How to set up your own OpenVPN server
Your own VPN — the classic protocol, works on older devices. Cresdock runs it on a server you own, from a catalogue, with no Docker and no reverse proxy to configure.
What Cresdock does for you with OpenVPN
Installed, started and kept running for you — no Dockerfile, no compose file, no reverse-proxy configuration to write.
Reached through your panel login. There is no second password to invent for OpenVPN and no port to open on your firewall.
OpenVPN lets your own devices reach this machine privately, and meets nothing else here.
It and WireGuard cover the same ground, so most people keep the one their devices get on with best.
Why run OpenVPN yourself
A VPN you run yourself has one user — you. There is no shared exit address, no logging policy to take on trust, and no subscription.
What kind of server OpenVPN needs
Almost nothing while idle. The limit is your server's own connection speed, since everything you send through the tunnel goes out through it.
Cresdock itself is undemanding — it runs on a small rented server, an old desktop or a mini PC, on Ubuntu or Debian. Everything it installs shares that machine, so the honest question is not "will this app run" but "how much am I going to put on here in total".
Where to run OpenVPN
OpenVPN runs wherever Cresdock runs, and the choice is about the machine, not the app:
- At home, on hardware you already own. A mini PC, an old desktop or a NAS that can run Debian. Cresdock works behind a home router with no port forwarding and no domain, so OpenVPN is reachable on your own network first and from outside only if you choose.
- On a rented server. A small VPS is enough for most apps and is the usual answer when OpenVPN should be reachable from anywhere. The setup guide covers the specs and the one-command install.
- Through a provider that runs Cresdock. Hosting companies deploy Cresdock workspaces for their customers, so OpenVPN can come with a server you rent rather than one you set up — ask your provider, or see how providers offer it.
Installing OpenVPN
- Put Cresdock on a server
One line on any Ubuntu or Debian machine — a rented VPS, a spare PC, a home server. It sets itself up.
- Pick OpenVPN from the catalogue
Click Install. The panel pulls the image, writes the configuration, gets a certificate and starts it.
- Open it from your dashboard
Its address and any login details are on its card. Start, stop, update, roll back or remove it from the same place, any time.
Common questions
Do I need to know Docker to run OpenVPN?
No. Cresdock installs OpenVPN in one click from its catalogue: it pulls the image, writes the configuration, gets an HTTPS certificate and starts it. OpenVPN runs on the tenant's own private network, reachable through the panel login and nothing else.
What happens to my OpenVPN data when it updates?
Cresdock updates the OpenVPN image and leaves its stored data in place. OpenVPN keeps its own files in its own folder, which survives an update, a rebuild and a reinstall — and Cresdock never writes into it.
Can I run OpenVPN at home instead of on a VPS?
Yes. Cresdock runs on a mini PC, an old desktop or anything that boots Debian, behind a normal home router with no port forwarding, and OpenVPN is reachable on your own network first. A rented server is only needed when OpenVPN must be reachable from anywhere without a VPN.
Can I remove OpenVPN later?
Yes. Cresdock removes OpenVPN in one click, and asks whether to keep its configuration for a future reinstall. Nothing else you have installed is affected.
Looking for what OpenVPN itself can do? That lives in its own documentation — this page is only about running it.
Pairs well with: WireGuard · qBittorrent · Overseerr · how OpenVPN connects to your other apps
Before you start: where to rent a server · what it needs to run · Cresdock vs Cloudron