The Impreza catalog brings application deployment and ongoing operations into My Apps. Choose a supported app and a server with the Impreza Agent online, configure its required settings and follow the deployment status. Installation time depends on the app, image downloads and available resources.
What you get
- A curated catalog of ready-to-run apps for websites, files, automation and other workloads
- Automatic HTTPS for eligible web apps through Let’s Encrypt
- An optional Tor mirror for most web apps, published in the same install
- A custom domain or a free subdomain on imprezaapps.com for eligible web apps
What is in the catalog
- Security and privacy: Vaultwarden (passwords), SearXNG (private search), PrivateBin (encrypted pastes)
- Productivity and files: Nextcloud, Memos, MinIO (S3-compatible storage)
- Communication: Matrix (Synapse), Mattermost, Evolution API
- Automation: n8n, Activepieces
- AI: Ollama, Open WebUI, OpenClaw
- Developer tools: Gitea, Uptime Kuma
- Media: Jellyfin, PhotoPrism
- Sites and shops: WordPress, PrestaShop
- Databases: PostgreSQL, MySQL, MariaDB, MongoDB, Redis
- Remote access: RustDesk
Install it
Browse the catalog
Open the catalog in your clientarea, or ask your AI assistant to list it. Each entry states what it needs: CPU cores, memory and disk.
Check the app fits the server
Compare the catalog requirements with the available CPU, memory and disk on your VPS. Leave room for data growth and recovery operations. Available resources are a current reading, not a reservation. A server running a traditional hosting panel follows a different workflow from the agent app catalog.
Choose a hostname
For an eligible web app, point a custom domain at it or take a free imprezaapps.com subdomain. HTTPS is issued automatically for that web route. Most web apps can also publish a .onion address. Databases and RustDesk use their own access and transport settings instead.
Install and save the credentials
Review the settings required by the selected app, confirm installation and follow its status. Save any generated or supplied credentials in your password manager. Check that the app is ready and access is configured before sharing its address; account setup differs by application.
The database entries listen on raw ports such as 5432, 3306, 27017 and 6379, and those are scanned continuously across the whole internet. Keep database ports private even when transport encryption is enabled. These entries do not use the web-app HTTPS certificate or Tor mirror; each database deployment has its own TLS certificate. New Redis installs require TLS by default, while existing installs keep their previous setting. See offshore database hosting for connection and recovery limits. RustDesk also follows a separate access flow.
On a compatible server, new web deployments start with Impreza Shield’s standard profile, which observes requests without blocking them. In the app’s Shield card you can review aggregate counters and choose hardened or max; WAF blocking needs a separate confirmation after you check for false positives. Existing deployments do not switch profiles automatically. See the Shield guide for supported agents and limits.
Most catalog apps can publish a Tor v3 .onion address alongside the public hostname, or instead of it. A password manager or a private search instance reachable only over Tor is a genuinely stronger setup. See how to publish a Tor .onion site.
You choose when to update and what to authorize. Use the app inspection and maintenance tools to investigate the app, and schedule supported recurring tasks when needed. Back up important data and test recovery before depending on an app in production.
Check connections to services on the server
If the app connects to a database, cache or other service running directly on the host, check the Agent version and firewall policy. Agent 0.6.25 lets the host firewall decide first and preserves access to published application ports. Older agents 0.6.21–0.6.24 blocked new container-to-host connections before the host’s own allow rules. Update those servers explicitly and follow container-to-host connection guidance; keep database ports private rather than opening them broadly.
Protect the app after installation
Use the app backup and restore guide for supported data stored in the Impreza S3 service associated with your account. Check that storage is available, inspect the app’s backup schedule and wait for a completed result. A requested or running backup is not yet a recovery point.
These backups cover the application data included by the deployment’s backup job. They are different from a whole-VPS backup: see how to manage your VPS from chat. A custom Compose stack can have storage outside the paths covered by that job, so check the coverage before relying on it.
Restoring a completed backup changes the app’s current data and interrupts service. With agent 0.6.25, file restoration verifies the archive before stopping the app for the data exchange, keeps it stopped while a restore job may still be writing, and recovers the previous data if the exchange fails. Existing servers need an explicit agent update. Replaced data is kept aside, using disk space until explicitly removed. Follow the app backup guide for coverage, maintenance planning and recovery checks.
Move to another server when needed
Follow the app migration guide to prepare a compatible destination, then restore the app backup into it. The source remains in place while you check the destination. Plan traffic changes and handle data written after the backup before retiring the source. This is a migration workflow, not a promise of uninterrupted service or automatic synchronization.
Start now
Spin up an offshore VPS and install from the catalog, or let your assistant do it from the chat after you connect with OAuth.









