Back to articles
Technology Insight

Deploying PocketBase on a VPS: The Minimalist Backend for Lean SaaS Applications

May 30, 2026

Introduction: The Lean SaaS Dilemma

In the modern software-as-a-service (SaaS) ecosystem, speed to market and operational efficiency are paramount. For independent developers, startups, and small engineering teams, building a scalable backend often presents a paradox. Traditional architectures require orchestrating multiple moving parts: a database server (like PostgreSQL), an authentication service (like Auth0), a file storage solution (like AWS S3), and a custom API layer. Managing this overhead on a limited budget consumes precious cycles that could otherwise be spent perfecting the core user experience.

Enter PocketBase. As an open-source, single-file Go backend, PocketBase consolidates an embedded SQLite database, user authentication, real-time subscriptions, and a file storage web-admin interface into a single, highly performant executable. When paired with a cost-effective Virtual Private Server (VPS), PocketBase emerges as a disruptive solution for lean SaaS products, offering maximum utility with minimal infrastructure friction. This article provides a comprehensive, production-ready blueprint for deploying PocketBase on a VPS.

Why PocketBase? Architecture and Advantages

Before diving into the deployment mechanics, it is essential to understand why PocketBase is uniquely suited for small to medium SaaS applications. At its core, PocketBase leverages an embedded SQLite database optimized with Write-Ahead Logging (WAL) mode. This architectural choice yields exceptional read and write speeds, frequently outperforming network-bound database clusters for moderate workloads.

Key Architectural Benefits:

  • Single-File Binary: The entire backend runs from a single executable file, eliminating complex dependencies and runtime environment configurations.
  • Embedded SQLite: Offers zero-configuration database management while easily handling thousands of concurrent requests when properly tuned.
  • Built-in Authentication & File Storage: PocketBase natively supports OAuth2 providers (Google, GitHub, Apple), email/password auth, and local or S3-compatible object storage out of the box.
  • Real-time WebSockets: Subscriptions are handled natively, allowing you to build reactive dashboards and real-time features without configuring a separate Redis or Socket.io server.

By deploying PocketBase on an independent VPS, you retain absolute ownership of your data, bypass vendor lock-in, and eliminate the unpredictable usage-based pricing models common among serverless platforms.

Prerequisites and VPS Preparation

To successfully implement this deployment, ensure you possess the following foundational elements:

  1. A VPS instance running a modern Linux distribution (e.g., Ubuntu 22.04 LTS or newer) with SSH access.
  2. A registered domain name pointing to your VPS IP address (e.g., api.yoursaas.com).
  3. Basic familiarity with the Linux command-line interface.

Step 1: System Updates and Security Hardening

First, establish an SSH connection to your VPS and update the system packages to their latest versions to patch potential security vulnerabilities:

sudo apt update && sudo apt upgrade -y

Next, configure a basic Uncomplicated Firewall (UFW) to secure your ports, allowing only SSH, HTTP, and HTTPS traffic:

sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable

Downloading and Configuring PocketBase

PocketBase is distributed as a pre-compiled binary. We will create a dedicated system user to isolate the application process, enhancing security posture by adhering to the principle of least privilege.

Step 2: Isolate the PocketBase Process

Create a system user and an associated application directory:

sudo useradd -r -m -d /var/www/pocketbase -s /bin/false pocketbase
cd /var/www/pocketbase

Step 3: Fetch the Binary

Retrieve the latest stable release of PocketBase from the official GitHub repository. (Note: Ensure you verify the latest version tag prior to download):

sudo wget [https://github.com/pocketbase/pocketbase/releases/download/v0.24.4/pocketbase_0.24.4_linux_amd64.zip](https://github.com/pocketbase/pocketbase/releases/download/v0.24.4/pocketbase_0.24.4_linux_amd64.zip)
sudo apt install unzip -y
sudo unzip pocketbase_0.24.4_linux_amd64.zip
sudo rm pocketbase_0.24.4_linux_amd64.zip

Set correct ownership permissions so the isolated user can manage the execution and database writes:

sudo chown -R pocketbase:pocketbase /var/www/pocketbase

Establishing Persistence with Systemd

To ensure PocketBase runs continuously in the background and automatically restarts upon server reboots or unexpected process failures, we must configure a Systemd service unit file.

Step 4: Create the Service File

Open a new service file using your preferred text editor:

sudo nano /etc/systemd/system/pocketbase.service

Populate the file with the following configuration block:[Unit] Description=PocketBase SaaS Backend After=network.target [Service] Type=simple User=pocketbase Group=pocketbase WorkingDirectory=/var/www/pocketbase ExecStart=/var/www/pocketbase/pocketbase serve --http="127.0.0.1:8090" Restart=always RestartSec=5 [Install] WantedBy=multi-user.target

Security Note: Binding the application service to 127.0.0.1:8090 ensures that the PocketBase HTTP server is internal-only. It cannot be accessed directly from the public internet, mitigating direct attacks on the application port. We will expose it safely via a reverse proxy.

Save and close the file, then enable and initiate the service:

sudo systemctl daemon-reload
sudo systemctl enable pocketbase
sudo systemctl start pocketbase

Configuring Nginx as a Reverse Proxy with SSL

To safely route external traffic to PocketBase and enable HTTPS encryption, we will utilize Nginx alongside Let's Encrypt certificates.

Step 5: Install Nginx

Install the web server package:

sudo apt install nginx -y

Step 6: Configure the Server Block

Create a dedicated Nginx configuration file for your SaaS domain:

sudo nano /etc/nginx/sites-available/pocketbase

Insert the following configuration layout, substituting your actual domain name:

server {
    listen 80;
    server_name api.yoursaas.com;

    location / {
        proxy_pass [http://127.0.0.1:8090](http://127.0.0.1:8090);
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # Enable WebSockets support for real-time events
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}

Link the configuration to enable it, verify correctness, and restart Nginx:

sudo ln -s /etc/nginx/sites-available/pocketbase /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl restart nginx

Step 7: Automated Let's Encrypt SSL Provisioning

Secure the transport layer completely using Certbot to fetch and maintain free, auto-renewing SSL certificates:

sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d api.yoursaas.com

Follow the interactive prompts to complete the automated HTTPS deployment. Certbot will rewrite your Nginx file seamlessly to handle SSL redirection safely.

Production Considerations and Optimization

While PocketBase is remarkably performant right out of the box, operating a live SaaS app requires deliberate maintenance habits. Implementing database backups and optimizing operating system file limits will safeguard against unexpected operational bottlenecks.

Automated Backups

PocketBase includes a built-in backup utility accessible via its admin UI or command line. Because SQLite writes to local files, backing up your database is as simple as copying the pb_data folder. It is highly recommended to schedule a cron job that executes a nightly backup and uploads the archive to off-site object storage (such as AWS S3 or Cloudflare R2).

Increasing File Descriptor Limits

Because SQLite handles requests concurrently and every real-time connection maintains an open connection file handle, high traffic spikes can occasionally exhaust default Linux limits. To prevent this, modify system resource parameters in /etc/security/limits.conf by adding:

pocketbase soft nofile 65535
pocketbase hard nofile 65535

Conclusion: Embracing Architectural Minimalism

Deploying PocketBase on a self-hosted VPS strikes an exceptional equilibrium for SaaS founders seeking velocity without astronomical infrastructure bills. By combining the database, API layer, and user management into an optimized single binary, you strip away layers of continuous integration overhead and architectural vulnerability. As your product grows, this setup can comfortably scale to accommodate millions of operations monthly on a modest VPS instance. Start lean, retain complete ownership over your architecture, and channel your focus into what truly matters: delivering direct, tangible value to your target market.

Deploying PocketBase on a VPS: The Minimalist Backend for Lean SaaS Applications | DPTCloud