Back to articles
Technology Insight

Self-Hosting a Lightweight Firebase Auth Alternative: Deploying SuperTokens in a Docker Rootless Environment

June 6, 2026

Introduction: The Shift Away from Proprietary Auth Providers

In the modern cloud-native landscape, authentication is the gateway to application security. For years, Google's Firebase Authentication has been the default choice for startups and enterprises alike due to its rapid setup and ease of use. However, as applications scale, organizations increasingly encounter significant challenges with proprietary cloud providers: unpredictable pricing tiers, vendor lock-in, compliance rigidities (such as GDPR and HIPAA), and data sovereignty concerns. Sending sensitive user credentials to a third-party managed service is no longer an acceptable risk for many enterprise security architectures.

To mitigate these challenges, engineering teams are turning toward open-source, self-hosted identity and access management (IAM) solutions. Among the contenders, SuperTokens stands out as a highly customizable, lightweight, and developer-friendly alternative to Firebase Auth. When paired with a Docker Rootless deployment strategy, it forms an exceptionally secure, isolated, and resource-efficient authentication infrastructure. This guide provides a comprehensive blueprint for deploying SuperTokens in a production-ready, security-hardened Docker Rootless environment.


Why Choose SuperTokens as Your Firebase Alternative?

While platforms like Keycloak are powerful, they are often notoriously resource-heavy and complex to configure. SuperTokens solves this by providing a modular, architecture-first approach to identity management. It splits the architecture into two distinct components: the frontend/backend SDKs that manage the application logic, and the SuperTokens Core, a self-hosted HTTP service responsible for database interactions, cryptography, and session management.

Here is why SuperTokens serves as an ideal replacement for Firebase Auth:

  • Granular Data Control: Your user data remains strictly within your isolated database instances, completely eliminating third-party data tracking or leaks.
  • Advanced Session Management: SuperTokens provides out-of-the-box, secure anti-CSRF tokens and rotating refresh tokens, drastically reducing the risk of session hijacking.
  • Extensive Recipe System: Easily enable or disable features like Email/Password login, Passwordless (OTP/Magic Links), Social Third-Party OAuth (Google, Apple, GitHub), and Multi-Factor Authentication (MFA).
  • Lightweight Resource Footprint: Unlike heavy Java-based IAM solutions, the SuperTokens Core service is highly optimized, consuming minimal CPU and RAM under heavy concurrent traffic loads.

Maximizing Security with Docker Rootless

Deploying a self-hosted authentication service means assuming full responsibility for its underlying infrastructure security. If a vulnerability is discovered within the containerized application or its dependencies, an attacker exploiting the container running as the standard root user could potentially gain root privileges on the entire host machine.

To prevent this catastrophic scenario, we utilize Docker Rootless mode. Docker Rootless allows the Docker daemon and containers to run inside a user namespace without requiring administrative root privileges on the host. Even if the SuperTokens container or the underlying database is compromised, the attacker remains trapped within an unprivileged user context on the host engine, strictly mitigating lateral movement or system-wide exploitation.


System Architecture Overview

Before executing the deployment, it is vital to visualize how the system components interact inside the unprivileged user space. The stack consists of three core structural pillars:

  1. The Edge Layer (Reverse Proxy): Handles incoming HTTPS requests, terminates TLS, and securely routes traffic to the internal unprivileged network interface.
  2. The Core Layer (SuperTokens Core): A stateless container running the SuperTokens engine, handling authorization flows, token issuance, and cryptography.
  3. The Storage Layer (PostgreSQL Database): A dedicated database instance optimized to store user credentials, metadata, and active session states securely.
Security Note: In a production environment, ensure that all internal network traffic between the SuperTokens Core and the PostgreSQL database is strictly isolated via internal Docker networks and encrypted using TLS.

Step-by-Step Deployment Guide

Step 1: Preparing the Host for Docker Rootless

First, ensure your Linux host meets the prerequisites for running unprivileged user namespaces. Execute the following commands to install uidmap dependencies and set up the unprivileged user environment:

# Install necessary dependencies on Ubuntu/Debian
sudo apt-get update && sudo apt-get install -y uidmap dbus-user-session

# Set up the non-root deployment user
sudo useradd -m -s /bin/bash authadmin
sudo loginctl enable-linger authadmin
sudo su - authadmin

Once logged in as the unprivileged authadmin user, install Docker Rootless by executing the official installation script:

curl -fsSL [https://get.docker.com/rootless](https://get.docker.com/rootless) | sh

# Append environment variables to your .bashrc
echo 'export PATH=$HOME/bin:$PATH' >> ~/.bashrc
echo 'export DOCKER_HOST=unix://$XDG_RUNTIME_DIR/docker.sock' >> ~/.bashrc
source ~/.bashrc

Step 2: Designing the Docker Compose Configuration

With the rootless environment active, create a dedicated project directory and configure the multi-container environment via a docker-compose.yml file. We will define both the SuperTokens Core service and a hardened PostgreSQL database instance:

version: '3.8'

services:
  supertokens-db:
    image: postgres:15-alpine
    environment:
      POSTGRES_USER: supertokens_user
      POSTGRES_PASSWORD: SecretProductionPassword123!
      POSTGRES_DB: supertokens
    volumes:
      - ./db-data:/var/lib/postgresql/data
    networks:
      - auth-network
    restart: always

  supertokens-core:
    image: supertokens/supertokens-postgresql:9.2
    depends_on:
      - supertokens-db
    ports:
      - "3567:3567"
    environment:
      POSTGRES_CONNECTION_URI: "postgresql://supertokens_user:SecretProductionPassword123!@supertokens-db:5432/supertokens"
      API_KEYS: "Your-Secure-Global-SuperTokens-API-Key-Here"
    networks:
      - auth-network
    restart: always

networks:
  auth-network:
    driver: bridge

Step 3: Launching and Verifying the Authentication Cluster

Initialize your containerized network stack by executing the Docker Compose daemon command within the unprivileged user terminal context:

docker compose up -d

To guarantee that your instances are operating soundly without hidden errors, query the application's health status via an HTTP handshake request:

curl http://localhost:3567/hello

If successfully initialized, the SuperTokens Core will return a simple Hello string or a JSON configuration status, validating that your self-hosted, lightweight Firebase alternative is officially online and running securely in an isolated, non-root user space.


Conclusion: Future-Proofing Your Identity Infrastructure

Transitioning from Firebase Authentication to a self-hosted SuperTokens setup deployed via Docker Rootless is a strategic move for any security-conscious business. It mitigates unpredictable vendor scaling costs, halts external data aggregation, and hardens the host operating system against potential security container breaches. By taking complete ownership of your identity stack today, you ensure that your business remains highly compliant, fiercely independent, and prepared for future enterprise-grade growth.