Documentation menu

Linux, proxies & hosting panels

PRODUCT / 0.2.0-alpha.1Repository reference 32ecfb2 ↗
On this page

Use a supported Linux release with Docker Engine and Compose installed through the vendor's documentation. Keep system packages current, allow HTTPS at the firewall, and restrict SSH and database access. Clone the repository, configure .env and follow Compose installation. Reserve storage for PostgreSQL, assets, backups and image build layers. Test restoration before accepting customer data.

The following proxy recipes assume the web port is available only at 127.0.0.1:3000. Set BETTER_AUTH_URL=https://quotes.example.com. Preserve the requested host; do not replace every tenant domain with the canonical hostname.

Caddy

Examplecaddyfile
quotes.example.com, quote.customer.example.com {
    reverse_proxy 127.0.0.1:3000
}

Configure real DNS records first. Caddy obtains certificates for configured names. Add each verified customer domain explicitly or implement your own restricted certificate authorization policy. An unbounded on-demand TLS policy is unsafe. OpenQuoteStack verifies tenant DNS ownership; it does not configure Caddy or issue certificates. Use the domain guide.

Nginx

Obtain and renew certificates separately. Replace certificate paths with your actual deployment files. An HTTP listener may redirect configured hosts to HTTPS.

Examplenginx
server {
    listen 443 ssl;
    server_name quotes.example.com quote.customer.example.com;
    ssl_certificate /etc/ssl/oqs/fullchain.pem;
    ssl_certificate_key /etc/ssl/oqs/private.key;
    client_max_body_size 3m;

    location / {
        proxy_pass http://127.0.0.1:3000;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_http_version 1.1;
    }
}

A certificate must cover every configured name. Add network rate limits according to installation load. Do not log authorization headers, cookies, request bodies or query strings containing credentials.

Dokploy and Coolify

Use a Docker Compose deployment from this repository, retain all four services and both named volumes, and supply the environment variables through the panel's secret configuration. Route the public hostname to web:3000, not the migration or worker service. Panel-managed proxies normally reach the internal service network; adjust host port publication to that network model rather than exposing PostgreSQL.

Set the canonical HTTPS origin, enable TLS, preserve Host, and allow the migration service to complete before web/worker startup. Configure asset persistence for both web and worker, plus scheduled database/storage backups. Customer domains also need panel routing and certificates after application verification.

These are manual deployment recipes. Panel UI versions, routing networks and backup features vary. They have not been tested as one-click installations. Verify /health, worker heartbeat, uploads, registration and a published estimate on your installation.