Sunday, October 4
United Kingdom
2

Deploying Your First App to a $5 VPS Without Losing Your Mind

Deployment  |  October 4, 2026
Deploying Your First App to a $5 VPS Without Losing Your Mind

There's a moment every indie developer hits where your app works on localhost, and you have absolutely no idea what comes next. Managed platforms are wonderful until the bill arrives, and Kubernetes feels like bringing a flamethrower to light a candle. A plain VPS sits in the sweet spot: cheap, predictable, and fully yours. The tradeoff is that you're now the sysadmin, so let's make that as painless as possible.

Start by creating a non-root user and locking down SSH. Log in as root once, add your public key to a new user, give that user sudo, then disable password authentication and root login in your SSH config. This takes five minutes and prevents the most common attack your fresh server will see within hours of going live. A firewall that only allows SSH, HTTP, and HTTPS closes most of the rest of the door.

Getting Your App Running Reliably

Copy your code to the server, install your runtime, and get the app running manually first. Resist the urge to automate before you understand the steps. Once it works, wrap it in a systemd service so it starts on boot and restarts when it crashes. A minimal unit file needs the command to run, the working directory, the user to run as, and a restart policy. That's it. Don't overthink it.

For a reverse proxy, Caddy is the friendliest option for indie projects because it handles TLS certificates automatically. Point your domain's A record at the server, write three lines of Caddyfile, and you have HTTPS with auto-renewal. If you prefer nginx, that's fine too, but you'll be wiring up certbot yourself. Either way, the proxy sits in front of your app, terminates TLS, and forwards requests to the port your app listens on. Keep the app bound to localhost so nothing bypasses the proxy.

Backups, Logs, and Not Fooling Yourself

The part everyone skips is the part that saves you. Set up automated backups of your database and any uploaded files to object storage. Test restoring at least once, because an untested backup is a hope, not a plan. For logs, systemd's journal is usually enough at this scale; learn a few journalctl flags and you can debug most issues without installing anything. If your app writes its own logs, make sure they rotate so they don't quietly fill the disk.

Finally, write down what you did. Not for a blog post, for future you at 2am when something breaks. A simple deploy script that pulls, installs dependencies, restarts the service, and checks the health endpoint will save you more time than any fancy tool. You can graduate to containers and orchestration later, when you actually have the problems they solve. For now, a $5 box and a bit of discipline will carry a surprising amount of traffic.