Back to articles
Technology Insight

Deploying Logto on a Cloud VPS: A Modern, Elegant Identity Management Solution (OIDC/OAuth2) for Enterprises

June 1, 2026

Introduction to Modern Identity Management

In the contemporary digital ecosystem, security and user experience are no longer mutually exclusive parameters. As businesses scale, managing user identities, securing API endpoints, and implementing robust authentication flows become critical operational requirements. Traditionally, development teams relied on heavy, complex legacy identity providers or expensive third-party Software-as-a-Service (SaaS) solutions like Auth0 or Okta.

However, the paradigm is shifting. Open-source and self-hosted Identity and Access Management (IAM) solutions have matured significantly. Among these, Logto has emerged as a disruptive force. Built on top of standard protocols like OpenID Connect (OIDC) and OAuth2, Logto offers an exceptionally beautiful, developer-centric interface combined with enterprise-grade security features. This guide provides a comprehensive, step-by-step walkthrough on how to configure and deploy the Logto Auth Server on a Cloud Virtual Private Server (VPS), delivering a self-hosted, highly customizable identity solution without the premium SaaS price tag.

Why Choose Logto Over Traditional IAM Solutions?

Selecting the right authentication infrastructure requires balancing developer velocity, maintenance overhead, and financial predictability. Logto addresses these challenges effectively through several distinct advantages:

1. Exceptional User and Developer Experience

Unlike traditional tools like Keycloak, which often require extensive front-end customization to look modern, Logto features a meticulously designed, out-of-the-box user interface. The sign-in experience is smooth, responsive, and easily brandable through a centralized administrative console. For developers, Logto provides an intuitive dashboard that simplifies application integration, webhooks management, and user auditing.

2. Standard-Based Security

Logto is built entirely on the OAuth2 and OpenID Connect (OIDC) specifications. This ensures compatibility with virtually any modern frontend framework (React, Vue, Next.js) and backend stack (Node.js, Python, Go, Java). It supports advanced authorization models, including Role-Based Access Control (RBAC), multi-tenant setups, and secure machine-to-machine (M2M) communication.

3. Cost Efficiency and Data Sovereignty

By hosting Logto on your own Cloud VPS, you eliminate the volatile monthly active user (MAU) pricing tiers associated with commercial identity providers. Furthermore, hosting your own instance guarantees complete data sovereignty—a critical requirement for compliance with regulations such as GDPR, CCPA, or localized cybersecurity laws.

Prerequisites and System Architecture

Before initiating the deployment process, ensure your infrastructure meets the following baseline technical specifications:

  • Cloud VPS: Minimum 1 vCPU, 2GB RAM running an LTS Linux distribution (Ubuntu 22.04 or 24.04 LTS recommended).
  • Database: A PostgreSQL instance (v14 or higher). This can be hosted on the same VPS or via a managed database service.
  • Domain Name: A dedicated domain or subdomain (e.g., auth.yourcompany.com) with DNS A/AAAA records pointed to your VPS IP address.
  • Software Dependencies: Docker Engine (v20.10+) and Docker Compose (v2.0+) installed on the host system.
Note: While Logto can run on 1GB of RAM in strict testing environments, 2GB is strongly advised for production environments to handle container spikes during heavy authentication traffic and database migrations.

Step-by-Step Deployment Guide via Docker Compose

Utilizing Docker Compose is the most reliable, reproducible method for deploying Logto and its associated services. Follow these structured steps to initialize your environment.

Step 1: Directory Setup and Environment Configuration

Connect to your Cloud VPS via SSH and create a dedicated workspace directory for your Logto deployment:mkdir -p /opt/logto && cd /opt/logto

Next, create an environment configuration file named .env to store essential variables securely. Populate it with your database credentials and primary endpoint details:

# Database Configuration
POSTGRES_USER=logto_admin
POSTGRES_PASSWORD=YourSecurePasswordHere
POSTGRES_DB=logto_core

# Logto Core Configuration
ENDPOINT=[https://auth.yourcompany.com](https://auth.yourcompany.com)
ADMIN_ENDPOINT=[https://admin.yourcompany.com](https://admin.yourcompany.com)
DB_URL=postgresql://logto_admin:YourSecurePasswordHere@postgres:5432/logto_core
PORT=3001
ADMIN_PORT=3002

Step 2: Crafting the Docker Compose File

Create a docker-compose.yml file within the same directory. This file defines the PostgreSQL database container, the initialization process for database schemas, and the core Logto engine container.

version: '3.8'

services:
  postgres:
    image: postgres:15-alpine
    container_name: logto-postgres
    environment:
      POSTGRES_USER: ${POSTGRES_USER}
      POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
      POSTGRES_DB: ${POSTGRES_DB}
    volumes:
      - pgdata:/var/lib/postgresql/data
    networks:
      - logto-network
    restart: always

  # Temporary container to execute database migrations
  logto-migration:
    image: ghcr.io/logto-io/logto:latest
    entrypoint: ["npm", "run", "alter"]
    environment:
      - DB_URL=${DB_URL}
    depends_on:
      - postgres
    networks:
      - logto-network

  logto:
    image: ghcr.io/logto-io/logto:latest
    container_name: logto-core
    environment:
      - DB_URL=${DB_URL}
      - ENDPOINT=${ENDPOINT}
      - ADMIN_ENDPOINT=${ADMIN_ENDPOINT}
      - PORT=${PORT}
      - ADMIN_PORT=${ADMIN_PORT}
    ports:
      - "127.0.0.1:3001:3001"
      - "127.0.0.1:3002:3002"
    depends_on:
      postgres:
        condition: service_healthy
      logto-migration:
        condition: service_completed_successfully
    networks:
      - logto-network
    restart: always

volumes:
  pgdata:

networks:
  logto-network:
    driver: bridge

Step 3: Executing the Deployment

With configurations in place, initiate the containers. The setup architecture safely ensures that the database schema migration completes successfully before spinning up the actual Logto engine application service:

docker compose up -d

Verify that all containers are operational by checking the process logs: docker compose ps.

Configuring Nginx Reverse Proxy and SSL Certificates

To expose Logto safely to the public internet, you must implement a reverse proxy. This setup handles incoming SSL/TLS encryption, terminating traffic at the proxy layer before forwarding requests to the internal Docker containers. This ensures your user credentials are never transmitted over unencrypted HTTP channels.

1. Install Nginx and Certbot

On your Ubuntu host, execute the following commands to install the Nginx web server and Let's Encrypt Certbot utility:

sudo apt update
sudo apt install nginx certbot python3-certbot-nginx -y

2. Configure Nginx Server Blocks

Create a dedicated Nginx configuration file for your Logto installation at /etc/nginx/sites-available/logto.conf:server { listen 80; server_name auth.yourcompany.com admin.yourcompany.com; location / { return 301 https://$host$request_uri; } }

Enable the site configuration by creating a symbolic link to the active sites folder and reloading Nginx:

sudo ln -s /etc/nginx/sites-available/logto.conf /etc/nginx/sites-enabled/
sudo systemctl reload nginx

3. Provision SSL Certificates

Execute Certbot to request and deploy trusted SSL certificates for both domains automatically:

sudo certbot --nginx -d auth.yourcompany.com -d admin.yourcompany.com

Certbot will automatically alter your Nginx configuration to support HTTP/2 and embed the correct paths to the generated SSL keys. Update your Nginx configuration blocks under the newly generated SSL server entries to proxy traffic to internal ports 3001 (for the main auth service) and 3002 (for the admin dashboard) respectively, ensuring proper headers like X-Forwarded-For and X-Forwarded-Proto are preserved.

Production Hardening and Best Practices

Running an identity provider demands strict adherence to system operational security. Consider implementing the following hardening steps prior to production rollouts:

  1. Database Backups: Implement cron jobs using pg_dump to routinely back up your PostgreSQL volumes to an off-site, encrypted storage repository daily.
  2. Isolate the Admin Console: Limit access to your admin domain (admin.yourcompany.com) by enforcing IP address whitelisting at the Nginx layer, or requiring an active corporate VPN connection to reach the management dashboard.
  3. Configure SMTP Settings immediately: Logto relies on transactional emails for critical paths like password resets, multi-factor authentication (MFA) setups, and account verifications. Integrate an enterprise service provider (e.g., SendGrid, Amazon SES) directly inside the Admin Console upon initial configuration.

Conclusion

Deploying Logto on a self-hosted Cloud VPS strikes an exceptional equilibrium between operational control, economic efficiency, and UI elegance. By structuring your deployment around Docker Compose and scaling securely behind an Nginx reverse proxy, you create a robust, production-ready environment capable of safeguarding enterprise workloads. With standard OIDC and OAuth2 capabilities ready, your development team can now confidently integrate secure single-sign-on (SSO) experiences into all corporate applications.

Deploying Logto on a Cloud VPS: A Modern, Elegant Identity Management Solution (OIDC/OAuth2) for Enterprises | DPTCloud