Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Canvas LMS can run on Ubuntu, but it is not an application you install with one apt install command. A production deployment combines the open-source AGPLv3 Canvas code with PostgreSQL, Redis, Ruby, Node.js, Apache/Passenger, SMTP, background jobs, HTTPS, storage, backups and ongoing administration. Instructure’s current production guide is written for 64-bit Ubuntu 22.04 LTS, at least 8 GB of RAM, PostgreSQL 14 or newer, Ruby 3.4.1 or newer (Ruby 3.5+ is untested), Node.js 20 and Redis 6.x or newer: official Production Start guide.
Use the native installation below only if you can maintain a Linux/Ruby/PostgreSQL service. Use Docker for development and evaluation, not a public school or institutional service. If you need managed uptime, support and upgrades, choose a hosted LMS instead.
What you are actually installing
“Canvas” can mean several different products:
- Canvas Cloud: Instructure’s commercial, hosted service. It includes managed infrastructure and support; no Ubuntu server is required.
- Open-source Canvas LMS: Rails application code released under AGPLv3. You supply the server, services, security, backups and operations.
- Development environment: A disposable setup for coding, themes, plugins and evaluation.
- Production deployment: A maintained service with a real domain, email delivery, background jobs, HTTPS, storage, monitoring and recovery procedures.
Installing the core repository does not provide Instructure’s hosted infrastructure, commercial support, managed upgrades, Studio, Impact, analytics, AI features or every ancillary service. The Rich Content Service and other ecosystem components may need separate deployment or configuration.
Choose the right installation method
Native Ubuntu for production
This is the production path described by Instructure. It gives you control over code, database, storage and networking, but your organization owns patching, scaling, security, email, backups and incident response. A single all-in-one server is also a single point of failure.
#1 Best Overall
Docker for development
For local development, follow the official Quick Start and run:
git clone https://github.com/instructure/canvas-lms.git
cd canvas-lms
./script/docker_dev_setup.sh
The guide recommends at least 150 GB free disk space, 8 GB RAM and a quad-core CPU for this development environment. It does not provide production email delivery, daemonized delayed jobs, a proper application server or message-bus integration, so do not expose it as your institutional LMS.
Do not use the archived self-hosted Docker repository for production
Instructure’s canvas-self-hosted repository was archived on June 2, 2026, is labelled alpha quality and warns against production reliance. Its historical flow (./setup.sh followed by docker compose up -d) is useful only as context, not as a recommended deployment.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Production prerequisites
| Requirement | Baseline or decision |
|---|---|
| Operating system | Ubuntu Server 22.04 LTS, 64-bit, as named by the current production guide. Verify the branch matrix before choosing Ubuntu 24.04 or another release. |
| Memory | At least 8 GB recommended for the documented baseline; workload, jobs and database size may require more. |
| Database | PostgreSQL 14 or newer, local or on a restricted separate server. |
| Runtime | Ruby 3.4.1 or newer; Ruby 3.5+ is untested in the guide. |
| JavaScript | Node.js 20 and Yarn. |
| Cache and jobs | Redis 6.x or newer and a continuously running Canvas job service. |
| Web tier | Apache 2 with Passenger, or a carefully validated equivalent proxy/application design. |
| Operations | DNS name, synchronized time, firewall, SMTP, SSD capacity, TLS certificate, monitoring and off-site backups. |
You should already be comfortable with Apache, Ruby/Rails, Git, PostgreSQL permissions and Linux service management. The open-source license does not make hosting, labor, support or infrastructure free.
1. Prepare Ubuntu
Use these as starting commands, then apply your organization’s hardening standard:
sudo apt update
sudo apt full-upgrade -y
sudo apt install -y git-core curl ca-certificates build-essential
software-properties-common
sudo timedatectl set-timezone America/New_York
sudo adduser --disabled-password --gecos "" canvasuser
Replace the timezone with the server’s real location. Set a real hostname such as canvas.example.org, synchronize the clock, permit SSH only from trusted networks, and permit HTTPS (and HTTP only if needed for certificate issuance or redirection). Create your backup destination before putting user data on the server.
2. Install and secure PostgreSQL
The documented baseline is PostgreSQL 14 or newer. The database may be local or remote.
sudo apt install -y postgresql-14
sudo -u postgres createuser canvas
--no-createdb --no-superuser --no-createrole --pwprompt
sudo -u postgres createdb canvas_production --owner=canvas
Record the password in a secret manager, not in shell history or Git. If PostgreSQL is remote, set an appropriate listen_addresses, add a narrowly scoped pg_hba.conf rule for the Canvas application address, restrict the database firewall, use TLS where appropriate, and test connectivity before migrations. Never open PostgreSQL to the public Internet.
3. Download and pin Canvas
Clone the repository and select the branch specified by the current production documentation:
Rank #2
git clone https://github.com/instructure/canvas-lms.git canvas
cd canvas
git checkout prod
For a reproducible installation, record a reviewed commit or release after checking the repository’s current compatibility matrix. Do not silently deploy whatever prod happens to point to months later.
sudo mkdir -p /var/canvas
sudo chown -R "$USER":"$USER" /var/canvas
cp -a . /var/canvas/
cd /var/canvas
Confirm that the root contains directories such as app, config, db, public and script.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
4. Install Ruby, Node.js and dependencies
Ruby and native packages
The current guide uses Instructure’s Ruby PPA. Review any third-party repository and its signing-key procedure before enabling it; package availability varies by Ubuntu release.
sudo apt install -y software-properties-common
sudo add-apt-repository ppa:instructure/ruby
sudo apt update
sudo apt install -y ruby3.4 ruby3.4-dev zlib1g-dev
libxml2-dev libsqlite3-dev postgresql libpq-dev
libxmlsec1-dev libyaml-dev libidn11-dev curl make g++
Node.js 20
curl -sL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs
sudo npm install -g npm@latest
ruby --version
node --version
npm --version
npm@latest changes over time. Record the installed versions and pin them in your deployment process rather than assuming today’s latest will reproduce tomorrow’s build.
Ruby gems and JavaScript packages
sudo gem install bundler
bundle config set --local path vendor/bundle
bundle install
sudo npm install --global yarn
yarn install
The required Bundler version may be constrained by the branch lockfile and CI configuration. Native-gem errors usually indicate a missing development package, incompatible Ruby or dependency-version mismatch; read the first compiler error before adding packages at random.
5. Create and protect Canvas configuration
Copy the branch’s example files, then edit each production value:
for config in amazon_s3 database vault_contents
delayed_jobs domain file_store outgoing_mail security external_migration
do
cp "config/${config}.yml.example" "config/${config}.yml"
done
cp config/dynamic_settings.yml.example config/dynamic_settings.yml
cp config/cache_store.yml.example config/cache_store.yml
cp config/redis.yml.example config/redis.yml
These YAML files can contain database passwords, SMTP credentials, encryption keys and other secrets. Never commit them or publish them. Use the checked-out branch’s examples for exact keys and syntax.
Database
Edit config/database.yml:
sudoedit config/database.yml
Match the production host, port, database name, canvas user, password and any required SSL settings.
SMTP
Edit config/outgoing_mail.yml and set the SMTP host, port, encryption mode, credentials, required domain and optional outgoing_address. Test delivery with a real mailbox. Login success does not prove that email, DNS SPF/DKIM/DMARC or the background job path works.
Rank #3
Public domain
Edit config/domain.yml using the current example file. A typical production section is:
Free tools Windows power users keep installed
One-click scans. No signup required.
production:
domain: canvas.example.org
ssl: true
Use the hostname users will actually visit. It affects generated notification links and other URLs made outside a browser request.
Storage
Local disk is simplest for one server but requires capacity monitoring, permissions and file backups. Object storage such as Amazon S3 is more suitable when application servers must scale independently. Backing up PostgreSQL alone does not preserve locally stored uploads.
Permissions
sudo chown -R canvasuser:canvasuser /var/canvas
sudo chown canvasuser config/*.yml
sudo chmod 400 config/*.yml
Adjust ownership carefully for Apache/Passenger, logs, uploaded files and deployment tooling. Verify that only the service account and approved administrators can read secrets.
6. Initialize the application
Run the tasks documented by the exact Canvas branch you checked out. The expected sequence in the current production path is:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsRAILS_ENV=production bundle exec rake db:initial_setup
RAILS_ENV=production bundle exec rake db:migrate
RAILS_ENV=production bundle exec rake canvas:compile_assets
If the branch’s documentation or rake -T shows different task names, follow that branch rather than copying an old tutorial. Setup and asset compilation can take substantial time and fail because of credentials, runtime mismatch, insufficient memory or package-network errors. Create the initial administrator when the setup flow requests it; do not reuse a weak system password.
7. Configure Redis
Redis is used for caching and is required by some functionality, including OAuth2, according to the production guide.
sudo apt install -y redis-server
sudo systemctl enable --now redis-server
redis-cli ping
Expected output is PONG. Edit config/cache_store.yml and config/redis.yml according to the current examples, selecting Redis for production and setting its local or private-network endpoint. Bind and firewall Redis so it is never publicly reachable.
8. Put Apache and Passenger in front
sudo apt install -y apache2
audo apt install -y dirmngr gnupg apt-transport-https ca-certificates
sudo apt install -y libapache2-mod-passenger
sudo a2enmod rewrite passenger
There is a typographical trap in many copied guides: the second command must begin with sudo, as shown below.
Rank #4
sudo apt install -y dirmngr gnupg apt-transport-https ca-certificates
Passenger’s repository-key instructions have changed; avoid deprecated apt-key recipes and use the current Passenger documentation for your Ubuntu release.
Create an Apache virtual host with ServerName canvas.example.org, DocumentRoot /var/canvas/public, a production Rails environment, Passenger settings, AllowOverride All, correct directory permissions and dedicated access/error logs. Add an HTTPS listener and redirect HTTP after certificates are working. Then enable and validate it:
sudo a2ensite canvas
sudo apachectl configtest
sudo systemctl reload apache2
The expected configuration-test result is Syntax OK. A 403 usually means a wrong document root, directory rule, ownership or Passenger user. A 500 usually points to Ruby, database, assets, environment or application-log errors.
9. Enable trusted HTTPS
Point DNS to the server before requesting a publicly trusted certificate, commonly from Let’s Encrypt. You may terminate TLS in Apache, a reverse proxy such as Caddy or Nginx, or a cloud load balancer. In every design:
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute- Allow ports 80 and 443 as required.
- Redirect HTTP to HTTPS.
- Automate renewal and test renewal.
- Pass the correct
X-Forwarded-Protowhen a proxy terminates TLS. - Do not use Ubuntu’s self-signed “snakeoil” certificate for public production; browsers do not trust it by default.
10. Run Canvas background jobs
Canvas needs automated jobs for email reports, statistics and other work; the production guide warns that it will not function properly without them. The guide shows an older init-script method:
sudo ln -s /var/canvas/script/canvas_init /etc/init.d/canvas_init
sudo update-rc.d canvas_init defaults
sudo /etc/init.d/canvas_init start
Because this is legacy SysV-style integration, verify whether your checked-out branch supplies a systemd unit or another current runner before deploying. Whichever method you use, make the service start on boot, run as the intended account, restart on failure and expose a health check or status command.
11. Validate the deployment
Run service checks:
sudo systemctl status postgresql
sudo systemctl status redis-server
sudo systemctl status apache2
sudo apachectl configtest
curl -I https://canvas.example.org
Then exercise the application as a user and administrator:
- Open the login page and confirm there are no certificate warnings.
- Sign in to the administrator account.
- Create a test course and enroll a test user.
- Upload and download a file.
- Send a notification and confirm delivery.
- Confirm background jobs execute and Redis-backed functions work.
- Review Apache and Canvas logs for repeated errors.
sudo tail -f /var/log/apache2/canvas_errors.log
sudo tail -f /var/log/apache2/canvas_access.log
ls -lah /var/canvas/log
Application logs normally live under the Canvas log directory; exact filenames depend on the branch and logging configuration.
Recommended Free Tools
12. Backups, upgrades and service boundaries
Back up more than PostgreSQL
- Take tested, encrypted PostgreSQL backups and practice restoring them.
- Back up local uploads, or ensure the object-storage bucket has versioning and a separate recovery policy.
- Protect configuration files and encryption material in a restricted backup system.
- Treat Redis as rebuildable cache unless your specific configuration stores durable state there.
- Keep off-site copies and monitor backup age, disk space and certificate expiry.
Upgrade in a staging environment
Pin the Canvas commit, Ruby, Bundler, Node, Yarn, PostgreSQL and Redis versions used in each release. Test migrations, asset compilation, integrations, SMTP, uploads and restore procedures before production. Upgrades can require coordinated changes to Ruby, database, JavaScript packages, jobs, plugins and external services.
Best Value
Know what remains separate
A healthy core LMS does not automatically deploy the Rich Content Service, file-delivery infrastructure, analytics, Studio, Impact or other commercial and ecosystem components. Confirm each feature’s deployment and licensing requirements.
Common failures and recovery checks
Ruby or Bundler errors
ruby --version
bundle --version
bundle config list
Check the branch’s supported Ruby (Ruby 3.5+ is untested in the current guide), the lockfile’s Bundler expectation and missing development headers before changing dependencies.
PostgreSQL connection failures
sudo -u postgres psql -c 'l'
Recheck database.yml, credentials, ownership, listening address, pg_hba.conf, firewall rules, DNS and whether a remote database requires TLS.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Asset compilation failures
node --version
npm --version
yarn --version
free -h
df -h
Look for Node/Yarn mismatch, low memory, missing libraries or registry failures. Do not delete the lockfile unless current Canvas documentation explicitly directs you to.
Apache 403 or 500
sudo apachectl configtest
sudo apachectl -M | grep -E 'passenger|rewrite|ssl'
sudo tail -f /var/log/apache2/canvas_errors.log
For 403, inspect DocumentRoot, <Directory> rules, ownership and AllowOverride. For 500, inspect Passenger’s Ruby path, compiled assets, database settings, environment and the Canvas application log.
Email, Redis or upload problems
- Email: verify SMTP host/port, TLS, credentials, sender domain, SPF/DKIM/DMARC, outbound firewall rules, job status and provider logs.
- Redis: run
redis-cli ping, checkredis-serverstatus and compare both Redis YAML files with the branch examples. - Uploads: check storage permissions, disk space, Apache and proxy upload limits, S3 credentials and bucket policy.
When a hosted service is the better answer
Canvas Cloud
Instructure currently presents Canvas Core, Canvas Plus and Canvas Next, with personalized quote-based pricing rather than a public list: Canvas tiers. It is a better fit when you need vendor support, managed backups, uptime and commercial Canvas features, and a poor fit when you require complete infrastructure control.
MoodleCloud
If Canvas is not mandatory, MoodleCloud’s published plans start at AUD 170 annually for 50 users and rise to AUD 2,110 for 750 users; plans are billed annually in AUD, storage varies, and standard sites do not allow user-installed plugins or integrations. It reduces administration but is Moodle, not Canvas, and has published user and storage limits.
Managed Moodle hosting
Moodle’s official hosting service targets organizations wanting managed, secure and scalable Moodle without operating the full Linux stack. Larger or customized deployments are directed to a quote.
For a school or nonprofit handling student records, compare the total cost of administration, monitoring, security, disaster recovery, email and staffing—not just the price of an Ubuntu virtual machine.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

