Back to articles
Technology Insight

Building an Automated Code Analysis and Scoring System: Deploying SonarQube SAST on a Virtual Private Server (VPS)

May 28, 2026

Introduction: The Imperative of Automated Code Quality and Security

In the modern software development lifecycle (SDLC), the speed of delivery often clashes with the necessity for security and code quality. Relying solely on manual code reviews is no longer viable for agile teams. Security vulnerabilities, technical debt, and architectural flaws hidden within source code can lead to catastrophic failures if left unchecked until production.

To mitigate these risks, organizations turn to Static Application Security Testing (SAST). SAST allows teams to analyze source code for security vulnerabilities and quality defects without executing the program. Among the market-leading tools, SonarQube stands out as an enterprise-grade platform that continuously inspects code quality and performs automatic reviews with static analysis. This comprehensive guide details how to architect and deploy an automated source code analysis and scoring system using SonarQube on a Virtual Private Server (VPS).

1. System Architecture and VPS Requirements

Before initiating the deployment, it is critical to understand the architecture of a SonarQube ecosystem. The platform comprises three primary components:

  • SonarQube Server: Coordinates web services, search capabilities (via an embedded Elasticsearch instance), and calculation of quality metrics.
  • Database Server: Stores configuration, quality profiles, and historical metrics. PostgreSQL is the recommended database engine.
  • SonarScanner: The client-side tool that analyzes the source code locally on CI/CD runners or developer machines and sends reports to the server.

Hardware Prerequisites

SonarQube embeds Elasticsearch for its search indexing functionalities, making it memory-intensive. For a stable production or staging environment on a VPS, we recommend the following minimum specifications:

  • CPU: 2 vCPUs or higher.
  • RAM: 4GB minimum (8GB highly recommended to prevent out-of-memory errors during heavy analysis).
  • Storage: 20GB+ SSD with high I/O throughput.
  • OS: Ubuntu Server 22.04 LTS or 24.04 LTS.

2. Step-by-Step VPS Environment Preparation

Deploying SonarQube requires specific operating system configurations, particularly for memory mapping limits due to its internal Elasticsearch component.

Step 2.1: Adjusting System Limits

Connect to your VPS via SSH and modify the virtual memory allocation limit by editing the system control file:

sudo nano /etc/sysctl.conf

Append the following lines to ensure Elasticsearch has sufficient virtual memory resources:

vm.max_map_count=524288
fs.file-max=131072
ulimit -n 131072
ulimit -u 8192

Apply the changes instantly using: sudo sysctl -p

Step 2.2: Database Provisioning

SonarQube dropped support for MySQL, meaning PostgreSQL is the industry-standard choice. Install and secure PostgreSQL on your VPS:

sudo apt update
sudo apt install postgresql postgresql-contrib -y

Access the PostgreSQL prompt, create a dedicated database user, and provision the schema:

CREATE USER sonar WITH PASSWORD 'YourSecurePasswordHere';
CREATE DATABASE sonarqube OWNER sonar;
GRANT ALL PRIVILEGES ON DATABASE sonarqube TO sonar;

3. Deploying SonarQube via Docker Compose

While a bare-metal installation is possible, utilizing Docker Compose ensures container isolation, easier upgrades, and reproducible environments. Create a docker-compose.yml file in your chosen working directory:

version: '3.8'

services:
  sonarqube:
    image: sonarqube:community-lts
    container_name: sonarqube
    depends_on:
      - db
    ports:
      - "9000:9000"
    networks:
      - sonar-network
    environment:
      - SONAR_JDBC_USERNAME=sonar
      - SONAR_JDBC_PASSWORD=YourSecurePasswordHere
      - SONAR_JDBC_URL=jdbc:postgresql://db:5432/sonarqube
    ulimits:
      nofile:
        soft: 131072
        hard: 131072
    volumes:
      - sonar_data:/opt/sonarqube/data
      - sonar_extensions:/opt/sonarqube/extensions
      - sonar_logs:/opt/sonarqube/logs

  db:
    image: postgres:15-alpine
    container_name: postgres
    networks:
      - sonar-network
    environment:
      - POSTGRES_USER=sonar
      - POSTGRES_PASSWORD=YourSecurePasswordHere
      - POSTGRES_DB=sonarqube
    volumes:
      - postgres_data:/var/lib/postgresql/data

volumes:
  sonar_data:
  sonar_extensions:
  sonar_logs:
  postgres_data:

networks:
  sonar-network:
    driver: bridge

Execute docker compose up -d to spin up the services. Navigate to http://your-vps-ip:9000 to verify access. The default credentials are admin/admin; you will be forced to update them immediately upon initial login.

4. Securing the System with Nginx and SSL

Exposing port 9000 directly to the internet is a severe security risk. To protect sensitive source code insights, configure Nginx as a reverse proxy coupled with a Let's Encrypt SSL certificate.

  1. Install Nginx: Run sudo apt install nginx -y.
  2. Configure Reverse Proxy: Point your domain (e.g., sonar.yourcompany.com) to localhost port 9000.
  3. Enforce HTTPS: Install Certbot via snap and run sudo certbot --nginx to acquire an automated, free SSL certificate.

This implementation guarantees that all static analysis metrics transmitted from external CI/CD pipelines to the VPS are completely encrypted.

5. Establishing Automated Code Scoring: Quality Gates

Once SonarQube is operational, you must define what constitutes "passing" code. This is managed via Quality Gates. A Quality Gate is a set of boolean conditions that a project must meet before it can be integrated into production branches.

A standard enterprise-grade Quality Gate includes conditions such as:

  • New Vulnerabilities: 0 (Critical or Major security flaws).
  • Code Coverage on New Code: Greater than 80%.
  • Duplicated Lines on New Code: Less than 3%.
  • Maintainability Rating: A (determined by technical debt ratio).

If a code push fails any of these thresholds, SonarQube fails the Quality Gate, signaling the CI/CD pipeline to block the deployment or merge request.

6. Integrating SonarQube into CI/CD Pipelines

To achieve true automation, the SonarScanner must run on every commit or pull request. Below is a declarative blueprint for integrating SonarQube scanning into a GitHub Actions workflow:

name: Code Security & Quality Analysis

on:
  push:
    branches: [ main, develop ]
  pull_request:
    types: [opened, synchronize, reopened]

jobs:
  sonar-scan:
    name: SonarQube Analysis
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0  # Shallow clones should be disabled for a better relevancy of analysis

      - name: SonarQube Scan
        uses: SonarSource/sonarqube-scan-action@v2
        env:
          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
          SONAR_HOST_URL: [https://sonar.yourcompany.com](https://sonar.yourcompany.com)
        with:
          args: >
            -Dsonar.projectKey=my_enterprise_app
            -Dsonar.sources=src
            -Dsonar.tests=tests
            -Dsonar.javascript.lcov.reportPaths=coverage/lcov.info

By leveraging GitHub Secrets to store your SONAR_TOKEN, your source code is continuously analyzed securely, with comprehensive reporting instantly visible on your VPS-hosted dashboard.

Conclusion: Cultivating a Secure Development Culture

Implementing an automated code analysis and scoring system with SonarQube on a VPS transitions security testing from a late-stage hurdle to an integrated, continuous process. It empowers development leaders with objective metrics regarding technical debt, code health, and structural vulnerabilities. By automating SAST, your engineering team can identify defects early in the lifecycle, significantly reducing remediation costs and safeguarding production systems from malicious exploitation.

Building an Automated Code Analysis and Scoring System: Deploying SonarQube SAST on a Virtual Private Server (VPS) | DPTCloud