How to run AdGuard Home on your own server
Blocks ads and trackers for every device on your network. One per server; point your router's DNS at it. Cresdock runs it on a server you own, from a catalogue, with no Docker and no reverse proxy to configure.
What Cresdock does for you with AdGuard Home
Its configuration is written before the container ever starts, so AdGuard Home comes up already set up rather than showing you a blank first-run form.
Given its own web address, with its own login seeded in advance. AdGuard Home can't live under a shared path, and apps like this are reached by clients that don't carry a browser session — so it gets a real password rather than being left open.
AdGuard Home filters what the devices on your network look up, and works entirely on its own — nothing else here reads from it, and it needs nothing else to be useful.
Why run AdGuard Home yourself
Tools like this see everything on your network by design, which is exactly why it is worth them being yours rather than someone else's service.
What kind of server AdGuard Home needs
Barely registers. These run comfortably on the smallest server you can rent, and are usually installed alongside something bigger rather than on their own.
Cresdock itself is undemanding — it runs on a small rented server, an old desktop or a mini PC, on Ubuntu or Debian. Everything it installs shares that machine, so the honest question is not "will this app run" but "how much am I going to put on here in total".
Where to run AdGuard Home
AdGuard Home runs wherever Cresdock runs, and the choice is about the machine, not the app:
- At home, on hardware you already own. A mini PC, an old desktop or a NAS that can run Debian. Cresdock works behind a home router with no port forwarding and no domain, so AdGuard Home is reachable on your own network first and from outside only if you choose.
- On a rented server. A small VPS is enough for most apps and is the usual answer when AdGuard Home should be reachable from anywhere. The setup guide covers the specs and the one-command install.
- Through a provider that runs Cresdock. Hosting companies deploy Cresdock workspaces for their customers, so AdGuard Home can come with a server you rent rather than one you set up — ask your provider, or see how providers offer it.
Installing AdGuard Home
- Put Cresdock on a server
One line on any Ubuntu or Debian machine — a rented VPS, a spare PC, a home server. It sets itself up.
- Pick AdGuard Home from the catalogue
Click Install. The panel pulls the image, writes the configuration, gets a certificate and starts it.
- Open it from your dashboard
Its address and any login details are on its card. Start, stop, update, roll back or remove it from the same place, any time.
What's left for you to do
Cresdock does not pretend to do the parts that are genuinely yours to decide. After it's running:
Sign in with the login on this card
In AdGuard, open Settings → DNS settings → Access settings and add your home IP address under 'Allowed clients'. Do this FIRST — until you do, anyone on the internet can use this as a DNS server
Then set your router's DNS to this server's address, so every device on your network is protected — or set it on one device to try it out first
Check the Query Log after a few minutes: if you see your devices' requests, it is working
Stuck? Docs ↗ in the ⋯ menu opens AdGuard's own guide
What this replaces
Doing it by hand means writing something like this, then keeping it working:
services:
adguard:
image: adguard/adguardhome:v0.107.78
restart: unless-stopped
ports:
- "3000:3000"
environment:
- PUID=1000
- PGID=1000
- TZ=Etc/UTC
volumes:
- ./adguard/config:/config
And that is the easy half. Still to do:
Install a reverse proxy and write a server block for it
Get a TLS certificate and set up automatic renewal
Create the folders above with the right ownership, or it will not start
Point a DNS record at the server, because AdGuard Home cannot run under a shared path
Repeat all of it for the next app, and again on every server rebuild
On Cresdock, AdGuard Home is one click and none of the above exists.
Common questions
Do I need to know Docker to run AdGuard Home?
No. Cresdock installs AdGuard Home in one click from its catalogue: it pulls the image, writes the configuration, gets an HTTPS certificate and starts it. AdGuard Home gets its own web address and its own certificate, because it cannot run under a shared path.
What happens to my AdGuard Home data when it updates?
Cresdock updates the AdGuard Home image and leaves its stored data in place. AdGuard Home keeps its own files in its own folder, which survives an update, a rebuild and a reinstall — and Cresdock never writes into it.
How is AdGuard Home protected if it isn't behind the panel login?
It gets its own password, generated and set before it first starts, shown on its card in your dashboard. Apps end up here when they are reached by programs rather than a web browser, so a shared login can't be used.
Can I run AdGuard Home at home instead of on a VPS?
Yes. Cresdock runs on a mini PC, an old desktop or anything that boots Debian, behind a normal home router with no port forwarding, and AdGuard Home is reachable on your own network first. A rented server is only needed when AdGuard Home must be reachable from anywhere without a VPN.
Can I remove AdGuard Home later?
Yes. Cresdock removes AdGuard Home in one click, and asks whether to keep its configuration for a future reinstall. Nothing else you have installed is affected.
Looking for what AdGuard Home itself can do? That lives in its own documentation — this page is only about running it.
Pairs well with: DuckDNS · LibreSpeed · Audiobookshelf
Before you start: where to rent a server · what it needs to run · Cresdock vs Cloudron