Back to articles
Technology Insight

Self-Hosting Activepieces on a VPS: The Ultimate Enterprise Guide to Open-Source Workflow Automation

May 27, 2026

Introduction: The Shift Toward Self-Hosted Automation

In the modern digital ecosystem, workflow automation is no longer a luxury; it is a core operational necessity. For years, proprietary Integration Platform as a Service (iPaaS) providers like Zapier and Make have dominated the market. However, as enterprises scale, they increasingly encounter substantial roadblocks with these commercial platforms, notably escalating subscription costs, strict task execution limits, and stringent data privacy regulations such as GDPR and HIPAA.

Enter Activepieces: a premier, open-source workflow automation platform designed specifically as a self-hosted alternative. By deploying Activepieces on your own Virtual Private Server (VPS), your organization can bypass third-party data processing, eliminate arbitrary per-task fees, and maintain absolute control over your automation infrastructure. This guide provides a definitive, production-ready blueprint for deploying, configuring, and securing Activepieces on a VPS.


Why Choose Activepieces Over Zapier or Make?

Before diving into the technical implementation, it is vital to understand the strategic advantages of transitioning to a self-hosted Activepieces instance:

  • Data Sovereignty and Compliance: Because the entire infrastructure resides on your VPS, sensitive customer data, API keys, and proprietary workflows never leave your secure perimeter. This is essential for industries handling protected health information (PHI) or financial records.
  • Cost Predictability: Commercial iPaaS models charge per task execution. A high-volume looping workflow can unexpectedly spike your monthly bill. With Activepieces on a VPS, your costs are flat and tied strictly to your underlying hardware compute power.
  • Extensibility: Being open-source, Activepieces allows developers to build custom pieces (integrations) using a robust TypeScript framework, offering flexibility that closed ecosystems simply cannot match.

Prerequisites and System Architecture

To ensure a stable, production-grade deployment, your environment should meet or exceed the following technical specifications:

1. Hardware Requirements

  • CPU: 2 vCPUs minimum (4 vCPUs recommended for high-concurrency environments).
  • RAM: 4 GB RAM minimum (8 GB recommended to comfortably run PostgreSQL, Redis, and the Activepieces worker pool).
  • Storage: 20 GB+ of SSD/NVMe storage (scaled based on your execution log retention policy).

2. Software Environment

  • A clean installation of a modern Linux distribution (e.g., Ubuntu 22.04 LTS or 24.04 LTS).
  • A fully qualified domain name (FQDN) pointed via DNS A-Record to your VPS public IP address (e.g., automation.yourcompany.com).
  • Docker Engine (v20.10+) and Docker Compose (v2.0+) installed on the host system.

Step-by-Step Deployment Guide

Step 1: System Preparation and Docker Installation

First, establish an SSH connection to your VPS and update the system packages to their latest stable versions:

sudo apt update && sudo apt upgrade -y

Next, install Docker and Docker Compose if they are not already present on the system:

sudo apt install docker.io docker-compose-plugin -y
sudo systemctl enable --now docker

Step 2: Configuring the Activepieces Directory and Environment

Create a dedicated directory to house your configuration and persistent data volumes. This keeps your deployment organized and simplifies backup routines:

mkdir -p /opt/activepieces
cd /opt/activepieces

Activepieces relies heavily on environment variables to manage database connections, encryption keys, and system behavior. Create an .env file within this directory:

nano .env

Populate the file with the following production-grade configuration template. Ensure you replace the placeholder values with secure, randomly generated strings:

Security Note: Never use default passwords or short strings for encryption keys in a production environment. Use a utility like openssl rand -hex 32 to generate secure values.
AP_ENVIRONMENT=production
AP_ENCRYPTION_KEY=your_super_secret_32_byte_encryption_key
AP_JWT_SECRET=your_secure_jwt_signing_secret

# Database Configuration
AP_POSTGRES_DATABASE=activepieces
AP_POSTGRES_USER=ap_admin
AP_POSTGRES_PASSWORD=secure_db_password_here

# Execution Mode
AP_EXECUTION_MODE=SANDBOXED

# URL Configuration
AP_FRONTEND_URL=[https://automation.yourcompany.com](https://automation.yourcompany.com)

Step 3: Crafting the Docker Compose File

Activepieces utilizes a multi-container architecture consisting of a frontend/backend server, a PostgreSQL database for structured data, and Redis for task queuing and caching. Create a docker-compose.yml file to orchestrate these services:

nano docker-compose.yml

Insert the following configuration block:

version: '3.8'

services:
  postgres:
    image: postgres:15-alpine
    container_name: activepieces_postgres
    environment:
      POSTGRES_DB: ${AP_POSTGRES_DATABASE}
      POSTGRES_USER: ${AP_POSTGRES_USER}
      POSTGRES_PASSWORD: ${AP_POSTGRES_PASSWORD}
    volumes:
      - postgres_data:/var/lib/postgresql/data
    restart: always

  redis:
    image: redis:7-alpine
    container_name: activepieces_redis
    restart: always

  activepieces:
    image: activepieces/activepieces:latest
    container_name: activepieces_server
    depends_on:
      - postgres
      - redis
    ports:
      - "8080:80"
    env_file:
      - .env
    environment:
      - AP_POSTGRES_HOST=postgres
      - AP_POSTGRES_PORT=5432
      - AP_REDIS_HOST=redis
      - AP_REDIS_PORT=6379
    volumes:
      - activepieces_data:/root/.activepieces
    restart: always

volumes:
  postgres_data:
  activepieces_data:

Step 4: Launching the Containers

With your environment and orchestration files firmly established, initialize the stack in detached mode:

sudo docker compose up -d

Verify that all containers are operational and running without errors by examining the process status and container logs:

sudo docker compose ps
sudo docker compose logs -f activepieces

Securing Your Instance with an Nginx Reverse Proxy and SSL

Exposing raw HTTP ports directly to the internet poses a severe security risk. To protect API keys and authentication payloads, you must implement an Nginx reverse proxy equipped with an SSL/TLS certificate from Let's Encrypt.

1. Install Nginx and Certbot

sudo apt install nginx certbot python3-certbot-nginx -y

2. Configure Nginx

Create a new server block configuration file for your activepieces instance:

sudo nano /etc/nginx/sites-available/activepieces

Add the following configuration block, replacing the domain name with your own:

server {
    listen 80;
    server_name automation.yourcompany.com;

    location / {
        proxy_pass http://localhost:8080;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # WebSockets support for real-time log streaming
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}

Enable the site configuration and restart Nginx to apply the changes:

sudo ln -s /etc/nginx/sites-available/activepieces /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl restart nginx

3. Provision a Let's Encrypt SSL Certificate

Execute Certbot to automatically provision and inject a valid SSL certificate into your Nginx setup:

sudo certbot --nginx -d automation.yourcompany.com

Follow the on-screen prompts to enforce an automatic HTTPS redirect. Your self-hosted automation dashboard is now fully encrypted and securely accessible via browser at [https://automation.yourcompany.com](https://automation.yourcompany.com).


Day-Two Operations: Post-Installation and Maintenance

Deploying the software is only the first phase. Maintaining an enterprise automation engine requires regular upkeep and operational awareness.

1. Initial Administrator Setup

Upon your first visit to the secured URL, you will be prompted to create the primary administrator account. Enter your corporate email and a robust password. Once inside the dashboard, you can explore the extensive template library or begin designing custom linear workflows immediately.

2. Executing Upgrades

Activepieces is actively developed, with performance enhancements and new pieces released frequently. To update your instance to the latest version, execute this standard sequence:

cd /opt/activepieces
sudo docker compose pull
sudo docker compose up -d --remove-orphans

3. Backup Strategy

To guard against data loss, configure a automated cron job to regularly back up the .env file, the configuration directory, and perform a database dump of the PostgreSQL container using the pg_dump utility.


Conclusion: Embracing Sovereign Automation

By migrating your automation workloads from expensive proprietary ecosystems to a self-hosted Activepieces instance on a VPS, you unlock uncompromised data privacy, infinite scaling potential, and massive cost savings. With complete control over your workflows, your development and operational teams can build highly integrated solutions tailored precisely to your business requirements without worrying about arbitrary task quotas. Your journey toward fully sovereign enterprise automation begins with this single deployment.

Self-Hosting Activepieces on a VPS: The Ultimate Enterprise Guide to Open-Source Workflow Automation | DPTCloud