A Docker VPS on real KVM.
Your kernel, your root, your containers.
Run Docker and Compose on a full KVM virtual machine in Los Angeles: your own kernel, NVMe storage for fast image pulls, a dedicated IPv4 from SC-1, and an encrypted backup vault for your volumes. From $3 a month, renewing at the price you signed up at.
Why KVM matters
Docker wants a whole machine. You get one.
Some budget servers are containers themselves, sharing the host's kernel with everyone else on the box. Running Docker inside one of those means nested containers, missing kernel features and storage drivers that quietly fall back to slow modes. A KVM virtual machine avoids all of it. Each ServerCrate server boots its own kernel, so Docker gets the overlay2 storage driver, its own firewall rules, custom bridge networks and any kernel module you need to load.
NVMe for pulls, builds and databases
Container work is disk work: pulling layers, extracting images, building, and the steady small writes of a database volume. Every plan runs on NVMe storage, so docker compose pull and a Postgres checkpoint are not waiting on spinning drives.
A real address from SC-1
SC-1, SC-2 and SC-3 each include a dedicated IPv4 with every port open. Put a reverse proxy on 80 and 443, route by hostname to as many containers as you like, and let it handle certificates. SC-0 uses a shared IPv4 with SSH plus 20 forwarded ports, which suits a single bot, a worker or a private tool. Read more on our dedicated IPv4 VPS page.
Sizing honestly
RAM is usually the limit, not CPU. SC-0's 512 MB fits one lightweight container. SC-1's 1 GB fits a reverse proxy plus a small app. A stack with Postgres or MySQL, a cache and an app server is happier on SC-2 with 2 GB or SC-3 with 4 GB. Start smaller if you are unsure: the 30-day money-back guarantee covers the experiment.
From a fresh server to a running stack.
On Debian 12 or Ubuntu, Docker's own install script sets up the engine and the Compose plugin. Then write a compose file and bring it up. The last two lines back up your stack to the encrypted vault included with every server.
The firewall gotcha
Docker writes its own firewall rules for every published port, and they are evaluated before ufw. A database published as 5432:5432 is reachable from the internet even if ufw says otherwise. The fix is in the compose file: publish internal services as 127.0.0.1:5432:5432, or do not publish them at all and let containers talk over a Compose network. Only the reverse proxy needs a public port.
What to back up
Images can always be pulled again. What you need offsite is the compose file, any .env files, named volumes and a fresh database dump. Restic encrypts all of it on your server before upload, and the vault lives on separate ZFS-backed storage. There are no restore fees, so rehearse a restore onto a spare server. Our recovery drill shows a full restore end to end, and VPS with backups covers the vault in detail.
Docker-ready server plans.
Monthly prices shown. Yearly billing is 10 times monthly, two months free. Renewal is always the signup price.
- 25 GB encrypted backup vault included
- 1 vCPU
- 512 MB RAM
- 10 GB NVMe
- Shared IPv4: SSH + 20 forwarded ports
- 25 Mbps port
- 1 TB transfer
- $30/yr billed yearly, 2 months free
- 100 GB encrypted backup vault included
- 1 vCPU
- 1 GB RAM
- 20 GB NVMe
- Dedicated IPv4
- 50 Mbps port
- 3 TB transfer
- $70/yr billed yearly, 2 months free
- 250 GB encrypted backup vault included
- 2 vCPU
- 2 GB RAM
- 40 GB NVMe
- Dedicated IPv4
- 50 Mbps port
- 3 TB transfer
- $120/yr billed yearly, 2 months free
- 500 GB encrypted backup vault included
- 2 vCPU
- 4 GB RAM
- 60 GB NVMe
- Dedicated IPv4
- 50 Mbps port
- 3 TB transfer
- $200/yr billed yearly, 2 months free
Choose Debian 12, Ubuntu, AlmaLinux 9 or Rocky Linux 9 at checkout. Browser VNC and serial console are there if a firewall rule locks you out. IPv6 is not available yet. Logins to the portal and panel use post-quantum TLS, and the rest of how we run the platform is on our security page. Compare servers on cloud servers or the Los Angeles VPS page, and every product on pricing. Pay by card, PayPal or Bitcoin.
Docker VPS questions.
Does Docker run without restrictions?
Yes. Each server is a full KVM virtual machine with its own kernel, so Docker, Docker Compose and Podman run as they would on bare metal, including overlay2 storage, custom networks and kernel modules.
Which plan should I pick for Docker?
SC-1 with 1 GB of RAM is a sensible floor for a reverse proxy and one or two small apps. SC-2 or SC-3 suit a stack with a database. SC-0 works for a single lightweight container.
Can I expose containers on port 80 and 443?
On SC-1, SC-2 and SC-3, yes: each has a dedicated IPv4 with every port open. SC-0 uses a shared IPv4 with SSH plus 20 forwarded ports, so containers publish on the ports assigned to you.
Why does Docker ignore my ufw rules?
Docker writes its own firewall rules for published ports, and they are evaluated before ufw. Bind internal services to 127.0.0.1 in your compose file and expose only your reverse proxy.
How do I back up containers?
Back up your compose files, named volumes and database dumps with Restic to the vault included with your server. Images can be pulled again, so they do not need backing up.
Is IPv6 available for containers?
IPv6 is not available yet. Every plan is IPv4 today.