Back to articles
Technology Insight

Building a Secure, Private Pastebin: How to Self-Host MicroBin on a VPS for Confidential Code and Text Sharing

May 30, 2026

Introduction: The Risk of Public Paste Services

In the modern corporate landscape, data privacy is no longer a luxury—it is a critical operational requirement. Developers, system administrators, and business professionals frequently need to share snippets of code, server logs, configurations, or temporary text blocks across teams. For years, public services like Pastebin or Ghostbin have been the default solutions. However, utilizing third-party public platforms introduces significant compliance and security vulnerabilities.

When you paste a snippet containing sensitive logic, API keys, or infrastructure details onto a public platform, you lose custody of that data. Even if the link is unlisted, the platform operators, potential data breaches, or aggressive web scrapers can expose your proprietary information. The solution? Self-hosting a private alternative. By deploying MicroBin on your own Virtual Private Server (VPS), you create an internal, secure, and entirely private paste utility that guarantees absolute data sovereignty.

What is MicroBin?

MicroBin is a minimalist, ultra-fast, and highly secure self-hosted pastebin alternative written in Rust. Unlike heavy enterprise suites, MicroBin requires negligible system resources while providing robust features engineered for privacy-conscious users.

Key Features of MicroBin:

  • Zero External Dependencies: It operates natively without needing complex external database management systems like PostgreSQL or MySQL.
  • Client-Side Encryption: Ensures that data can be encrypted before it ever leaves the user's browser.
  • Automatic Expiration: Allows users to set precise time-to-live (TTL) limits or force "burn-after-reading" mechanics.
  • Raw Text & QR Code Support: Simplifies data retrieval for terminal operations and mobile device sharing.
  • Extremely Lightweight: Runs seamlessly on the smallest, most affordable VPS instances available.
Security Note: By managing the underlying infrastructure, your enterprise ensures that no third-party data analytics tools, tracking cookies, or unauthorized actors have access to internal logs.

Prerequisites for Deployment

Before initiating the installation process, ensure your environment meets the following baseline requirements:

  1. A VPS (Virtual Private Server) running a modern Linux distribution (Ubuntu 22.04 LTS or Debian 12 recommended).
  2. A registered Domain Name or subdomain (e.g., paste.yourcompany.com) pointed to your VPS IP address.
  3. Docker and Docker Compose installed on the server to facilitate containerized deployment.
  4. Basic familiarity with the Linux command-line interface (SSH).

Step-by-Step Installation Guide

Deploying MicroBin via Docker Compose is the most efficient and maintainable method. Follow this structured workflow to configure and launch your private instance.

Step 1: System Update and Directory Allocation

Connect to your VPS via SSH and update your package lists to ensure system security and stability. Then, create a dedicated directory for the MicroBin deployment configuration.

sudo apt update && sudo apt upgrade -y
mkdir -p ~/microbin
cd ~/microbin

Step 2: Configuring Docker Compose

Create a configuration file named docker-compose.yml using a standard text editor like Nano. This file defines how the MicroBin container operates, maps network ports, and sets persistent data volumes.

nano docker-compose.yml

Insert the following configuration into the file:

version: '3.8'

services:
  microbin:
    image: danielszabo99/microbin:latest
    container_name: microbin
    restart: unless-stopped
    ports:
      - "8080:8080"
    volumes:
      - ./microbin-data:/app/microbin_data
    environment:
      - MICROBIN_PUBLIC_PATH=[https://paste.yourcompany.com](https://paste.yourcompany.com)
      - MICROBIN_QR_CODE_ENABLED=true
      - MICROBIN_EDITABLE=false
      - MICROBIN_PRIVATE=true
      - MICROBIN_HIDE_FOOTER=true

Save and close the file (Press Ctrl+O, Enter, then Ctrl+X in Nano).

Step 3: Launching the MicroBin Container

Execute the Docker Compose command to pull the latest official MicroBin image and execute the service in the background (detached mode).

docker compose up -d

Verify that the container is operational by executing docker ps. You should see the MicroBin service routing traffic from port 8080.

Securing Infrastructure with Nginx and SSL

Exposing raw ports directly to the internet is not standard practice for enterprise security. To protect data in transit, we must deploy Nginx as a reverse proxy and implement Let's Encrypt SSL certificates for forced HTTPS communication.

Step 1: Install Nginx

Install the Nginx web server using the native package manager:

sudo apt install nginx -y

Step 2: Configure the Reverse Proxy

Create an Nginx server block configuration for your domain:

sudo nano /etc/nginx/sites-available/microbin

Add the following directives, replacing paste.yourcompany.com with your actual domain:

server {
    listen 80;
    server_name paste.yourcompany.com;

    location / {
        proxy_pass [http://127.0.0.1:8080](http://127.0.0.1:8080);
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

Enable the site configuration and restart Nginx to apply changes:

sudo ln -s /etc/nginx/sites-available/microbin /etc/nginx/sites-enabled/
sudo systemctl restart nginx

Step 3: Provision SSL Certificates via Certbot

Automate SSL configuration to ensure all connections are fully encrypted via TLS 1.3:

sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d paste.yourcompany.com

Follow the on-screen prompts to complete the certificate issuance. Certbot will automatically rewrite the Nginx files to redirect all non-secure HTTP traffic to secure HTTPS.

Best Practices for Enterprise Administration

Once your private pastebin is operational, implementing operational governance ensures long-term security and service availability:

  • Enforce Strict Retention Policies: Educate team members to utilize the "Burn on Read" feature for critical configurations, passwords, or temporary credentials. This guarantees that even if a server image is compromised later, the data no longer exists.
  • Automate Backups: Although MicroBin uses an internal database structure, backing up the ./microbin-data directory daily to an offsite, encrypted cloud storage location prevents catastrophic loss.
  • Restricting Network Access: If your team works exclusively via a corporate VPN or dedicated static IPs, consider restricting access to your MicroBin subdomain at the firewall level (UFW) to prevent external bad actors from attempting brute-force exploration or DDoS attacks.

Conclusion

Building a private pastebin using MicroBin on a self-hosted VPS removes reliance on unpredictable third-party ecosystems. It gives IT departments and technical teams absolute transparency regarding where text and code segments live, how long they persist, and who can access them. By following this deployment framework, your business secures an agile, highly performant tool that optimizes workflow efficiency while strictly upholding critical data protection principles.

Building a Secure, Private Pastebin: How to Self-Host MicroBin on a VPS for Confidential Code and Text Sharing | DPTCloud