This preparation is shared by Source, Archive, and Registry. You need a new VPS with Ubuntu 24.04 LTS, x86_64 (linux/amd64), public IPv4, and root access from the hosting panel. For two-server deployment, prepare both VPS machines.
Replace 203.0.113.10 with your IP, example.com with your domain, and example_project with your technical project name. The persistent directory path must match Runtime directory in your Deployment environments profile.
1. Connect to the new server
On your computer:
ssh root@203.0.113.10
On first connection, SSH asks you to confirm the new server. After sign-in, this section's commands run on the VPS as root. Check the system:
cat /etc/os-release
uname -m
Ubuntu 24.04 and x86_64 are required. Keep this terminal open until preparation finishes.
2. Install Docker and tools
On the new VPS as root:
apt-get update
apt-get install -y ca-certificates curl jq util-linux coreutils tar openssh-client python3 sudo git nano
install -m 0755 -d /etc/apt/keyrings
curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
chmod a+r /etc/apt/keyrings/docker.asc
cat > /etc/apt/sources.list.d/docker.sources <<EOF
Types: deb
URIs: https://download.docker.com/linux/ubuntu
Suites: noble
Components: stable
Architectures: amd64
Signed-By: /etc/apt/keyrings/docker.asc
EOF
apt-get update
apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
systemctl enable --now docker
docker version
docker compose version
docker buildx version
Docker must respond without daemon connection errors. You need Compose v2, Buildx, and Docker client and daemon with API 1.49 or newer, shown by docker version. If the server is already used and Docker installed, check its version and package compatibility first.
Go, Node, and Admingen itself are unnecessary on the VPS: Source builds through Docker, while Archive/Registry receives a built application.
3. Create a user and data directory
On the VPS as root:
adduser --disabled-password --gecos "" deploy
usermod -aG docker deploy
install -d -o deploy -g deploy -m 700 /home/deploy/.ssh
install -d -o deploy -g deploy -m 700 /srv/admingen/example_project/production
Creation commands assume a new user. If deploy exists, check its docker group membership and directory permissions instead.
/srv/admingen/example_project/production is the persistent database, file, and state directory. The deploy user must own it and have write access. Source code later resides separately, for example in /home/deploy/projects/example-project. Do not use symbolic links in the data directory path.
The docker group grants privileged server access. Only a trusted user should manage releases. Continue OS administration from the root terminal: password-based sudo is not configured for deploy here.
4. Open network access
In the hosting panel, permit TCP 80 and 443 for the application, and SSH from your computer. Also check any existing server firewall. Ports 80/443 must be free for Nginx. Do not expose PostgreSQL to the internet. Docker port publication may bypass ordinary UFW rules.
The server needs outbound internet for Docker images and certificate issuance. Source also needs build dependencies. With two servers, frontend must reach the API over HTTPS.
5. Point domains at the VPS
Create records in your domain's DNS panel:
| Type | Name | Address |
|---|---|---|
| A | admin | Your VPS IPv4 |
| A | api | Same IPv4 |
For split, point admin at the frontend VPS and api at the backend VPS. With Cloudflare: DNS → Records → Add record, Proxy status DNS only (gray cloud), TTL Auto. The domain's nameservers must point to this DNS panel.
Update conflicting A/CNAME records rather than adding another address. If IPv6 is not configured, remove old AAAA records only for these two names. Leave other domain records unchanged.
On your computer, check responses:
dig +short A admin.example.com
dig +short A api.example.com
dig +short AAAA admin.example.com
dig +short AAAA api.example.com
A records must return the correct IPv4 addresses; AAAA responses should be empty if IPv6 is absent. Wait for DNS propagation. During future provision, Certbot issues HTTPS certificates, requiring working DNS and inbound port 80. The application will not open in a browser before deployment. These steps do not publish the root domain example.com.