AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Vps Docker Traefik Deploy

skill-thienanblog-awesome-ai-agent-skills-vps-docker-traefik-deploy · by thienanblog

Plan and implement secure production deployments of Docker Compose applications on self-hosted VPS or cloud servers using Docker Engine, Docker Compose, Traefik, private registries, SSH tunnels, least-privilege users, persistent volumes, backups, DNS, and storage growth planning. Use when an AI agent needs to design, review, document, or execute a real deploy for websites, APIs, websockets, worke…

No reviews yet
0 installs
10 views
0.0% view→install

Install

$ agentstack add skill-thienanblog-awesome-ai-agent-skills-vps-docker-traefik-deploy

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-thienanblog-awesome-ai-agent-skills-vps-docker-traefik-deploy)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Vps Docker Traefik Deploy? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

VPS Docker Traefik Deploy

Overview

Use this skill to turn an application stack into a real production deployment plan with secure host setup, reverse proxying, registry-based releases, private admin access, persistent storage, backups, and rollback.

Prefer Ubuntu LTS or Debian stable. Prefer immutable image tags. Prefer Traefik for public ingress and SSH tunnels for admin-only access.

Workflow

  1. Establish facts before changing anything.
  2. Minimize the public network surface.
  3. Baseline the host with a non-root operator account.
  4. Install Docker from the official stable channel.
  5. Deploy Traefik separately from the app stack.
  6. Keep state outside container writable layers.
  7. Deploy app images by pull, not by rebuilding on the server.
  8. Validate health, backup, restore, rollback, and pruning.

Establish Facts

Confirm these points first:

  • operating system and version
  • public domains and subdomains
  • TLS strategy: HTTP challenge or DNS challenge
  • public services: website, API, websocket, admin UI, registry
  • private services: database, Redis, dashboards
  • registry type: managed or self-hosted
  • persistent data locations
  • backup destination and retention
  • restore expectations
  • whether a single VPS is still acceptable

If the project already has deployment docs, read them first and treat them as the application-specific contract.

Public Exposure Rules

Default public ports:

  • 22/tcp for SSH
  • 80/tcp for HTTP redirect and ACME when needed
  • 443/tcp for HTTPS

Keep these private unless there is a strong reason:

  • Traefik dashboard
  • MariaDB or PostgreSQL
  • Redis
  • private registry
  • app service ports that can sit behind Traefik
  • internal admin tools

If a GUI tool is required, bind the service to 127.0.0.1 only and use an SSH tunnel from the operator workstation.

Output Requirements

When using this skill, produce a deployment answer that includes:

  • target topology
  • exact public ports
  • folder layout
  • user and permission model
  • Docker and Traefik install method
  • DNS record plan
  • Traefik routing plan
  • registry flow
  • persistent data plan
  • storage growth plan
  • backup and restore plan
  • rollout and rollback commands

Mandatory Guardrails

  • Do not recommend public exposure of database, Redis, registry, or proxy dashboards by default.
  • Do not recommend deploying as the host root account.
  • Do not recommend mutable latest tags for production.
  • Do not keep important state only inside container writable layers.
  • Do not call a plan complete unless backup and rollback are addressed.

Reference Files

Read these files only when needed:

  • [references/server-baseline.md](references/server-baseline.md)

Use for Ubuntu 24.04 host prep, non-root users, SSH hardening, swap, firewall, Docker install.

  • [references/traefik-dns.md](references/traefik-dns.md)

Use for Traefik layout, dashboard tunneling, DNS, subdomains, Cloudflare, and routing patterns.

  • [references/registry-storage-backup.md](references/registry-storage-backup.md)

Use for private registries, image retention, bind mounts versus volumes, S3-compatible storage, backup, restore, and cleanup.

  • [references/deploy-checklist.md](references/deploy-checklist.md)

Use for rollout steps, post-deploy verification, rollback, and maintenance cadence.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.