Deploy DevGuard with Docker Compose

Run DevGuard using the devguard-docker-deployment repo — suitable for evaluation, self-hosted setups, or production when Kubernetes is not available.

Prerequisites

  • Docker and Docker Compose installed

Choose a Deployment Option

OptionBest for
LocalhostA simple initial test on your own machine
OrbStackLocalhost testing with zero-config SSL, if you already use OrbStack
TraefikMaking DevGuard reachable from other computers — the recommended option for production

Deployment Steps

Clone the repo

Run the guided setup

The interactive setup asks which deployment option you want (Localhost, OrbStack, or Traefik), then writes .env and generates the encryption key, the Kratos identity config, and the database init script. Re-running it keeps existing secrets and files, so it's also how you switch deployment options later.

Initialize the database

Launch DevGuard

Access DevGuard

Open http://localhost:3000 in your browser, or the domain you configured (DEVGUARD_WEB_DOMAIN in .env).

Important Notes

Email verification: No SMTP server is configured by default, and KRATOS_VERIFICATION_ENABLED/KRATOS_RECOVERY_ENABLED are false in .env.example. During registration, skip email verification by clicking "Back".

To enable email delivery, set KRATOS_SMTP_CONNECTION_URI, KRATOS_SMTP_FROM_ADDRESS, and KRATOS_SMTP_FROM_NAME in .env, then set KRATOS_VERIFICATION_ENABLED/KRATOS_RECOVERY_ENABLED to true as needed and restart the kratos service.

Vulnerability database: The API downloads the latest vulnerability database on first start. This may take several minutes. Vulnerability data and scan results won't be complete until the download finishes.

Hardening for Production

.env.example groups every value that must change before going live under "Variables to change for production deployment" at the top of the file. The key items are:

WhatVariableAction
Domains & protocolDEVGUARD_WEB_DOMAIN, DEVGUARD_API_DOMAIN, DEVGUARD_PROTOCOLSet to your public https:// domains
DevGuard DB passwordPOSTGRES_DEVGUARD_PASSWORDSet a strong random password
Kratos DB passwordPOSTGRES_KRATOS_PASSWORDSet a separate strong password for the kratos DB user
Session/cipher secretsKRATOS_COOKIE_SECRET, KRATOS_CIPHER_SECRETGenerate with openssl rand -base64 24 — the guided setup already does this for you. KRATOS_CIPHER_SECRET must be exactly 32 characters
Passkey/WebAuthn RP idKRATOS_PASSKEY_RP_IDRoot domain only — no scheme, no port (e.g. example.com if DEVGUARD_WEB_DOMAIN=app.example.com)
Log levelDEVGUARD_LOG_LEVELChange from debug to info or warn

TLS

  • Traefik deployment terminates TLS for you. Put your certificate and key at certs/domain.cert and certs/domain.key in the repo root (see .traefik/dynamic/tls.yml) before starting.
  • OrbStack deployment gets TLS for free via OrbStack's zero-config domains — no certificate setup needed.
  • Localhost deployment has no TLS. Don't expose the devguard-api/devguard-web ports beyond your machine; for a network-reachable production deployment use the Traefik option or place your own TLS-terminating reverse proxy in front instead.

Next Steps

Have feedback? We want to hear from you!

Fields marked with * are required