Deploy Penpot 2 Design and Prototyping
Open-source Figma alternative for design and prototyping, fully yours.
S3 Gateway
Just deployed
Just deployed
Valkey
Just deployed
Backend
Just deployed
Just deployed
Exporter
Just deployed
Frontend
Just deployed
Bucket
Bucket
Just deployed
Deploy and Host Penpot with Railway
Penpot is an open-source design and prototyping platform for product teams, built on open standards like SVG, CSS and HTML. This community template runs Penpot 2 on Railway with its backend, exporter, MCP server, PostgreSQL, Valkey and a Railway Bucket for images and fonts.
About Hosting Penpot
Penpot consists of an nginx frontend that serves the web app and routes requests, a JVM backend with the API and real-time collaboration, an exporter that renders PNG, SVG and PDF exports with a headless browser, and an MCP server for AI agents. It needs PostgreSQL and a Redis-compatible store (Valkey). Uploaded images, fonts and thumbnails go to object storage: this template stores them in a Railway Bucket through a small private S3 gateway, because Penpot's S3 client uses an addressing style Railway Buckets do not accept. The frontend image is adjusted for Railway: nginx workers follow the container's CPU quota, internal services are re-resolved after redeploys, and a local healthcheck keeps deploys independent.
Common Use Cases
- UI and UX design for web and mobile products, owned by your team instead of a SaaS vendor.
- Interactive prototypes for user testing and stakeholder reviews.
- Design systems with shared components, colors and typography across teams.
- Developer handoff with inspectable CSS, SVG and code output.
- Design work by AI agents through Penpot's MCP server.
Dependencies for Penpot Hosting
- Penpot frontend, backend, exporter and MCP server (
penpotapp/*images) - PostgreSQL 18
- Valkey 8.1
- S3-compatible object storage (Railway Bucket, reached through an rclone S3 gateway)
- Optional: SMTP server for invitations and notifications (Railway Pro plan)
Deployment Dependencies
- Penpot self-hosting guide: https://help.penpot.app/technical-guide/getting-started/
- Penpot configuration reference: https://help.penpot.app/technical-guide/configuration/
- Penpot releases: https://github.com/penpot/penpot/releases
- rclone serve s3: https://rclone.org/commands/rclone_serve_s3/
- Railway Buckets: https://docs.railway.com/storage-buckets
Implementation Details
| Service | Image | Role | Public |
|---|---|---|---|
Frontend | penpotapp/frontend:2.18.3 + Railway nginx adjustments | Web app, routing, asset delivery | HTTPS domain |
Backend | penpotapp/backend:2.18.3 | API, collaboration, background jobs | — |
Exporter | penpotapp/exporter:2.18.3 | PNG, SVG and PDF exports | — |
MCP | penpotapp/mcp:2.18.3 | AI agent integration | via Frontend |
Valkey | valkey/valkey:8.1.10 | Notifications, rate limits, export queue | — |
S3 Gateway | rclone/rclone:1.75.2 + start script | Private S3 endpoint storing files in the Bucket | — |
Postgres | ghcr.io/railwayapp-templates/postgres-ssl:18 | Database | — |
Bucket | Railway Bucket | Images, fonts, thumbnails | — |
First login. When Frontend is healthy, open its domain and create an account. Registration with email and password is open and email verification is off, matching Penpot's default Docker setup.
Restricting sign-ups. Add PENPOT_REGISTRATION_DOMAIN_WHITELIST (for example yourcompany.com) to Backend, or replace enable-registration with disable-registration in Backend.PENPOT_FLAGS once your team has joined. With registration disabled, new accounts are created with Penpot's command-line tool inside the backend (python3 manage.py create-profile).
Email. Penpot sends email over SMTP, which Railway allows on the Pro plan. Add enable-smtp to PENPOT_FLAGS and set the PENPOT_SMTP_* variables on Backend.
Custom domain. Change PENPOT_PUBLIC_URI on Backend to https://{your-domain}; the other services reference it.
Scaling. Add replicas to Frontend and Exporter for more traffic and parallel exports. Give Backend more memory and raise -Xmx in JVM_OPTS for large files.
Pinning and upgrades. Penpot's components must run the same version. Change 2.18.3 in services/frontend/Dockerfile and on the Backend, Exporter and MCP images together, after reading Penpot's upgrade notes; the backend migrates the database on start.
Why Deploy Penpot on Railway?
Railway runs Penpot's frontend, backend, exporter and MCP server together with PostgreSQL, Valkey and storage on a private network with automatic HTTPS, so your team gets a self-hosted Figma alternative without managing servers. Files live in a low-cost Bucket, services scale independently, and you pay for the resources your designers actually use.
Template Content
S3 Gateway
baranberkay96/penpot-railwayValkey
valkey/valkey:8.1.10Backend
penpotapp/backend:2.18.3Exporter
penpotapp/exporter:2.18.3Frontend
baranberkay96/penpot-railwayBucket
Bucket
