Back to articles
Technology Insight

Self-Hosting Penpot on a VPS: The Ultimate Open-Source Figma Alternative for Modern Design Teams

June 3, 2026

Introduction: The Paradigm Shift in Collaborative UI/UX Design

For years, proprietary cloud platforms have dominated the UI/UX design landscape. However, modern enterprises and security-conscious engineering teams increasingly face challenges related to escalating subscription costs, vendor lock-in, and stringent data sovereignty regulations. Enter Penpot, the first open-source, web-based design and prototyping platform built natively on open standards like SVG and ClojureScript.

By choosing to self-host Penpot on a Virtual Private Server (VPS), organizations can reclaim complete ownership of their intellectual property, customize their design infrastructure, and eliminate per-seat licensing fees. This comprehensive guide explores why Penpot is the ultimate self-hosted alternative to Figma and delivers a technical roadmap for deploying it successfully on your own infrastructure.

---

Why Choose Penpot Over Proprietary Alternatives?

While cloud-hosted design tools offer convenience, they introduce operational vulnerabilities. Self-hosting Penpot bridges the gap between collaborative design agility and enterprise-grade infrastructure control.

1. Data Sovereignty and Absolute Privacy

Design files often contain confidential product roadmaps, proprietary user flows, and unreleased feature concepts. Hosting Penpot on your own VPS ensures that all design assets, comments, and user data remain entirely within your secure network perimeter, satisfying compliance mandates such as GDPR and local data protection laws.

2. Open Standards Architecture

Unlike proprietary tools that lock your designs into closed, binary formats, Penpot uses SVG (Scalable Vector Graphics) as its native file format. This means your designs are inherently compatible with the web, readable by developers, and deeply integrated with code right out of the box.

3. Elite Performance with CSS Grid and Flexbox

Penpot bridges the gap between design and development by implementing native CSS Grid and Flexbox layouts directly into the design canvas. Designers build layouts exactly how web browsers render them, significantly reducing friction during developer handoffs.

4. Predictable Infrastructure Costs

Proprietary SaaS platforms typically scale their pricing per user, which becomes prohibitively expensive as cross-functional product teams grow. Deploying Penpot on a dedicated VPS shifts your expenses from a fluctuating variable cost to a predictable, flat-rate infrastructure cost.

---

Prerequisites for VPS Deployment

Before initiating the installation, ensure your environment meets the minimum technical specifications to maintain optimal rendering speeds and real-time collaboration performance.

  • Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS (highly recommended).
  • Hardware Specs: Minimum 2 vCPUs, 4GB RAM, and 40GB of SSD storage (scale upwards based on concurrent active users).
  • Software Dependencies: Docker Engine (v20.10+) and Docker Compose (v2.0+).
  • Networking: A fully qualified domain name (FQDN) pointed to your VPS IP address via an A record, plus ports 80 and 443 open.
---

Step-by-Step Guide: Deploying Penpot via Docker Compose

Docker Compose offers the most robust, predictable production-ready installation method for Penpot. It orchestrates the frontend, backend, asynchronous workers, and database instances cleanly.

Step 1: System Preparation and Updates

Connect to your VPS via SSH and update the system packages to their latest versions to ensure security stability:

sudo apt update && sudo apt upgrade -y

Step 2: Retrieve the Official Configuration

Create a dedicated directory for your Penpot environment and download the official production Docker Compose configuration file directly from the Penpot repository:

mkdir -p /opt/penpot && cd /opt/penpot
curl -o docker-compose.yaml [https://raw.githubusercontent.com/penpot/penpot/main/docker/images/docker-compose.yaml](https://raw.githubusercontent.com/penpot/penpot/main/docker/images/docker-compose.yaml)

Step 3: Configuring Environment Variables

Penpot relies on an environment configuration file to manage secrets, database credentials, and email settings. Download the sample configuration file and open it for editing:

curl -o .env [https://raw.githubusercontent.com/penpot/penpot/main/docker/images/config.env](https://raw.githubusercontent.com/penpot/penpot/main/docker/images/config.env)
nano .env

Within the .env file, update the following critical parameters to secure your installation:

  • PENPOT_PUBLIC_URI: Set this to your secure domain (e.g., [https://design.yourcompany.com](https://design.yourcompany.com)).
  • PENPOT_SECRET_KEY: Generate a long, random cryptographic string to secure user sessions.
  • Database Credentials: Change the default passwords for the PostgreSQL and Redis containers.
  • SMTP Configuration: Configure your corporate SMTP server settings to enable user registration emails and real-time design notifications.

Step 4: Launching the Penpot Containers

With your configurations securely in place, initialize and pull the required microservices Docker images, then launch them in detached mode:

sudo docker compose up -d

Verify that all internal microservices (frontend, backend, exporter, postgres, and redis) are operating nominally by monitoring the container states:

sudo docker compose ps
---

Securing the Deployment with an Nginx Reverse Proxy

To safely expose your Penpot instance to your design team over the open web, you must implement a reverse proxy handling SSL termination via Let's Encrypt.

1. Install Nginx and Certbot

sudo apt install nginx certbot python3-certbot-nginx -y

2. Configure the Nginx Server Block

Create an active Nginx configuration file routing standard traffic directly into the internal Penpot frontend container running locally on port 9001:

sudo nano /etc/nginx/sites-available/penpot

Insert a clean upstream proxy configuration block targeting http://localhost:9001, ensuring headers for WebSockets are appropriately maintained for Penpot's real-time collaborative workspace engines.

3. Provision SSL Certificates

Execute Certbot to automatically fetch and configure a free, auto-renewing SSL certificate from the Let's Encrypt Certificate Authority:

sudo certbot --nginx -d design.yourcompany.com

Restart Nginx to apply the secure HTTPS policies across your design platform:

sudo systemctl restart nginx
---

Post-Deployment Best Practices for Enterprise Teams

Transitioning production design workloads to a self-hosted platform requires proactive infrastructure management. Adhering to these operations workflows ensures high availability and business continuity.

Automated Database Backups

Penpot utilizes PostgreSQL to store critical project metadata, vector structures, and user permissions. Establish a nightly cron job that handles pg_dump database backups, compressing the output files and syncing them securely to an isolated, offsite object storage bucket (such as AWS S3 or MinIO).

Performance Monitoring

Vector rendering and file exports can occasionally spike CPU usage. Implement monitoring agents like Prometheus and Grafana on your VPS to track RAM consumption, storage capacity, and network throughput, alerting your DevOps team before bottlenecks impact the design workflow.

---

Conclusion: Unlocking True Design Freedom

Self-hosting Penpot on a private VPS provides modern businesses with a powerful, enterprise-grade design workspace that eliminates recurring user-licensing costs while granting complete control over sensitive data assets. By bridging the native architectural language of design directly to standard web code through SVG and CSS Grid, Penpot is not merely an alternative to Figma—it represents an evolutionary milestone for scalable, collaborative open-source product design infrastructure.

Self-Hosting Penpot on a VPS: The Ultimate Open-Source Figma Alternative for Modern Design Teams | DPTCloud