Dokploy
Deploy Bifrost on Dokploy with Docker Compose.
Dokploy deploys the repository's docker/compose.yaml as a Compose
application.
- Create → Compose, and point it at this repository (or paste the
docker/compose.yaml). - Set the secrets in the application's environment settings:
MASTER_KEY—openssl rand -base64 48ENCRYPTION_KEYRING— e.g.{"primary":"<openssl rand -hex 32>"}ACTIVE_ENCRYPTION_KEY_ID—primary
- Deploy. The bundled Postgres/Redis and the
migratejob run inside the application's network. - In Domains, add only long-running HTTP services:
- gateway, container port
4000 - dashboard (optional), container port
3001— its own host, e.g.dash.example.com - docs (optional), container port
3000
- gateway, container port
The dashboard is an independent deployment on its own hostname — a plain app at the root of its
domain, with no path prefix for Dokploy to preserve. It needs one setting, GATEWAY_URL, which
inside the application's network is the gateway's service name.
See Operator dashboard → Serving it for both settings and the two curl commands that tell you which side is misconfigured.
Do not create a domain for migrate, Postgres, or Redis. Dokploy injects the Traefik routing labels
for the selected service and applies domain changes on redeployment. The base Compose file publishes
no raw host ports.
Postgres/Redis are reached over the private network in plaintext — no TLS, no Bun TLS issue.
As with Coolify, if you use Dokploy's standalone database services they present self-signed
certificates, which Bun's TLS may reject. The simplest setup is to disable SSL on both the Postgres
and Redis services and connect over the internal network with postgres://… and redis://… (no
sslmode, not rediss://), or use a managed provider. Never
expose the database publicly in plaintext — see the security note.