Deploying Windmill on a VPS: The Ultimate Open-Source Alternative to Retool and Temporal for DevOps Engineers
Introduction: The DevOps Orchestration Dilemma
Modern DevOps engineers frequently find themselves caught between two distinct paradigms when managing infrastructure, automation, and internal tooling. On one hand, they need a robust internal developer platform (IDP) or user interface to empower teams—a need traditionally fulfilled by platforms like Retool. On the other hand, they require a resilient, distributed workflow engine to handle long-running, stateful background jobs and complex asynchronous pipelines—the classic domain of Temporal.
Maintaining separate stacks for these two requirements introduces significant operational overhead, complex state synchronization issues, and fragmented developer experiences. Enter Windmill: an open-source, ultra-fast developer platform that unifies workflow orchestration and internal UI generation into a single, cohesive ecosystem. Powered natively by TypeScript and Python, Windmill allows engineering teams to turn simple scripts into production-ready web apps, low-code dashboards, and highly scalable background workflows instantly. In this comprehensive guide, we will explore why Windmill is a game-changer for DevOps engineers and provide a step-by-step blueprint for deploying it on a Virtual Private Server (VPS).
Why Windmill? The Best of Retool and Temporal Combined
Windmill is not just another low-code tool; it is a developer-first platform designed to eliminate the boilerplate code associated with building backend workflows and frontend dashboards. It bridges the gap between raw scripting and enterprise automation.
1. Native TypeScript and Python Support
Unlike traditional automation platforms that force developers into rigid, proprietary visual builders, Windmill prioritizes code. DevOps engineers can write scripts in their native languages—Python, TypeScript, Go, or Bash. Windmill automatically parses the main function's arguments to generate a validated UI form instantly. This means no more manually mapping JSON payloads to frontend inputs.
2. High-Performance Execution Engine
Written in Rust, Windmill's core execution engine is built for extreme speed and low latency. It boasts sub-millisecond overhead for script execution, making it significantly faster than heavy enterprise alternatives. For heavy workloads, Windmill scales horizontally via distributed worker nodes, giving you the resilience of Temporal without the daunting architectural complexity.
3. Embedded App Builder
While Retool requires complex data fetching setups to bind APIs to UI components, Windmill lets you build dashboards directly on top of your scripts. You can drag and drop UI components (tables, buttons, charts) and bind them directly to the outputs of your Python data pipelines or TypeScript cloud automation scripts.
Prerequisites for VPS Deployment
Before initiating the deployment process, ensure your Virtual Private Server meets the following minimum requirements to guarantee stability and performance under load:
- Operating System: Ubuntu 22.04 LTS or newer (recommended).
- Hardware Specs: Minimum 2 vCPUs and 4GB of RAM (8GB recommended for production environments handling concurrent workflows).
- Software: Docker Engine v20.10+ and Docker Compose v2.0+ installed.
- Networking: A fully qualified domain name (FQDN) pointed to your VPS public IP address, with ports 80 and 443 open.
Step-by-Step Architecture & Deployment Guide
Deploying Windmill on a self-hosted VPS gives you complete control over your data, compliance, and infrastructure costs. We will utilize a production-ready Docker Compose configuration that orchestrates Windmill's core components: the web frontend, the backend API server, worker nodes, and a PostgreSQL database for state management.
Step 1: Preparing the Server Environment
Connect to your VPS via SSH and update the system packages to their latest versions to prevent dependency conflicts:
sudo apt update && sudo apt upgrade -y
sudo apt install curl git build-essential -y
Step 2: Configuring the Docker Compose Stack
Create a dedicated directory for your Windmill deployment and navigate into it:
mkdir -p /opt/windmill && cd /opt/windmill
Next, create a docker-compose.yml file. This configuration sets up the Postgres database, the primary Windmill server, and the dedicated worker instances that execute your TypeScript and Python scripts:
Note: For production environments, always ensure you change the default database passwords and secret tokens to strong, randomly generated keys.
version: '3.8'
services:
db:
image: postgres:15-alpine
restart: unless-stopped
volumes:
- pgdata:/var/lib/postgresql/data
environment:
POSTGRES_DB: windmill
POSTGRES_USER: postgres
POSTGRES_PASSWORD: super_secure_password_change_me
ports:
- "5432:5432"
windmill-server:
image: ghcr.io/windmill-labs/windmill:main
restart: unless-stopped
depends_on:
- db
ports:
- "8000:8000"
environment:
- DATABASE_URL=postgres://postgres:super_secure_password_change_me@db:5432/windmill?sslmode=disable
- MODE=server
- JWT_SECRET=generate_a_long_random_string_here
windmill-worker:
image: ghcr.io/windmill-labs/windmill:main
restart: unless-stopped
depends_on:
- db
environment:
- DATABASE_URL=postgres://postgres:super_secure_password_change_me@db:5432/windmill?sslmode=disable
- MODE=worker
- NUM_WORKERS=4
volumes:
pgdata:
Step 3: Launching the Stack
With the configuration file ready, initialize the containers in detached mode using Docker Compose:
docker compose up -d
Verify that all services are up and running perfectly by inspecting the container statuses:
docker compose ps
Configuring a Reverse Proxy with Nginx and Let's Encrypt
To ensure your automation platform is secure, you should never expose port 8000 directly to the public internet. Instead, route your traffic through an Nginx reverse proxy secured with SSL certificates from Let's Encrypt.
Install Nginx and Certbot on your host system:
sudo apt install nginx certbot python3-certbot-nginx -y
Create a new Nginx configuration block for your Windmill domain:
sudo nano /etc/nginx/sites-available/windmill.conf
Paste the following reverse proxy configuration, replacing yourdomain.com with your actual domain:
server {
listen 80;
server_name yourdomain.com;
location / {
proxy_pass http://localhost:8000;
proxy_set_header Host $$host;
proxy_set_header X-Real-IP $$remote_addr;
proxy_set_header X-Forwarded-For $$proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $$scheme;
# WebSocket support for live logs
proxy_http_version 1.1;
proxy_set_header Upgrade $$http_upgrade;
proxy_set_header Connection "upgrade";
}
}
Enable the site configuration and restart Nginx:
sudo ln -s /etc/nginx/sites-available/windmill.conf /etc/nginx/sites-enabled/
sudo systemctl restart nginx
Finally, provision your SSL certificate to enforce HTTPS encryption across all platform interactions:
sudo certbot --nginx -d yourdomain.com
Best Practices for DevOps Engineers on Windmill
Deploying the platform is only the first step. To unlock the full power of Windmill as a self-hosted powerhouse for cloud infrastructure management, consider implementing these production-grade strategies:
- GitOps Integration: Windmill features native bidirectional Git synchronization. You can commit your Python and TypeScript code directly to GitHub or GitLab, and have Windmill sync changes automatically, maintaining a clean CI/CD lifecycle for your operational workflows.
- Strict Secret Management: Utilize Windmill’s encrypted variable store to manage cloud tokens, API keys, and database credentials safely. Avoid hardcoding variables within your scripts.
- Resource Constraints: For unpredictable scripts, configure execution timeouts and memory limits per worker container to ensure a single malfunctioning job does not degrade your entire VPS performance.
Conclusion
By migrating internal infrastructure management to Windmill, DevOps teams can bypass the licensing costs of Retool and avoid the steep learning curve of Temporal. Windmill’s unified approach to code-first workflows and lightning-fast execution creates an ideal landscape for infrastructure automation, auto-remediation loops, and interactive developer dashboards. Hosted on your own VPS, it provides complete data autonomy with unmatched processing performance.
