once it's running, open http://localhost:8080 in your browser.