# Setting up a server

For production we recommend a dedicated server. This example uses **Hetzner Cloud**, but
applies to any x86_64 server with Docker.

## Provision the server

We recommend at least a **CPX31** (x86_64/amd64). Create the server with a current
Ubuntu LTS and install Docker:

```bash
curl -fsSL https://get.docker.com | sh
```

## Set up TLS

Never expose Lalabase unencrypted. Put a reverse proxy (e.g. Caddy or Traefik) in front
of it that obtains Let's Encrypt certificates automatically.

<div class="docs-callout docs-callout--danger">
  <div class="docs-callout__title">Warning</div>
  <p>Only expose ports 80 and 443. The database and Redis must never be publicly reachable.</p>
</div>

## Next steps

Once the server is up, follow the [Docker Compose guide](https://lalabase.com/docs/en/self-hosting/installation/docker-compose)
and then set your [environment variables](https://lalabase.com/docs/en/self-hosting/configuration/environment).
