Building Your Own Self-Hosted Canva Alternative: A Comprehensive Guide to Deploying Penpot on a VPS
Introduction: The Growing Need for Design Autonomy
In modern business operations, visual content is paramount. From marketing collateral and social media graphics to UI/UX prototypes, organizations rely heavily on collaborative design platforms. For years, proprietary SaaS solutions like Canva and Figma have dominated this landscape. However, as enterprise scale increases, so do the associated challenges: rising subscription overheads, vendor lock-in, and stringent data compliance risks.
For organizations seeking absolute data sovereignty and cost predictability, the open-source movement offers a robust alternative: Penpot. Positioned as the premier open-source, web-based design and prototyping platform, Penpot delivers professional-grade vector graphics and collaborative features without the proprietary restrictions. By deploying Penpot as a self-hosted Canva alternative on a Virtual Private Server (VPS), your business can establish an independent, secure, and highly scalable creative workstation.
Why Choose Penpot as Your Self-Hosted Design Platform?
Penpot is not merely a cost-cutting alternative; it is a sophisticated platform built on open standards like SVG (Scalable Vector Graphics). This foundational architecture ensures that your designs remain natively compatible with the web, preventing proprietary file format lock-in.
Deploying Penpot on your own infrastructure yields several strategic advantages:
- Complete Data Privacy: All proprietary design assets, corporate branding materials, and user data remain on your infrastructure, complying strictly with GDPR, CCPA, or localized data residency laws.
- Zero Seat-Based Licensing Costs: Scale your internal and external design teams infinitely without worrying about fluctuating monthly per-user fees.
- Uncompromised Performance: By utilizing a dedicated VPS, you eliminate the noisy-neighbor effect typical of shared SaaS infrastructures, ensuring rapid rendering and seamless real-time collaboration.
- Extensive Customization: Gain full access to configuration files, allowing seamless integration with corporate single sign-on (SSO) systems and automated backup pipelines.
Prerequisites and System Requirements
Before initiating the deployment process, ensure your infrastructure meets the necessary baseline requirements to handle real-time collaborative rendering smoothly.
Recommended VPS Hardware Specifications
- CPU: Minimum 2 vCPUs (4 vCPUs recommended for production environments with multiple concurrent users).
- RAM: 4GB RAM minimum (8GB RAM preferred to accommodate PostgreSQL and Redis caching efficiently).
- Storage: 40GB+ SSD/NVMe storage (scalable based on the volume of visual assets stored).
- OS: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS (highly recommended for stability and packages availability).
Software and Network Prerequisites
Ensure you have a fully qualified domain name (FQDN), such as design.yourcompany.com, pointed to your VPS IP address via an A Record. Additionally, Docker and Docker Compose must be pre-installed on the server instance.
Step-by-Step Deployment Guide
Follow this structured, technical blueprint to deploy Penpot using Docker Compose, securing it with an Nginx reverse proxy and Let's Encrypt SSL certificates.
Step 1: System Update and Docker Installation
Connect to your VPS via SSH and update the core system packages to ensure a secure environment:
sudo apt update && sudo apt upgrade -y
sudo apt install curl git software-properties-common -y
If Docker is not yet installed, execute the official convenience script:
curl -fsSL [https://get.docker.com](https://get.docker.com) -o get-docker.sh
sudo sh get-docker.sh
Step 2: Downloading the Official Penpot Configuration
Create a dedicated directory for your Penpot deployment to keep configuration assets organized:
mkdir -p /opt/penpot && cd /opt/penpot
Download the official Docker Compose configuration manifest provided by the Penpot core team:
wget [https://raw.githubusercontent.com/penpot/penpot/main/docker/images/docker-compose.yaml](https://raw.githubusercontent.com/penpot/penpot/main/docker/images/docker-compose.yaml)
Step 3: Configuring Environment Variables
Penpot relies on a dedicated environment file to manage application keys, database credentials, and email server configurations. Open the configuration file to customize parameters:
Ensure you modify the essential keys within the configuration file to harden security:
Crucial Security Notice: Always replace default database passwords and secret keys before launching any containerized application into a production environment.
PENPOT_PUBLIC_URI: Set this to your exact domain (e.g.,[https://design.yourcompany.com](https://design.yourcompany.com)).PENPOT_DATABASE_PASSWORD: Define a complex, unique alphanumeric string for the PostgreSQL backend.PENPOT_SECRET_KEY: Generate a secure cryptographic random string to sign user sessions safely.
Configure SMTP settings accurately to enable user registration emails, password resets, and team invitations seamlessly.
Step 4: Launching the Penpot Services
With the configuration finalized, pull the verified container images and initialize the multi-container architecture in detached mode:
sudo docker compose up -d
Verify that all essential microservices—including the frontend, backend, asynchronous worker, Redis cache, and PostgreSQL database—are active and healthy:
sudo docker compose ps
Step 5: Securing with an Nginx Reverse Proxy and SSL
To expose Penpot securely over HTTPS, configure Nginx as a reverse proxy. Install Nginx along with the Certbot utility:
sudo apt install nginx certbot python3-certbot-nginx -y
Create a new server block configuration file at /etc/nginx/sites-available/penpot and include the following directive:
server {
listen 80;
server_name design.yourcompany.com;
location / {
proxy_pass http://localhost:9001;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# WebSockets support for real-time collaboration
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}
Enable the site and restart Nginx to apply changes:
sudo ln -s /etc/nginx/sites-available/penpot /etc/nginx/sites-enabled/
sudo systemctl restart nginx
Execute Certbot to provision a trusted Let's Encrypt SSL certificate automatically:
sudo certbot --nginx -d design.yourcompany.com
Post-Deployment Optimization and Backups
To guarantee business continuity, your self-hosted instance must incorporate a dependable optimization and backup protocol.
Automating Database Backups
Regularly export your PostgreSQL data to safeguard design files against accidental corruption or server failure. Implement a automated cron job that executes a standard database dump:
sudo docker compose exec -t penpot-postgres pg_dumpall -U penpot > /backup/penpot_backup_$(date +%F).sql
Performance Tuning
Monitor your memory footprint using docker stats. If your design team scales up significantly, allocate additional memory overhead to the Redis container to keep collaborative websocket connections fluid and ultra-responsive.
Conclusion: True Creative Independence
By investing the time to self-host Penpot on a private VPS, your enterprise achieves far more than cost containment. You establish a secure, localized corporate asset that protects intellectual property, scales freely according to organic demand, and maintains absolute adherence to open web standards. Transitioning to a self-hosted alternative eliminates subscription fatigue and places creative control exactly where it belongs—firmly in the hands of your organization.
