What is Plausible Analytics?
Plausible Analytics is a lightweight, privacy-friendly alternative to Google Analytics. It is open source under the AGPL-3.0 license, uses no cookies, and its tracking script is under 1 KB. Plausible Community Edition (CE) is the self-hosted version, with a one-page dashboard showing visitors, sources, pages, locations, devices, goals and custom events.
Requirements
- A Linux server with 2 vCPU and 4 GB of RAM. ClickHouse is the heaviest part of the stack.
- A CPU with SSE 4.2 on x86-64 or NEON on ARM64, which ClickHouse requires.
- Docker Engine and Docker Compose v2, plus
git. - A domain name, for example
plausible.example.com, with DNS pointing at the server.
Step 1: Prepare the server
This guide assumes Ubuntu 24.04 with Docker installed. If you need Docker, follow the official install guide. The Plausible team publishes the CE setup as a Git repository, because ClickHouse needs several small config files next to the Compose file. Clone the current release:
git clone -b v3.2.1 --single-branch https://github.com/plausible/community-edition plausible-ce
cd plausible-ce
Check the community-edition repository for the newest tag before you clone.
Step 2: Create the Docker Compose file
The cloned compose.yml already defines three services: plausible_db (Postgres 16), plausible_events_db (ClickHouse) and plausible (the app, pinned to ghcr.io/plausible/community-edition:v3.2.1). You do not edit it. Instead, configure it with a .env file and publish the port with a compose.override.yml.
Create .env:
BASE_URL=https://plausible.example.com
SECRET_KEY_BASE=CHANGE_ME
TOTP_VAULT_KEY=CHANGE_ME
HTTP_PORT=8000
DISABLE_REGISTRATION=invite_only
Generate SECRET_KEY_BASE with openssl rand -base64 48, which produces the 64 characters Plausible requires. Generate TOTP_VAULT_KEY, used to encrypt two-factor secrets, with openssl rand -base64 32. BASE_URL must be the exact public address. DISABLE_REGISTRATION=invite_only means that after you create the first account, new users can join only by invitation.
Then create compose.override.yml, which Docker Compose merges automatically:
services:
plausible:
ports:
- "127.0.0.1:8000:8000"
Binding to 127.0.0.1 keeps the plain HTTP port private, so only your reverse proxy can reach it. If you prefer to let Plausible obtain Let's Encrypt certificates itself, the README describes setting HTTP_PORT=80 and HTTPS_PORT=443 instead.
Step 3: Start and open the app
docker compose up -d
docker compose logs -f plausible
The app waits for Postgres and ClickHouse to become healthy, then creates and migrates the databases. Complete Step 4, then open https://plausible.example.com and register the first account, which becomes the owner. Add your website and copy the tracking snippet into the <head> of your site. It looks like <script defer data-domain="yoursite.com" src="https://plausible.example.com/js/script.js"></script>. Visit your site and the visitor appears in the dashboard within seconds.
Step 4: Put it behind HTTPS
With Caddy:
plausible.example.com {
reverse_proxy 127.0.0.1:8000
}
Caddy passes the client IP in X-Forwarded-For, which Plausible uses for country detection and unique-visitor hashing. With Nginx Proxy Manager, create a proxy host to port 8000 and make sure the forwarded headers are kept. For country-level data, CE uses a free DB-IP database by default; set MAXMIND_LICENSE_KEY and MAXMIND_EDITION for MaxMind's more accurate city data.
Backups and upgrades
Back up all three volumes: db-data (Postgres: users, sites, goals), event-data (ClickHouse: all your analytics), and plausible-data. Keep your .env too. For a consistent copy, stop the stack briefly and archive the volumes, or dump Postgres with pg_dump and use ClickHouse's BACKUP command for the events.
To upgrade, read the release notes, which sometimes include manual migration steps, then:
git fetch --tags && git checkout v3.2.1
docker compose pull && docker compose up -d
Replace v3.2.1 with the new release tag.
Troubleshooting
- ClickHouse exits immediately: the CPU lacks SSE 4.2 or NEON, or the server has too little memory. Check
docker compose logs plausible_events_db. - No visitors recorded: an ad blocker on your test browser is blocking the script, or
data-domaindoes not match the site name you added in Plausible. - All visitors show the same country: the proxy is not forwarding the client IP. Make sure
X-Forwarded-Forreaches Plausible. - App fails with a secret key error:
SECRET_KEY_BASEis shorter than 64 bytes. Regenerate it withopenssl rand -base64 48.
Next steps
Set up goals and custom events, configure SMTP so you can invite teammates and receive weekly email reports, proxy the script through your own domain to reduce blocking, and import historical Google Analytics data.
Spotted something out of date? Tell us and we will update the guide.