# Deploy Cerbos on DigitalOcean

Run the Cerbos PDP on DigitalOcean using App Platform, Droplets, or Kubernetes clusters.

[Container documentation](https://docs.cerbos.dev/cerbos/latest/installation/container.html) [Binary installation](https://docs.cerbos.dev/cerbos/latest/installation/binary.html)

### Multiple deployment options

Run Cerbos as a container on App Platform, a binary on Droplets, or within a DigitalOcean Managed Kubernetes cluster

### App Platform support

Deploy the Cerbos container image directly to App Platform for managed scaling and networking

### Stateless scaling

Scale Cerbos horizontally across Droplets or pods with no coordination between instances

## What is Cerbos?

Cerbos is an open-source authorization layer that decouples access control from your application code. It runs as a stateless Policy Decision Point (PDP) that evaluates fine-grained policies at request time.

Authorization policies are written in human-readable YAML supporting [RBAC](/content/features-benefits-and-use-cases/rbac/index.html), [ABAC](/content/features-benefits-and-use-cases/abac/index.html), and [conditional rules](/content/features-benefits-and-use-cases/pbac/index.html). They can be updated, tested, and deployed independently of your application.

Deploying Cerbos via DigitalOcean gives you a production-ready authorization service that scales horizontally and fits naturally into your existing infrastructure and observability stack.

[Policy-as-code Human-readable YAML policies managed like source code](/content/features-benefits-and-use-cases/human-readable-authorization/index.html) [Scalable PDP Stateless policy decision point with sub-millisecond latency](/content/features-benefits-and-use-cases/scalability/index.html) [Centralized management Manage, test, and deploy policies from a single control plane](/content/features-benefits-and-use-cases/centralized-management/index.html)

### How to deploy Cerbos on DigitalOcean

1. **Choose a deployment target**, Select App Platform for managed containers, a Droplet for VM-based deployment, or Managed Kubernetes for orchestrated workloads.
2. **Deploy Cerbos**, Use the official container image or download the static binary depending on your chosen deployment target.
3. **Configure policy loading**, Point Cerbos at a local policy directory, Git repository, or Cerbos Hub for policy storage.
4. **Connect your application**, Use a Cerbos SDK to send authorization checks to the running PDP.

## FAQ

### How do I deploy Cerbos on DigitalOcean?

Deploy the official Cerbos container image to DigitalOcean App Platform, run the binary on a Droplet, or deploy to a DigitalOcean Managed Kubernetes cluster. Configure your policy source and expose the HTTP and gRPC ports.

### Does Cerbos require any external dependencies?

No. Cerbos is self-contained with no database or message queue required. Policies load from the filesystem, a Git repository, or Cerbos Hub.

### Which DigitalOcean service should I use for Cerbos?

App Platform is the simplest option for container deployments. Droplets give full VM control. Managed Kubernetes works well if you already run a cluster for other services.

## Cerbos + DigitalOcean

- Cerbos runs alongside your workloads in DigitalOcean
- No external databases or message queues required
- Built-in metrics, distributed tracing, and structured logging
- Stateless PDP instances scale horizontally
