Back to articles
Technology Insight

Self-Hosting Penpot on a VPS: The Ultimate Enterprise-Grade, Cost-Effective Figma Alternative for Collaborative Teams

June 5, 2026

Introduction: The Changing Landscape of Collaborative Design Tools

In the modern digital product development lifecycle, collaborative design tools are no longer a luxury—they are the backbone of product strategy, user experience mapping, and cross-functional execution. For years, Figma has held a near-monopoly in this space, driving industry standards for real-time multiplayer design. However, as enterprise software pricing models evolve, many organization leaders, DevOps managers, and design agency owners face a critical challenge: escalating subscription costs and a lack of granular control over proprietary data privacy.

For teams looking to optimize their operational expenses without sacrificing advanced design capabilities, the solution lies in the open-source movement. Penpot has emerged as the first open-source, web-based design and prototyping platform built inherently for cross-functional teams. By self-hosting Penpot on your own Virtual Private Server (VPS), your business can establish a secure, independent, and completely free design ecosystem that serves as a powerful drop-in replacement for Figma. This guide provides a strategic blueprint for deploying and scaling self-hosted Penpot to elevate your team’s collaborative workflow.


Why Choose Penpot Over Figma? A Strategic Business Assessment

Before initiating a migration of infrastructure, a rigorous cost-benefit analysis is required. Switching to Penpot is not merely a cost-cutting measure; it is a strategic decision that aligns with open standards and digital sovereignty. Here is why enterprise teams are increasingly adopting Penpot:

  • Open Web Standards (SVG Native): Unlike proprietary platforms that lock designs into closed file formats, Penpot uses standard SVG natively. This means your design data is completely transparent, highly portable, and perfectly compatible with code, bridging the gap between designers and developers seamlessly.
  • CSS Grid Layout Integration: Penpot is engineered with modern web layouts in mind. It features native CSS Grid capabilities, allowing designers to create layouts that match the technical reality of front-end development far more accurately than Figma’s Auto Layout.
  • Absolute Data Privacy and Compliance: For enterprises handling sensitive IP, healthcare data, or financial software, cloud-hosted SaaS tools introduce compliance risks. Hosting Penpot on a private VPS ensures all design assets, user access logs, and code prototypes remain strictly within your sovereign infrastructure.
  • Elimination of Seat-Based Pricing Bottlenecks: Figma’s pricing model can penalize growth, charging heavily for every 'editor' seat. With self-hosted Penpot, you can scale your team to hundreds of designers, developers, and stakeholders without paying a single additional dollar in licensing fees. Your only overhead is the cost of your VPS infrastructure.

Hardware and Infrastructure Requirements for a Production-Ready VPS

To ensure smooth, real-time multiplayer editing and rapid rendering of complex vector files, your VPS must be correctly provisioned. While a minimal setup can run on minor specifications, a professional enterprise design team requires robust hardware resources.

Note on Scaling: The resources required will scale directly with the size of your active files and the number of concurrent users editing a canvas simultaneously.

We recommend the following hardware baselines for your VPS deployment:

Resource ComponentMinimum Requirement (1-5 Users)Recommended Enterprise Base (5-20+ Users)
Processor (CPU)2 vCPUs (Modern architecture)4 to 8 vCPUs (Dedicated compute-optimized)
System Memory (RAM)4 GB RAM8 GB to 16 GB RAM (Crucial for large vector assets)
Storage Type20 GB SSD / NVMe50 GB+ NVMe SSD (Scales with project asset library size)
Network Throughput1 Gbps Port / 1 TB Bandwidth1 Gbps Dedicated Port / Unmetered or High Bandwidth
Operating SystemUbuntu Server 22.04 LTS / 24.04 LTSUbuntu Server 24.04 LTS / Debian 12

Step-by-Step Architecture Deployment: Installing Penpot via Docker Compose

Penpot is architected using microservices, utilizing Clojure for its backend and robust frontend web technologies. Managing these components individually can be highly complex. Therefore, the industry standard for deploying Penpot is using Docker Compose. This encapsulates the application, the database, and the asynchronous workers into isolated, predictable containers.

Step 1: Preparing the Server and Installing Docker Ecosystem

First, access your clean VPS via SSH and update the system repositories to ensure security patches are current. Next, install Docker and the Docker Compose plugin.

sudo apt update && sudo apt upgrade -y
sudo apt install curl git software-properties-common -y
curl -fsSL [https://get.docker.com](https://get.docker.com) -o get-docker.sh
sudo sh get-docker.sh

Step 2: Downloading the Official Penpot Orchestration Configuration

Create a dedicated directory for your design platform infrastructure and pull the official docker-compose configuration directly from Penpot's open-source repository:

mkdir -p /opt/penpot && cd /opt/penpot
wget [https://raw.githubusercontent.com/penpot/penpot/main/docker/images/docker-compose.yaml](https://raw.githubusercontent.com/penpot/penpot/main/docker/images/docker-compose.yaml)

Step 3: Configuring Environmental Variables and Security Credentials

Penpot utilizes an environment configuration file to manage system flags, SMTP configurations for transactional emails, and secure encryption keys. Download the template file and modify it using a text editor such as Nano:

wget [https://raw.githubusercontent.com/penpot/penpot/main/docker/images/docker-compose.env](https://raw.githubusercontent.com/penpot/penpot/main/docker/images/docker-compose.env)
nano docker-compose.env

Within the docker-compose.env file, ensure you generate complex, random keys for security. Crucially, configure your corporate SMTP server details so that Penpot can successfully send invitation links, password resets, and team notifications to your workforce:

PENPOT_SECRET_KEY=generate-a-secure-random-long-string-here
PENPOT_DATABASE_PASSWORD=your-secure-db-password
[email protected]
PENPOT_SMTP_HOST=smtp.yourprovider.com
PENPOT_SMTP_PORT=587
PENPOT_SMTP_USERNAME=your-smtp-auth-username
PENPOT_SMTP_PASSWORD=your-smtp-auth-password

Step 4: Launching the Containers and Establishing the Application Reverse Proxy

Once configuration parameters are thoroughly audited, initialize the Docker containers in detached production mode:

sudo docker compose up -d

To guarantee security and allow your team to access Penpot over a safe, encrypted web standard, you should configure a reverse proxy such as Nginx or Caddy. This will handle incoming traffic on standard ports (80 and 443) and provision an automated SSL certificate via Let's Encrypt. Point your corporate subdomain (e.g., design.yourcompany.com) directly to your server's public IP address.


Optimizing the Deployment for Real-Time Team Collaboration

Deploying the software is only the first half of the equation. To truly replace Figma, your self-hosted instance must deliver seamless, low-latency collaboration. Consider implementing these optimization best practices:

  1. Enable Websocket Optimization: Real-time cursor tracking and multi-user live editing rely entirely on persistent WebSockets. Ensure your reverse proxy configuration does not timeout or drop WebSocket upgrades. If utilizing Nginx, ensure the Upgrade and Connection HTTP headers are explicitly forwarded.
  2. Implement Automated Daily Backups: Design assets represent immense intellectual capital. Automate an automated crontab task on your VPS to execute hot backups of the PostgreSQL database and copy user-uploaded assets directly to an off-site S3-compatible object storage repository.
  3. Configuring Object Storage (Optional for Enterprise): By default, Penpot stores uploaded images, fonts, and assets on the local file system of the VPS. For large-scale teams, update the configuration file to link directly to external object storage providers. This ensures your server’s storage space does not fill up and allows for horizontal scaling of the server if necessary.

Conclusion: Reclaiming Digital Sovereignty and Streamlining Costs

Transitioning from a proprietary SaaS framework to a self-hosted Penpot ecosystem allows businesses to reclaim digital sovereignty. By utilizing a cost-effective VPS, you eliminate unpredictable monthly per-seat subscription models, ensure uncompromised data handling compliance, and provide your design and engineering teams with a modern tool built explicitly on open web standards.

While self-hosting requires initial architectural setup and minimal ongoing system administration overhead, the long-term strategic benefits—both financially and operationally—are profound. Take full control of your design pipeline today, deploy Penpot on your terms, and empower your product teams to collaborate with absolute creative freedom.