A Docker Compose deployment for FleetDM with Traefik handling TLS termination.
- MySQL 8.0
- Redis 7
- Fleet
- Traefik
- Docker and Docker Compose v2
- Ports
80and443open on the host - A DNS A-record pointing to your host (e.g.
fleet.example.com)
# Create required directories
mkdir -p fleet/{logs,vulndb} mysql/data
# Fix permissions
sudo chmod -R o+w fleet/{logs,vulndb} mysql/data
chmod 600 config/ACME/acme.json
# Create the Docker network for Traefik
docker network create traefik_proxy
# Copy and edit the environment file
cp .env.example .env
nano .env
# Edit service credentials
nano fleet/default.env
nano mysql/default.env
# Edit the Traefik config and replace email@example.com with your address
nano config/traefik.toml.env controls the Fleet version and domain:
FLEET_VERSION=v4.58.0
FLEET_DOMAIN=fleet.example.comfleet/default.env and mysql/default.env hold service credentials. Replace all example passwords before exposing the instance publicly.
All operations go through fleet.sh:
# Start the stack
./fleet.sh up
# Stop the stack
./fleet.sh down
# Restart only the Fleet service
./fleet.sh restart
# Upgrade Fleet to a new version
./fleet.sh upgradeTo follow logs after starting:
docker compose -f docker-compose-traefik-standalone.yml logs -f fleet./fleet.sh upgradeThe script will prompt for the new version tag (e.g. v4.59.0), update .env, pull the new image, run migrations, and restart the Fleet service.
All data is stored on the host under the service folders (mysql/data, fleet/logs, fleet/vulndb). Data survives container restarts as long as those directories are not deleted.
If you prefer to run Traefik as a separate stack shared across multiple projects, use docker-compose-traefik.yml instead:
docker compose -f docker-compose-traefik.yml up -dSee this example repository for a reference Traefik stack setup.