Deploy PocketBase to production
Deploy PocketBase as a standalone binary or Docker container behind HTTPS, with persistent data and a controlled restart path.
This tutorial takes you from a prepared PocketBase application to a production service reachable over HTTPS. You will choose a standalone binary or Docker, place a reverse proxy in front when needed, preserve pb_data, and verify the service before handing it traffic.
Before you begin
Prepare a domain name, a server or container host, a release binary that matches the target OS and architecture, and any pb_migrations or pb_hooks directories your application needs. Arrange a non-root service account where your host permits it, and define how you will back up pb_data before the first production start.
Deploy a standalone binary
Keep the executable with the application assets, migrations, and hooks:
myapp/
├── pocketbase
├── pb_migrations/
└── pb_hooks/Build a static executable for a supported target when you build from Go, for example GOOS=linux GOARCH=amd64 CGO_ENABLED=0 go build. Confirm the binary starts in a staging directory before uploading it.
Copy the directory to the server using your controlled deployment channel:
rsync -avz -e ssh ./myapp/ deploy@example.com:/srv/pocketbase/The remote directory contains the executable and application assets. Use a service account and a destination with permissions limited to the deployment team.
For PocketBase-managed TLS, start the executable with the production domain:
/srv/pocketbase/pocketbase serve example.comPocketBase requests a Let’s Encrypt certificate for the domain. Binding directly to ports 80 and 443 may require the appropriate host privilege; a reverse proxy avoids giving the application that privilege.
Use a reverse proxy when you need shared hosting, network policy, or centralized TLS. Pass the original host and client IP headers, and configure PocketBase’s trusted proxy settings to match the headers your proxy sends.
For NGINX, the upstream should point to the PocketBase listener, such as http://127.0.0.1:8090, and forward Host, X-Real-IP, X-Forwarded-For, and X-Forwarded-Proto. Caddy can use reverse_proxy 127.0.0.1:8090 and manage HTTPS for the domain.
Request the health endpoint and inspect the response:
curl -fsS https://example.com/api/healthThe command succeeds with HTTP 200 and the message API is healthy.. Sign in to the admin UI, confirm the expected collections and rules, and inspect Health checks, logs, and statistics for failed requests.
Deploy with Docker
PocketBase does not publish an official Docker image. Build your own image and pin the release version rather than using a floating application version:
FROM alpine:latest
ARG PB_VERSION=0.40.4
RUN apk add --no-cache unzip ca-certificates
ADD https://github.com/pocketbase/pocketbase/releases/download/v${PB_VERSION}/pocketbase_${PB_VERSION}_linux_amd64.zip /tmp/pb.zip
RUN unzip /tmp/pb.zip -d /pb/
COPY ./pb_migrations /pb/pb_migrations
COPY ./pb_hooks /pb/pb_hooks
EXPOSE 8080
CMD ["/pb/pocketbase", "serve", "--http=0.0.0.0:8080"]Mount a durable volume at /pb/pb_data. Without that volume, records, uploaded files, and settings are lost when the container is replaced. Put HTTPS termination at the platform or reverse proxy and route it to port 8080.
pb_data volume is attached. A healthy container without its data volume is not a healthy deployment.Next steps
Run Production readiness checklist, then document your supported backup and restore procedure before accepting production traffic.