Installing and Configuring Dify on Linux with Docker: Building Production-Ready AI Workflows and RAG

Artificial Intelligence tutorial - IT technology blog
Artificial Intelligence tutorial - IT technology blog

Building an entire RAG pipeline from scratch with LangChain or LlamaIndex is time-consuming, especially when you have to build the UI, manage sessions, and handle access control. After running Dify for over 50 internal team members for six months, I found it to be the best self-hosted LLMOps platform balancing usability and flexibility.

1. Quick Start: Deploy Dify in 5 Minutes

Prepare an Ubuntu 22.04 or 24.04 VPS with docker and docker compose pre-installed. You only need 4 steps:

# 1. Clone the official repository
git clone https://github.com/langgenius/dify.git
cd dify/docker

# 2. Create the environment file from the template
cp .env.example .env

# 3. Pull images and launch all services
docker compose up -d

# 4. Check container status
docker compose ps

Wait about 1–2 minutes for the services to initialize. Once all containers show the Up status, open your browser and navigate to:

http://<YOUR_SERVER_IP>/install

Set up your initial Admin account to complete the setup and access the Studio dashboard directly.

2. Service Architecture and Core Environment Variables

Dify is not a single container. The system consists of a microservices cluster working closely together.

Key Background Services

  • dify-web (Nginx/Frontend): Next.js frontend for users and the admin dashboard.
  • dify-api: Python backend (Flask/Celery) handling business logic, LLM orchestration, and data extraction.
  • dify-sandbox: Isolated sandbox environment to safely run LLM-generated Python/Node.js code.
  • Vector Database: Built-in Weaviate (or Qdrant) by default for storing and querying vector embeddings.
  • PostgreSQL & Redis: Stores metadata, chat history, and manages asynchronous task queues.

Essential Environment Variables (.env) to Change Immediately

Never use default configurations in a public environment. Open the .env file and update the following lines:

# Generate a random secret key for session encryption (run: openssl rand -base64 42)
SECRET_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY789

# Specify your actual domain when using an Nginx reverse proxy
CONSOLE_WEB_URL=https://dify.example.com
CONSOLE_API_URL=https://dify.example.com
SERVICE_API_URL=https://dify.example.com
APP_WEB_URL=https://dify.example.com

# Increase the file upload size limit for the Knowledge Base (default is only 15MB)
UPLOAD_FILE_SIZE_LIMIT=50

3. Configuring Nginx Reverse Proxy and SSL

Exposing port 80 directly to the Internet poses significant security risks. You should place Dify behind an Nginx reverse proxy and configure a Let’s Encrypt SSL certificate.

Here is a standard Nginx configuration file that supports streaming data:

server {
    listen 80;
    server_name dify.example.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl http2;
    server_name dify.example.com;

    ssl_certificate /etc/letsencrypt/live/dify.example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/dify.example.com/privkey.pem;

    client_max_body_size 50M;

    location / {
        proxy_pass http://127.0.0.1:80;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # Buffering must be disabled for smooth real-time token streaming (SSE)
        proxy_buffering off;
        proxy_cache off;
        proxy_read_timeout 300s;
        proxy_http_version 1.1;
        proxy_set_header Connection "";
    }
}

The two directives proxy_buffering off; and proxy_read_timeout 300s; are required. If buffering is enabled, Server-Sent Events (SSE) responses will be held until the bot finishes generating the entire response, ruining the real-time typing experience.

4. Production Best Practices and Battle-Tested Tips

Here are 3 practical lessons to help you avoid out-of-memory errors and system bottlenecks:

1. Hardware Resource Planning

The minimum specification for running Dify smoothly is 4 vCPUs and 8GB RAM. When your team concurrently uploads large 100–300 page PDF documents, Celery workers parsing text will consume memory rapidly. In that case, allocate at least 16GB RAM along with 4GB Swap to prevent Out Of Memory (OOM) crashes.

2. Decouple the Vector Database for Large Datasets

The bundled Weaviate container works well for knowledge bases with fewer than 100,000 chunks. Once your data exceeds this threshold, vector search queries will slow down. You should point the VECTOR_STORE variable to a dedicated Qdrant or Milvus cluster running on a separate server.

3. Automated Data Backups

All databases and uploaded files are stored in the dify/docker/volumes directory. Set up a nightly cron job to dump the database to protect against unexpected failures:

# Dump the entire PostgreSQL database
docker compose exec -T db pg_dumpall -U postgres > /backup/dify_db_$(date +%F).sql

Dify neatly handles UI, access management, and model connectivity out of the box. This allows you to focus entirely on prompt engineering and optimizing business logic for your AI agents.

Share: