Penpot Open-Source Design Platform

AWS Developer Tools
Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

Self-host Penpot on AWS in minutes - skip Docker setup, get a secure admin account on first boot, and design with your team backed by 24/7 cloudimg support.

Why the cloudimg image

This image arrives installed, configured and hardened, so there is no manual setup before you can use it. It is built on a patched base, runs with credentials generated uniquely for your instance on first boot, and passes an automated health check before every release. Every deployment is backed by 24/7 support from cloudimg engineers.

Key features

  • Ready in minutes, not hours: the official five-service Penpot stack (frontend, backend, exporter, PostgreSQL 15, Redis) ships preconfigured on port 80. You skip installing Docker, wiring Compose, generating secrets, and provisioning storage. Your team can start designing interfaces and prototyping immediately after launch.
  • Secure by default with zero shared credentials: a unique application secret key, database password, and admin account with a random password are generated fresh on every first boot. Open self-registration is disabled, no default password ever exists, and all build-time state is wiped before image capture.
  • 24/7 expert support from cloudimg: hands-on engineering help with TLS termination, backups, user management, and scaling via email and live chat, giving you reliable assistance that community forums cannot match.

See it running

Real screenshots taken while testing this image against its deployment guide.

Penpot Open-Source Design Platform screenshot 1 Penpot Open-Source Design Platform screenshot 2 Penpot Open-Source Design Platform screenshot 3 Penpot Open-Source Design Platform screenshot 4

Description

This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

## Why This AMI Instead of Self-Deploying?

Penpot is an open source, self-hosted design and prototyping platform - a self-hostable alternative to Figma for building user interfaces and design systems, collaborative by default and running entirely in the browser. Deploying it yourself means installing Docker, wiring up the official five-service Compose stack (frontend, backend, exporter, PostgreSQL and Redis), generating application secrets, seeding an admin account, and maintaining the stack over time. This AMI eliminates that effort entirely - your design workspace is running within minutes of launch, not hours. You get a pre-hardened, tested configuration backed by 24/7 expert support, something community forums cannot provide.

The current release available is Penpot 2.5.4.

## Application Stack

The official Penpot self-host Compose stack ships preconfigured and pinned by version: penpot-frontend (the bundled nginx that publishes the SPA and proxies the API on port 80), penpot-backend (the application server), penpot-exporter (the headless render/export service), PostgreSQL 15 (the primary database) and Redis (cache, queue and realtime). Only port 80 is published; every backing service stays on the internal Docker network and is never exposed on the host. All application state - the database, the Redis data and your uploaded design assets - lives on a dedicated, independently-resizable EBS data volume, so your work survives restarts, reboots and resizes.

## Secure By Default

Many pre-built images ship with shared or default credentials - a common vulnerability that exposes instances immediately after launch. This image eliminates that risk entirely:

  • A fresh application secret key and database password are generated for every instance on its first boot, before the application starts
  • Open self-registration is disabled and a single per-instance admin account is created automatically with a random password, stored in a root-only file inaccessible to unprivileged users
  • No shared or default password ships in the image
  • Build-time state is wiped before capture, so the database, cache and all secrets are re-created fresh on your instance

## Ready To Use

Browse to the instance on port 80 and sign in with the generated admin account. Design user interfaces and design systems, prototype interactive flows, and invite your team from the Penpot settings - open registration stays disabled so only invited users can join.

## Evaluate at Minimal Cost

Launch on a small instance to explore the platform. The hourly billing model means you can test the full Penpot experience - designing, prototyping and collaborating - without a long-term commitment. Scale up when you are ready.

## What You Avoid By Using This AMI

  • Installing Docker and wiring up a five-service Compose stack
  • Generating and securely storing the application secret key and database password
  • Seeding and hardening the first admin account
  • Provisioning a dedicated data disk for the database, cache and design assets
  • Ongoing maintenance and security patching without expert guidance

## cloudimg Support

24/7 technical support by email and chat. Our engineers help with deployment, TLS termination, backups, user management and scaling.

## Use Cases

  • Product teams designing user interfaces and design systems in a private, self-hosted workspace they control
  • Teams with data-residency requirements keeping design files inside their own VPC rather than a third-party SaaS design tool
  • Designers and developers collaborating on interactive prototypes and handoff without per-seat SaaS licensing

All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

Related technologies

penpotfigma alternativeopen source designui ux design toolprototyping platformdesign systemscollaborative designself hosted designwireframing toolinterface designdocker design appsvg design