Docker Stacks is a container deployment and orchestration feature built directly into the RunCloud control panel. It allows you to deploy, manage, and scale containerized applications on your servers without manual command-line configuration or complex networking setups.
This allows you to run popular open-source software, self-hosted developer tools, and custom microservices alongside your traditional web applications, all managed through a unified dashboard.
The Challenge of Self-Hosting Containers
Modern web development requires multiple software services such as automation tools (n8n), search engines (Meilisearch), uptime monitors (Uptime Kuma), analytics platforms (Plausible), or artificial intelligence runners (Ollama).
Before Docker Stacks, running these tools on a managed server was quite difficult for several reasons:
- Manual Command-Line Setup: You had to log in to your server via SSH, install Docker manually, write complex
docker-compose.ymlconfiguration files, and manage background system services manually. - Loss of Management Benefits: Once you deployed an application via the command line, you lost the core benefits provided by the RunCloud dashboard. Reverse proxying, automated SSL certificate issuance, automated renewals, database management, and centralized server monitoring had to be configured independently.
- Complex Multi-Service Networking: Connecting an application container to a database container or a cache service required you to manually create Docker bridge networks, manage port conflicts, and troubleshoot internal container routing.
- Update Risks and Configuration Drift: Updating a self-hosted container required pulling new images manually and restarting services. If an update failed, rolling back to a previous state was difficult and often resulted in downtime.
How RunCloud Simplifies Docker Hosting
RunCloud allows you to control and manage Docker Stacks across two levels on RunCloud dashboard:
- Global Stacks Dashboard: This menu is located in your main left navigation sidebar (named Stacks) and provides a centralized view of all container stacks running across all servers in your workspace.

- Server-Level Stacks: This menu is located within each containerized server menu (Server > Stacks).

On these screens, you can perform the following actions:
- You can deploy pre-configured applications or pull custom container images from any public or private container registry.
- RunCloud automatically configures the server web server as a reverse proxy for your container. You can attach your custom domain or use an instant, automated temporary domain, with SSL certificates issued and renewed via Let’s Encrypt.
- When your stack requires a database or cache, RunCloud can automatically provision managed MariaDB or Redis services and inject the connection credentials directly into your container environment variables.
- You can monitor real-time health metrics, resource monitoring, automated webhooks, deployment manifests, and container lifecycle actions.
Advantages of Using Docker Stacks on RunCloud
1. Significant Time Savings
Managing server software manually consumes hours of setup and maintenance time every week. Docker Stacks automates the most time-consuming operational tasks:
- Zero Command-Line Configuration: You don’t need to open a terminal, write shell scripts, or configure system daemons. You can launch a fully functional software stack in under two minutes through a guided web wizard.
- Instant Reverse Proxying: Port mapping and reverse proxy rules are generated automatically by RunCloud. You don’t need to edit NGINX configuration files to route public domain traffic to private container ports.
- Automated SSL Certificates: You don’t need to install certbot or configure cron jobs for certificate renewals. RunCloud automatically requests, validates, installs, and renews SSL certificates.
- Push-to-Deploy Automation: You can connect your container registry to RunCloud using automated webhooks. Whenever you push a new image tag to Docker Hub, GitHub Container Registry (GHCR), or GitLab, RunCloud detects the change and automatically redeploys your stack.
2. Substantial Cost Savings Compared to SaaS
Many modern web tools are sold as SaaS (software-as-a-service) products with recurring monthly subscriptions that scale rapidly as your usage grows.
Docker Stacks allows you to self-host the open-source editions of these tools on your existing VPS without paying per-user or per-event fees:
| Tool Category | Example SaaS Solution | Typical SaaS Monthly Cost | Self-Hosted with RunCloud Docker Stacks |
|---|---|---|---|
| Workflow Automation | Make / Zapier | $20 to $100+ per month | $0 (Run self-hosted n8n on your server) |
| Website Analytics | Google Analytics / Plausible Cloud | $9 to $50+ per month | $0 (Run self-hosted Plausible on your server) |
| Search Engine | Algolia / Meilisearch Cloud | $30 to $250+ per month | $0 (Run self-hosted Meilisearch on your server) |
| Uptime Monitoring | Pingdom / Better Stack | $20 to $80+ per month | $0 (Run self-hosted Uptime Kuma on your server) |
| Publishing Platform | Ghost(Pro) | $25 to $199+ per month | $0 (Run self-hosted Ghost on your server) |
| Infrastructure Metrics | Datadog / Grafana Cloud | $15 to $100+ per month | $0 (Run self-hosted Grafana on your server) |
By hosting these applications on a single cloud server powered by RunCloud you consolidate your infrastructure expenses into your base server hosting cost. This saves you hundreds of dollars annually while enabling you to retain complete ownership of your data.
3. Enterprise-Grade Security
Running Docker containers manually often exposes servers to security vulnerabilities, such as exposing unencrypted database ports to the public internet or storing sensitive API keys in plain text. Docker Stacks enforces strict security best practices by default:
- Private Network Isolation: Containers run inside an isolated internal Docker bridge network. Services that don’t require public access (such as databases, background queues, and cache servers) remain internal and cannot be reached from the public internet.
- Centralized Secrets Vault: RunCloud provides an encrypted, write-only Secrets Vault at the workspace level. Sensitive tokens, private keys, and passwords are never stored in plain-text environment variables. Instead, RunCloud injects them as secure file mounts inside the container filesystem.
- Automated HTTPS and Access Controls: Public-facing containers receive automated SSL certificates, with optional IP allowlists and HTTP Basic Authentication controls.
- Cryptographic Webhook Signatures: When setting up continuous deployment webhooks, you can enforce payload verification to ensure redeployment commands originate strictly from your trusted registry provider.
- State Reconciliation and Recovery: RunCloud provides built-in tools under stack settings to synchronize live server state and reset inconsistent states without touching running workloads.
Vocabulary and Key Concepts
To help you navigate Docker Stacks effectively, we recommend being familiar with these key terms:
- Stack: The parent management unit within RunCloud. A stack contains one or more containers that share a private network, environment configuration, and lifecycle.
- Container: A running instance of a software image. Each container runs as an isolated process with its own designated CPU and memory limits.
- Catalog App: A pre-packaged, curated application maintained and tested by RunCloud. Catalog apps include pre-tuned resource defaults, recommended environment variables, and pre-configured port mappings to ensure reliable operation.
- Custom Image: Any standard Docker container image pulled from a public registry (such as Docker Hub) or a private authenticated registry (such as GitHub Container Registry or AWS ECR).
- Managed Service: An auxiliary database or cache service (such as MariaDB or Redis) provisioned directly by RunCloud and wired into your container network automatically.
- Reverse Proxy: A server configuration (powered by RunCloud NGINX) that sits between the public internet and your container, routing incoming domain requests on ports 80 and 443 to your container’s internal application port.
- State Synchronization: A mechanism to reconcile the RunCloud dashboard representation with the physical state on the server without disrupting active container services.
System Requirements
To use Docker Stacks, ensure your account and infrastructure meet the following prerequisites:
- Subscription Plan: Docker Stacks is available to users on active Business and Enterprise subscription plans.
- Server Architecture: Docker Stacks requires a server deployed with the Containerized architecture option on RunCloud. This architecture includes integration with the Docker Swarm engine and the NGINX reverse proxy service.
- Workspace Permissions: Team members must have appropriate permissions assigned within the RunCloud workspace. Users can view and manage stacks on servers that they own or that have been shared with them by a workspace administrator.
Supported Container Registries
Docker Stacks supports pulling images from both public repositories and authenticated private registries:
- Docker Hub: Public library images and private user repositories.
- GitHub Container Registry (GHCR): Private and organizational container packages hosted on GitHub.
- Google Container Registry (GCR) & Google Artifact Registry: Private images hosted on Google Cloud Platform.
- AWS Elastic Container Registry (ECR): Private container repositories hosted on Amazon Web Services.
- Azure Container Registry (ACR): Private container images hosted on Microsoft Azure.
- Custom Self-Hosted Registries: Any standard registry compliant with the OCI (Open Container Initiative) distribution specification, authenticated using a custom URL, username, and access token.
If you have any other questions or need help, please feel free to get in touch with our 24/7 support team. We’re here to help!