Self-Hosting Serverless Functions: A Comprehensive Guide to Deploying OpenFaaS on a VPS
Introduction to Self-Hosted Serverless
Serverless computing has revolutionized how modern engineering teams build and deploy application features. By abstracting the underlying server infrastructure, developer workflows become strictly focused on code execution. However, leveraging public cloud giants like AWS Lambda or Google Cloud Functions often introduces structural challenges: vendor lock-in, unpredictable scaling bills, and regulatory hurdles regarding data residency. For small-to-medium enterprises (SMEs) and independent developers, the cost of managing variable serverless invoices can quickly outpace predictability.
This is where OpenFaaS (Functions as a Service) enters the picture. OpenFaaS is an open-source framework designed to turn any infrastructure into a highly scalable, event-driven serverless platform. By deploying OpenFaaS on a standard Virtual Private Server (VPS), you reclaim absolute control over your infrastructure, cap your operational costs, and benefit from the modular velocity of serverless architecture. In this comprehensive guide, we will walk you through the structural blueprint of deploying OpenFaaS on your own VPS from scratch.
Why OpenFaaS on a VPS?
Choosing to deploy an open-source serverless framework on private compute instances provides a distinct set of operational advantages over public cloud variants:
- Cost Predictability: Public clouds charge per invocation and millisecond of compute. While cost-effective for micro-scale projects, high-throughput applications can generate exorbitant bills. A VPS offers a fixed, predictable monthly operational expenditure.
- Bypassing Vendor Lock-In: Writing functions specifically for proprietary cloud environments tightly binds your codebase to their native Software Development Kits (SDKs). OpenFaaS uses standard Docker containers, allowing you to run your functions anywhere OCI-compliant containers are supported.
- Minimal Resource Overhead: Unlike monolithic orchestration stacks, OpenFaaS is lightweight. It runs efficiently on constrained environments, making it entirely feasible to execute on an entry-level, cost-effective VPS.
- Complete Hardware and Software Control: You dictate the exact limits, configurations, timeout windows, and system libraries available to your execution environment.
Prerequisites and Infrastructure Provisioning
Before launching our deployment, we must ensure the host infrastructure is properly provisioned and meets foundational system requirements. To follow this guide seamlessly, secure a VPS instance with the following minimal configuration:
- Operating System: Ubuntu 22.04 LTS or 24.04 LTS (Clean installation recommended).
- Compute Resources: Minimum 2 vCPUs and 2GB of RAM.
- Networking: A public IPv4 address with full root or sudo access.
- Domain Management: A fully qualified domain name (FQDN) pointed to your VPS IP via an A record (e.g.,
faas.yourcompany.com).
Step 1: Setting Up the Lightweight Container Engine
OpenFaaS relies heavily on containerization to pack, ship, and isolate functions. While it natively runs on standard Kubernetes, managing a full-scale Kubernetes cluster on a single VPS introduces unnecessary overhead. For our standalone VPS architectural model, we will utilize faasd—a highly optimized, lightweight distribution of OpenFaaS that swaps out heavy Kubernetes clusters for containerd, the industry-standard container runtime engine.
First, update your local package lists and upgrade existing system packages to prevent security discrepancies:
sudo apt-get update && sudo apt-get upgrade -yNext, we must install basic developer utilities and dependencies, including git, curl, and network bridges:
sudo apt-get install -y git curl bridge-utilsStep 2: Automating the OpenFaaS (faasd) Installation
The OpenFaaS core team maintains a robust installation script for faasd that automatically provisions containerd, downloads the necessary binary releases, configures networking bridges, and structures the systemd system services. Run the official automated installer using the following sequence:
curl -sSLf https://raw.githubusercontent.com/openfaas/faasd/master/hack/install.sh | sudo bashOnce the script executes successfully, it generates a unique cryptographic administrator password for your gateway dashboard. It is structurally imperative to extract and save this password immediately. You can retrieve it by looking into the localized installation directory:
cat /var/lib/faasd/secrets/basic-auth-passwordVerify that the underlying OpenFaaS system services are fully operational by executing a status check via systemd:
sudo systemctl status faasd.serviceNote: The service state should explicitly read active (running). If it displays any errors, verify that your VPS kernel supports network bridging and that port 8080 isn't bound by a pre-existing reverse proxy.
Step 3: Setting Up the Command Line Interface (faas-cli)
To interact with your newly deployed serverless platform, build functions, and handle deployments, you need the OpenFaaS Command Line Interface (faas-cli) installed on your local machine or directly on the VPS.
Install the binary using the automated distribution script:
curl -sSL https://cli.openfaas.com | sudo shWith the CLI available, authenticate against your newly initialized remote serverless gateway. Replace with your server's actual public IP address, and use the password extracted in the previous step:
export OPENFAAS_URL=http://:8080
echo -n "" | faas-cli login --username admin --password-stdin A successful authentication message establishes that your local environment is securely linked to your remote serverless controller.
Step 4: Writing and Deploying Your First Serverless Function
OpenFaaS streamlines development using localized language templates. Let's create an production-grade, asynchronous serverless function using Node.js. First, initialize a dedicated working directory on your development machine:
mkdir -p ~/openfaas-workspace && cd ~/openfaas-workspace
faas-cli template pullScaffold a brand new Node.js function using the boilerplate engine:
faas-cli new analytic-processor --lang node18This execution generates a configuration manifest named analytic-processor.yml alongside a discrete directory containing your functional logic inside handler.js. Open analytic-processor.yml and configure your Docker Hub or private container registry namespace:
provider:
name: openfaas
gateway: http://:8080
functions:
analytic-processor:
lang: node18
handler: ./analytic-processor
image: your-dockerhub-username/analytic-processor:latest Now, open analytic-processor/handler.js to define the execution workload logic:
'use strict'
module.exports = async (event, context) => {
const logPayload = {
timestamp: new Date().toISOString(),
status: "success",
message: "Serverless function executed smoothly on your private VPS!",
inputData: event.body
};
return context
.status(200)
.headers({"Content-Type": "application/json"})
.succeed(logPayload);
};With your code written, invoke the unified build-and-deploy pipeline. This sequence handles compilation, Docker image pushing, and instantiation inside your VPS ecosystem:
faas-cli up -f analytic-processor.ymlOnce the pipeline prints a completion status, trigger your function instantly over standard HTTP curl requests:
curl -d '{"userId": 1024}' http://:8080/function/analytic-processor Step 5: Production Hardening, Reverse Proxies, and SSL
Exposing port 8080 over unencrypted channels introduces extreme operational risk. To secure a production infrastructure, implement a reverse proxy via Nginx coupled with Let's Encrypt SSL certificates to handle Transport Layer Security (TLS).
Install Nginx on your VPS:
sudo apt-get install -y nginxCreate a dedicated host configuration at /etc/nginx/sites-available/openfaas.conf:
server {
listen 80;
server_name faas.yourcompany.com;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}Enable the site configuration and trigger a daemon reload:
sudo ln -s /etc/nginx/sites-available/openfaas.conf /etc/nginx/sites-enabled/
sudo systemctl restart nginxTo automatically acquire and install a free, auto-renewing SSL certificate, run the Certbot utility:
sudo apt-get install -y certbot python3-certbot-nginx
sudo certbot --nginx -d faas.yourcompany.comYour OpenFaaS deployment is now fully accessible behind secure, encrypted https://faas.yourcompany.com endpoints, protected from intercept threats and man-in-the-middle exploits.
Conclusion: Embracing Architectural Sovereignty
Deploying OpenFaaS on a VPS successfully unlocks a cost-effective alternative to proprietary cloud platforms. By integrating faasd, Docker containerization, and TLS-hardened Nginx entry points, you build an institutional runtime platform that delivers microservice scaling velocities alongside full operational sovereignty. As your workloads expand, this footprint easily shifts upwards from a localized single-node VPS into an advanced multi-node Kubernetes ecosystem—ensuring your architecture remains modern, independent, and entirely within your financial control.
