Dev.to AI 🤖 Ai 👁 0 📖 3 min read

Self-Hosting a Business Stack with Dokploy, Traefik, CrowdSec

Most small and mid-sized businesses run on a patchwork of separate tools: one for accounting, one for customers, one for sales, one for messaging. Data gets duplicated and processes break between systems. A cleaner appr

Self-Hosting a Business Stack with Dokploy, Traefik, CrowdSec

Most small and mid-sized businesses run on a patchwork of separate tools: one for accounting, one for customers, one for sales, one for messaging. Data gets duplicated and processes break between systems.

A cleaner approach is to deploy an integrated stack on infrastructure the business controls. This post covers the deployment and security setup we use at Greatzern Software Solutions to run business systems on a single VPS: Dokploy for deployment, Traefik for routing, and CrowdSec for protection, behind Cloudflare.

What we deploy

A typical client stack includes:

Each application runs as its own container, with its own subdomain.

The architecture

Traffic reaches the server in four layers:

  1. Cloudflare at the edge handles DNS, caching and basic filtering.
  2. A Cloudflared tunnel carries traffic to the server, so the VPS does not need to expose its web ports directly to the internet.
  3. CrowdSec inspects behavior and blocks malicious IPs.
  4. Traefik routes each request to the right container.

Dokploy manages the containers, domains and deployments on top of this.

Why Dokploy

Dokploy gives you a deployment dashboard on your own server. You connect a repository or a Docker image, set environment variables, attach a domain, and deploy. Traefik is configured for you, which removes most of the manual routing work.

For a business that wants to own its infrastructure, this means one server, one dashboard, and no per-app hosting fees.

The network gotcha that costs hours

When one service needs to talk to another, for example an automation tool calling a database, containers must share a network. In Dokploy, that network is dokploy-network.

If a service does not declare it, it cannot resolve other containers by name. You will see DNS resolution failures even though both containers are running.

Declare the network explicitly in your compose file:

services:
  app:
    image: your-image:latest
    networks:
      - dokploy-network

networks:
  dokploy-network:
    external: true

After this change, containers can reach each other by service name.

Adding behavioral protection with CrowdSec

A firewall blocks ports. It does not notice a client hammering your login page. CrowdSec reads your logs, detects patterns such as brute force attempts and scanners, and blocks those IPs through a bouncer.

With Traefik in front of your apps, the CrowdSec bouncer sits in the request path and rejects flagged IPs before they reach your applications. Combined with Cloudflare at the edge, this gives you protection at two layers without paying for a managed security product.

Security checklist

  • Keep web ports closed on the VPS and route traffic through the tunnel.
  • Put every application on its own subdomain.
  • Use strong, unique credentials and rotate them.
  • Back up databases and volumes on a schedule, and test restores.
  • Keep the host and container images updated.
  • Monitor CrowdSec decisions regularly.

Who this is for

This setup suits businesses that want one integrated system, control over their data, and predictable costs. It takes time to build and maintain properly, which is why many companies hand it to a team that does it daily.

If you want this deployed and maintained for your business, Greatzern configures, deploys and supports these systems on your own infrastructure.

What does your self-hosting stack look like? Share it in the comments.

📰 Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.