Arama Yap Mesaj Submit
Request a Callback
+90
X
X

Select Your Currency

Turkish Lira $ US Dollar Euro
X
X

Select Your Currency

Turkish Lira $ US Dollar Euro

Contact Us

Location Halkali merkez neighborhood fatih st ozgur apt no 46 , Kucukcekmece , Istanbul , 34303 , TR

Paperless-ngx Setup: Document and Invoice Archive with OCR

Deploy Paperless-ngx with PostgreSQL, Redis and OCR on Ubuntu, including scanner intake, email consumption, document rules, Nginx TLS, exporter backup, restore and integrity checks.

Paperless-ngx Setup: Document and Invoice Archive with OCR
What will be running at the end?

Deploy Paperless-ngx with PostgreSQL, Redis and OCR on Ubuntu, including scanner intake, email consumption, document rules, Nginx TLS, exporter backup, restore and integrity checks. Every command is presented as an operational step; replace example hostnames, passwords and secrets before execution.

Architecture and requirements before installation

  • Ubuntu 24.04 LTS with sudo access and a dedicated IPv4 address
  • Docker Engine and Compose v2 where the deployment uses containers
  • A DNS A record pointing the application hostname to the server
  • NVMe capacity sized for application data, logs, temporary files and backups
  • Memory and CPU headroom based on measured concurrency rather than vendor minimums

DNS and port plan

  • 80/443 TCP: HTTPS
  • 8000/TCP: yalnız reverse proxy
  • 5432/6379: yalnız Docker ağı

Hands-on installation steps

1. Kurulum dosyaları
mkdir -p /opt/paperless-ngx
cd /opt/paperless-ngx
curl -L https://raw.githubusercontent.com/paperless-ngx/paperless-ngx/main/docker/compose/docker-compose.postgres.yml -o docker-compose.yml
curl -L https://raw.githubusercontent.com/paperless-ngx/paperless-ngx/main/docker/compose/docker-compose.env -o docker-compose.env
2. Temel ayarlar
PAPERLESS_URL=https://documents.example.com
PAPERLESS_TIME_ZONE=Europe/Istanbul
PAPERLESS_OCR_LANGUAGE=tur+eng+deu
PAPERLESS_OCR_LANGUAGES=tur deu
PAPERLESS_SECRET_KEY=GUCLU_RASTGELE_SECRET
PAPERLESS_ADMIN_USER=ekaadmin
PAPERLESS_ADMIN_PASSWORD=ILK_GIRISTEN_SONRA_DEGISTIR
PAPERLESS_REDIS=redis://broker:6379
PAPERLESS_DBHOST=db
3. Dizinler
mkdir -p consume export data media
sudo chown -R 1000:1000 consume export data media
sudo docker compose --env-file docker-compose.env config
sudo docker compose --env-file docker-compose.env up -d
4. Sağlık ve OCR
sudo docker compose ps
sudo docker compose logs --tail 150 webserver
sudo docker compose exec webserver tesseract --list-langs
curl -I http://127.0.0.1:8000
5. Tam exporter yedeği
sudo docker compose exec -T webserver document_exporter ../export --compare-checksums --delete --no-progress-bar
find export -type f | wc -l
sha256sum export/manifest.json
6. Geri yükleme
sudo docker compose down
sudo docker compose up -d db broker
sudo docker compose run --rm webserver document_importer ../export --no-progress-bar
sudo docker compose up -d
7. Bütünlük denetimi
sudo docker compose exec webserver document_sanity_checker
sudo docker compose exec webserver document_index reindex --if-needed
sudo docker compose exec webserver document_create_classifier
8. Nginx reverse proxy
sudo apt update
sudo apt install -y nginx certbot python3-certbot-nginx
sudo tee /etc/nginx/sites-available/documents.example.com > /dev/null <<'NGINX'
server {
    listen 80;
    listen [::]:80;
    server_name documents.example.com;
    client_max_body_size 10G;
    proxy_read_timeout 3600;
    proxy_send_timeout 3600;
    location / {
        proxy_pass http://127.0.0.1:8000;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}
NGINX
sudo ln -s /etc/nginx/sites-available/documents.example.com /etc/nginx/sites-enabled/documents.example.com
sudo nginx -t
sudo systemctl reload nginx
9. Let’s Encrypt SSL ve yenileme testi
sudo certbot --nginx -d documents.example.com --redirect --agree-tos --no-eff-email -m [email protected]
sudo certbot renew --dry-run
curl -I https://documents.example.com
openssl s_client -connect documents.example.com:443 -servername documents.example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates

What to know before production

Production note
Paperless-ngx Setup must be isolated behind HTTPS; databases, queues and internal APIs must not be published directly to the internet.
Production note
Pin tested image versions before production. Read release notes and take an application-consistent backup before database migrations.
Production note
A database dump alone may be incomplete. Preserve persistent files, configuration, encryption keys and the exact deployed version together.
Production note
Validate the installation with a real transaction or workload, then reboot the host and confirm automatic recovery before accepting production traffic.

Common failures and root causes

Belirti / SymptomKök neden ve çözüm / Root cause and fix
Service or container does not startInspect compose configuration, dependency health, file permissions and the first fatal log line instead of repeatedly restarting.
Domain opens but HTTPS failsCheck A/AAAA records, ports 80/443, proxy mode, certificate challenge and conflicting reverse proxies.
Application cannot reach its database or queueUse the internal service hostname, verify credentials and health checks, and keep database ports off the public interface.
Works initially but fails under loadMeasure memory peaks, disk latency, connection pools and worker concurrency; increase capacity only after identifying the bottleneck.

Post-installation validation checklist

  • All services are running and their health checks pass
  • The public hostname serves a valid HTTPS certificate
  • Only explicitly required ports are reachable
  • Administrator MFA and recovery access are configured
  • Backup checksums have been recorded
  • A restore was completed in an isolated environment
  • Logs contain no repeating critical failure
  • Services recover automatically after a host reboot

Official technical sources

Related EKA Sunucu guides

Frequently asked questions

Is this suitable for production?

Yes after secrets are replaced, public access is restricted and a complete restore test has succeeded.

Are minimum resources enough?

Minimums only prove the software can start. Size CPU, memory, IOPS and storage from representative workload measurements.

Can I use Cloudflare?

Yes. Use Full (strict) TLS and configure origin certificates, WebSockets and client IP forwarding where required.

Should upgrades be automatic?

Do not automatically apply major releases. Review migrations, back up data and retain the previous tested image.

What must be backed up?

Back up databases, uploaded files, persistent volumes, configuration, encryption keys and the deployed version together.

VPS or GPU server?

An NVMe VPS fits normal web workloads. Inference, accelerated OCR and video transcoding may require a compatible GPU.

Contact us for deployment

Deploy Paperless-ngx with PostgreSQL, Redis and OCR on Ubuntu, including scanner intake, email consumption, document rules, Nginx TLS, exporter backup, restore and integrity checks.

Explore VPS plansContact us for deployment
Top