メインコンテンツにスキップ

Deploy Casdoor with Docker

This guide explains how to run Casdoor in production with Docker or Docker Compose and how to put a reverse proxy with HTTPS in front of it.


Learning outcomes​

  • Prepare the configuration files that the Casdoor container reads.
  • Start Casdoor with Docker Compose or docker run.
  • Serve Casdoor over HTTPS through Traefik, Nginx, or Caddy.
  • Check that the deployment works and find the cause when it doesn't.

What you need​

  • Docker, and Docker Compose for the Compose setups
  • A supported database that the container can reach
  • For HTTPS: a domain name that points to your server, and ports 80 and 443 open

Don't want to run it yourself?

Casdoor Cloud gives you a dedicated Casdoor instance that we host and keep upgraded for you, from $29/month with no per-user fees. New accounts get $20 in free credit to try it.

Prepare the configuration​

  1. Create the directories that you mount into the container:

    mkdir -p conf logs
  2. Download the default configuration files:

    wget https://raw.githubusercontent.com/casdoor/casdoor/master/conf/app.conf -O conf/app.conf
    wget https://raw.githubusercontent.com/casdoor/casdoor/master/init_data.json.template -O conf/init_data.json
  3. Edit conf/app.conf for your environment. At least set the database connection. See Configure the database and the Configuration reference.

注

Casdoor runs as uid and gid 1000 inside the container. Make the mounted directories readable by uid 1000, and writable if Casdoor writes to them, for example for logs or a SQLite file. Otherwise Casdoor fails with permission denied.

Start Casdoor​

  1. Create a docker-compose.yml file:

    services:
    casdoor:
    image: casbin/casdoor:latest
    container_name: casdoor
    restart: unless-stopped
    ports:
    - "8000:8000"
    volumes:
    - ./conf:/conf
    - ./logs:/logs
    networks:
    - casdoor-network

    networks:
    casdoor-network:
    driver: bridge
  2. Start the service:

    docker compose up -d

Casdoor now listens on port 8000 of the server.

Add a reverse proxy with HTTPS​

In production, serve Casdoor over HTTPS through a reverse proxy. In the following examples, replace your-domain.com with your domain and your-email@example.com with your email address.

Traefik reads its routes from the labels of the Casdoor container and gets certificates from Let's Encrypt.

  1. Create a docker-compose.yml file:

    services:
    traefik:
    image: traefik:v2.10
    container_name: traefik
    restart: unless-stopped
    ports:
    - "80:80"
    - "443:443"
    volumes:
    - /var/run/docker.sock:/var/run/docker.sock:ro
    - ./traefik/acme.json:/acme.json
    command:
    - --api.dashboard=true
    - --providers.docker=true
    - --providers.docker.exposedbydefault=false
    - --entrypoints.web.address=:80
    - --entrypoints.websecure.address=:443
    - --certificatesresolvers.letsencrypt.acme.email=your-email@example.com
    - --certificatesresolvers.letsencrypt.acme.storage=/acme.json
    - --certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web
    networks:
    - casdoor-network

    casdoor:
    image: casbin/casdoor:latest
    container_name: casdoor
    restart: unless-stopped
    volumes:
    - ./conf:/conf
    - ./logs:/logs
    labels:
    - "traefik.enable=true"
    - "traefik.http.routers.casdoor.rule=Host(`your-domain.com`)"
    - "traefik.http.routers.casdoor.entrypoints=websecure"
    - "traefik.http.routers.casdoor.tls.certresolver=letsencrypt"
    - "traefik.http.services.casdoor.loadbalancer.server.port=8000"
    networks:
    - casdoor-network

    networks:
    casdoor-network:
    driver: bridge
  2. Create the file in which Traefik stores the certificates:

    touch traefik/acme.json
    chmod 600 traefik/acme.json
  3. Start the services with docker compose up -d.

Verify the deployment​

Open Casdoor in a browser:

SetupURL
Docker Compose or docker run without a proxyhttp://<your-server-ip>:8000
With a reverse proxyhttps://your-domain.com

The Casdoor sign-in page appears. Sign in as built-in/admin with the password 123, and then change the password.

トラブルシューティング​

Casdoor doesn't start​

Read the container logs:

# For Docker Compose
docker compose logs casdoor

# For docker run
docker logs casdoor

The proxy doesn't reach Casdoor​

Check that the containers run and that Casdoor answers on port 8000:

# Check if containers are running
docker ps

# Test connectivity
curl -I http://localhost:8000

The certificate isn't issued​

  • Check that your domain points to the IP address of the server, for example with nslookup your-domain.com.
  • Check that the firewall allows ports 80 and 443.

See also​