Rocket.Chat is an open-source team communication platform with channels, direct messages, threads, file sharing and integrations, which you can host on your own server. Its supported deployment method is Docker, with MongoDB running as a replica set. In this tutorial you will run Rocket.Chat and MongoDB with Docker Compose on Ubuntu 24.04, publish Rocket.Chat over HTTPS through Nginx with a Let's Encrypt certificate, complete the setup wizard and schedule database backups.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS, for example a CubePath VPS, with at least 2 vCPUs, 4 GB of RAM and 30 GB of disk.
- A non-root user with
sudoprivileges. - A domain or subdomain, such as
chat.your_domain, with a DNS A record pointing to your server's public IP. This guide usesyour_domainas a placeholder. - Docker Engine and the Docker Compose plugin installed from Docker's official repository. Step 1 shows the commands.
Step 1 - Installing Docker Engine
Skip this step if docker compose version already works on your server. Otherwise, add Docker's signing key and repository:
sudo apt update
sudo apt install -y ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc
echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
Install Docker Engine and the Compose plugin:
sudo apt update
sudo apt install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
Check both:
sudo docker version --format '{{.Server.Version}}'
docker compose version
The first command prints the Docker Engine version and the second one a line such as Docker Compose version v2.x.x.
Step 2 - Opening the firewall
Allow SSH, HTTP and HTTPS in UFW:
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
ImportantDocker writes its own iptables rules, and a port published as
3000:3000is reachable from the Internet even if UFW does not allow it. In the Compose file below, Rocket.Chat is published only on127.0.0.1, so Nginx is the only way in.
Step 3 - Writing the Docker Compose file
Create a directory for the deployment:
sudo mkdir -p /opt/rocketchat
cd /opt/rocketchat
Create an environment file with the values that change between installations:
sudo nano /opt/rocketchat/.env
RELEASE=latest
ROOT_URL=https://your_domain
Tip
latestalways pulls the newest release when you update. For predictable upgrades, replace it with a specific version from the Rocket.Chat releases page on GitHub (for example7.10.0), and check the release notes for the supported MongoDB versions before changing it.
Create the Compose file:
sudo nano /opt/rocketchat/compose.yml
services:
mongodb:
image: mongo:7.0
restart: unless-stopped
command: ["--replSet", "rs0", "--bind_ip_all"]
volumes:
- mongodb_data:/data/db
rocketchat:
image: registry.rocket.chat/rocketchat/rocket.chat:${RELEASE}
restart: unless-stopped
depends_on:
- mongodb
environment:
ROOT_URL: ${ROOT_URL}
PORT: 3000
MONGO_URL: mongodb://mongodb:27017/rocketchat?replicaSet=rs0
DEPLOY_METHOD: docker
ports:
- "127.0.0.1:3000:3000"
volumes:
mongodb_data:
A few details of this file:
- Rocket.Chat requires MongoDB to run as a replica set, even with a single node, because it relies on MongoDB change streams for real-time updates. The
--replSet rs0option enables that. - MongoDB has no published port, so only containers on this Compose network can reach it.
- Uploaded files are stored in MongoDB (GridFS) by default, so the
mongodb_datavolume holds all your workspace data.
Validate the file:
sudo docker compose config --quiet && echo OK
OK
Step 4 - Starting MongoDB and initializing the replica set
Start only MongoDB first:
sudo docker compose up -d mongodb
Initialize the single-node replica set. The member host name must be mongodb:27017, the service name that Rocket.Chat uses to connect:
sudo docker compose exec mongodb mongosh --quiet --eval 'rs.initiate({_id: "rs0", members: [{_id: 0, host: "mongodb:27017"}]})'
{ ok: 1 }
Wait a few seconds and confirm that this node became the primary:
sudo docker compose exec mongodb mongosh --quiet --eval 'rs.status().members[0].stateStr'
PRIMARY
You only need to initialize the replica set once; the configuration is stored in the data volume.
Step 5 - Starting Rocket.Chat
Pull the image and start the whole stack:
sudo docker compose up -d
The first start creates the database and takes one to two minutes. Follow the logs until you see the server banner:
sudo docker compose logs -f rocketchat
rocketchat-1 | +----------------------------------------------+
rocketchat-1 | | SERVER RUNNING |
rocketchat-1 | +----------------------------------------------+
rocketchat-1 | | Rocket.Chat Version: x.y.z |
rocketchat-1 | | MongoDB Version: 7.0.x |
rocketchat-1 | | Site URL: https://your_domain |
...
Press Ctrl+C to stop following the logs. Confirm that Rocket.Chat answers on the loopback address:
curl -s -o /dev/null -w '%{http_code}\n' http://127.0.0.1:3000
200
Step 6 - Configuring Nginx and HTTPS
Install Nginx and Certbot:
sudo apt install -y nginx certbot python3-certbot-nginx
Create a site for Rocket.Chat:
sudo nano /etc/nginx/sites-available/rocketchat
Paste the following, replacing your_domain. The Upgrade and Connection headers are required because Rocket.Chat delivers messages over WebSockets:
server {
listen 80;
listen [::]:80;
server_name your_domain;
client_max_body_size 100M;
location / {
proxy_pass http://127.0.0.1:3000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Nginx-Proxy true;
proxy_read_timeout 86400s;
}
}
Enable the site, remove the default one and reload Nginx:
sudo ln -s /etc/nginx/sites-available/rocketchat /etc/nginx/sites-enabled/
sudo rm /etc/nginx/sites-enabled/default
sudo nginx -t
sudo systemctl reload nginx
Request a certificate. Certbot adds the TLS settings and an HTTP to HTTPS redirect to the site:
sudo certbot --nginx -d your_domain
Check that automatic renewal works:
sudo certbot renew --dry-run
Congratulations, all simulated renewals succeeded:
/etc/letsencrypt/live/your_domain/fullchain.pem (success)
Step 7 - Completing the setup wizard
Open https://your_domain in your browser. The setup wizard asks for:
- Admin info: your name, username, email and a strong password. This account becomes the workspace administrator.
- Organization info: organization name, type, industry, size and country.
- Register your workspace: Rocket.Chat asks you to register the workspace with its cloud service, which is needed for push notifications to the mobile apps and for the Marketplace. Follow the prompts, including the email confirmation.
After the wizard you land in the workspace with a #general channel. Open Administration > Workspace > Settings to review two areas:
- Email > SMTP: enter your SMTP server, port, user and password so invitations and password resets are delivered.
- Accounts > Registration: choose whether anyone can register, or only invited users.
Invite people from Administration > Workspace > Users > Invite, or create accounts directly with New user.
Step 8 - Backing up and updating
Because MongoDB holds both messages and uploaded files, a mongodump of the rocketchat database is a complete backup. Create a backup directory and take a first dump:
sudo mkdir -p /var/backups/rocketchat
sudo chmod 700 /var/backups/rocketchat
cd /opt/rocketchat
sudo docker compose exec -T mongodb mongodump --db rocketchat --archive --gzip | sudo tee "/var/backups/rocketchat/rocketchat-$(date +%F).archive.gz" > /dev/null
sudo ls -lh /var/backups/rocketchat
To run it nightly and keep 14 days of dumps, create a cron file:
sudo nano /etc/cron.d/rocketchat-backup
30 2 * * * root cd /opt/rocketchat && docker compose exec -T mongodb mongodump --db rocketchat --archive --gzip > "/var/backups/rocketchat/rocketchat-$(date +\%F).archive.gz" 2>/dev/null
45 3 * * * root find /var/backups/rocketchat -name 'rocketchat-*.archive.gz' -mtime +14 -delete
To restore a dump into a running stack, use mongorestore --archive --gzip --drop with the file on standard input, in the same way.
To update Rocket.Chat, take a backup, change RELEASE in .env if you pinned a version, then pull the new image and recreate the container:
cd /opt/rocketchat
sudo docker compose pull
sudo docker compose up -d
Troubleshooting
- Rocket.Chat restarts in a loop with a MongoDB error: the replica set was not initialized or the host name is wrong. Run
rs.status()as in Step 4 and check that the member host ismongodb:27017. - The page loads but messages do not update: WebSockets are not passing through Nginx. Confirm the
UpgradeandConnectionheaders are in the site configuration. - Links in emails point to the wrong address:
ROOT_URLdoes not match your public URL. Fix it in.env, then runsudo docker compose up -d, and check Administration > Workspace > Settings > General > Site URL. - Uploads fail with "413 Request Entity Too Large": raise
client_max_body_sizein Nginx and the maximum file size under Settings > File Upload.
Conclusion
Rocket.Chat now runs on Ubuntu 24.04 in Docker, with MongoDB as a replica set, HTTPS through Nginx and nightly database backups. Next, you can connect the desktop and mobile apps to https://your_domain, add incoming webhooks under Administration > Workspace > Integrations to post alerts from your monitoring tools, and enable two-factor authentication for all users under Settings > Accounts > Two Factor Authentication.
