Ghost (container)
Free and open-source blogging platform
Image details
Configuration
TypeContainerlinuxghost:latest2368/tcp/var/lib/ghost/contentTemplate by portainer
Report issueNotes
/ghost/.Standalone Install
Select an install method, to see config/commands for deploying Ghost (container)
Install on Portainer
Import all app templates into your Portainer instance, for easy 1-click deploys
- Ensure both Docker and Portainer are installed, and up-to-date
- Log into your Portainer web UI
- Under Settings → App Templates, paste the below URL
- Head to Home → App Templates, and the list of apps will show up
- Select Ghost (container), fill in any config options, and hit Deploy
Template Import URL
https://raw.githubusercontent.com/Lissy93/portainer-templates/main/templates.json
Show Me
More install options in our documentation.
Quick reference
- Maintained by:
[Ghost Foundation](https://ghost.org)- Where to get help:
[the Docker Community Slack](https://dockr.ly/comm-slack), [Server Fault](https://serverfault.com/help/on-topic), [Unix & Linux](https://unix.stackexchange.com/help/on-topic), or [Stack Overflow](https://stackoverflow.com/help/on-topic)Supported tags and respective Dockerfile links
Quick reference (cont.)
- Where to file issues:
[https://github.com/TryGhost/docker-library-ghost/issues](https://github.com/TryGhost/docker-library-ghost/issues?q=is:issue+is:pr)- Supported architectures: (more info)
[`amd64`](https://hub.docker.com/r/amd64/ghost/), [`arm32v7`](https://hub.docker.com/r/arm32v7/ghost/), [`arm64v8`](https://hub.docker.com/r/arm64v8/ghost/)- Published image artifact details:
[repo-info repo's `repos/ghost/` directory](https://github.com/docker-library/repo-info/blob/master/repos/ghost) ([history](https://github.com/docker-library/repo-info/commits/master/repos/ghost))
(image metadata, transfer size, etc)- Image updates:
[official-images repo's `library/ghost` label](https://github.com/docker-library/official-images/issues?q=label%3Alibrary%2Fghost)
[official-images repo's `library/ghost` file](https://github.com/docker-library/official-images/blob/master/library/ghost) ([history](https://github.com/docker-library/official-images/commits/master/library/ghost))- Source of this description:
[docs repo's `ghost/` directory](https://github.com/docker-library/docs/tree/master/ghost) ([history](https://github.com/docker-library/docs/commits/master/ghost))Ghost
Ghost is an independent platform for publishing online by web and email newsletter. It has user signups, gated access and subscription payments built-in (with Stripe) to allow you to build a direct relationship with your audience. It's fast, user-friendly, and runs on Node.js & MySQL8.Ghost.org

How to use this image
This will start a Ghost development instance listening on the default Ghost port of 2368.$ docker run -d --name some-ghost -e NODE_ENV=development ghostCustom port
If you'd like to be able to access the instance from the host without the container's IP, standard port mappings can be used:$ docker run -d --name some-ghost -e NODE_ENV=development -e url=http://localhost:3001 -p 3001:2368 ghostIf all goes well, you'll be able to access your new site on
http://localhost:3001 and http://localhost:3001/ghost to access Ghost Admin (or http://host-ip:3001 and http://host-ip:3001/ghost, respectively).Upgrading Ghost
You will want to ensure you are running the latest minor version of Ghost before upgrading major versions. Otherwise, you may run into database errors.For upgrading your Ghost container you will want to mount your data to the appropriate path in the predecessor container (see below): import your content from the admin panel, stop the container, and then re-mount your content to the successor container you are upgrading into; you can then export your content from the admin panel.
Stateful
Mount your existing content. In this example we also use the Alpine Linux based image.$ docker run -d \
--name some-ghost \
-e NODE_ENV=development \
-e database__connection__filename='/var/lib/ghost/content/data/ghost.db' \
-p 3001:2368 \
-v /path/to/ghost/blog:/var/lib/ghost/content \
ghost:alpineNote:
database__connection__filename is only valid in development mode and is the location for the SQLite database file. If using development mode, it should be set to a writeable path within a persistent folder (bind mount or volume). It is not available in production mode because an external MySQL server is required (see the Docker Compose example below).Docker Volume
Alternatively you can use a named docker volume instead of a direct host path for/var/lib/ghost/content:$ docker run -d \
--name some-ghost \
-e NODE_ENV=development \
-e database__connection__filename='/var/lib/ghost/content/data/ghost.db' \
-p 3001:2368 \
-v some-ghost-data:/var/lib/ghost/content \
ghostConfiguration
All Ghost configuration parameters (such asurl) can be specified via environment variables. See the Ghost documentation for details about what configuration is allowed and how to convert a nested configuration key into the appropriate environment variable name:$ docker run -d --name some-ghost -e NODE_ENV=development -e url=http://some-ghost.example.com ghost(There are further configuration examples in the
compose.yaml listed below.)Docker Secrets
As an alternative to passing sensitive configuration values via environment variables,_FILE may be appended to a Ghost configuration environment variable, causing Ghost to read that value from a file in the container instead. In particular, this can be used to load secrets from Docker secrets stored in /run/secrets/<secret_name> files. For example:$ docker run -d \
--name some-ghost \
-e database__client=mysql \
-e database__connection__host=some-mysql \
-e database__connection__user=ghost \
-e database__connection__password_FILE=/run/secrets/ghost-db-password \
-e database__connection__database=ghost \
ghostThis is supported for any nested configuration key (that is, any key containing at least one
__ separator), such as database__connection__password or mail__options__auth__pass. Top-level keys such as url are deliberately excluded, so that unrelated variables like SSL_CERT_FILE are not mistaken for Ghost configuration.A single trailing newline is stripped from the file's contents (matching
$(cat file) behavior); any other surrounding whitespace is preserved, in case it is part of the secret. Setting both foo__bar and foo__bar_FILE, or pointing two variables which resolve to the same configuration key at different files, is an error and Ghost will refuse to start.Note: this requires Ghost 6.58.0 or newer.
What is the Node.js version?
When opening a ticket at https://github.com/TryGhost/Ghost/issues it becomes necessary to know the version of Node.js in use:$ docker exec <container-id> node --version
[node version output]Note about Ghost-CLI
While the Docker images do have Ghost-CLI available and do use some of its commands to set up the base Ghost image, many of the other Ghost-CLI commands won't work correctly, and really aren't designed/intended to. For more info see docker-library/ghost#156 (comment)Ghost-CLI is not included in the
next variant at all (see below).The next variant
The next tags (ghost:next, ghost:6-next, ghost:next-alpine, plus fully qualified variants such as ghost:6.61.0-next-alpine3.23) are a preview of the image that will become the standard ghost image in Ghost 7.0. They track the same stable upstream Ghost releases as the default tags; what differs is how the image is built and laid out, not which version of Ghost is inside. The next tags never carry latest.When Ghost 7.0 ships, this layout becomes the plain
ghost:<version> image and the next tags go away, so trying next now is the way to find breakage in your setup ahead of that switch.Differences from the default variant
- Ghost is installed at
/home/ghostinstead of/var/lib/ghost, so content lives at/home/ghost/content:
```console
$ docker run -d \
--name some-ghost \
-e NODE_ENV=development \
-e database__connection__filename='/home/ghost/content/data/ghost.db' \
-p 3001:2368 \
-v some-ghost-data:/home/ghost/content \
ghost:next
```
If a volume with existing Ghost content is still mounted at the old `/var/lib/ghost/content`, the container refuses to start rather than quietly booting an empty site alongside it; an empty mount at the old path only prints a warning. Nothing at the old path is modified either way.- No Ghost-CLI. Ghost is installed from the tarball attached to its GitHub release, using the lockfile shipped in that tarball, rather than through
ghost install. Theghostcommand is not present in the image. All configuration is still done with environment variables as described above.
- Ghost is at the root of the install directory, not in a
current/subdirectory, and the default command isnode index.jsrather thannode current/index.js.
- Ghost runs as the
ghostuser rather thannode. It keeps uid/gid 1000, so existing bind mounts continue to work once they point at the new path.
- Configuration ships with the image.
config.production.jsonis a file baked into the image instead of being generated at build time by Ghost-CLI. It sets the same defaults, minus the Ghost-CLI-onlyprocesskey, and every value remains overridable via__environment variables.
- Smaller runtime image. The build doesn't include Ghost-CLI and ships a pruned Ghost install, so build toolchains, package manager caches, TypeScript sources and vendored C/C++ are not shipped.
Production mode
To run Ghost for production you'll also need to be running with MySQL 8, https, and a reverse proxy configured with appropriateX-Forwarded-For, X-Forwarded-Host, and X-Forwarded-Proto (https) headers.The following example demonstrates some of the necessary configuration for running with MySQL. For more detail, see Ghost's "Configuration options" documentation.
... via docker compose
Example compose.yaml for ghost:services:
ghost:
image: ghost:6-alpine
restart: always
ports:
- 8080:2368
environment:
# see https://ghost.org/docs/config/#configuration-options
database__client: mysql
database__connection__host: db
database__connection__user: root
database__connection__password: example
database__connection__database: ghost
# this url value is just an example, and is likely wrong for your environment!
url: http://localhost:8080
# contrary to the default mentioned in the linked documentation, this image defaults to NODE_ENV=production (so development mode needs to be explicitly specified if desired)
#NODE_ENV: development
volumes:
- ghost:/var/lib/ghost/content
db:
image: mysql:8.0
restart: always
environment:
MYSQL_ROOT_PASSWORD: example
volumes:
- db:/var/lib/mysql
volumes:
ghost:
db:Run
docker compose up, wait for it to initialize completely, and visit http://localhost:8080 or http://host-ip:8080 (as appropriate).Image Variants
Theghost images come in many flavors, each designed for a specific use case.ghost:<version>
This is the defacto image. If you are unsure about what your needs are, you probably want to use this one. It is designed to be used both as a throw away container (mount your source code and start the container to start your app), as well as the base to build other images off of.Some of these tags may have names like bookworm in them. These are the suite code names for releases of Debian and indicate which release the image is based on. If your image needs to install any additional packages beyond what comes with the image, you'll likely want to specify one of these explicitly to minimize breakage when there are new releases of Debian.
ghost:<version>-alpine
This image is based on the popular Alpine Linux project, available in the alpine official image. Alpine Linux is much smaller than most distribution base images (~5MB), and thus leads to much slimmer images in general.This variant is useful when final image size being as small as possible is your primary concern. The main caveat to note is that it does use musl libc instead of glibc and friends, so software will often run into issues depending on the depth of their libc requirements/assumptions. See this Hacker News comment thread for more discussion of the issues that might arise and some pro/con comparisons of using Alpine-based images.
To minimize image size, it's uncommon for additional related tools (such as
git or bash) to be included in Alpine-based images. Using this image as a base, add the things you need in your own Dockerfile (see the alpine image description for examples of how to install packages if you are unfamiliar).License
View license information for the software contained in this image.As with all Docker images, these likely also contain other software which may be under other licenses (such as Bash, etc from the base distribution, along with any direct or indirect dependencies of the primary software being contained).
Some additional license information which was able to be auto-detected might be found in the
repo-info repository's ghost/ directory.As for any pre-built image usage, it is the image user's responsibility to ensure that any use of this image complies with any relevant licenses for all software contained within.
Serve Ghost (container) on your own domain behind Caddy, Nginx or Traefik. Fill in your domain and copy the result. It's a starting point, some apps need their own base URL or extra headers set too.
Proxying ghost-container.example.com to http://ghost-container:2368
Add this to your Caddyfile
ghost-container.example.com {
reverse_proxy http://ghost-container:2368
}Check the logs first
Nine times out of ten the logs tell you exactly what went wrong.
- In Portainer, go to Containers, click the container, then Logs. Or run
docker logs <container> - Exit codes help too:
137means killed, usually out of memory.126or127means the command inside the image is broken.
Published on a random port
This template exposes 2368/tcp without setting a host port,
so Docker picks a random free one on every deploy.
- Find it in the Ports column of Portainer's container list, or with
docker port <container>
Image won't pull
Test the pull directly on the host: docker pull ghost:latest
- "manifest unknown" means the tag no longer exists. This template uses
latest, so try pinning a specific version instead. - "toomanyrequests" is the Docker Hub rate limit. Log in with
docker loginto raise it. - "no space left on device" means a full disk. Reclaim space with
docker system prune
"exec format error"
This means the image was built for a different CPU architecture than your server.
- This image supports:
amd64, arm/v7, arm64/v8 - Check yours with
uname -m: x86_64 is amd64, aarch64 is arm64. Raspberry Pi and other ARM boards are the usual culprits.
Raise an issue
Found something which isn't working as it should? Here's how to report it.
- Bug within the app: Open an issue within the app's repo
- Template not working: Open an issue on portainer/templates
- This website not working: Open an issue on lissy93/portainer-templates
A single container
Ghost (container) runs as one container, the simplest kind of app here. Just the one image to pull and nothing else wired up alongside it.
The app image
An image is the app packed up ready to go, everything Ghost (container) needs bundled into one download. This template pulls ghost:latest, which Docker fetches once (about 155 MB) and then starts your own copy from.
Where the image comes from
Docker pulls its images from registries, public libraries of ready-built apps. Ghost (container)'s comes from Docker Hub as one of its official, curated images.
Version tags
The bit after the colon in the image name is the version tag. Here it's latest, which always points at the newest build, so a redeploy can bump you to a newer release without you asking. Newest right now is 6.67.0-next-bookworm. Pin a specific tag if you would rather stay on one version.
Which machines it runs on
Every image is built for particular CPU types. This one ships for amd64, arm/v7, arm64/v8, so it runs on both regular x86 servers and ARM boards like a Raspberry Pi.
Ports
A port is the door the app answers on. Here the app exposes a port but leaves the host side blank, so Docker picks a free one for you. It opens:
2368, published on a random host port
Volumes
A volume is where Ghost (container) keeps its files so they survive an update or a restart. Without one, anything it saves would sit inside the container and vanish the moment it's recreated. This template mounts:
/var/lib/ghost/contentas a volume Docker manages for you
Networking
Nothing custom is set, so Ghost (container) sits on Docker's default bridge network: its own private space that reaches the outside world only through the ports it publishes.
Platform
The platform is linux, the kind of system the container is built to run on. Docker and Portainer handle this on a normal Linux server.
Portainer app templates
Zooming out, this whole page comes from a Portainer app template: a short recipe telling Portainer how to set Ghost (container) up. Add the template list to Portainer once, then deploying Ghost (container) is a click rather than a wall of config.