Przejdź do głównej zawartości

Deploy Casdoor with Docker

This guide explains how to run Casdoor in production with Docker or Docker Compose and how to put a reverse proxy with HTTPS in front of it.


Learning outcomes​

  • Prepare the configuration files that the Casdoor container reads.
  • Start Casdoor with Docker Compose or docker run.
  • Serve Casdoor over HTTPS through Traefik, Nginx, or Caddy.
  • Check that the deployment works and find the cause when it doesn't.

What you need​

  • Docker, and Docker Compose for the Compose setups
  • A supported database that the container can reach
  • For HTTPS: a domain name that points to your server, and ports 80 and 443 open

Don't want to run it yourself?

Casdoor Cloud gives you a dedicated Casdoor instance that we host and keep upgraded for you, from $25/month with no per-user fees.

Prepare the configuration​

  1. Create the directories that you mount into the container:

    mkdir -p conf logs
  2. Download the default configuration files:

    wget https://raw.githubusercontent.com/casdoor/casdoor/master/conf/app.conf -O conf/app.conf
    wget https://raw.githubusercontent.com/casdoor/casdoor/master/init_data.json.template -O conf/init_data.json
  3. Edit conf/app.conf for your environment. At least set the database connection. See Configure the database and the Configuration reference.

notatka

Casdoor runs as uid and gid 1000 inside the container. Make the mounted directories readable by uid 1000, and writable if Casdoor writes to them, for example for logs or a SQLite file. Otherwise Casdoor fails with permission denied.

Start Casdoor​

  1. Create a docker-compose.yml file:

    services:
    casdoor:
    image: casbin/casdoor:latest
    container_name: casdoor
    restart: unless-stopped
    ports:
    - "8000:8000"
    volumes:
    - ./conf:/conf
    - ./logs:/logs
    networks:
    - casdoor-network

    networks:
    casdoor-network:
    driver: bridge
  2. Start the service:

    docker compose up -d

Casdoor now listens on port 8000 of the server.

Add a reverse proxy with HTTPS​

In production, serve Casdoor over HTTPS through a reverse proxy. In the following examples, replace your-domain.com with your domain and your-email@example.com with your email address.

Traefik reads its routes from the labels of the Casdoor container and gets certificates from Let's Encrypt.

  1. Create a docker-compose.yml file:

    services:
    traefik:
    image: traefik:v2.10
    container_name: traefik
    restart: unless-stopped
    ports:
    - "80:80"
    - "443:443"
    volumes:
    - /var/run/docker.sock:/var/run/docker.sock:ro
    - ./traefik/acme.json:/acme.json
    command:
    - --api.dashboard=true
    - --providers.docker=true
    - --providers.docker.exposedbydefault=false
    - --entrypoints.web.address=:80
    - --entrypoints.websecure.address=:443
    - --certificatesresolvers.letsencrypt.acme.email=your-email@example.com
    - --certificatesresolvers.letsencrypt.acme.storage=/acme.json
    - --certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web
    networks:
    - casdoor-network

    casdoor:
    image: casbin/casdoor:latest
    container_name: casdoor
    restart: unless-stopped
    volumes:
    - ./conf:/conf
    - ./logs:/logs
    labels:
    - "traefik.enable=true"
    - "traefik.http.routers.casdoor.rule=Host(`your-domain.com`)"
    - "traefik.http.routers.casdoor.entrypoints=websecure"
    - "traefik.http.routers.casdoor.tls.certresolver=letsencrypt"
    - "traefik.http.services.casdoor.loadbalancer.server.port=8000"
    networks:
    - casdoor-network

    networks:
    casdoor-network:
    driver: bridge
  2. Create the file in which Traefik stores the certificates:

    touch traefik/acme.json
    chmod 600 traefik/acme.json
  3. Start the services with docker compose up -d.

Verify the deployment​

Open Casdoor in a browser:

SetupURL
Docker Compose or docker run without a proxyhttp://<your-server-ip>:8000
With a reverse proxyhttps://your-domain.com

The Casdoor sign-in page appears. Sign in as built-in/admin with the password 123, and then change the password.

Troubleshooting​

Casdoor doesn't start​

Read the container logs:

# For Docker Compose
docker compose logs casdoor

# For docker run
docker logs casdoor

The proxy doesn't reach Casdoor​

Check that the containers run and that Casdoor answers on port 8000:

# Check if containers are running
docker ps

# Test connectivity
curl -I http://localhost:8000

The certificate isn't issued​

  • Check that your domain points to the IP address of the server, for example with nslookup your-domain.com.
  • Check that the firewall allows ports 80 and 443.

See also​