Back to articles
Technology Insight

Self-Hosting a Lightweight Firebase Auth Alternative: Deploying SuperTokens in a Docker Rootless Environment

June 7, 2026

Introduction: The Shift Away from Proprietary Auth Providers

In the modern web development ecosystem, authentication is a foundational pillar of any application. For years, developers have flocked to Backend-as-a-Service (BaaS) platforms like Firebase Authentication for its ease of integration and generous free tier. However, as applications scale and data privacy regulations tighten, engineering teams are increasingly encountering the limitations of proprietary, cloud-hosted auth solutions. Vendor lock-in, unpredictable pricing tiers, and compliance anxieties regarding user data sovereignty have sparked a massive migration toward self-hosted alternatives.

Enter SuperTokens: an open-source, highly customizable, and remarkably lightweight authentication solution designed to compete directly with Firebase Auth, Auth0, and Keycloak. Unlike heavy enterprise identity providers, SuperTokens focuses on providing an optimal balance between modular architecture and developer experience. But simply choosing the right software is only half the battle; how you deploy it matters just as much. In this technical deep dive, we will explore how to architecture and deploy a production-ready SuperTokens instance using Docker Rootless—an advanced containerization approach that eliminates root privileges, dramatically minimizing your infrastructure's attack surface.

---

Why SuperTokens Over Firebase Auth?

While Firebase Auth remains popular, it abstracts away control over your user database, which can be a critical compliance issue under frameworks like GDPR, HIPAA, or CCPA. SuperTokens addresses these operational challenges through a decoupled architecture consisting of an open-source core (written in Java/Go) and dedicated frontend/backend SDKs.

Here is why forward-thinking development teams are making the switch:

  • Data Ownership and Sovereignty: Your user credentials, session data, and access logs reside entirely within your own managed databases.
  • Cost Predictability: Eliminate the risk of sudden bill spikes tied to Monthly Active Users (MAUs) or verification SMS volumes.
  • Extensive Customization: SuperTokens allows deep overrides of authentication workflows, token schemas, and UI elements without hitting platform-defined ceilings.
  • Resource Efficiency: The core engine is built to be extremely lightweight, consuming significantly less memory and CPU than heavyweight alternatives like Keycloak.
---

The Imperative of Docker Rootless for Security Hardening

Deploying self-hosted infrastructure requires a strict adherence to security best practices. By default, the standard Docker daemon runs with root privileges. If an attacker manages to exploit a vulnerability within a containerized application, they could potentially escape the container container boundary and gain full root access to the host operating system.

Docker Rootless mode mitigates this catastrophic risk entirely. It allows the Docker daemon and containers to run inside a user namespace without root privileges. Even in the highly unlikely event of a container breakout, the malicious actor is confined to an unprivileged user account on the host system, rendering standard privilege-escalation exploits ineffective. For a critical piece of infrastructure like your identity provider, combining SuperTokens with Docker Rootless creates a defense-in-depth architecture.

---

Prerequisites and Environment Preparation

Before launching our deployment, ensure your host environment meets the necessary structural criteria. We will be utilizing a Linux-based virtual private server (VPS) running Ubuntu 22.04 LTS or later.

1. Installing Docker Rootless Dependencies

Docker Rootless relies on newuidmap and newgidmap to allocate user and group IDs within the unprivileged namespace. Install these dependencies via your package manager:

sudo apt-get update
sudo apt-get install -y dbus-user-session uidmap

2. Configuring Docker in Rootless Mode

Disable the system-wide Docker service if it is already installed, and run the official installation script under a non-root deployment user:

curl -fsSL [https://get.docker.com/rootless](https://get.docker.com/rootless) | sh

Following the installation script's prompt, append the necessary environment variables to your ~/.bashrc file to ensure your shell can communicate with the rootless daemon socket:

export PATH=$HOME/bin:$PATH
export DOCKER_HOST=unix://$XDG_RUNTIME_DIR/docker.sock

Apply the changes by running source ~/.bashrc and verify the status using docker info. Look for the line indicating Security Options: rootless.

---

Step-by-Step Architecture Deployment

Our production-grade deployment consists of two primary components: the SuperTokens Core container and a PostgreSQL database container acting as the persistent storage layer. We will coordinate these services using Docker Compose within our rootless environment.

1. Structuring the Project Directory

Create a dedicated workspace directory on your host to store configuration files and persistent volume data:

mkdir -p ~/supertokens-auth/postgres-data
cd ~/supertokens-auth

2. Crafting the Docker Compose Configuration

Create a docker-compose.yml file. Notice that we bind ports above 1024, as rootless containers cannot natively bind to privileged system ports (like 80 or 443) without explicit kernel adjustments.

version: '3.8'

services:
  supertokens-db:
    image: postgres:15-alpine
    container_name: supertokens-db
    environment:
      POSTGRES_USER: supertokens_user
      POSTGRES_PASSWORD: StrongSecurePassword123!
      POSTGRES_DB: supertokens
    volumes:
      - ./postgres-data:/var/lib/postgresql/data
    ports:
      - "5432:5432"
    restart: unless-stopped
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U supertokens_user -d supertokens"]
      interval: 5s
      timeout: 5s
      retries: 5

  supertokens-core:
    image: supertokens/supertokens-postgresql:9.2
    container_name: supertokens-core
    depends_on:
      supertokens-db:
        condition: service_healthy
    ports:
      - "3567:3567"
    environment:
      POSTGRES_CONNECTION_URI: "postgresql://supertokens_user:StrongSecurePassword123!@supertokens-db:5432/supertokens"
      API_KEYS: "YourSecretApiKeyChangeMe"
    restart: unless-stopped
Security Warning: Always replace placeholders like StrongSecurePassword123! and YourSecretApiKeyChangeMe with cryptographically secure strings generated using utilities such as openssl rand -hex 32.

3. Initializing the Services

With the composition script finalized, launch your decoupled authentication stack by executing the standard compose detach command:

docker compose up -d

Monitor the initialization logs to ensure successful connection handshakes between the SuperTokens engine core and the database server:

docker compose logs -f supertokens-core
---

Integrating SuperTokens with Your Application

Once your rootless core engine is active, integrating it into your tech stack requires linking SuperTokens' backend and frontend SDKs. Below is a conceptual implementation architectural outline.

Backend SDK Integration (Node.js / Express Example)

Install the required driver package inside your backend ecosystem: npm install supertokens-node. Initialize the framework to point toward your self-hosted instance:

import supertokens from "supertokens-node";
import Session from "supertokens-node/recipe/session";
import EmailPassword from "supertokens-node/recipe/emailpassword";

supertokens.init({
    framework: "express",
    supertokens: {
        connectionURI: "http://localhost:3567",
        apiKey: "YourSecretApiKeyChangeMe",
    },
    appInfo: {
        appName: "Enterprise Platform",
        apiDomain: "[https://api.yourdomain.com](https://api.yourdomain.com)",
        websiteDomain: "[https://yourdomain.com](https://yourdomain.com)",
        apiBasePath: "/auth",
    },
    recipeList: [
        EmailPassword.init(),
        Session.init()
    ]
});

Frontend SDK Initialization (React Example)

On your frontend application layer, install supertokens-auth-react and wrap your high-level component structures to handle user session states securely, ensuring cookies are transmitted natively over secure domains.

---

Production Operations & Best Practices

Moving a self-hosted authentication service into production demands rigorous attention to telemetry, backup mechanisms, and scaling boundaries.

  • Reverse Proxy and TLS Encryption: Never expose the SuperTokens port 3567 directly to the public internet. Always deploy a reverse proxy like Nginx, Caddy, or Traefik in front of the core to manage automated Let's Encrypt SSL/TLS certificate handshakes.
  • Automated Backups: Schedule daily cron jobs utilizing pg_dump from inside the rootless context to back up your user database schema and data records to encrypted, off-site cloud object storage.
  • High Availability Configuration: The SuperTokens Core is stateless. You can scale horizontally by running multiple core instances behind a load balancer, all communicating with the same managed, high-availability PostgreSQL cluster.
---

Conclusion

Transitioning from a cloud-managed service like Firebase Auth to a self-hosted SuperTokens setup on Docker Rootless strikes the ultimate balance between absolute data ownership, cost efficiency, and infrastructure hardening. By eliminating root privilege requirements from your containerization layers, you protect your infrastructure against critical escalation vulnerabilities while retaining total sovereignty over your application's identity protocols. As data privacy regulations continue to expand globally, taking control of your authentication layer is no longer just an engineering optimization—it is a strategic business necessity.