bolt Valebyte VPS from $4/mo — NVMe, 60s deploy.

Get a VPS arrow_forward
eco Beginner Tutorial/How-to

Installing Fider on a VPS: Self-Hosted Feedback Collection, SSL, and SMTP

calendar_month Oct 06, 2026 schedule 22 min read visibility 103 views
Установка Fider на VPS: self-hosted сбор обратной связи, SSL и SMTP
info

Need a server for this guide? We offer dedicated servers and VPS in 50+ countries with instant setup.

Need a server for this guide?

Deploy a VPS or dedicated server in minutes.

Installing Fider on a VPS: self-hosted feedback collection, SSL, and SMTP

TL;DR

Fider is a self-hosted platform for collecting ideas, votes, and user feedback. In this guide, you will deploy Fider on an Ubuntu VPS via Docker Compose, connect PostgreSQL, configure HTTPS with Caddy, SMTP notifications, backups, and basic server protection.

  • For a small public idea board, a VPS with 2 vCPUs, 2 GB RAM, and 25 GB SSD is sufficient.
  • Fider runs in Docker together with PostgreSQL, so updating and migrating the service remain predictable.
  • Caddy automatically issues and renews Let's Encrypt TLS certificates.
  • SMTP is required for invitations, login confirmation, and notifications about new ideas or comments.
  • Backups should include the PostgreSQL dump, environment file, Docker Compose configuration, and Caddy data.
  • After installation, the service will be available at an address such as https://feedback.example.com.

What we are configuring and why

Fider is an open-source application for managing user suggestions. It allows you to create a public or private feedback portal: visitors publish ideas, other users vote and leave comments, while the team changes the status of suggestions and reports on the progress.

A typical scenario is a SaaS product, online store, gaming community, internal corporate service, or open-source project. Instead of collecting ideas in email, Telegram, Discord, Google Forms, and Jira tasks, you provide users with one clear entry point.

After completing the setup, you will have a separate subdomain, such as feedback.example.com, with an active HTTPS certificate, a PostgreSQL database, SMTP email delivery, and automated backups. The architecture will consist of four components:

  • Fider — a web application available to users through a browser.
  • PostgreSQL — a database containing users, votes, posts, comments, and settings.
  • Caddy — a reverse proxy that accepts HTTPS traffic, obtains certificates, and forwards requests to Fider.
  • Docker Compose — a tool that describes containers, networks, persistent volumes, and environment variables.

What Fider can do

In its basic configuration, Fider lets you create feedback spaces, moderate posts, vote for ideas, comment on suggestions, mark posts with statuses, and send notifications. The administrator can manage access, configure the domain, customize the appearance, and set authentication methods.

For a small product, this is often simpler than implementing a heavyweight task management system and giving customers access to it. Users see only a clear interface with suggestions, while the team receives a signal about what truly matters to the audience: ideas with more votes automatically move higher.

Cloud service or self-hosted Fider

Cloud feedback services are convenient because they require no administration. However, they usually limit the number of users, public boards, or integrations, or require a monthly subscription. An external platform also stores user data, names, email addresses, and suggestion texts with a third party.

Self-hosting Fider on a VPS makes sense if you value control over your data, your own domain, predictable costs, the ability to create a private internal board, or compliance with data residency requirements. You are responsible for updates and backups, but you gain full control over the infrastructure.

Criteria Cloud-managed service Fider on your own VPS
Deployment A few minutes without a server About 1–2 hours with domain and SMTP configuration
Data control Data is held by an external provider Data is stored in your PostgreSQL database
Cost Usually increases with the number of participants Fixed VPS and SMTP costs
Updates Performed by the provider Performed by you on a schedule
Customization Limited by the plan Settings, API, and your own infrastructure are available

What you will need before getting started

  • A VPS or dedicated server with a public IPv4 address.
  • A domain or subdomain, such as feedback.example.com.
  • The ability to create an A DNS record.
  • Access to an SMTP provider or your own mail server.
  • A local SSH client: OpenSSH, Windows Terminal, PuTTY, or an equivalent.
  • Ubuntu Server 24.04 LTS or Debian 12/13. The examples use Ubuntu 24.04 LTS.

Do not expose Fider directly to the internet on port 3000. The application container should be accessible only to the reverse proxy inside the Docker network, while externally you should leave only SSH, HTTP, and HTTPS open.

What VPS configuration is needed for this task

Fider is not a resource-intensive application when dealing with several hundred or thousand registered users and moderate activity. PostgreSQL, Docker containers, and the operating system's file cache account for most memory usage. Therefore, 1 GB of RAM may technically run the service, but for stable operation it is better not to use such a minimal configuration.

Scenario CPU RAM Disk Network
Test environment, up to 100 active users 1 vCPU 1–2 GB 20 GB SSD 100 Mbps
Small product, up to 5,000 users 2 vCPUs 2–4 GB 25–40 GB NVMe/SSD 100 Mbps or 1 Gbps
Several boards and an active community 4 vCPUs 8 GB 80 GB NVMe 1 Gbps
High load, separate database 4–8 vCPUs 16 GB 160 GB NVMe 1 Gbps

A practical starting configuration is 2 vCPUs, 4 GB RAM, 40 GB NVMe, and a connection of at least 100 Mbps. This is sufficient for Fider, PostgreSQL, Caddy, automated backups, and some room for growth. For example, you can choose a VPS with the specified characteristics, install Ubuntu 24.04 LTS, and follow the commands in this guide.

Why having spare memory matters

When RAM is insufficient, Linux begins actively using swap. This does not always cause Fider to crash, but it noticeably increases the response time of PostgreSQL and the web application. With 2 GB of memory, the service usually works fine, but 4 GB provides more comfortable headroom for updates, backups, and brief activity spikes.

Keep track of available disk space. PostgreSQL grows not only because of data, but also because of transaction logs, indexes, and temporary files. Docker also stores images and container layers. Do not fill the filesystem beyond 80–85%: on a full disk, the database may stop accepting writes.

When you need a dedicated server instead of a VPS

A dedicated server is not needed for one or several ordinary Fider boards. A VPS is easier to scale, cheaper to back up, and faster to migrate. A dedicated server makes sense for a very active public community, tens of thousands of daily visitors, strict resource isolation requirements, or hosting several heavy systems alongside Fider.

If the database grows to tens of gigabytes and users constantly create posts and comments, first separate the roles: keep Fider and Caddy on one VPS, and move PostgreSQL to a separate server or managed PostgreSQL. This is usually more effective than immediately switching to a large dedicated server.

Choosing a location

The server location affects latency, personal data processing requirements, and email delivery speed. Choose the region closest to your primary audience. For a team and customers in Europe, a European data center is usually the logical choice; for an audience in Asia, choose an Asian location.

If Fider is used inside a company, check whether employee and customer data may be stored in the selected jurisdiction. Also make sure that the SMTP provider allows email delivery from the IP address of the selected region and that port 25 is not the only available option: using 587 with STARTTLS or 465 with TLS is preferable.

Server Preparation

It is assumed below that you have received the server's IP address and the temporary password for the root user. Connect to the server via SSH, perform the initial update, create a separate user for administration, and disable dangerous methods of remote access.

On the local computer, first create a key if you do not already have one. Do not send the private key to the server or share it with other people. You can view the public key with the command cat ~/.ssh/id_ed25519.pub.


# Создайте современную пару SSH-ключей на локальном компьютере
ssh-keygen -t ed25519 -a 100 -C "admin@feedback-server"

Connect to the server as root. Replace SERVER_IP with the actual IPv4 address. On the first login, SSH will ask you to confirm the server fingerprint—compare it with the hosting panel data if such information is available.


# Подключитесь к новому серверу
ssh root@SERVER_IP

Update the operating system packages. It is best to run this command immediately after creating the VPS and then repeat it regularly. If the kernel was updated, reboot the server at a convenient time.


# Обновите индекс пакетов и установите все доступные обновления безопасности
apt update && apt upgrade -y

Create a separate account, add it to the sudo group, and install the basic tools. The example uses the deploy user; you can choose another name without spaces or special characters.


# Создайте пользователя для администрирования и выдайте ему права sudo
adduser deploy
usermod -aG sudo deploy
apt install -y curl wget git nano vim ufw fail2ban ca-certificates gnupg unzip

Copy the public SSH key for the new user. This command must be run on your local computer, not on the server. Then open a second terminal window and make sure that logging in as the new user works before disabling root access.


# С локального компьютера установите публичный ключ для пользователя deploy
ssh-copy-id deploy@SERVER_IP
ssh deploy@SERVER_IP

SSH Security

After successfully verifying key-based login, disable root login and password authentication. This reduces the risk of password-guessing attacks by bots. Do not close the current SSH session until you have confirmed that a new session under the deploy user opens without a password.


# Создайте отдельный конфигурационный файл для усиления SSH
sudo tee /etc/ssh/sshd_config.d/99-hardening.conf <<'EOF'
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
X11Forwarding no
MaxAuthTries 3
AllowUsers deploy
EOF

# Проверьте конфигурацию и перезапустите SSH-службу
sudo sshd -t && sudo systemctl restart ssh

Firewall and Fail2ban

Open only the SSH, HTTP, and HTTPS ports. If you have already changed the SSH port, replace the number 22 in the example. UFW does not immediately close an existing connection, but an incorrect firewall configuration can leave the server inaccessible, so check the SSH rule once again before enabling it.


# Разрешите только SSH, HTTP и HTTPS, затем включите firewall
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose

Fail2ban analyzes SSH logs and temporarily blocks IP addresses after repeated unsuccessful login attempts. Even with password authentication disabled, it is useful as an additional layer of protection.


# Включите Fail2ban и настройте базовую защиту SSH
sudo tee /etc/fail2ban/jail.d/sshd.local <<'EOF'
[sshd]
enabled = true
maxretry = 5
findtime = 10m
bantime = 1h
EOF

sudo systemctl enable --now fail2ban
sudo fail2ban-client status sshd

Check the current load and disk status. On a clean server, free space should make up most of the partition. Later, these commands will be useful for diagnosing performance issues.


# Проверьте память, диск, нагрузку и активные сетевые порты
free -h
df -h
uptime
sudo ss -tulpn

Software Installation — Step by Step

Docker Engine and the Docker Compose Plugin are convenient for Fider. On Ubuntu 24.04 LTS, you should not rely on the old docker.io package from the standard repository if an up-to-date Docker version is required. It is better to add the official Docker repository and install Docker Engine 28.x or a newer stable branch available at the time of installation.

The following components are used below: Ubuntu Server 24.04 LTS, Docker Engine 28+, Docker Compose v2, PostgreSQL 17 in a container, and Caddy 2.x. The Fider image will use the stable tag; before updating, always check the project's changelog and test the new version on a backup.


# Добавьте официальный GPG-ключ и репозиторий Docker для Ubuntu
sudo install -m 0755 -d /etc/apt/keyrings
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg
sudo chmod a+r /etc/apt/keyrings/docker.gpg

echo \
  "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu \
  $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \
  sudo tee /etc/apt/sources.list.d/docker.list > /dev/null

# Установите Docker Engine, CLI, Buildx и современный Docker Compose Plugin
sudo apt update
sudo apt install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
sudo systemctl enable --now docker
docker version
docker compose version

Add the deploy user to the docker group. This allows containers to be managed without sudo. Members of this group effectively receive root-level privileges, so add only trusted administrators to it.


# Разрешите пользователю deploy выполнять docker-команды без sudo
sudo usermod -aG docker deploy
newgrp docker
docker run --rm hello-world

Create the project directory. All important Fider files will be stored in /opt/fider: the Compose manifest, secrets file, Caddyfile, and backup directory. This approach simplifies migration to another server.


# Создайте структуру каталогов для приложения, proxy и резервных копий
sudo mkdir -p /opt/fider/{caddy,backups,scripts}
sudo chown -R deploy:deploy /opt/fider
cd /opt/fider

Generate cryptographically strong secrets for PostgreSQL and JWT. Do not use simple passwords, copy example values from the article, or store the .env file in a public Git repository. The database password and JWT secret will be needed in the next step.


# Сгенерируйте отдельные секреты для PostgreSQL и подписи пользовательских сессий
openssl rand -base64 32
openssl rand -hex 48

Before starting the containers, create a DNS record. In the registrar or DNS provider's panel, add an A record: name feedback, value—the IPv4 address of your VPS. If a root domain is required, use @ instead of a subdomain name.


# Проверьте с сервера, что DNS-запись указывает на нужный IP-адрес
getent hosts feedback.example.com

The output should contain your VPS's IP address. If DNS has not propagated yet, wait: this usually takes a few minutes, but depends on the TTL and DNS provider. Caddy will not be able to obtain a Let's Encrypt certificate until the domain points to the server and ports 80/443 are accessible externally.

Checking Images Before Startup

The images will be downloaded automatically by the docker compose up command, but preloading helps detect network or DNS issues more quickly. PostgreSQL 17 Alpine is used for the database: version 17 is stable, compact, and well suited to this scenario. Fider should work with a supported PostgreSQL version specified in the project's official documentation.


# Загрузите образы приложения и базы данных до запуска стека
docker pull getfider/fider:stable
docker pull postgres:17-alpine
docker image ls | grep -E 'getfider|postgres'

The stable tag is convenient for the first deployment, but in production it is better to pin the image version or digest after testing. This prevents automatic container recreation from unexpectedly updating the application.

Fider, SSL, and SMTP Configuration

This section creates three files: .env with secrets, docker-compose.yml with container definitions, and Caddyfile for HTTPS. Substitute your domain, sender email address, and actual SMTP credentials. Do not leave example values in the configuration.

Environment Variables File

Create /opt/fider/.env. Compose will automatically load variables from this file. Set permissions to 600 so that other system users cannot read the database and SMTP passwords.


# Create the secrets file and change the values before the first launch
cd /opt/fider
cat > .env <<'EOF'
FIDER_DOMAIN=feedback.example.com

POSTGRES_DB=fider
POSTGRES_USER=fider
POSTGRES_PASSWORD=CHANGE_TO_A_LONG_RANDOM_DATABASE_PASSWORD

JWT_SECRET=CHANGE_TO_A_LONG_RANDOM_JWT_SECRET

SMTP_HOST=smtp.example-mail-provider.com
SMTP_PORT=587
SMTP_USERNAME=SMTP_LOGIN_OR_API_KEY
SMTP_PASSWORD=SMTP_PASSWORD_OR_API_KEY
SMTP_FROM=Feedback Team <[email protected]>
EOF

chmod 600 .env

For SMTP, use separate credentials for transactional emails. Do not specify the primary password for the corporate mailbox. Most email providers support API keys or app passwords. Port 587 uses STARTTLS; port 465 often requires implicit TLS, and variables may differ depending on the Fider version and SMTP provider.

Docker Compose for Fider and PostgreSQL

Below, PostgreSQL does not expose a port externally: it is available only to the Fider container on the internal Docker network. Fider itself also has no exposed host port—it will be accessible only through Caddy. This reduces the attack surface.


services:
  db:
    image: postgres:17-alpine
    container_name: fider-db
    restart: unless-stopped
    environment:
      POSTGRES_DB: ${POSTGRES_DB}
      POSTGRES_USER: ${POSTGRES_USER}
      POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
    volumes:
      - postgres_data:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER} -d ${POSTGRES_DB}"]
      interval: 10s
      timeout: 5s
      retries: 10
    networks:
      - fider_internal

  fider:
    image: getfider/fider:stable
    container_name: fider-app
    restart: unless-stopped
    depends_on:
      db:
        condition: service_healthy
    environment:
      BASE_URL: https://${FIDER_DOMAIN}
      DATABASE_URL: postgres://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db:5432/${POSTGRES_DB}?sslmode=disable
      JWT_SECRET: ${JWT_SECRET}
      EMAIL_NOREPLY: ${SMTP_FROM}
      EMAIL_SMTP_HOST: ${SMTP_HOST}
      EMAIL_SMTP_PORT: ${SMTP_PORT}
      EMAIL_SMTP_USERNAME: ${SMTP_USERNAME}
      EMAIL_SMTP_PASSWORD: ${SMTP_PASSWORD}
      EMAIL_SMTP_ENABLE_STARTTLS: "true"
    networks:
      - fider_internal
      - proxy
    healthcheck:
      test: ["CMD-SHELL", "wget -qO- http://localhost:3000/ > /dev/null || exit 1"]
      interval: 30s
      timeout: 10s
      retries: 5

  caddy:
    image: caddy:2-alpine
    container_name: fider-caddy
    restart: unless-stopped
    depends_on:
      - fider
    ports:
      - "80:80"
      - "443:443"
    environment:
      FIDER_DOMAIN: ${FIDER_DOMAIN}
    volumes:
      - ./caddy/Caddyfile:/etc/caddy/Caddyfile:ro
      - caddy_data:/data
      - caddy_config:/config
    networks:
      - proxy

volumes:
  postgres_data:
  caddy_data:
  caddy_config:

networks:
  fider_internal:
    internal: true
  proxy:

Save this file as /opt/fider/docker-compose.yml. Before starting, verify that Compose sees the variables correctly. The command must not print passwords to shared logs or screenshots; if you are working on a shared system, do not use docker compose config unless necessary, because it reveals substituted values.


# Check the Compose file syntax and prepare the container configuration
cd /opt/fider
docker compose config --quiet

Configuring Caddy and Automatic HTTPS

Caddy automatically requests a Let's Encrypt certificate, redirects HTTP to HTTPS, and renews the certificate. For this to work, the domain must already point to the server, and the firewall and external network filter must allow TCP ports 80 and 443.


{
    email [email protected]
    acme_ca https://acme-v02.api.letsencrypt.org/directory
}

{$FIDER_DOMAIN} {
    encode zstd gzip

    reverse_proxy fider:3000 {
        header_up Host {host}
        header_up X-Real-IP {remote_host}
        header_up X-Forwarded-For {remote_host}
        header_up X-Forwarded-Proto {scheme}
    }

    log {
        output stdout
        format console
    }
}

Save the configuration in /opt/fider/caddy/Caddyfile. In the email directive, specify a working administrator address: notifications from the certificate authority may be sent to it. The caddy_data storage contains certificates and the ACME account, so it must also be included in backups.

Start the stack in the background and immediately review the logs. On first launch, Fider creates the required tables in PostgreSQL, and Caddy obtains a certificate. Depending on DNS and network speed, this usually takes from a few seconds to a couple of minutes.


# Start PostgreSQL, Fider, and Caddy in the background
cd /opt/fider
docker compose up -d
docker compose ps
docker compose logs --tail=100 -f

Exit log viewing mode with Ctrl+C. In the container status table, containers should be running or healthy. If Caddy did not obtain a certificate, do not make dozens of repeated requests: first check DNS, the firewall, and port availability from an external network.

Initial Fider Setup

Open https://feedback.example.com in a browser. On the first visit, Fider will prompt you to create a workspace and the first administrator. Use an address that can receive emails through the configured SMTP server. If emails do not arrive, fix SMTP first rather than creating new workspaces and users.

After the first login, configure the portal name, description, logo, publication statuses, and moderation rules. It is useful to immediately create the statuses Planned, In Progress, Implemented, and Not Planned. This makes feedback transparent: users can see that ideas do not disappear without a response.

Operational Verification

Check HTTPS headers and the HTTP redirect from the server itself. Normally, an HTTP request should return a 308 or 301 redirect, and HTTPS should return status 200, 302, or 303 depending on the initial setup state.


# Check the HTTP redirect, HTTPS, and container status
curl -I http://feedback.example.com
curl -I https://feedback.example.com
docker compose ps
docker inspect --format='{{.State.Health.Status}}' fider-db

Check email delivery logs after registering a test user or sending an invitation. A successful SMTP connection does not always mean delivery: also check the inbox, spam folder, and SMTP provider logs.


# Filter application logs for mail and SMTP messages
cd /opt/fider
docker compose logs --since=15m fider | grep -iE 'smtp|mail|email|error'

For good deliverability, configure DNS records for the email domain: SPF, DKIM, and DMARC. If the sender is [email protected], the example.com domain must be verified with the SMTP provider. Otherwise, emails may end up in spam even if Fider connects to SMTP without errors.

Backups and Maintenance

A Docker volume is not a backup. If the VPS disk fails, a volume is accidentally deleted, or the database is corrupted, it will be impossible to recover the data without an external backup. The minimum strategy for Fider is a daily logical PostgreSQL dump, a copy of the configuration, and sending the archive outside the primary server.

What needs to be saved

  • PostgreSQL dump — all users, suggestions, votes, comments, and system settings.
  • /opt/fider/docker-compose.yml — infrastructure description.
  • /opt/fider/.env — secrets, SMTP credentials, and domain name.
  • /opt/fider/caddy/Caddyfile — reverse proxy settings.
  • Caddy Docker volume — certificates and ACME data. They can be reissued, but saving them speeds up recovery.
  • Documentation with DNS records, the SMTP access method, and the recovery procedure.

Do not rely solely on a VPS snapshot. Snapshots are useful for quick rollbacks, but they are usually located in the same infrastructure as the server. The 3-2-1 rule remains relevant: at least three copies of the data, on two different media, with one copy outside the primary server.

Daily backup script

The following script creates a compressed database dump, archives the configuration, and sends the directory to S3-compatible storage via Restic. Restic encrypts the data on the server side before sending it. You can use Backblaze B2 S3, Wasabi, MinIO on a separate server, or another compatible object storage service.


# Установите Restic и инструменты для архивирования
sudo apt install -y restic tar

Create a file with the Restic parameters. S3 access credentials should have only write and read permissions for the required bucket, without access to other projects. The file also contains the repository encryption password: losing this password permanently makes the backups unreadable.


# Создайте защищённый файл окружения для Restic и S3-хранилища
sudo tee /etc/fider-restic.env <<'EOF'
export RESTIC_REPOSITORY="s3:https://s3.example-storage.net/fider-backups"
export RESTIC_PASSWORD="CHANGE_TO_A_LONG_RESTIC_REPOSITORY_PASSWORD"
export AWS_ACCESS_KEY_ID="S3_ACCESS_KEY"
export AWS_SECRET_ACCESS_KEY="S3_SECRET_KEY"
EOF

sudo chmod 600 /etc/fider-restic.env

Initialize the remote repository only once. After that, Restic will create the structure for encrypted snapshots. Run the command as the user who will execute the backup; in this example, it is root via cron because the environment file is located in /etc.


# Создайте новый зашифрованный репозиторий Restic в удалённом S3-бакете
sudo bash -c 'source /etc/fider-restic.env && restic init'

Create the script. It uses pg_dump inside the PostgreSQL container, so it does not require installing the PostgreSQL client on the host. The script keeps local dumps for seven days, while Restic applies separate retention rules to remote snapshots.


#!/usr/bin/env bash
set -euo pipefail

APP_DIR="/opt/fider"
BACKUP_DIR="${APP_DIR}/backups"
DATE="$(date +%F_%H-%M-%S)"
DUMP_FILE="${BACKUP_DIR}/fider_${DATE}.sql.gz"
CONFIG_FILE="${BACKUP_DIR}/fider_config_${DATE}.tar.gz"

mkdir -p "${BACKUP_DIR}"

cd "${APP_DIR}"

docker compose exec -T db sh -c \
  'pg_dump -U "$POSTGRES_USER" -d "$POSTGRES_DB" --format=plain' \
  | gzip -9 > "${DUMP_FILE}"

tar -czf "${CONFIG_FILE}" \
  "${APP_DIR}/docker-compose.yml" \
  "${APP_DIR}/.env" \
  "${APP_DIR}/caddy/Caddyfile"

source /etc/fider-restic.env

restic backup "${DUMP_FILE}" "${CONFIG_FILE}" --tag fider
restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --prune

find "${BACKUP_DIR}" -type f -mtime +7 -delete

Save the code as /opt/fider/scripts/backup.sh, make it executable, and run it manually. The first run is important: it shows whether Docker and the S3 bucket are accessible and whether there is enough disk space.


# Установите права на скрипт и выполните тестовый бэкап вручную
sudo chmod 700 /opt/fider/scripts/backup.sh
sudo /opt/fider/scripts/backup.sh
sudo bash -c 'source /etc/fider-restic.env && restic snapshots'

Add a task to root-cron, for example, daily at 03:25. Choose a time outside periods of high activity. The output will be written to a log; if local mail is not configured on the server, it is more convenient to redirect cron messages to a centralized monitoring system.


# Добавьте ежедневный запуск резервного копирования в root-cron
sudo crontab -e

25 3   * /opt/fider/scripts/backup.sh >> /var/log/fider-backup.log 2>&1

Recovery testing

A backup is considered functional only after a test recovery. Once a quarter, create a temporary VPS or a separate Docker project, download a Restic snapshot, start a clean PostgreSQL database, and import the dump. Verify that spaces, ideas, and users are visible.


# Пример восстановления SQL-дампа в чистую базу PostgreSQL
gunzip -c fider_YYYY-MM-DD_HH-MM-SS.sql.gz | \
docker compose exec -T db psql -U fider -d fider

For an actual recovery, first stop Fider, restore the database to an empty PostgreSQL container, restore the configuration files, and only then start the application. Do not import a dump over a running production database without a clear plan: this may create inconsistent data.

Updating Fider, PostgreSQL, and Docker

For Fider, a short maintenance window model is usually suitable. The update takes a few minutes, but always make a backup and read the release notes beforehand. Pay particular attention to major PostgreSQL updates: they cannot be performed by simply changing the container tag, because the data directory format changes between major versions.


# Создайте бэкап, загрузите свежие образы и безопасно пересоздайте контейнеры
cd /opt/fider
sudo /opt/fider/scripts/backup.sh
docker compose pull
docker compose up -d
docker compose ps
docker compose logs --tail=100 fider

Do not blindly run docker system prune -a on a production server. The command may remove images needed for a quick rollback. Instead, periodically review Docker usage and remove only unused layers after confirmation.


# Проверьте объём Docker-данных и удалите только безопасно неиспользуемые ресурсы
docker system df
docker image prune -f

Install Ubuntu updates weekly or monthly after reviewing the package list. For a small Fider instance, a planned 15–30-minute maintenance window is acceptable. If a kernel reboot is required, first make sure the backup has completed, then reboot the server and check the containers.

Troubleshooting and FAQ

Why does Caddy fail to obtain an SSL certificate, and why is there an ACME error in the logs?

First, check DNS: the command getent hosts feedback.example.com should return your VPS's public IP. Then make sure ports 80 and 443 are open in UFW and that there is no additional firewall in the provider's control panel. Check availability from an external network, not only from the server. Also make sure there is no conflicting AAAA record for the domain: if IPv6 is specified but not configured on the server, the certificate authority may try to connect via IPv6 and fail the validation.

Fider opens but displays a database connection error. What should I check?

Check the container logs with the commands docker compose logs db and docker compose logs fider. Most often, the problem is a mismatch between POSTGRES_PASSWORD and the DATABASE_URL string, or the database was already created with a different password. Changing the password in .env does not automatically change the password of an existing PostgreSQL user. If the instance is new and contains no data, delete the volume and recreate it; if data already exists, change the password using an SQL command inside PostgreSQL.

Why do Fider emails not arrive after registration?

Check EMAIL_SMTP_HOST, the port, username, password, and the EMAIL_NOREPLY address. For most providers, port 587 requires STARTTLS, which is enabled in the example configuration. Check the application logs for the words smtp and email. If the SMTP connection succeeds but the email is not delivered, check spam, the provider's logs, SPF, DKIM, and DMARC. The sender address must belong to a verified domain or sender identity.

The Fider container keeps restarting. How can I find the cause?

Run docker compose ps, then docker compose logs --tail=200 fider. Look for the first error before the restart: it is usually an incorrect PostgreSQL connection string, a missing required environment variable, a migration error, or insufficient memory. Check free -h and dmesg -T | grep -i oom. If the kernel terminated the process due to insufficient memory, increase the VPS RAM to 2–4 GB and temporarily add swap.

What is the minimum VPS configuration suitable for Fider?

For a test or small private board, the minimum suitable configuration is 1 vCPU, 2 GB RAM, and 20–25 GB SSD. A configuration with 1 GB of memory is possible only as a temporary test environment: PostgreSQL, Docker, and the system will operate with almost no reserve. For production with SMTP, HTTPS, backups, and several hundred users, it is more reasonable to start with 2 vCPUs, 4 GB RAM, and 40 GB NVMe. Account for database growth and keep at least 15–20% of the disk free.

Which should you choose — VPS or dedicated for this task?

A VPS is almost always sufficient for Fider. The service generates a relatively small load, while a VPS is easier to scale, back up, and migrate. A dedicated server is justified with a large number of active users, dozens of related services, your own email infrastructure, or requirements for guaranteed physical resources. In practice, as Fider grows, it is initially more useful to move PostgreSQL to a separate server or managed database than to purchase a dedicated machine solely for the web application.

Can PostgreSQL be opened on port 5432 for connection from a home computer?

Technically, yes, but this is bad practice for permanent operation. In the current Compose file, the database is isolated on the internal Docker network and is not accessible from outside. For diagnostics, use docker compose exec db psql on the server or an SSH tunnel. If external access is truly necessary, restrict access to a specific IP address in the firewall, use a separate user with minimal privileges, and enable TLS. Never expose PostgreSQL to the entire internet without restrictions.

How can I move Fider to another VPS without losing data?

Prepare the new server, install Docker, and create the same /opt/fider directory. Copy the Compose file, Caddyfile, and .env through a secure channel, restore the latest SQL dump to a clean PostgreSQL database, and then start the containers. After verification, change the domain's DNS record to the new IP. Before switching, reduce the DNS TTL to 300 seconds. Do not delete the old server for several days: leave it powered off or blocked by the firewall until the new instance's stable operation is confirmed.

Conclusions and next steps

You now have self-hosted Fider on a VPS: the application runs over HTTPS, stores data in PostgreSQL, sends notifications via SMTP, and regularly creates encrypted backups. This setup is suitable for a public idea board, a private corporate portal, or a SaaS product feedback channel.

  1. Create your first space, configure suggestion statuses, and describe the rules for publishing ideas.
  2. Test registration, voting, comments, and email delivery using a test user account.
  3. Add monitoring for HTTPS availability, disk space, Docker container status, and the result of the nightly backup.
  4. As the load grows, move PostgreSQL to a separate server, add centralized log collection, and pin Docker image versions.

Was this guide helpful?

Your feedback helps us improve our guides.

Share this post:

Send this guide to someone who may find it useful.

Telegram VKVK WhatsApp Facebook LinkedIn XX

Fider installation on VPS: self-hosted feedback collection, SSL and SMTP
support_agent
Valebyte Support
Usually replies within minutes
Hi there!
Send us a message and we'll reply as soon as possible.