Back to articles
Technology Insight

Building a Private PaaS for Digital Agencies: Centralized Management of 100+ WordPress Sites with Kamal 2

June 3, 2026

The Hosting Dilemma for Growing Digital Agencies

Digital agencies managing a large portfolio of client websites eventually hit a formidable bottleneck. In the early days, managed WordPress hosting providers offer convenience. However, as your portfolio scales to 50, 100, or more websites, those premium per-site hosting fees quickly erode your profit margins. Suddenly, you are paying thousands of dollars a month for resources you aren't fully utilizing.

The alternative has traditionally been managing your own virtual private servers (VPS) or wrestling with enterprise-grade container orchestration like Kubernetes. While VPS setups become a configuration nightmare at scale, Kubernetes introduces immense complexity, requiring dedicated DevOps engineers just to keep the lights on. Agencies need a middle ground: a solution that offers the costefficiency of raw infrastructure with the deployment simplicity of a modern Platform as a Service (PaaS).

Enter Kamal 2. Originally developed by Basecamp and 37signals, Kamal 2 allows you to deploy and manage Docker-optimized applications on any server with zero downtime, out-of-the-box SSL management, and absolute zero vendor lock-in. For agencies managing over 100 WordPress sites, building a private PaaS with Kamal 2 is the ultimate paradigm shift.

---

Why Kamal 2 is the Perfect Engine for a Custom Agency PaaS

Kamal 2 treats servers as commodity hardware. It doesn't care if you are using AWS, DigitalOcean, Hetzner, or on-premises bare metal. By utilizing Docker under the hood, Kamal 2 allows you to standardize your WordPress environment across hundreds of distinct client sites while keeping them perfectly isolated.

Here is why Kamal 2 outshines traditional control panels and orchestration tools for agency workflows:

  • Zero-Downtime Deploys: Kamal 2 uses a built-in proxy (Kamal Proxy) to seamlessly route traffic from old containers to new containers during updates, ensuring your clients' sites never drop for a second.
  • Automated SSL Provisioning: Kamal 2 handles Let's Encrypt certificates automatically at the proxy level, eliminating the headache of manual SSL renewals across hundreds of domains.
  • Infrastructure Agnostic: You can mix and match cloud providers based on client budgets or geographic requirements without altering your deployment pipeline.
  • Declarative Configuration: Each website's configuration is defined in a simple, version-controlled deploy.yml file. Your infrastructure becomes documentation.
---

Architecting a 100+ WordPress Site Infrastructure

When managing over 100 WordPress instances, a naive 'one server fits all' approach will quickly collapse under resource contention. To build a resilient private PaaS, you must decouple your architectural layers.

1. The Routing and Proxy Layer

Instead of exposing every WordPress container directly to the web, Kamal 2 routes traffic through its highly efficient proxy. For a massive multi-tenant setup, you can establish dedicated load balancer nodes that handle initial SSL termination and route requests to the specific application servers hosting the requested WordPress containers.

2. The Compute Layer (Application Servers)

Rather than cramming 100 sites onto a single massive instance, group your sites into clusters across multiple medium-sized application servers (e.g., 4-8 vCPUs, 16-32GB RAM each). You can categorize these servers by client tiers: a 'Premium' server cluster for high-traffic e-commerce clients and a 'Standard' cluster for brochure websites.

3. The Centralized Database Layer

Running a MySQL or MariaDB instance inside every single WordPress container is highly inefficient. Instead, route your containerized WordPress applications to a highly available, centralized database cluster. Managed database services (like DigitalOcean Managed Databases or AWS RDS) are highly recommended here to ensure automated backups, scaling, and high performance without manual DBA overhead.

4. Shared Storage Layer

WordPress relies heavily on the local filesystem for media uploads (the wp-content/uploads directory). In a multi-server PaaS environment, you must offload this media to avoid synchronization issues. Utilizing plugins that automatically offload media assets to S3-compatible object storage (such as AWS S3 or Cloudflare R2) ensures your local containers remain stateless and lightweight.

---

Step-by-Step Blueprint: Deploying WordPress with Kamal 2

To successfully containerize and deploy a WordPress site via Kamal 2, your agency will follow a standardized blueprint. Here is an overview of how the configuration is structured.

Step 1: Containerizing WordPress

First, we create a standardized Dockerfile for the agency. This ensures every WordPress site runs the exact same optimized version of PHP, essential extensions, and security configurations.

Note: By pinning your Docker image to specific PHP and WordPress versions, you eliminate the classic 'it works on my machine but breaks in production' dilemma across your entire portfolio.

Step 2: Configuring the Kamal Deployment File

The heart of a Kamal 2 deployment is the config/deploy.yml file. This file dictates which servers the site lives on, environment variables, and proxy settings. A typical agency configuration for a specific client site looks like this:

service: client-alpha-wp
image: [registry.agencyname.com/client-alpha](https://registry.agencyname.com/client-alpha)

servers:
  web:
    - 192.168.1.50

proxy:
  ssl: true
  host: client-alpha.com

env:
  secret:
    - WORDPRESS_DB_PASSWORD
  clear:
    WORDPRESS_DB_HOST: db-cluster.agencyname.com
    WORDPRESS_DB_USER: client_alpha_user
    WORDPRESS_DB_NAME: client_alpha_db

Step 3: Executing the Setup and Deployment

With Kamal 2 installed locally or integrated into your CI/CD pipeline, initializing and deploying the site requires just a single command:

kamal setup

This single command instructs Kamal to connect to your target server via SSH, install Docker if it isn't already present, set up the Kamal Proxy, pull your WordPress image from your private registry, configure the SSL certificates, and launch the application safely.

---

Centralized Management and Day-2 Operations

Building the PaaS is only half the battle; maintaining 100+ websites sustainably requires robust centralized operations. When you control the underlying containers via Kamal 2, maintenance tasks that used to take days can now be automated in minutes.

Bulk Updates and CI/CD Automation

When a critical core WordPress security patch is released, standard agencies scramble to log into multiple dashboards or run risky automated plugins. With your custom PaaS, your team simply updates the base Docker image, tests it internally, and pushes the code to your repository. Your CI/CD pipeline (such as GitHub Actions) can sequentially loop through your Kamal configuration files, running kamal deploy across your portfolio automatically and with zero client downtime.

Centralized Monitoring and Logging

Because every site is running inside a Docker container managed by Kamal, you can easily deploy a unified monitoring stack across your servers. Tools like Grafana, Prometheus, and Vector can pull resource metrics and container logs centrally. If Client X's website experiences a sudden traffic spike, your dashboard will immediately flag the specific container, allowing you to scale up resources or allocate the container to a different node seamlessly.

---

Conclusion: Financial and Operational Freedom

Building a private PaaS using Kamal 2 moves your digital agency away from being a mere reseller of third-party hosting platforms and positions you as a true technology partner. By abstracting the complexities of Docker and server orchestration, Kamal 2 delivers the control of enterprise systems with the simplicity small teams require.

The financial rewards are clear: instead of paying escalating per-site monthly premiums to managed hosts, your infrastructure costs scale linearly with raw cloud hardware. More importantly, the operational efficiency gained through version-controlled deployment configurations, zero-downtime updates, and centralized logging empowers your engineering team to focus on what truly drives revenue—building exceptional digital experiences for your clients.

Building a Private PaaS for Digital Agencies: Centralized Management of 100+ WordPress Sites with Kamal 2 | DPTCloud