Choose a cloud provider and give it access
The New deployment wizard can deploy your app to DigitalOcean, AWS, Google Cloud or Microsoft Azure. This page compares them and explains, for each one, what changes in the wizard and which credentials to create so the deployment gets only the access it needs. For the full walk-through of the wizard, see Deploy your app to a cloud account.
Before you start
- This is meant for team admins.
- You need an account with the provider and permission to create users, service accounts or app registrations in it.
- The prices below are the estimates the wizard showed at the time of writing (30 September 2026). They change with the provider's pricing and your region, so always check the Estimated monthly cost in the wizard itself.
Compare the providers
| DigitalOcean | AWS | Google Cloud | Microsoft Azure | |
|---|---|---|---|---|
| Card badge | Recommended | Flexible | Scalable | Enterprise |
| Deployment model | Droplet, or Droplet + Genesis | EC2 instance | Compute Engine instance | Virtual machine |
| Regions offered | 16 (Frankfurt 1 at first) | 7 (Asia Pacific (Singapore) at first) | 7 (Singapore at first) | 7 (Southeast Asia (Singapore) at first) |
| Default server size | s-2vcpu-4gb, $24.00/mo | t3.medium, $38.54/mo | e2-medium, $28.62/mo | Standard_B2ms, $77.38/mo |
| Server sizes | 6, from $6 to $96/mo | 6, from $19.27 to $174.76/mo | 4, from $28.62 to $114.46/mo | 5, from $38.54 to $175.20/mo |
| Persistent disk | 0.10 USD/GiB, 50 GiB at first | EBS gp3, 0.080 USD/GiB, 50 GiB at first | pd-balanced, 0.17 USD/GiB, 50 GiB at first | Billed by tier; P10 (128 GiB), $19.71/mo at first |
| Database | Managed PostgreSQL, on the same server, or bring your own | On the same server, or bring your own | On the same server, or bring your own | On the same server, or bring your own |
| File uploads (default) | On the data disk; object storage with CDN available | S3 with CloudFront | Cloud Storage with CDN | Blob Storage with CDN |
| Server backups | Optional (+20% of the server price) | Not offered | Not offered | Not offered |
| Default estimate | $29.00/mo total | $42.54/mo minimum | $37.12/mo minimum | $102.09/mo minimum |
| Credentials | API token | Access key ID and secret access key | Project ID and service account JSON key | Subscription, directory (tenant) and application (client) IDs, plus a client secret |
| Server access (step 4) | Key file, your own key or none, plus allowed addresses | Not asked | Key file, your own key or none, plus allowed addresses | SSH public key |
| Extra step 4 fields | — | VPC (optional) and Subnet (optional) | — | SSH public key |
Prices are estimates shown by the wizard at the time of writing. For AWS, Google Cloud and Azure the wizard shows an Estimated minimum, because usage-based items (object storage, CDN traffic, outbound data and, where noted, the container registry) aren't included. Your real bill will be higher. The wizard's Google Cloud prices are typed-in list prices, while the AWS and Azure prices come from their billing systems.
What changes per provider
DigitalOcean
The recommended provider, and the only one with a second deployment model, Managed PostgreSQL and server backups. Deploy your app to a cloud account walks through it step by step.
- Step 2: Droplet (one virtual machine, recommended) or Droplet + Genesis (a second machine with the editor and preview, so the client can change their own app).
- Step 3: 16 regions; server sizes from s-1vcpu-1gb ($6/mo) to s-8vcpu-16gb ($96/mo), with s-2vcpu-4gb recommended; optional Server backups (+20%).
- Step 4: API token, plus Server access (generate a key file, use your own public key, or no shell access, and the addresses allowed to connect). Choose the key now: DigitalOcean can't add one to a droplet later without rebuilding it.
- Managed DNS: DigitalOcean uses the same nameservers for every zone (ns1, ns2 and ns3.digitalocean.com), so the wizard shows them straight away.
Access to create: a personal access token with custom scopes. Select What access does DigitalOcean need? in step 4 for the exact list.
- Give read and write on droplets, block storage, reserved IPs, firewalls, container registry, databases and CDN.
- Include the delete scopes, so a half-finished deployment can be cleaned up.
- Don't miss
database:view_credentials. It's required and easy to overlook. - Set an expiry of 7–14 days.
Steps
Pick the provider
In step 1 of the wizard, Where do you want to deploy?, select the provider's card. Use the comparison above to choose; if you're unsure, DigitalOcean is the cheapest and simplest.
Open the access guide
In step 4, Application & security, select What access does … need? under the provider's credentials. The Access … needs window lists the steps, any warnings and, for AWS, Google Cloud and Azure, the policy or permission list. "Grant exactly this and no more."
Create a dedicated credential
In the provider's own console, create a token, user, service account or app registration used only for this deployment, with just the access the window lists (see the provider's tab above).
Enter the credentials
Back in the wizard, fill in every credential field. They're sent with this request only, never stored, and cleared from the form once the deployment has been created.
Keep or delete the credential afterwards
You need the same kind of credentials again to Remove the deployment later. When you no longer need access, delete the token, IAM user, service account or app registration in the provider's console.
Tip: Give the deployment its own credential rather than reusing an admin account. If anything goes wrong, you can revoke that one credential without affecting anything else in the account.
Deploying creates real, billable resources in the cloud account these credentials belong to. Removing a deployment needs credentials too, so if you delete the IAM user, service account or app registration first, create a new one with the same access before you select Remove.