Deploy DevGuard with Docker Compose
Run DevGuard using the devguard-docker-deployment repo — suitable for evaluation, self-hosted setups, or production when Kubernetes is not available.
Prerequisites
- Docker and Docker Compose installed
Choose a Deployment Option
| Option | Best for |
|---|---|
| Localhost | A simple initial test on your own machine |
| OrbStack | Localhost testing with zero-config SSL, if you already use OrbStack |
| Traefik | Making DevGuard reachable from other computers — the recommended option for production |
Deployment Steps
Clone the repo
Run the guided setup
The interactive setup asks which deployment option you want (Localhost, OrbStack, or Traefik), then writes .env and generates the encryption key, the Kratos identity config, and the database init script. Re-running it keeps existing secrets and files, so it's also how you switch deployment options later.
Initialize the database
Launch DevGuard
Access DevGuard
Open http://localhost:3000 in your browser, or the domain you configured (DEVGUARD_WEB_DOMAIN in .env).
Important Notes
Email verification: No SMTP server is configured by default, and KRATOS_VERIFICATION_ENABLED/KRATOS_RECOVERY_ENABLED are false in .env.example. During registration, skip email verification by clicking "Back".
To enable email delivery, set KRATOS_SMTP_CONNECTION_URI, KRATOS_SMTP_FROM_ADDRESS, and KRATOS_SMTP_FROM_NAME in .env, then set KRATOS_VERIFICATION_ENABLED/KRATOS_RECOVERY_ENABLED to true as needed and restart the kratos service.
Vulnerability database: The API downloads the latest vulnerability database on first start. This may take several minutes. Vulnerability data and scan results won't be complete until the download finishes.
Hardening for Production
.env.example groups every value that must change before going live under "Variables to change for production deployment" at the top of the file. The key items are:
| What | Variable | Action |
|---|---|---|
| Domains & protocol | DEVGUARD_WEB_DOMAIN, DEVGUARD_API_DOMAIN, DEVGUARD_PROTOCOL | Set to your public https:// domains |
| DevGuard DB password | POSTGRES_DEVGUARD_PASSWORD | Set a strong random password |
| Kratos DB password | POSTGRES_KRATOS_PASSWORD | Set a separate strong password for the kratos DB user |
| Session/cipher secrets | KRATOS_COOKIE_SECRET, KRATOS_CIPHER_SECRET | Generate with openssl rand -base64 24 — the guided setup already does this for you. KRATOS_CIPHER_SECRET must be exactly 32 characters |
| Passkey/WebAuthn RP id | KRATOS_PASSKEY_RP_ID | Root domain only — no scheme, no port (e.g. example.com if DEVGUARD_WEB_DOMAIN=app.example.com) |
| Log level | DEVGUARD_LOG_LEVEL | Change from debug to info or warn |
TLS
- Traefik deployment terminates TLS for you. Put your certificate and key at
certs/domain.certandcerts/domain.keyin the repo root (see.traefik/dynamic/tls.yml) before starting. - OrbStack deployment gets TLS for free via OrbStack's zero-config domains — no certificate setup needed.
- Localhost deployment has no TLS. Don't expose the
devguard-api/devguard-webports beyond your machine; for a network-reachable production deployment use the Traefik option or place your own TLS-terminating reverse proxy in front instead.
Next Steps
- Run your first scan: Getting Started Guide
- Configure monitoring
- Set up backups