Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Canvas LMS can run on Ubuntu, but it is not an application you install with one apt install command. A production deployment combines the open-source AGPLv3 Canvas code with PostgreSQL, Redis, Ruby, Node.js, Apache/Passenger, SMTP, background jobs, HTTPS, storage, backups and ongoing administration. Instructure’s current production guide is written for 64-bit Ubuntu 22.04 LTS, at least 8 GB of RAM, PostgreSQL 14 or newer, Ruby 3.4.1 or newer (Ruby 3.5+ is untested), Node.js 20 and Redis 6.x or newer: official Production Start guide.

Use the native installation below only if you can maintain a Linux/Ruby/PostgreSQL service. Use Docker for development and evaluation, not a public school or institutional service. If you need managed uptime, support and upgrades, choose a hosted LMS instead.

What you are actually installing

“Canvas” can mean several different products:

  • Canvas Cloud: Instructure’s commercial, hosted service. It includes managed infrastructure and support; no Ubuntu server is required.
  • Open-source Canvas LMS: Rails application code released under AGPLv3. You supply the server, services, security, backups and operations.
  • Development environment: A disposable setup for coding, themes, plugins and evaluation.
  • Production deployment: A maintained service with a real domain, email delivery, background jobs, HTTPS, storage, monitoring and recovery procedures.

Installing the core repository does not provide Instructure’s hosted infrastructure, commercial support, managed upgrades, Studio, Impact, analytics, AI features or every ancillary service. The Rich Content Service and other ecosystem components may need separate deployment or configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the right installation method

Native Ubuntu for production

This is the production path described by Instructure. It gives you control over code, database, storage and networking, but your organization owns patching, scaling, security, email, backups and incident response. A single all-in-one server is also a single point of failure.

Docker for development

For local development, follow the official Quick Start and run:

git clone https://github.com/instructure/canvas-lms.git
cd canvas-lms
./script/docker_dev_setup.sh

The guide recommends at least 150 GB free disk space, 8 GB RAM and a quad-core CPU for this development environment. It does not provide production email delivery, daemonized delayed jobs, a proper application server or message-bus integration, so do not expose it as your institutional LMS.

Do not use the archived self-hosted Docker repository for production

Instructure’s canvas-self-hosted repository was archived on June 2, 2026, is labelled alpha quality and warns against production reliance. Its historical flow (./setup.sh followed by docker compose up -d) is useful only as context, not as a recommended deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Production prerequisites

Requirement Baseline or decision
Operating system Ubuntu Server 22.04 LTS, 64-bit, as named by the current production guide. Verify the branch matrix before choosing Ubuntu 24.04 or another release.
Memory At least 8 GB recommended for the documented baseline; workload, jobs and database size may require more.
Database PostgreSQL 14 or newer, local or on a restricted separate server.
Runtime Ruby 3.4.1 or newer; Ruby 3.5+ is untested in the guide.
JavaScript Node.js 20 and Yarn.
Cache and jobs Redis 6.x or newer and a continuously running Canvas job service.
Web tier Apache 2 with Passenger, or a carefully validated equivalent proxy/application design.
Operations DNS name, synchronized time, firewall, SMTP, SSD capacity, TLS certificate, monitoring and off-site backups.

You should already be comfortable with Apache, Ruby/Rails, Git, PostgreSQL permissions and Linux service management. The open-source license does not make hosting, labor, support or infrastructure free.

1. Prepare Ubuntu

Use these as starting commands, then apply your organization’s hardening standard:

sudo apt update
sudo apt full-upgrade -y
sudo apt install -y git-core curl ca-certificates build-essential 
  software-properties-common
sudo timedatectl set-timezone America/New_York
sudo adduser --disabled-password --gecos "" canvasuser

Replace the timezone with the server’s real location. Set a real hostname such as canvas.example.org, synchronize the clock, permit SSH only from trusted networks, and permit HTTPS (and HTTP only if needed for certificate issuance or redirection). Create your backup destination before putting user data on the server.

2. Install and secure PostgreSQL

The documented baseline is PostgreSQL 14 or newer. The database may be local or remote.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo apt install -y postgresql-14
sudo -u postgres createuser canvas 
  --no-createdb --no-superuser --no-createrole --pwprompt
sudo -u postgres createdb canvas_production --owner=canvas

Record the password in a secret manager, not in shell history or Git. If PostgreSQL is remote, set an appropriate listen_addresses, add a narrowly scoped pg_hba.conf rule for the Canvas application address, restrict the database firewall, use TLS where appropriate, and test connectivity before migrations. Never open PostgreSQL to the public Internet.

3. Download and pin Canvas

Clone the repository and select the branch specified by the current production documentation:

git clone https://github.com/instructure/canvas-lms.git canvas
cd canvas
git checkout prod

For a reproducible installation, record a reviewed commit or release after checking the repository’s current compatibility matrix. Do not silently deploy whatever prod happens to point to months later.

sudo mkdir -p /var/canvas
sudo chown -R "$USER":"$USER" /var/canvas
cp -a . /var/canvas/
cd /var/canvas

Confirm that the root contains directories such as app, config, db, public and script.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Install Ruby, Node.js and dependencies

Ruby and native packages

The current guide uses Instructure’s Ruby PPA. Review any third-party repository and its signing-key procedure before enabling it; package availability varies by Ubuntu release.

sudo apt install -y software-properties-common
sudo add-apt-repository ppa:instructure/ruby
sudo apt update
sudo apt install -y ruby3.4 ruby3.4-dev zlib1g-dev 
  libxml2-dev libsqlite3-dev postgresql libpq-dev 
  libxmlsec1-dev libyaml-dev libidn11-dev curl make g++

Node.js 20

curl -sL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs
sudo npm install -g npm@latest
ruby --version
node --version
npm --version

npm@latest changes over time. Record the installed versions and pin them in your deployment process rather than assuming today’s latest will reproduce tomorrow’s build.

Ruby gems and JavaScript packages

sudo gem install bundler
bundle config set --local path vendor/bundle
bundle install
sudo npm install --global yarn
yarn install

The required Bundler version may be constrained by the branch lockfile and CI configuration. Native-gem errors usually indicate a missing development package, incompatible Ruby or dependency-version mismatch; read the first compiler error before adding packages at random.

5. Create and protect Canvas configuration

Copy the branch’s example files, then edit each production value:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
for config in amazon_s3 database vault_contents 
  delayed_jobs domain file_store outgoing_mail security external_migration
do
  cp "config/${config}.yml.example" "config/${config}.yml"
done
cp config/dynamic_settings.yml.example config/dynamic_settings.yml
cp config/cache_store.yml.example config/cache_store.yml
cp config/redis.yml.example config/redis.yml

These YAML files can contain database passwords, SMTP credentials, encryption keys and other secrets. Never commit them or publish them. Use the checked-out branch’s examples for exact keys and syntax.

Database

Edit config/database.yml:

sudoedit config/database.yml

Match the production host, port, database name, canvas user, password and any required SSL settings.

SMTP

Edit config/outgoing_mail.yml and set the SMTP host, port, encryption mode, credentials, required domain and optional outgoing_address. Test delivery with a real mailbox. Login success does not prove that email, DNS SPF/DKIM/DMARC or the background job path works.

Public domain

Edit config/domain.yml using the current example file. A typical production section is:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
production:
  domain: canvas.example.org
  ssl: true

Use the hostname users will actually visit. It affects generated notification links and other URLs made outside a browser request.

Storage

Local disk is simplest for one server but requires capacity monitoring, permissions and file backups. Object storage such as Amazon S3 is more suitable when application servers must scale independently. Backing up PostgreSQL alone does not preserve locally stored uploads.

Permissions

sudo chown -R canvasuser:canvasuser /var/canvas
sudo chown canvasuser config/*.yml
sudo chmod 400 config/*.yml

Adjust ownership carefully for Apache/Passenger, logs, uploaded files and deployment tooling. Verify that only the service account and approved administrators can read secrets.

6. Initialize the application

Run the tasks documented by the exact Canvas branch you checked out. The expected sequence in the current production path is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
RAILS_ENV=production bundle exec rake db:initial_setup
RAILS_ENV=production bundle exec rake db:migrate
RAILS_ENV=production bundle exec rake canvas:compile_assets

If the branch’s documentation or rake -T shows different task names, follow that branch rather than copying an old tutorial. Setup and asset compilation can take substantial time and fail because of credentials, runtime mismatch, insufficient memory or package-network errors. Create the initial administrator when the setup flow requests it; do not reuse a weak system password.

7. Configure Redis

Redis is used for caching and is required by some functionality, including OAuth2, according to the production guide.

sudo apt install -y redis-server
sudo systemctl enable --now redis-server
redis-cli ping

Expected output is PONG. Edit config/cache_store.yml and config/redis.yml according to the current examples, selecting Redis for production and setting its local or private-network endpoint. Bind and firewall Redis so it is never publicly reachable.

8. Put Apache and Passenger in front

sudo apt install -y apache2
audo apt install -y dirmngr gnupg apt-transport-https ca-certificates
sudo apt install -y libapache2-mod-passenger
sudo a2enmod rewrite passenger

There is a typographical trap in many copied guides: the second command must begin with sudo, as shown below.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo apt install -y dirmngr gnupg apt-transport-https ca-certificates

Passenger’s repository-key instructions have changed; avoid deprecated apt-key recipes and use the current Passenger documentation for your Ubuntu release.

Create an Apache virtual host with ServerName canvas.example.org, DocumentRoot /var/canvas/public, a production Rails environment, Passenger settings, AllowOverride All, correct directory permissions and dedicated access/error logs. Add an HTTPS listener and redirect HTTP after certificates are working. Then enable and validate it:

sudo a2ensite canvas
sudo apachectl configtest
sudo systemctl reload apache2

The expected configuration-test result is Syntax OK. A 403 usually means a wrong document root, directory rule, ownership or Passenger user. A 500 usually points to Ruby, database, assets, environment or application-log errors.

9. Enable trusted HTTPS

Point DNS to the server before requesting a publicly trusted certificate, commonly from Let’s Encrypt. You may terminate TLS in Apache, a reverse proxy such as Caddy or Nginx, or a cloud load balancer. In every design:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Allow ports 80 and 443 as required.
  • Redirect HTTP to HTTPS.
  • Automate renewal and test renewal.
  • Pass the correct X-Forwarded-Proto when a proxy terminates TLS.
  • Do not use Ubuntu’s self-signed “snakeoil” certificate for public production; browsers do not trust it by default.

10. Run Canvas background jobs

Canvas needs automated jobs for email reports, statistics and other work; the production guide warns that it will not function properly without them. The guide shows an older init-script method:

sudo ln -s /var/canvas/script/canvas_init /etc/init.d/canvas_init
sudo update-rc.d canvas_init defaults
sudo /etc/init.d/canvas_init start

Because this is legacy SysV-style integration, verify whether your checked-out branch supplies a systemd unit or another current runner before deploying. Whichever method you use, make the service start on boot, run as the intended account, restart on failure and expose a health check or status command.

11. Validate the deployment

Run service checks:

sudo systemctl status postgresql
sudo systemctl status redis-server
sudo systemctl status apache2
sudo apachectl configtest
curl -I https://canvas.example.org

Then exercise the application as a user and administrator:

  • Open the login page and confirm there are no certificate warnings.
  • Sign in to the administrator account.
  • Create a test course and enroll a test user.
  • Upload and download a file.
  • Send a notification and confirm delivery.
  • Confirm background jobs execute and Redis-backed functions work.
  • Review Apache and Canvas logs for repeated errors.
sudo tail -f /var/log/apache2/canvas_errors.log
sudo tail -f /var/log/apache2/canvas_access.log
ls -lah /var/canvas/log

Application logs normally live under the Canvas log directory; exact filenames depend on the branch and logging configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

12. Backups, upgrades and service boundaries

Back up more than PostgreSQL

  • Take tested, encrypted PostgreSQL backups and practice restoring them.
  • Back up local uploads, or ensure the object-storage bucket has versioning and a separate recovery policy.
  • Protect configuration files and encryption material in a restricted backup system.
  • Treat Redis as rebuildable cache unless your specific configuration stores durable state there.
  • Keep off-site copies and monitor backup age, disk space and certificate expiry.

Upgrade in a staging environment

Pin the Canvas commit, Ruby, Bundler, Node, Yarn, PostgreSQL and Redis versions used in each release. Test migrations, asset compilation, integrations, SMTP, uploads and restore procedures before production. Upgrades can require coordinated changes to Ruby, database, JavaScript packages, jobs, plugins and external services.

Know what remains separate

A healthy core LMS does not automatically deploy the Rich Content Service, file-delivery infrastructure, analytics, Studio, Impact or other commercial and ecosystem components. Confirm each feature’s deployment and licensing requirements.

Common failures and recovery checks

Ruby or Bundler errors

ruby --version
bundle --version
bundle config list

Check the branch’s supported Ruby (Ruby 3.5+ is untested in the current guide), the lockfile’s Bundler expectation and missing development headers before changing dependencies.

PostgreSQL connection failures

sudo -u postgres psql -c 'l'

Recheck database.yml, credentials, ownership, listening address, pg_hba.conf, firewall rules, DNS and whether a remote database requires TLS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Asset compilation failures

node --version
npm --version
yarn --version
free -h
df -h

Look for Node/Yarn mismatch, low memory, missing libraries or registry failures. Do not delete the lockfile unless current Canvas documentation explicitly directs you to.

Apache 403 or 500

sudo apachectl configtest
sudo apachectl -M | grep -E 'passenger|rewrite|ssl'
sudo tail -f /var/log/apache2/canvas_errors.log

For 403, inspect DocumentRoot, <Directory> rules, ownership and AllowOverride. For 500, inspect Passenger’s Ruby path, compiled assets, database settings, environment and the Canvas application log.

Email, Redis or upload problems

  • Email: verify SMTP host/port, TLS, credentials, sender domain, SPF/DKIM/DMARC, outbound firewall rules, job status and provider logs.
  • Redis: run redis-cli ping, check redis-server status and compare both Redis YAML files with the branch examples.
  • Uploads: check storage permissions, disk space, Apache and proxy upload limits, S3 credentials and bucket policy.

When a hosted service is the better answer

Canvas Cloud

Instructure currently presents Canvas Core, Canvas Plus and Canvas Next, with personalized quote-based pricing rather than a public list: Canvas tiers. It is a better fit when you need vendor support, managed backups, uptime and commercial Canvas features, and a poor fit when you require complete infrastructure control.

MoodleCloud

If Canvas is not mandatory, MoodleCloud’s published plans start at AUD 170 annually for 50 users and rise to AUD 2,110 for 750 users; plans are billed annually in AUD, storage varies, and standard sites do not allow user-installed plugins or integrations. It reduces administration but is Moodle, not Canvas, and has published user and storage limits.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Managed Moodle hosting

Moodle’s official hosting service targets organizations wanting managed, secure and scalable Moodle without operating the full Linux stack. Larger or customized deployments are directed to a quote.

For a school or nonprofit handling student records, compare the total cost of administration, monitoring, security, disaster recovery, email and staffing—not just the price of an Ubuntu virtual machine.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.