Small and mid-sized businesses often suffer from fragmented tooling, where accounting, CRM, and messaging systems exist in isolated silos, leading to data duplication and broken workflows. Bryan Gitonga of Greatzern Software Solutions outlines a consolidated approach using a single VPS architecture that replaces these patchworks with an integrated, self-hosted stack. The solution leverages Dokploy for container management, Traefik for routing, and CrowdSec for behavioral security, all shielded by Cloudflare.
The Architecture Stack
The deployment model routes traffic through four distinct layers to ensure security and efficiency. Cloudflare handles edge DNS and caching, while a Cloudflared tunnel connects the edge to the server, eliminating the need to expose VPS web ports directly to the public internet. CrowdSec inspects traffic for malicious patterns, and Traefik directs requests to the appropriate containers. Dokploy sits on top of this infrastructure, managing deployments and domains via a unified dashboard.
Practical Deployment and Network Gotchas
Dokploy simplifies the deployment process by automating Traefik configuration, allowing developers to connect repositories or Docker images and deploy with minimal manual routing setup. However, Gitonga highlights a critical networking pitfall: services must explicitly declare the dokploy-network in their compose files to communicate. Without this configuration, containers fail to resolve each other by name, causing DNS errors despite both services running successfully. This requires setting external: true for the network in the compose definition.
Security and Operational Reality
Security is handled through a combination of edge filtering and behavioral analysis. CrowdSec acts as a bouncer, blocking IPs that exhibit brute-force or scanner behavior before they reach the applications. The article provides a checklist for maintaining this stack, emphasizing closed web ports, unique credentials, scheduled database backups, and regular monitoring of CrowdSec decisions. While this setup offers control and predictable costs, it demands ongoing maintenance, which is why Greatzern offers managed deployment for businesses lacking internal DevOps capacity.
Key Takeaways
- Dokploy automates Traefik routing, reducing manual configuration overhead for multi-container deployments.
- Explicitly declaring
dokploy-networkin compose files is required for inter-container communication. - Using Cloudflared tunnels hides VPS ports, enhancing security by removing direct public exposure.
- CrowdSec provides behavioral protection that complements Cloudflare's edge filtering.
- Self-hosting eliminates per-app hosting fees but requires disciplined backup and update routines.
The Bottom Line
Self-hosting business stacks on a single VPS is a powerful strategy for data sovereignty and cost control, but the operational burden of network configuration and security maintenance is non-trivial. For teams without dedicated DevOps resources, the time saved by tools like Dokploy is often offset by the need for careful, ongoing management of the underlying infrastructure.