Self-hosting

Upvora is designed to be boring to operate: one stateless app container, one Postgres, and a reverse proxy for TLS.

TLS & reverse proxy

Upvora serves plain HTTP on port 3000. Terminate TLS in front of it with any proxy. Set BASE_URL to the public HTTPS URL so links, cookies and OAuth callbacks are correct.

One-click updates

The bundled docker-compose.example.yml includes an updater sidecar. The admin System panel shows your installed version against the latest GitHub release and, with the sidecar present, updates the instance from the browser — no SSH. The sidecar is the only container holding the Docker socket; the app itself never does. Remove it if you prefer to update by hand with docker compose pull && docker compose up -d.

A reboot alone does not adopt a new image tag — Docker restarts the existing container with its original image reference. Run docker compose up -d to recreate it.

Backups

All state lives in Postgres (plus any uploaded images, which by default are stored in the database too). Back up the Postgres volume or run pg_dump on a schedule. Restores are a standard Postgres restore.

Metrics

Prometheus metrics are exposed on port 4000 — keep that port internal (do not expose it publicly).

Pin a version

For predictable deploys, pin the image to an immutable release tag or digest rather than :latest:

image: ghcr.io/hodyhq/upvora:v0.38.0.6.0
Upvora is open source under AGPL-3.0 — a friendly fork of Fider, not affiliated with it.  ·  Built & maintained by HODY