macrostack

Layer 5 · self-hosting reality check

What it actually takes to self-host Penpot

The docs say 4 GiB. Penpot's Community Advocate gives 1–2 CPUs and 4 GiB in the forum FAQ; the official docs state no minimum.. In practice you want 4–8 GB for a small design team, with backend, frontend, exporter (a headless browser), PostgreSQL 15 and Valkey on one box. For the top end, the docs say 4 CPUs and 16 GB are enough for thousands of users.. Here is the honest version — real requirements, real monthly cost, what you will be maintaining, and the one thing that catches people out.

Usually reached from Figma alternatives, where Penpot is one of the picks.

Wondering whether you need to at all? Is Figma free? — what the free tier actually allows, and where the wall is.

RAM — documented minimum4 GiB. Penpot's Community Advocate gives 1–2 CPUs and 4 GiB in the forum FAQ; the official docs state no minimum.
RAM — what it really needs4–8 GB for a small design team, with backend, frontend, exporter (a headless browser), PostgreSQL 15 and Valkey on one box. For the top end, the docs say 4 CPUs and 16 GB are enough for thousands of users.
CPU2 vCPU for a small team. Designers' own machines matter too, because Penpot makes heavy use of the browser.
Disk50–100 GB for the database for up to 10 editors, plus about 5 GB per extra editor (vendor sizing). Uploads live in the penpot_assets volume.
Monthly cost$7–24/mo on a 4 GB VPS, plus an SMTP provider for invites and sign-up email
Setup time1 hour with Docker Compose. Half a day with HTTPS, SMTP and hardened flags.
How you install itThe official docker-compose.yaml (`docker compose -p penpot -f docker-compose.yaml up -d`): frontend, backend, exporter, admin console, MCP server, PostgreSQL 15, Valkey and a mailcatcher. There is a Helm chart for Kubernetes.
Ongoing maintenanceReleases come about monthly (2.17.0 in July, 2.17.1 and 2.17.2 in August, 2.18.0 in September 2026). The docs strongly recommend upgrading in small steps rather than jumping between distant versions. Back up the penpot_postgres_v15 and penpot_assets volumes first.
Where it stops scalingThe docs' reference box is 4 CPUs and 16 GB for thousands of users, with storage growing about 5 GB per editor past 10. Kubernetes (Helm) is the documented path beyond one host.

The thing that catches people out

The official docker-compose file is set up for localhost, not the internet. PENPOT_SECRET_KEY is literally "change-this-insecure-key". Flags turn off secure session cookies and email verification, and all mail goes to a local mailcatcher, so invites never arrive. The file's own comment says to remove those flags before exposing Penpot, and without HTTPS some browser features, such as the clipboard, don't work properly. Before the first real user: generate a random secret key, put Penpot behind HTTPS, remove the two disable flags and connect SMTP to a real provider.

When not to self-host Penpot

Your team has eight people or fewer and no rule about where data lives. Penpot's hosted Professional plan is free for up to 8 members with unlimited viewers, and there is no server to look after.

Every guide here carries this section. A site that only ever tells you to self-host is selling something — the useful answer is sometimes no.

Other Layer 5 self-hosting guides

Common questions

How much RAM does Penpot actually need?
4–8 GB for a small design team, with backend, frontend, exporter (a headless browser), PostgreSQL 15 and Valkey on one box. For the top end, the docs say 4 CPUs and 16 GB are enough for thousands of users. in practice. The documented minimum is 4 GiB. Penpot's Community Advocate gives 1–2 CPUs and 4 GiB in the forum FAQ; the official docs state no minimum., which is the figure at which the process starts rather than the figure at which it works under real use. 2 vCPU for a small team. Designers' own machines matter too, because Penpot makes heavy use of the browser. alongside it.
What does self-hosting Penpot cost per month?
$7–24/mo on a 4 GB VPS, plus an SMTP provider for invites and sign-up email This is commodity VPS pricing and excludes your time, which is the larger cost for most people — budget for releases come about monthly (2.17.0 in July, 2.17.1 and 2.17.2 in August, 2.18.0 in September 2026). The docs strongly recommend upgrading in small steps rather than jumping between distant versions. Back up the penpot_postgres_v15 and penpot_assets volumes first.
How long does it take to set up Penpot?
1 hour with Docker Compose. Half a day with HTTPS, SMTP and hardened flags., via The official docker-compose.yaml (`docker compose -p penpot -f docker-compose.yaml up -d`): frontend, backend, exporter, admin console, MCP server, PostgreSQL 15, Valkey and a mailcatcher. There is a Helm chart for Kubernetes..
When should I NOT self-host Penpot?
Your team has eight people or fewer and no rule about where data lives. Penpot's hosted Professional plan is free for up to 8 members with unlimited viewers, and there is no server to look after.
What is the most common mistake when self-hosting Penpot?
The official docker-compose file is set up for localhost, not the internet. PENPOT_SECRET_KEY is literally "change-this-insecure-key". Flags turn off secure session cookies and email verification, and all mail goes to a local mailcatcher, so invites never arrive. The file's own comment says to remove those flags before exposing Penpot, and without HTTPS some browser features, such as the clipboard, don't work properly. Before the first real user: generate a random secret key, put Penpot behind HTTPS, remove the two disable flags and connect SMTP to a real provider.
The Macrostack brief

New swaps, worth your inbox.

A short, occasional email when we add a high-intent alternative or ship a new head-to-head. No spam, no selling your address — unsubscribe in one click.