Back to articles
Technology Insight

Self-Hosting Penpot on a VPS: The Ultimate Open-Source UI/UX Alternative to Figma for Enterprise

June 3, 2026

The Paradigm Shift in UI/UX Design Tools

For the past several years, the digital product design ecosystem has been dominated by a handful of proprietary, cloud-native platforms. While these tools have undoubtedly revolutionized real-time collaboration and streamlined design workflows, they have also introduced significant operational challenges for modern enterprises. Organizations are increasingly facing shifting licensing models, unpredictable software-as-a-service (SaaS) cost escalations, and complex compliance hurdles regarding data residency and IP protection.

In this landscape, Penpot has emerged as a disruptive force. As the industry's first open-source, web-based UI/UX design and prototyping platform, Penpot provides a robust response to proprietary lock-in. By leveraging open web standards natively, specifically SVG (Scalable Vector Graphics) and CSS Layout features like Flexbox and Grid, Penpot bridges the historic chasm between designers and developers. However, the true strategic leverage of Penpot is realized when it is self-hosted on a private Virtual Private Server (VPS), granting organizations complete control over their design infrastructure.

Why Self-Host Penpot? The Enterprise Imperative

While Penpot offers a reliable cloud-managed service, establishing a self-hosted instance on an independent VPS provides critical strategic advantages for businesses, agencies, and technical teams:

  • Absolute Data Sovereignty: In high-compliance sectors such as fintech, healthcare, and defense, proprietary design files cannot reside on third-party multi-tenant servers. Self-hosting ensures all mockups, workflows, and user journey maps remain strictly within your corporate network perimeter.
  • Cost Predictability and Optimization: SaaS pricing scales linearly with headcount. A self-hosted VPS decouples infrastructure costs from user count, allowing organizations to scale their design, product, and engineering teams without incurring exponential software licensing fees.
  • Uncompromising Integration Capabilities: Operating Penpot on your own server enables deeper integrations with internal authentication mechanisms (such as LDAP, OAuth2, or OIDC), private repositories, and automated CI/CD deployment pipelines.

Technical Architecture and System Requirements

Before initiating the deployment process on a VPS, it is vital to provision an environment that ensures high availability, rapid rendering performance, and secure concurrent connections. Penpot is architected as a microservices system composed of a frontend application, a backend API storage engine, a real-time synchronization service, and a PostgreSQL database layer.

Recommended VPS Infrastructure Specifications

For a production environment supporting a cross-functional team of 5 to 15 concurrent users, we recommend the following minimum hardware footprint:

  • CPU: 4 vCPUs (Compute-optimized instances are preferable to handle concurrent SVG rendering computations).
  • RAM: 8 GB RAM (This accommodates the database caching layers and the synchronization state engine).
  • Storage: 50 GB+ NVMe SSD storage (Design assets, high-resolution imagery, and historical versioning blocks demand rapid read/write capabilities).
  • Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS for maximum package compatibility and stability.

Step-by-Step Deployment Guide via Docker Compose

The most maintainable and production-ready method to deploy Penpot on a VPS is utilizing Docker and Docker Compose. This containerized approach isolates dependencies and simplifies future upgrades.

Step 1: System Update and Docker Installation

Connect to your VPS instance via SSH and execute the following commands to update system packages and install the Docker engine ecosystem:

sudo apt update && sudo apt upgrade -y
sudo apt install docker.io docker-compose-v2 git -y

Step 2: Acquiring the Penpot Deployment Configuration

Penpot maintains an official, highly optimized Docker Compose configuration file. Create a dedicated directory and download the required manifest assets:

mkdir -p /opt/penpot && cd /opt/penpot
wget https://raw.githubusercontent.com/penpot/penpot/main/docker/images/docker-compose.yaml

Step 3: Configuring the Environment Matrix

The initialization of Penpot requires configuring an environment file to manage secure keys, database credentials, and external application flags. Generate or open the configuration file to review variables:

Within this configuration, ensure you modify the default encryption keys to prevent unauthorized access. Key variables include:

  • PENPOT_FLAGS: Enables or disables experimental or enterprise features like registration workflows or telemetry.
  • PENPOT_PUBLIC_URI: The definitive external domain name or IP address mapping to your server instance.
  • PENPOT_SECRET_KEY: A cryptographically secure random string used to sign session cookies and internal payloads.

Step 4: Launching the Microservices Stack

With configurations finalized, initiate the initialization and execution of the container network in detached production mode:

sudo docker compose up -d

Verify that all service blocks—including penpot-frontend, penpot-backend, penpot-postgres, and penpot-redis—are executing optimally by analyzing container status logs via sudo docker compose ps.

Hardening and Securing Your Penpot Production Instance

Exposing a design platform directly to the open internet via raw HTTP ports introduces major security liabilities. To ensure an enterprise-grade deployment, implementing a reverse proxy and an SSL/TLS layer is mandatory.

Implementing Nginx and Let's Encrypt

By routing inbound traffic through an Nginx Reverse Proxy, you can offload SSL decryption and effectively mask your internal container architecture. Once Nginx is mapped to direct traffic to internal port 9001, utilize the automated certbot utility to provision trusted, auto-renewing TLS certificates:

sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d design.yourcompany.com

This implementation ensures all collaborative telemetry, design assets, and administrative credentials are fully encrypted in transit with modern cryptographic primitives.

Maximizing Design-to-Code Velocity with Penpot

Once deployed, your organization can begin leveraging Penpot's unique technical advantages over legacy tools. Unlike traditional design platforms that treat web layouts as abstracted coordinate spaces, Penpot treats the design canvas exactly as a browser interprets a layout.

  1. Native CSS Grid Layouts: Designers can construct fully dynamic, responsive structural layouts using genuine CSS Grid properties. This ensures that the design inherently respects browser scaling paradigms, eliminating ambiguous spacing specs for engineers.
  2. The Power of Pure SVG: Because Penpot's native format is SVG, components are fundamentally compatible with the web. Code generation is clean, concise, and production-ready, radically minimizing the traditional friction observed during developer handoffs.
  3. True Collaborative Sovereignty: With open-source self-hosting, teams experience seamless real-time multiplayer editing and commenting without performance degradation caused by rate-limiting or external multi-tenant cloud bottlenecks.

Conclusion: Taking Control of Your Design Infrastructure

Migrating from centralized, closed-source SaaS solutions to a self-hosted Penpot instance on a VPS represents a strategic milestone for data-conscious organizations. By regaining control over design systems, user intelligence data, and intellectual property, enterprises can effectively protect their core assets while unlocking unparalleled design-to-code velocity. Penpot proves that modern, elegant, and collaborative UI/UX tools do not require sacrificing ownership or security.

Self-Hosting Penpot on a VPS: The Ultimate Open-Source UI/UX Alternative to Figma for Enterprise | DPTCloud