docs/main/deployment-guide/server/deploy-containers.mdx
You can deploy Mattermost Server using container technologies for exploring functionality, testing, and development purposes, as it allows you to quickly set up a Mattermost instance without needing to manage the underlying infrastructure. This deployment method shouldn't be used in production environments as it doesn't support clustered deployments or High Availability (HA) configurations out-of-the-box.
<Warning>If you don't have Docker installed, follow the instructions below based on your operating system. You'll need Docker Engine and Docker Compose (release 1.28 or later).
<Tip>Need a FIPS / STIG-compliant image? Mattermost publishes a FIPS-compliant, STIG-hardened variant of every container image. Swapping the image tag is the only change required — see FIPS / STIG container builds.
</Tip>This section provides a quick start guide for deploying Mattermost on Docker by leveraging Docker Compose.
<Note>In a terminal window, clone the repository and enter the directory.
git clone https://github.com/mattermost/docker
cd docker
Create your .env file by copying and adjusting the env.example file.
cp env.example .env
DOMAIN value in the .env file to correspond to the domain for your Mattermost server.MM_SUPPORTSETTINGS_SUPPORTEMAIL. This is the email address your users will contact when they need help.Create the required directories and set their permissions.
mkdir -p ./volumes/app/mattermost/{config,data,logs,plugins,client/plugins,bleve-indexes}
sudo chown -R 2000:2000 ./volumes/app/mattermost
(Optional) Configure TLS for NGINX. If you're not using the included NGINX reverse proxy, you can skip this step.
Resource limits: If you're using a custom docker-compose.yml file that sets <code>pids_limit</code>, we recommend using mem_limit instead to constrain resources while allowing normal connection scaling. Low pids_limit values can prevent the container from creating enough processes or threads, which may lead to unstable behavior under load. The current default in docker-compose.yml is set to mem_limit: 4G.
bash scripts/issue-certificate.sh -d <YOUR_MM_DOMAIN> -o ${PWD}/certs
To include the certificate and key, uncomment the following lines in your .env file and ensure they point to the appropriate files.
#CERT_PATH=./certs/etc/letsencrypt/live/${DOMAIN}/fullchain.pem
#KEY_PATH=./certs/etc/letsencrypt/live/${DOMAIN}/privkey.pem
mkdir -p ./volumes/web/cert
cp <PATH-TO-PRE-EXISTING-CERT>.pem ./volumes/web/cert/cert.pem
cp <PATH-TO-PRE-EXISTING-KEY>.pem ./volumes/web/cert/key-no-password.pem
To include the certificate and key, ensure the following lines in your .env file points to the appropriate files.
CERT_PATH=./volumes/web/cert/cert.pem
KEY_PATH=./volumes/web/cert/key-no-password.pem
docker compose -f docker-compose.yml -f docker-compose.without-nginx.yml up -d
To access your new Mattermost deployment, navigate to http://<YOUR_MM_DOMAIN>:8065/ in your browser.
To shut down your deployment:
docker compose -f docker-compose.yml -f docker-compose.without-nginx.yml down
docker compose -f docker-compose.yml -f docker-compose.nginx.yml up -d
To access your new Mattermost deployment via HTTPS, navigate to https://<YOUR_MM_DOMAIN>/ in your browser.
To shut down your deployment:
docker compose -f docker-compose.yml -f docker-compose.nginx.yml down
To use SSO with GitLab with a self-signed certificate, you have to add the PKI chain for your authority. This is required to avoid the Token request failed: certificate signed by unknown authority error.
To add the PKI chain, uncomment the following line in your .env file, and ensure it points to your pki_chain.pem file:
#GITLAB_PKI_CHAIN_PATH=<path_to_your_gitlab_pki>/pki_chain.pem
Then uncomment the following line in your docker-compose.yml file, and ensure it points to the same pki_chain.pem file:
# - ${GITLAB_PKI_CHAIN_PATH}:/etc/ssl/certs/pki_chain.pem:ro
The mattermost-docker GitHub repository is deprecated. Visit the mattermost/docker GitHub repository to access the official Docker deployment solution for Mattermost.
To migrate from an existing mattermost/mattermost-prod-app image, we recommend migrating to either mattermost/mattermost-enterprise-edition or mattermost/mattermost-team-edition images, which are the official images supported by Mattermost. These images support PostgreSQL v11+ databases, which we know has been a long-running challenge for the community, and you will not lose any features or functionality by moving to these new images.
For additional help or questions, please refer to this issue.
Shut down your deployment.
Run git pull to fetch any recent changes to the repository, paying attention to any potential env.example changes.
Adjust the MATTERMOST_IMAGE_TAG in the .env file to point your desired enterprise or team image version.
For production environments, we recommend using specific version tags such as MATTERMOST_IMAGE_TAG=release-10.5 rather than generic tags like MATTERMOST_IMAGE_TAG=release-10. Generic release-x tags are intended for development use only and do not automatically receive new patch releases within that major version. Using specific version tags ensures a more reproducible and deterministic environment for your production deployment.
Redeploy Mattermost.
If deploying on an M1 Mac and encountering permission issues in the Docker container, redo the "create the required directories" step above and skip this command:
sudo chown -R 2000:2000 ./volumes/app/mattermost
If having issues deploying on Docker generally, ensure the docker daemon is enabled and running:
sudo systemctl enable --now docker
To remove all data and settings for your Mattermost deployment:
sudo rm -rf ./volumes
For quick start deployments, you can change the Postgres username and/or password (recommended) in the .env file. If your database is managed externally, you'll need to change the password in your database management tool. Then, update the .env file with the new credentials.
For an in-depth guide to configuring the TLS certificate and key for Nginx, please refer to this document in the repository.
Looking for a way to evaluate Mattermost on a single local machine using Docker? We recommend using the Mattermost Docker Preview Image to install Mattermost in Preview Mode.
Install Docker.
Once you have Docker, run the following command in a terminal window:
docker run --name mattermost-preview -d --publish 8065:8065 --publish 8443:8443 mattermost/mattermost-preview
When Docker is done fetching the image, navigate to http://localhost:8065/ in your browser to preview Mattermost.
Select Don't have an account in the top right corner of the screen to create an account for your preview instance. If you don't see this option, ensure that the Enable open server configuration setting is enabled. This setting is disabled for self-hosted Mattermost deployments by default.
Log in to your preview instance with your user credentials.
The Preview Mode Docker instance for Mattermost is designed for product evaluation, and sets SendEmailNotifications=false so the product can function without enabling email. See the Configuration Settings documentation to customize your deployment.
To update your Mattermost preview image and container, you must first stop and delete your existing mattermost-preview container by running the following commands:
docker pull mattermost/mattermost-preview
docker stop mattermost-preview
docker rm mattermost-preview
Once the new image is pulled and the container is stopped and deleted you need to run the docker run command from above.
On Linux, include sudo in front of all docker commands.
To access a shell inside the container, run the following command:
docker exec -ti mattermost-preview /bin/bash
See the deployment troubleshooting documentation for resolutions to common deployment issues.
</Note>Deploying Mattermost using Docker containers can be made secure with proper configurations for HTTPS and reverse proxying. This guide outlines the steps to set up TLS and an NGINX reverse proxy for your Mattermost deployment, ensuring secure communication between users and your server.
- Bind Docker volumes for NGINX configuration files and TLS certificates to ensure persistent and secure storage of these assets.
- Use permission restrictions on host directories where sensitive files such as TLS keys are stored.
Create the NGINX Configuration File by designing a robust nginx.conf file to configure reverse proxying and HTTPS. Here's a basic example:
server {
listen 443 ssl;
server_name your-domain.com;
ssl_certificate /etc/nginx/certs/fullchain.pem;
ssl_certificate_key /etc/nginx/certs/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
location / {
proxy_pass http://mattermost:8065;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto https;
}
}
Verify the configuration with nginx -t before applying.
- Use Let's Encrypt for free, automated certificates. Tools like Certbot can help automate the process.
- Alternatively, purchase certificates from a trusted certificate authority (CA) and ensure proper setup of intermediate and root certificate chains.
Keep private keys secure and avoid storing them directly inside Docker images.
Connect Containers Using Docker Networking:
Use Docker's networking features to isolate and link containers.
Create a custom Docker bridge network to ensure secure communication. For example:
shdocker network create mattermost-networkLaunch the Mattermost and NGINX containers on the same network:
shdocker network connect mattermost-network mattermost docker network connect mattermost-network nginx
Point your domain to the server IP address:
Ensure your domain (e.g., your-domain.com) points to the public IP address of your server. If your IP is dynamic, consider setting up Dynamic DNS (DDNS) for seamless connectivity.
After placing the certificates and updating the configuration, restart the NGINX container:
Use logs (docker logs nginx) to troubleshoot and validate the container's operation.
Verify HTTPS Access by visiting https://your-domain.com in a web browser to confirm Mattermost is running securely over HTTPS.
Use tools such as SSL Labs : https://www.ssllabs.com/ssltest/ to validate the quality of your TLS setup.
Enable HTTP Strict Transport Security (HSTS) in your NGINX configuration to prevent downgrade attacks.
Use NGINX rate-limiting features to restrict abusive traffic, such as excessive requests:
Additionally, consider:
--privileged and utilize user namespaces.By following these steps, your Mattermost deployment using Docker containers will be accessible securely over HTTPS with efficient proxying through NGINX. Implementing the additional security recommendations will further protect your environment against evolving threats.