# Servers

Backends, browser apps, and websites run on a server that you connect to MainPath in one of four ways.

> Source: https://www.mainpath.ai/en/docs/servers/

As soon as a project contains a backend, a browser app, or a homepage, it needs a server; databases and other services of a backend run there as well. Mobile apps without a backend of their own do not need a server.

MainPath installs Docker, Traefik as the reverse proxy, a firewall, and HTTPS, and it creates the access the pipeline uses to deploy. The four options differ in how MainPath gets onto the server.

## The four ways to get a server

| Option | Requirement | Good fit when |
|--------|-------------|---------------|
| [Your own server (SSH)]({{< relref "own-server" >}}) | A Linux server with SSH access | You already have a server or want to decide yourself where it runs |
| [Cloud servers]({{< relref "cloud-servers" >}}) | A Hetzner or Hostinger account with an API token | You want cloud servers of your own without setting them up yourself |
| [Managed server]({{< relref "managed-server" >}}) | An active platform subscription | You do not want an account with a cloud provider |
| [Webspace (FTP/SFTP)]({{< relref "webspace-ftp" >}}) | FTP or SFTP access to an existing webspace | The project consists of homepages only |

The webspace works without Docker because Hugo and Astro produce nothing but static files; as soon as a project contains an app or a backend, this option is no longer offered.

## Creating a server and assigning it to a project

Open **Servers** in the sidebar and click **Add server**. There you choose the type and enter the details described on the respective subpage. Servers belong to the organization, and only administrators create or edit them.

When you create or edit a project, you choose the server it should run on; you can change this assignment later.

Once the server is assigned, the pipeline deploys on every change to `main`, as described under [Git workflow and deployment]({{< relref "git-workflow" >}}). To make the project reachable under a name of your own, continue with the [domain]({{< relref "domain" >}}).

## Monitoring and firewall

When you create or edit a server (not a webspace), two optional settings sit directly under the login details:

**Monitor server** installs the Beszel agent and shows utilisation and network traffic in MainPath. Under **Beszel hub**, **Managed by MainPath (recommended)** stays selected; you store your own hub under [Connections]({{< relref "connections" >}}) and pick it here, see [Beszel: your own hub]({{< relref "beszel-credentials" >}}).

**Configure firewall** restricts SSH (port 22) to the addresses you list. HTTP and HTTPS stay public so websites remain reachable. MainPath and the GitLab runners are always allowed. You add further IPs or CIDR ranges yourself; **Use current IP** takes the address you are connecting from. The same setting is available later in the server details.

## Network tunnels

If the server is not reachable over public SSH, create an SSH, WireGuard, or OpenVPN tunnel under **Network tunnels** and assign it to the server. The host may then be an internal address. Details are under [Network tunnels]({{< relref "network-tunnels" >}}).

