Security
Self-host ZITADEL
Identity platform with OIDC, SAML, passkeys and multi-tenancy — an open-source Auth0 you run yourself.
Deploy ZITADEL with Nixploy
Install Nixploy on any Docker host — a €5 VPS is enough for most of these:
curl -fsSL https://raw.githubusercontent.com/bablilayoub/nixploy/main/install.sh | sudo bash- 1
Open Templates in the panel
Search for ZITADEL and open it. The compose file, the variables and the suggested domain are already filled in.
- 2
Give it a domain
Point a DNS record at your server and enter it. Traefik requests the certificate on the first request — there is no separate certbot step and nothing to renew by hand.
- 3
Deploy
Nixploy renders the compose file, validates it against the platform's safety rules, and brings the stack up on a private per-environment network. Live logs stream while it happens.
- 4
Schedule a backup
ZITADEL keeps its state in a named volume (zitadel-db). Add a schedule and Nixploy streams the dump to S3 or to disk, encrypted, and can verify a restore.
What this deploys
- Images
- ghcr.io/zitadel/zitadel:latest
- postgres:17-alpine
- Routed to
- zitadel:8080
- Persistent volumes
- zitadel-db
- Variables it asks for
- ZITADEL_MASTERKEYExactly 32 characters used to encrypt secrets at rest (
openssl rand -hex 16) - ZITADEL_EXTERNALDOMAINHostname the instance is served on, without scheme or port
- ZITADEL_MASTERKEYExactly 32 characters used to encrypt secrets at rest (
- Secrets Nixploy generates
- POSTGRES_PASSWORDCreated at deploy time and stored encrypted — you never invent or paste them.
What you get with it
Automatic HTTPS through Traefik and Let's Encrypt, renewed for you.
Live logs, a web terminal into the container, and CPU/memory/network history.
Encrypted backups to S3 or disk, on a schedule, with verified restores.
Roll back to the previous version when an update goes wrong.
An MCP endpoint, so an AI agent can deploy, read the logs and diagnose it for you — see the MCP guide.
Why self-host ZITADEL?
Running it yourself means the data lives on a disk you control, there is no per-seat price as the team grows, and nothing is retired or repriced by somebody else. The cost is the part Nixploy takes over: a reverse proxy, certificates that renew, a volume that survives a redeploy, backups you can actually restore, and a way to see the logs when it misbehaves.
ZITADEL upstream
Nixploy packages the project; it is not affiliated with it. Website · Docs · Source
All 146 templates