Back to articles
Technology Insight

Self-Hosting Appwrite on a VPS: The Ultimate Guide to an Open-Source Firebase Alternative

June 3, 2026

Introduction: The Shift Toward Open-Source Backend-as-a-Service

For years, Google Firebase has been the go-to Backend-as-a-Service (BaaS) platform for developers looking to build and scale applications rapidly. It handles authentication, databases, and file storage seamlessly, allowing teams to focus entirely on frontend user experiences. However, as applications grow, developers frequently encounter Firebase's limitations: unpredictable pricing models, rigid querying capabilities, and data residency concerns. The lack of infrastructure control often leads to costly architectural rewrites.

Enter Appwrite—a powerful, open-source alternative that provides all the essential backend features of Firebase but gives you 100% control over your data and infrastructure. By self-hosting Appwrite on a Virtual Private Server (VPS), you eliminate vendor lock-in, enjoy predictable monthly hosting fees, and retain absolute data sovereignty. This comprehensive guide will walk you through the entire process of deploying Appwrite on your own VPS, configuring security, and preparing your infrastructure for production workloads.

Why Choose Appwrite Over Google Firebase?

Before diving into the technical setup, it is vital to understand why modern engineering teams are migrating to Appwrite. While Firebase offers a convenient ecosystem, self-hosted Appwrite delivers several distinct business and technical advantages:

  • Predictable Infrastructure Costs: Firebase charges based on usage metrics like document reads, writes, and network egress. A sudden surge in traffic can lead to astronomical bills. Hosting Appwrite on a VPS means you pay a fixed monthly fee for your server resources.
  • Absolute Data Ownership: For businesses operating under strict compliance frameworks like GDPR, HIPAA, or CCPA, storing user data on a third-party proprietary cloud can be a legal bottleneck. With self-hosted Appwrite, your data remains strictly on your isolated server.
  • Flexibility and Extensibility: Appwrite is built on a modular microservices architecture using Docker. You can easily extend its functionality, integrate your own custom Docker containers, or scale specific microservices independently.
  • Developer-Friendly Ecosystem: Appwrite provides SDKs for all major platforms and languages, including Flutter, React, Vue, iOS, Android, Node.js, and Python. Moving from Firebase requires minimal adjustments to your development workflow.

Prerequisites: Preparing Your Server Environment

To ensure a smooth, production-ready installation of Appwrite, your VPS must meet specific minimum hardware and software requirements. Ensure you have the following ready before executing any commands:

1. Hardware Recommendations

  • CPU: 1 vCPU minimum (2 vCPUs or more recommended for production).
  • RAM: 2 GB RAM minimum (4 GB recommended to comfortably run all background microservices).
  • Storage: 20 GB of SSD storage (scale up based on your expected media and database growth).

2. Software Environment

  • A clean installation of a modern Linux distribution, preferably Ubuntu 22.04 LTS or Ubuntu 24.04 LTS.
  • A registered domain name (e.g., backend.yourcompany.com) with an A record pointing directly to your VPS IP address.
  • Root access or a user account with full sudo privileges.

Step 1: Installing Docker and Docker Compose

Appwrite runs inside Docker containers, meaning we must first install the Docker engine and Docker Compose on our server. Connect to your VPS via SSH and execute the following commands to update your package manager and install dependencies:

sudo apt update && sudo apt upgrade -y
sudo apt install -y curl apt-transport-https ca-certificates software-properties-common

Next, add Docker’s official GPG key and repository to your system:

curl -fsSL [https://download.docker.com/linux/ubuntu/gpg](https://download.docker.com/linux/ubuntu/gpg) | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] [https://download.docker.com/linux/ubuntu](https://download.docker.com/linux/ubuntu) $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null

Update your package index once more and install Docker Engine and the Docker Compose plugin:

sudo apt update
sudo apt install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin

Verify that Docker is successfully installed and running on your system by executing:sudo systemctl status docker docker --version

Step 2: Deploying Appwrite via the Official Installer

The Appwrite core team provides an optimized, interactive installation script that handles the downloading of necessary Docker images, configures environment variables, and generates your docker-compose.yml file automatically. Run the following command to initiate the setup:

docker run -it --rm \
    --volume /var/run/docker.sock:/var/run/docker.sock \
    --volume "$(pwd)"/appwrite:/usr/src/code/appwrite:rw \
    --entrypoint="upgrade" \
    appwrite/appwrite:latest
Note: During the execution of this script, the installer will prompt you for several crucial configuration parameters. Ensure you fill them out carefully.

The interactive prompt will request the following configurations:

  1. Choose your server HTTP port: Press Enter to accept the default port 80, or change it if you use a reverse proxy.
  2. Choose your server HTTPS port: Press Enter to accept the default port 443.
  3. Choose your unique API secret key: Press Enter to auto-generate a secure random key. Keep this confidential.
  4. Enter your primary server hostname: Type your domain or subdomain (e.g., backend.yourcompany.com).
  5. Enter your DNS A record: Confirm the IP address points correctly to this server.

Once the prompt finishes, Docker will pull the required Appwrite architecture images (including MariaDB, Redis, InfluxDB, and Appwrite's core microservices) and initialize the cluster. This process typically takes between 2 to 5 minutes depending on your VPS network connection speed.

Step 3: Initializing the Administrative Dashboard

Once the terminal indicates that the setup is complete, open your preferred web browser and navigate to the domain name you assigned during the configuration (e.g., [https://backend.yourcompany.com](https://backend.yourcompany.com)). Because Appwrite includes built-in Traefik integration, it will automatically attempt to provision a free, valid Let's Encrypt SSL Certificate for your domain.

Upon landing on the page, you will be greeted by the Appwrite Sign Up screen. The first account created on your self-hosted instance is automatically granted administrative global privileges. Enter a secure email address and a strong alphanumeric password to initialize your administrative dashboard.

Step 4: Securing Your Production Installation

While Appwrite is secure out of the box, running a self-hosted instance for production applications requires strict architectural hardening. Implement these best practices immediately after setup:

1. Configure the Server Firewall

Your VPS should only expose the ports absolutely necessary for operation. If you are using Ubuntu, utilize the Uncomplicated Firewall (UFW) to lock down the system:

sudo ufw default deny incoming
sudo uf allow default allow outgoing
sudo ufw allow ssh
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable

2. Tweak the Appwrite Environment Variables

Navigate to your deployment directory (cd ~/appwrite) and open the hidden configuration file using a text editor like nano: nano .env. To optimize production stability and prevent security loopholes, review and adjust the following parameters:

  • _APP_ENV: Ensure this is explicitly set to production to disable verbose debugging logs.
  • _APP_OPTIONS_ABUSE: Set to enabled to protect your API endpoints against brute force and DDoS vectors.
  • _APP_STORAGE_LIMIT: Define the maximum file size users can upload to prevent server storage exhaustion.
  • _APP_SMTP_HOST: Configure external SMTP credentials (SendGrid, Mailgun, Amazon SES) so your Appwrite instance can successfully dispatch transactional verification and password-reset emails.

After saving adjustments to the .env file, apply the configuration changes by restarting your Docker containers:

docker compose up -d

Conclusion: Embracing Infrastructure Freedom

Congratulations! You have successfully deployed a fully functional, highly secure, self-hosted Appwrite instance on your own Virtual Private Server. You now possess a production-ready Backend-as-a-Service capable of managing secure user authentication, complex NoSQL databases, automated serverless cloud functions, and large file storage systems—all with zero vendor lock-in and a predictable monthly budget.

As you scale, remember to establish automated backup strategies for your ~/appwrite data directory and underlying Docker volumes. With full control over your infrastructure stack, you can comfortably grow your application's user base without ever fearing unpredictable scaling costs again.

Self-Hosting Appwrite on a VPS: The Ultimate Guide to an Open-Source Firebase Alternative | DPTCloud