Docker, Kubernetes, Jenkins, Prometheus, Helm, MongoDB, Kong and HAProxy are the building blocks of many modern deployment setups. This guide installs each of them the current, supported way on a Linux server you control, and explains which ones actually belong on a single VPS and which are better left for a cluster.
Every step needs root access, so it applies to a VPS or dedicated server you manage yourself. None of these tools can be installed on shared hosting, where you cannot change server software. See Docker on cPanel and DirectAdmin: the honest truth for what is possible there.
Use a current LTS distribution (Ubuntu 24.04 or AlmaLinux/Rocky Linux 9), not CentOS 7 or 8, which are end-of-life. Install Docker from Docker's official repository, use k3s for Kubernetes on one or a few VPSs, and install Jenkins, Helm and HAProxy from their official packages. Run Prometheus and MongoDB as containers with ports bound to 127.0.0.1. Check each project's install page for the current version before you copy a version number from any guide, including this one.
1. Before you start
The commands below target Ubuntu 24.04 LTS, with notes for AlmaLinux and Rocky Linux 9. Older guides for this topic were written for CentOS 7, which stopped receiving updates in 2024, and used repositories that have since been shut down, such as Google's old Kubernetes yum repository. Do not follow them on a new server.
Plan your memory. Docker and HAProxy are light; Jenkins wants at least 2 GB of RAM; a Kubernetes node plus monitoring wants 4 GB or more. Running everything in this guide on one small VPS will be slow. Do the baseline hardening first (non-root user, SSH keys, firewall), as described in From zero to production: the VPS setup guide.
2. Docker
Install Docker Engine from Docker's own repository, not the older docker.io distribution package:
sudo apt update && sudo apt -y install ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | sudo tee /etc/apt/sources.list.d/docker.list
sudo apt update
sudo apt -y install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
sudo docker run --rm hello-worldOn AlmaLinux or Rocky Linux 9:
sudo dnf -y install dnf-plugins-core
sudo dnf config-manager --add-repo https://download.docker.com/linux/rhel/docker-ce.repo
sudo dnf -y install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
sudo systemctl enable --now dockerCompose is now the docker compose plugin; the old standalone docker-compose command is retired.
Docker writes its own firewall rules, so -p 27017:27017 exposes a port to the internet even when UFW blocks it. Bind to localhost with -p 127.0.0.1:27017:27017 unless the service is meant to be public. Adding a user to the docker group is equivalent to giving them root.
3. Kubernetes: k3s for a VPS
Full kubeadm clusters need several machines to be worthwhile. On one VPS, or a few, use k3s, a certified lightweight Kubernetes distribution that installs as a single service:
curl -sfL https://get.k3s.io | sh -
sudo k3s kubectl get nodesThe kubeconfig is at /etc/rancher/k3s/k3s.yaml. k3s includes its own container runtime, so it does not need Docker. Multi-node setup, ingress and storage are covered in Lightweight Kubernetes with k3s.
If you do need kubeadm, use the community package repository at pkgs.k8s.io, which has one repository per minor version, and follow the official "Installing kubeadm" page for the version you choose. Do not disable SELinux to make it work; current releases support it.
4. Helm
Helm is the package manager for Kubernetes. Install it with the official install script or package from the Helm documentation at helm.sh, then check it:
helm version
helm repo add prometheus-community https://prometheus-community.github.io/helm-charts
helm repo updateOld guides pin a Helm 3.0 download from 2019; always take the current release. Point Helm at your cluster with export KUBECONFIG=/etc/rancher/k3s/k3s.yaml on a k3s node. A first chart deployment is walked through in Helm charts for beginners.
5. Jenkins
Jenkins needs a supported Java runtime (Java 17 or 21). Install it from the Jenkins stable repository:
sudo apt -y install fontconfig openjdk-21-jre
# Use the signing-key URL shown on https://pkg.jenkins.io/debian-stable/ (the key is rotated from time to time)
sudo wget -O /etc/apt/keyrings/jenkins-keyring.asc https://pkg.jenkins.io/debian-stable/<current-key-file>.key
echo "deb [signed-by=/etc/apt/keyrings/jenkins-keyring.asc] https://pkg.jenkins.io/debian-stable binary/" | sudo tee /etc/apt/sources.list.d/jenkins.list
sudo apt update && sudo apt -y install jenkins
sudo systemctl enable --now jenkins
sudo cat /var/lib/jenkins/secrets/initialAdminPasswordJenkins listens on port 8080. Do not open 8080 to the internet: put it behind your reverse proxy with HTTPS, or reach it through an SSH tunnel (ssh -L 8080:127.0.0.1:8080 user@server). If your code is on GitHub, a hosted CI service is often simpler than running Jenkins; see GitHub Actions CI/CD to a VPS.
6. Prometheus
Running Prometheus as a container keeps upgrades simple. Create a config file and start it on localhost:
mkdir -p ~/prometheus && cat > ~/prometheus/prometheus.yml <<'EOF'
global:
scrape_interval: 15s
scrape_configs:
- job_name: prometheus
static_configs:
- targets: ["localhost:9090"]
EOF
docker run -d --name prometheus --restart unless-stopped \
-p 127.0.0.1:9090:9090 \
-v ~/prometheus/prometheus.yml:/etc/prometheus/prometheus.yml:ro \
-v prometheus-data:/prometheus \
prom/prometheusAdd Node Exporter for server metrics and Grafana for dashboards. The complete stack, including log collection with Loki, is in Production observability with Prometheus, Grafana and Loki.
7. MongoDB
The MongoDB 4.2 repository in older guides is long out of support, and the mongo shell has been replaced by mongosh. The quickest current install is the official image, with authentication and a localhost-only port:
docker run -d --name mongo --restart unless-stopped \
-p 127.0.0.1:27017:27017 \
-e MONGO_INITDB_ROOT_USERNAME=admin \
-e MONGO_INITDB_ROOT_PASSWORD='use-a-long-random-password' \
-v mongo-data:/data/db \
mongo:8
docker exec -it mongo mongosh -u admin -pFor a package install with systemd, follow installing MongoDB on a VPS. Never expose 27017 publicly without authentication; unprotected MongoDB servers have caused many large data leaks.
8. HAProxy and Kong
HAProxy is a fast, dependable load balancer and TCP/HTTP proxy. The distribution package is a maintained long-term-support branch:
sudo apt -y install haproxy
sudo haproxy -c -f /etc/haproxy/haproxy.cfg
sudo systemctl enable --now haproxyEdit /etc/haproxy/haproxy.cfg to define a frontend on 80/443 and a backend listing your app servers, and run the -c check before every reload.
Kong is an API gateway built on Nginx, adding authentication, rate limiting and plugins in front of your APIs. Its packaging and the scope of its open-source edition have changed over the years, so install it by following Kong's current documentation for your distribution or for Docker, and check the licence terms of the edition you choose. For a single VPS, a plain reverse proxy is often enough; see Nginx vs Caddy for app gateways.
9. What to run where
| Tool | Needs root or a VPS | Sensible on one small VPS |
|---|---|---|
| Docker | Yes | Yes |
| k3s (Kubernetes) | Yes | Yes, with 4 GB RAM or more |
| Helm | Needs a Kubernetes cluster | With k3s |
| Jenkins | Yes | Only with spare RAM; hosted CI is lighter |
| Prometheus | Yes | Yes, as a container |
| MongoDB | Yes | Yes, bound to localhost |
| HAProxy | Yes | When you balance across several servers |
| Kong | Yes | Only if you need its API features |
10. Running this on Domain India
A Domain India VPS is self-managed with full root access on KVM, which is what these tools need. The VPS page lists the Linux distributions available, including Ubuntu, Debian, AlmaLinux and Rocky Linux.
- 2 vCPU
- 4 GB DDR4 RAM
- 128 GB NVMe SSD Storage
- 3 TB Monthly Bandwidth
- 4 vCPU
- 8 GB DDR4 RAM
- 256 GB NVMe SSD Storage
- 5 TB Monthly Bandwidth
If you only need to run an app in a container, the App Platform may be simpler than managing Docker yourself: Node.js apps are detected automatically, and anything else deploys from a Dockerfile, with a PostgreSQL database included. See Getting Started with App Platform. MongoDB cannot be reached from Domain India shared hosting.
Prices on the cards are Domain India list prices and exclude 18% GST.
Frequently asked questions
Can I install Docker or Kubernetes on shared hosting?
No. Docker, Kubernetes and the other tools in this guide need root access, which shared hosting does not provide. Use a VPS, or an app platform that runs containers for you.
Should I still use CentOS for these installs?
No. CentOS 7 and CentOS 8 are end-of-life and no longer receive security updates. Use a current long-term-support release such as Ubuntu 24.04 LTS, Debian 12, or AlmaLinux or Rocky Linux 9.
What is the easiest way to run Kubernetes on a VPS?
Use k3s, a certified lightweight Kubernetes distribution that installs as a single service with one command. It suits one VPS or a small cluster and includes its own container runtime, so Docker is not required.
How much RAM do I need for Jenkins?
Plan for at least 2 GB of RAM for Jenkins alone, more with many builds or plugins. On a small VPS a hosted CI service such as GitHub Actions is usually lighter.
Why can people reach my database even though UFW blocks the port?
Docker writes its own firewall rules, so a container port published without an address is reachable from the internet regardless of UFW. Publish it on 127.0.0.1 only, and always enable authentication on databases such as MongoDB.
Does a Domain India VPS support these tools?
A Domain India VPS is self-managed with full root access on KVM virtualization, so you can install Docker, k3s, Jenkins and the other tools yourself. You are responsible for installing, securing and updating them.
Ready to build your stack? Choose a server on the VPS page, harden it first, then install only the tools your project needs. For containers without server management, look at the App Platform, or open a ticket and tell us what you plan to run.
Full root access on KVM with your choice of Linux distribution, ready for Docker, k3s and your CI and monitoring tools.
Compare VPS plans