Paperclip AI Deployment Guide on Oracle Cloud Linux VPS (ARM) via Coolify A developer published a step-by-step guide for self-hosting the open-source Paperclip agent orchestration platform on an Oracle Cloud Infrastructure ARM64 VPS, using Coolify, Docker Compose, Traefik, Let's Encrypt, PostgreSQL 17, and OpenRouter. The walkthrough covers DNS A-record setup, OCI security-list ingress rules for ports 80 and 443, host-level iptables persistence, generating a 32-byte BETTER_AUTH_SECRET, and a Docker Compose stack running the ghcr.io/paperclipai/paperclip image behind Traefik on port 3100. A complete step-by-step guide to deploy and host the open-source Paperclip agent orchestration platform on an Oracle Cloud Infrastructure OCI ARM64 VPS using Coolify, Docker Compose, Traefik, Let's Encrypt SSL, PostgreSQL, and OpenRouter . Security note: Replace all example passwords, secrets, API keys, and domain names with your own values. Never commit secrets or API keys to Git. The deployment consists of the following components: | Component | Technology | |---|---| | Host | Oracle Cloud Infrastructure OCI Ampere A1 ARM64 VPS | | Operating System | Ubuntu | | Deployment/Orchestration | Coolify | | Container Runtime | Docker | | Reverse Proxy | Traefik | | SSL | Let's Encrypt | | Database | PostgreSQL 17 Alpine | | Application | ghcr.io/paperclipai/paperclip:latest | | Domain | https://paperclip.arpann8n.qzz.io | | AI Gateway | OpenRouter API | | Agent Runtime | OpenCode | User Browser | | HTTPS :443 v Oracle Cloud VPS | v Coolify / Traefik | | HTTPS termination + routing v Paperclip :3100 | +--------------------+ | | v v PostgreSQL 17 OpenRouter API | | v v Persistent Data AI Model Provider Before starting, make sure you have: Open your DNS provider dashboard and create an A record . | Setting | Value | |---|---| | Name / Host | paperclip | | Type | A | | Target / Value | Your Oracle Cloud VPS public IPv4 address | | TTL | Automatic or 300 seconds | The resulting hostname should resolve to your VPS, for example: paperclip.example.com This guide uses: https://yourDomain.com From your local machine: nslookup yourDomain.com or: dig yourDomain.com The returned IP should match your Oracle Cloud VPS public IPv4 address. Log in to the Oracle Cloud Console. Navigate to: Networking → Virtual Cloud Networks → Your VCN → Security Lists → Default Security List Under Ingress Rules , click Add Ingress Rules . Create an inbound rule with: | Field | Value | |---|---| | Source CIDR | 0.0.0.0/0 | | Protocol | TCP | | Destination Port Range | 80,443 | | Description | Allow HTTP and HTTPS web traffic | Save the rule. Some Oracle Ubuntu images may have host-level firewall rules that prevent incoming HTTP/HTTPS traffic. Allow ports 80 and 443: Allow HTTPS 443 at the top of the INPUT chain sudo iptables -I INPUT 1 -p tcp --dport 443 -j ACCEPT Allow HTTP 80 at the top of the INPUT chain sudo iptables -I INPUT 1 -p tcp --dport 80 -j ACCEPT Install persistent firewall-rule support: sudo apt-get update sudo apt-get install -y iptables-persistent netfilter-persistent Save the rules: sudo netfilter-persistent save Verify: sudo iptables -L INPUT -n --line-numbers You should see ports 80 and 443 with target ACCEPT , preferably before any broad REJECT or DROP rule. Important: Firewall configuration can differ between Ubuntu images and OCI networking setups. Review existing rules before changing them. Generate a secure 32-byte hexadecimal secret on the VPS: openssl rand -hex 32 Example output: 9b7c0f...64-character-secret...e21a Save the complete 64-character value securely. This value will be used as: BETTER AUTH SECRET Do not publish it or commit it to Git. Open your Coolify Dashboard . Project → + New → Docker Compose Paste the following Docker Compose configuration: version: '3.8' services: db: image: postgres:17-alpine restart: unless-stopped environment: POSTGRES DB: paperclip POSTGRES USER: paperclip POSTGRES PASSWORD: ${POSTGRES PASSWORD:-postgresSecurePass123} volumes: - pgdata:/var/lib/postgresql/data healthcheck: test: "CMD-SHELL", "pg isready -U paperclip -d paperclip" interval: 5s timeout: 5s retries: 5 paperclip: image: ghcr.io/paperclipai/paperclip:latest restart: unless-stopped depends on: db: condition: service healthy environment: NODE ENV: production PORT: "3100" SERVE UI: "true" HOST: "0.0.0.0" PAPERCLIP DEPLOYMENT MODE: "authenticated" PAPERCLIP DEPLOYMENT EXPOSURE: "public" PAPERCLIP PUBLIC URL: "https://yourDomain.com" BETTER AUTH SECRET: "${BETTER AUTH SECRET}" DATABASE URL: "postgres://paperclip:${POSTGRES PASSWORD:-postgresSecurePass123}@db:5432/paperclip" PAPERCLIP SECRETS MASTER KEY FILE: "/paperclip/instances/default/secrets/master.key" OPENROUTER API KEY: "${OPENROUTER API KEY}" volumes: - paperclip-data:/paperclip volumes: pgdata: paperclip-data: If you use a different domain, update: PAPERCLIP PUBLIC URL: "https://yourDomain.com" to your actual public URL. For example: PAPERCLIP PUBLIC URL: "https://yourDomain.com" In Coolify, open the stack's Environment Variables section. Add: POSTGRES PASSWORD=