Deploy your app to a cloud account
The New deployment wizard puts a copy of your app on servers in a cloud account you own, in five steps: provider, deployment model, infrastructure, application and security, then review. This page walks through it with DigitalOcean, the recommended provider. For what changes with AWS, Google Cloud or Microsoft Azure, see Choose a cloud provider and give it access.
This isn't the same as publishing. Publish your app and Deployment steps in detail cover the build Dalfin hosts for you. The wizard here creates servers in your cloud account, and your cloud provider bills you for them.
Deploy app creates real, billable cloud resources in the cloud account whose credentials you enter: servers, disks, addresses and a container registry. Your cloud provider charges you for them until they're removed. To take a deployment down, use Remove in the deployments list and type destroy to confirm (see Deployment Management: all deployments). Use Preview changes first if you want to see what would be created without creating anything.
Before you start
- This wizard is meant for team admins.
- The app needs a published build. A workspace that was only previewed has no build and can't be deployed. See Publish your app.
- You need access to a cloud account and permission to create credentials in it. For DigitalOcean, that's a personal access token (see step 4).
- Have an email address ready for certificate notices, and a hostname (for example app.yourcompany.com) if you want the app on your own domain.
Steps
Open the wizard
Open your app and select More, then Deployment Management. Select New deployment. The wizard opens under Deploy your application: "A guided setup to deploy this generated app".
The Deploy Setup bar shows the five steps: Choose provider, Deployment model, Infrastructure, Application & security and Review & deploy. Finished steps get a check mark. You can go back to a step you've already visited by selecting it, but later steps only open once the earlier ones are complete. Back and Continue › move between steps. If Continue is greyed out, the line Still needed to continue under the step says what's missing; select a name in it to jump to that field. To leave the wizard, select View Previous Deployments →.
Choose the provider
Under Where do you want to deploy?, select a provider card: DigitalOcean (Recommended), AWS (Flexible), Google Cloud (Scalable) or Microsoft Azure (Enterprise). The selected card is highlighted and the line below confirms it, for example Selected provider: DigitalOcean. Select Continue ›.
You can change the provider later, before you deploy. The models, questions, prices and credentials in the next steps all change with it.
Choose the deployment model
Under How should the app run?, choose how DigitalOcean should run the app:
- Droplet (Recommended): one virtual machine running your app. It's the cheapest option and the only one that can run its own database on the same server.
- Droplet + Genesis: two virtual machines in one private network, one for the app and one carrying the editor and preview, so the client can change their own app.
The line below confirms your choice, for example Selected model: …. Select Continue ›.
Set up Compute
Under Configure infrastructure, the resources are split into four tabs: Compute, Database, Storage and Notifications. On Compute, choose what to deploy (the app only, or the editor plus the app), the region (16 regions, Frankfurt 1 at first), the server size and the Persistent disk size in GiB.
At the time of writing (30 September 2026), the wizard offered DigitalOcean server sizes from s-1vcpu-1gb at about $6 a month up to s-8vcpu-16gb at about $96 a month, with s-2vcpu-4gb recommended. The Estimated monthly cost panel updates as you change anything. For example, it showed $29.00/mo for s-2vcpu-4gb with a 50 GiB disk in Frankfurt 1. These are the wizard's own estimates and can change.
Choose the database
Select the Database tab. Choose Managed PostgreSQL, on the same server (recommended: cheapest, but with no failover), or bring your own database.
Choose storage and backups
Select the Storage tab. Choose where file uploads go: on the data disk (recommended), object storage with a CDN, or not needed. Tick Server backups (+20%) if you want DigitalOcean to back up the server, which adds 20% to the server price.
Add the certificate email
Select the Notifications tab and enter the Certificate notification email. It's required: Let's Encrypt uses it to warn about certificates that are about to expire.
A tab with something still missing shows a count, for example Notifications 1, and the line Still needed before you can continue names the field and its tab. Next in this step lists the other tabs with a summary of what you chose; select one to open it. When nothing is missing, select Continue ›.
Check the application details
Under Confirm application & security details, the Application details section shows what's being deployed:
- Workspace / run id (required) is filled in from the app you're in. It also decides which database the app's data is copied from.
- Below it, the wizard shows the build it found, for example "Deploying … build …". If it says no image has been published for this run, publish the app first.
- Tenant database shows where the app's data lives today. The data is copied from there.
- Currently served by Dalfin at lists the app's Dalfin addresses. These stay with Dalfin: a deployment into your own cloud needs a domain you control.
Set the address and DNS
In Address & DNS, enter the Hostname the app should answer on, for example app.client.com. Separate several names with commas. The server's web address and HTTPS certificate are built from it. Without a hostname, the app answers on the server's IP address over plain HTTP.
Then choose a Domain option:
- No domain yet — reach it on the IP
- We manage DNS in the client's cloud account: also enter the Subdomain to delegate. The client adds NS records for that subdomain at their registrar, pointing at DigitalOcean's nameservers (ns1, ns2 and ns3.digitalocean.com), and the DNS records are then created for them. Never delegate the root domain: that would take the domain's email with it.
- The client manages their own DNS records: the records to add are listed in the deployment's Information once it's created.
Enter the DigitalOcean API token
In DigitalOcean credentials, enter the API token. The certificate email from the Notifications tab is shown here too. Select What access does DigitalOcean need? to see exactly which scopes to give the token (summarised in Choose a cloud provider and give it access).
As Secure by default explains, the token is sent with this request only, is never stored by the browser or the server, and is cleared from the form once a deployment has been created.
Choose server access
In Server access, choose how you log in to the server: generate a key file (recommended), use your own public key, or no shell access. Then list the addresses (CIDRs) allowed to connect. Leave them blank to keep the SSH port (22) closed. Decide now: DigitalOcean can't add a key to a droplet later without rebuilding it. Select Continue ›.
Review the deployment
Under Review and deploy, check the Ready to deploy banner (provider • model • region), the Deployment summary (provider, model, build, address, compute, disk, database, storage and workspace) and the Estimated monthly cost. Before you deploy reminds you that the final cost depends on the provider's pricing, the region and usage, and that HTTPS is set up automatically once your domain is connected.
Preview the changes (optional)
Select Preview changes. The wizard runs a dry run with your credentials and opens Preview changes, listing everything you configured and, once the plan is ready, what Will be created, Will be changed and Will be removed. Nothing is created. The dry run is saved and appears in the deployments list with the status Planned. Select Close, or Deploy app to go ahead from here.
Deploy the app
Select Deploy app. The wizard creates the resources in your cloud account and takes you back to All deployments, where the new deployment appears and its status moves from Pending to Deploying to Live. Open its Logs to follow along.
Tip: Live means the cloud resources exist, not that the app is ready. The server still has to start, load the app and get its certificate. Open the deployment's Information and select Check again to see how far it has got, and which DNS records still need adding.
If you chose to generate a key file, download it with Server key from the deployment's row menu or Information. Dalfin keeps no other copy.