[{"data":1,"prerenderedAt":656},["ShallowReactive",2],{"\u002Fguides\u002Fsecure-minecraft-server-docker-compose\u002F":3,"guides:en":487,"published-guide-paths":629},{"id":4,"title":5,"author":6,"body":7,"category":439,"date":440,"description":441,"excerpt":442,"extension":443,"faq":444,"featured":454,"featuredOrder":442,"indexOrder":455,"localeGroup":456,"meta":457,"navigation":458,"path":459,"primaryTool":442,"published":458,"related":460,"seo":464,"slug":465,"sources":466,"stem":485,"updated":440,"__hash__":486},"guides\u002Fguides\u002F22.secure-minecraft-server-docker-compose.md","Secure a Minecraft Server with Docker Compose: Practical Hardening","setupmc.com Team",{"type":8,"value":9,"toc":426},"minimark",[10,15,19,38,41,45,57,67,78,89,93,96,104,107,129,132,138,145,149,156,159,163,166,180,192,196,199,202,245,252,256,259,283,290,294,305,308,312,401,405],[11,12,14],"h2",{"id":13},"define-what-needs-protection","Define what needs protection",[16,17,18],"p",{},"A public Minecraft port exposes the server application to the internet. Plugins and mods execute code inside that application. Docker and SSH administer the host beneath it. Treat these as separate boundaries:",[20,21,22,26,29,32,35],"ol",{},[23,24,25],"li",{},"player authentication and allow-listing",[23,27,28],{},"Minecraft\u002FRCON network exposure",[23,30,31],{},"plugin and mod supply chain",[23,33,34],{},"container privileges and host mounts",[23,36,37],{},"host administration, patching, and recovery",[16,39,40],{},"No single Compose flag covers all five.",[11,42,44],{"id":43},"a-hardened-compose-baseline","A hardened Compose baseline",[16,46,47,48,52,53,56],{},"This example assumes ",[49,50,51],"code",{},".\u002Fdata"," is owned by UID\u002FGID ",[49,54,55],{},"1000:1000",":",[58,59,65],"pre",{"className":60,"code":62,"language":63,"meta":64},[61],"language-yaml","services:\n  mc:\n    image: itzg\u002Fminecraft-server:java25\n    restart: unless-stopped\n    user: \"1000:1000\"\n    read_only: true\n    tmpfs:\n      - \u002Ftmp:size=256m\n    cap_drop:\n      - ALL\n    security_opt:\n      - no-new-privileges:true\n    ports:\n      - \"25565:25565\"\n    environment:\n      EULA: \"TRUE\"\n      TYPE: PAPER\n      VERSION: \"26.1.2\"\n      ONLINE_MODE: \"TRUE\"\n      ENABLE_WHITELIST: \"TRUE\"\n      RCON_PASSWORD_FILE: \u002Frun\u002Fsecrets\u002Frcon_password\n    volumes:\n      - .\u002Fdata:\u002Fdata\n    secrets:\n      - rcon_password\n\nsecrets:\n  rcon_password:\n    file: .\u002Frcon_password.secret\n","yaml","",[49,66,62],{"__ignoreMap":64},[16,68,69,70,73,74,77],{},"Create a long random RCON password in ",[49,71,72],{},"rcon_password.secret",", restrict that host file, and exclude it from Git. Compose mounts it read-only at ",[49,75,76],{},"\u002Frun\u002Fsecrets\u002Frcon_password",".",[16,79,80,81,84,85,88],{},"The writable server state stays under ",[49,82,83],{},"\u002Fdata","; the image root filesystem is read-only and ",[49,86,87],{},"\u002Ftmp"," is temporary. The explicit non-root user lets the container drop all Linux capabilities without relying on root during startup.",[11,90,92],{"id":91},"validate-the-security-controls","Validate the security controls",[16,94,95],{},"Before starting, inspect the fully resolved Compose file. Docker treats Compose as trusted host instructions, including nested includes and bind mounts:",[58,97,102],{"className":98,"code":100,"language":101,"meta":64},[99],"language-bash","docker compose config\ndocker compose up -d mc\ndocker compose exec mc id\ndocker port \"$(docker compose ps -q mc)\"\ndocker inspect \"$(docker compose ps -q mc)\" --format 'readonly={{.HostConfig.ReadonlyRootfs}} user={{json .Config.User}} caps={{json .HostConfig.CapDrop}} security={{json .HostConfig.SecurityOpt}}'\n","bash",[49,103,100],{"__ignoreMap":64},[16,105,106],{},"Expected results:",[108,109,110,113,116,119,122],"ul",{},[23,111,112],{},"the process reports UID\u002FGID 1000",[23,114,115],{},"only Minecraft port 25565 is published",[23,117,118],{},"RCON 25575 is not mapped to the host",[23,120,121],{},"root filesystem is read-only",[23,123,124,125,128],{},"all capabilities are dropped and ",[49,126,127],{},"no-new-privileges"," is active",[16,130,131],{},"Then verify the application still works:",[58,133,136],{"className":134,"code":135,"language":101,"meta":64},[99],"docker compose exec mc rcon-cli version\ndocker compose exec mc rcon-cli whitelist add your-minecraft-name\ndocker compose exec mc rcon-cli whitelist list\ndocker compose exec mc rcon-cli save-all flush\n",[49,137,135],{"__ignoreMap":64},[16,139,140,141,144],{},"Replace ",[49,142,143],{},"your-minecraft-name"," with the real username before running the second command.",[11,146,148],{"id":147},"keep-authentication-enabled","Keep authentication enabled",[16,150,151,152,155],{},"Use ",[49,153,154],{},"ONLINE_MODE: \"TRUE\""," for a directly exposed Java server so Mojang\u002FMicrosoft account authentication remains active. A whitelist reduces who can join but does not replace online-mode authentication.",[16,157,158],{},"Offline mode belongs only behind a correctly secured proxy design that performs authentication and prevents direct backend access. It is not a shortcut for public servers.",[11,160,162],{"id":161},"publish-only-required-ports","Publish only required ports",[16,164,165],{},"For a normal Java server, publish TCP 25565. Do not publish these merely because they exist inside the container:",[108,167,168,171,174,177],{},[23,169,170],{},"RCON 25575",[23,172,173],{},"JMX 7091",[23,175,176],{},"arbitrary query or plugin ports",[23,178,179],{},"the Docker socket",[16,181,182,183,186,187,77],{},"Run administrative commands with ",[49,184,185],{},"docker compose exec mc rcon-cli ...",". Apply both the host firewall and, on Hetzner, the Cloud Firewall as described in the ",[188,189,191],"a",{"href":190},"\u002Fguides\u002Fopen-port-25565-minecraft-server-hetzner-linux\u002F","port 25565 guide",[11,193,195],{"id":194},"treat-plugins-mods-and-compose-files-as-code","Treat plugins, mods, and Compose files as code",[16,197,198],{},"Paper warns that plugins receive unrestricted access to the server and machine from the process perspective. Install only signed or checksummed releases from trusted project pages, pin versions, and keep an inventory.",[16,200,201],{},"Review third-party Compose files before running them. Be especially suspicious of:",[108,203,204,209,218,227,230,235],{},[23,205,206],{},[49,207,208],{},"privileged: true",[23,210,211,214,215],{},[49,212,213],{},"network_mode: host"," or ",[49,216,217],{},"pid: host",[23,219,220,223,224],{},[49,221,222],{},"cap_add",", especially ",[49,225,226],{},"SYS_ADMIN",[23,228,229],{},"host devices and broad bind mounts",[23,231,232],{},[49,233,234],{},"\u002Fvar\u002Frun\u002Fdocker.sock",[23,236,237,238,214,241,244],{},"remote ",[49,239,240],{},"include",[49,242,243],{},"extends"," content you did not inspect",[16,246,151,247,251],{},[188,248,250],{"href":249},"\u002Fguides\u002Finstall-paper-plugins-docker-compose\u002F","the Paper plugin runbook"," for a controlled lifecycle.",[11,253,255],{"id":254},"secure-the-host-and-recovery-path","Secure the host and recovery path",[16,257,258],{},"Container hardening cannot repair an exposed SSH account or an unpatched Docker daemon:",[108,260,261,264,267,274,277,280],{},[23,262,263],{},"use SSH keys and a non-root administrative account",[23,265,266],{},"install OS and Docker security updates",[23,268,269,270,273],{},"restrict who belongs to the ",[49,271,272],{},"docker"," group; Docker access is effectively host-root access",[23,275,276],{},"keep the host firewall narrow",[23,278,279],{},"send backups off-host and test restores",[23,281,282],{},"keep secrets out of Git, shell history, and screenshots",[16,284,285,286,77],{},"Backups writable from the same compromised host can be deleted too. Maintain a second failure domain with ",[188,287,289],{"href":288},"\u002Fguides\u002Fset-up-automatic-minecraft-backups-docker-mc-backup\u002F","automatic backups and off-host retention",[11,291,293],{"id":292},"update-without-losing-control","Update without losing control",[16,295,296,297,300,301,77],{},"Pull image security fixes regularly, but do not combine an unattended Minecraft version change with the image update. Pin ",[49,298,299],{},"VERSION",", back up, pull the Java image, and follow the ",[188,302,304],{"href":303},"\u002Fguides\u002Fupdate-minecraft-server-docker-compose-rollback\u002F","safe update and rollback runbook",[16,306,307],{},"If you adopt Docker rootless mode, follow Docker's official prerequisites and re-test port publishing, bind-mount ownership, cgroups, and service startup. Rootless reduces daemon\u002Fruntime privilege but is a host-level migration, not a single Compose option.",[11,309,311],{"id":310},"troubleshooting","Troubleshooting",[313,314,315,331],"table",{},[316,317,318],"thead",{},[319,320,321,325,328],"tr",{},[322,323,324],"th",{},"Symptom",[322,326,327],{},"Likely cause",[322,329,330],{},"Fix",[332,333,334,348,364,379,390],"tbody",{},[319,335,336,342,345],{},[337,338,339,341],"td",{},[49,340,83],{}," permission denied",[337,343,344],{},"Host directory not owned by UID\u002FGID 1000",[337,346,347],{},"Correct ownership; do not add capabilities",[319,349,350,355,358],{},[337,351,352,353],{},"Startup cannot write ",[49,354,87],{},[337,356,357],{},"Missing tmpfs with read-only root",[337,359,360,361,363],{},"Add the ",[49,362,87],{}," tmpfs shown above",[319,365,366,369,372],{},[337,367,368],{},"RCON authentication fails",[337,370,371],{},"Secret missing, unreadable, or changed",[337,373,374,375,378],{},"Grant the secret to ",[49,376,377],{},"mc"," and recreate the service",[319,380,381,384,387],{},[337,382,383],{},"Players cannot join",[337,385,386],{},"Whitelist is empty or firewall is closed",[337,388,389],{},"Add real usernames and verify only port 25565",[319,391,392,395,398],{},[337,393,394],{},"Plugin asks for broad host access",[337,396,397],{},"Unsafe design or untrusted instructions",[337,399,400],{},"Do not add mounts\u002Fprivileges until independently justified",[11,402,404],{"id":403},"next-steps","Next steps",[108,406,407,413,419],{},[23,408,409,410,77],{},"Verify internet exposure with the ",[188,411,412],{"href":190},"Hetzner and Linux firewall guide",[23,414,415,416,77],{},"Prepare recovery with ",[188,417,418],{"href":288},"automatic Docker Minecraft backups",[23,420,421,422,77],{},"Investigate instability with the ",[188,423,425],{"href":424},"\u002Fguides\u002Fminecraft-container-keeps-restarting-docker-compose\u002F","container restart-loop runbook",{"title":64,"searchDepth":427,"depth":427,"links":428},2,[429,430,431,432,433,434,435,436,437,438],{"id":13,"depth":427,"text":14},{"id":43,"depth":427,"text":44},{"id":91,"depth":427,"text":92},{"id":147,"depth":427,"text":148},{"id":161,"depth":427,"text":162},{"id":194,"depth":427,"text":195},{"id":254,"depth":427,"text":255},{"id":292,"depth":427,"text":293},{"id":310,"depth":427,"text":311},{"id":403,"depth":427,"text":404},"security","2026-07-18","Harden an itzg\u002Fminecraft-server deployment with online mode, a whitelist, file-based RCON secrets, a non-root container, reduced capabilities, limited ports, and trusted plugins.",null,"md",[445,448,451],{"question":446,"answer":447},"Should I publish the RCON port for remote administration?","No. Keep 25575 inside the Compose network and run rcon-cli through docker compose exec or use a protected management path. Publishing it increases attack surface unnecessarily.",{"question":449,"answer":450},"Does Docker make untrusted plugins safe?","No. Paper states that plugins have unrestricted access to the server process and its files. Container isolation reduces some host exposure but does not make malicious code trustworthy.",{"question":452,"answer":453},"Can I set ONLINE_MODE to false on a public server?","Do not do that unless a correctly secured proxy architecture performs authentication. For a directly exposed server, keep online mode enabled.",false,"1","minecraft-docker-security-hardening",{},true,"\u002Fguides\u002Fsecure-minecraft-server-docker-compose",[461,462,463],"velocity-modern-forwarding-paper","paper-plugins-docker-compose","docker-mc-backup-setup",{"title":5,"description":441},"secure-minecraft-server-docker-compose",[467,470,473,476,479,482],{"title":468,"url":469},"Docker Compose secrets documentation","https:\u002F\u002Fdocs.docker.com\u002Fcompose\u002Fhow-tos\u002Fuse-secrets\u002F",{"title":471,"url":472},"Docker Compose services reference","https:\u002F\u002Fdocs.docker.com\u002Freference\u002Fcompose-file\u002Fservices\u002F",{"title":474,"url":475},"Docker Compose trust model","https:\u002F\u002Fdocs.docker.com\u002Fcompose\u002Ftrust-model\u002F",{"title":477,"url":478},"Docker rootless mode documentation","https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Fsecurity\u002Frootless\u002F",{"title":480,"url":481},"itzg variables reference","https:\u002F\u002Fdocker-minecraft-server.readthedocs.io\u002Fen\u002Flatest\u002Fvariables\u002F",{"title":483,"url":484},"Paper adding plugins documentation","https:\u002F\u002Fdocs.papermc.io\u002Fpaper\u002Fadding-plugins\u002F","guides\u002F22.secure-minecraft-server-docker-compose","bi7bJuZAVyW90ZhcLlgh9Ga5d3gtA__XWrlkHoEliPU",[488,495,499,505,510,516,521,526,531,536,541,547,548,553,558,563,569,575,581,587,593,599,605,611,617,623],{"path":489,"title":490,"description":491,"excerpt":442,"author":6,"date":492,"category":493,"localeGroup":494},"\u002Fguides\u002Fvelocity-proxy-docker-compose-itzg-mc-proxy","Set Up a Velocity Proxy with Docker Compose and itzg\u002Fmc-proxy","Run Velocity and Paper together with Docker Compose, route players through the proxy, keep backend ports private, and validate the complete connection path.","2026-08-01","getting-started","velocity-proxy-docker-compose",{"path":496,"title":497,"description":498,"excerpt":442,"author":6,"date":492,"category":439,"localeGroup":461},"\u002Fguides\u002Fvelocity-modern-forwarding-paper-docker","Configure Velocity Modern Forwarding with Paper in Docker","Match Velocity and Paper forwarding settings, protect the forwarding secret, block direct backend access, and verify that player identity reaches Paper safely.",{"path":500,"title":501,"description":502,"excerpt":442,"author":6,"date":492,"category":503,"localeGroup":504},"\u002Fguides\u002Fvelocity-proxy-cannot-connect-backend-docker","Velocity Proxy Cannot Connect to a Backend in Docker: A Runbook","Fix Velocity backend connection failures by checking container state, Docker networks, service-name DNS, the container port, Paper readiness, and forwarding separately.","networking","velocity-backend-unreachable-docker",{"path":506,"title":507,"description":508,"excerpt":442,"author":6,"date":492,"category":503,"localeGroup":509},"\u002Fguides\u002Fgeyser-floodgate-velocity-proxy-docker","Run Geyser and Floodgate on a Velocity Proxy with Docker","Add Bedrock crossplay at the Velocity edge, publish UDP 19132 correctly, configure Floodgate authentication, and keep Geyser off the individual backends.","geyser-floodgate-velocity-proxy",{"path":511,"title":512,"description":513,"excerpt":442,"author":6,"date":440,"category":514,"localeGroup":515},"\u002Fguides\u002Fupdate-minecraft-server-docker-compose-rollback","Update a Minecraft Server with Docker Compose and Roll Back Safely","Update an itzg\u002Fminecraft-server deployment without gambling with your world. This runbook covers version pinning, a cold backup, validation, and a real rollback path.","docker-operations","docker-minecraft-update-rollback",{"path":517,"title":518,"description":519,"excerpt":442,"author":6,"date":440,"category":520,"localeGroup":462},"\u002Fguides\u002Finstall-paper-plugins-docker-compose","Install and Update Paper Plugins with Docker Compose","Install Paper plugins reproducibly with itzg\u002Fminecraft-server. Compare a read-only \u002Fplugins source mount with managed Modrinth downloads, then validate every plugin after restart.","mods-plugins",{"path":522,"title":523,"description":524,"excerpt":442,"author":6,"date":440,"category":520,"localeGroup":525},"\u002Fguides\u002Fmodrinth-modpack-itzg-minecraft-server-docker","Run a Modrinth Modpack with itzg\u002Fminecraft-server and Docker Compose","Deploy a server-compatible Modrinth modpack with Docker Compose, pin the pack version, match Java and client requirements, and validate the first start safely.","modrinth-modpack-docker",{"path":527,"title":528,"description":529,"excerpt":442,"author":6,"date":440,"category":514,"localeGroup":530},"\u002Fguides\u002Fmigrate-existing-minecraft-server-to-docker","Migrate an Existing Minecraft Server or World to Docker","Move an existing Minecraft server into itzg\u002Fminecraft-server without mixing migration and upgrades. This runbook covers world-only imports, full data moves, permissions, and rollback.","migrate-minecraft-server-to-docker",{"path":532,"title":533,"description":534,"excerpt":442,"author":6,"date":440,"category":514,"localeGroup":535},"\u002Fguides\u002Fminecraft-container-keeps-restarting-docker-compose","Minecraft Container Keeps Restarting: Diagnose the Docker Compose Loop","Find out why an itzg\u002Fminecraft-server container repeatedly restarts. This runbook preserves the first error, separates exited from unhealthy containers, and fixes the actual cause.","docker-minecraft-restart-loop",{"path":537,"title":538,"description":539,"excerpt":442,"author":6,"date":440,"category":520,"localeGroup":540},"\u002Fguides\u002Fcurseforge-modpack-itzg-minecraft-server-docker","Run a CurseForge Modpack with itzg\u002Fminecraft-server and Docker Compose","Deploy a CurseForge modpack with AUTO_CURSEFORGE, pin its file ID, protect the API key, handle manual downloads, and validate loader and client compatibility.","curseforge-modpack-docker",{"path":542,"title":543,"description":544,"excerpt":442,"author":6,"date":440,"category":545,"localeGroup":546},"\u002Fguides\u002Fminecraft-docker-exit-code-137-oomkilled","Minecraft Docker Exit Code 137: Diagnose OOMKilled Correctly","Exit code 137 means SIGKILL, not automatically an out-of-memory event. Confirm Docker OOMKilled state, compare JVM heap with container limits, and leave non-heap headroom.","performance","minecraft-docker-exit-137-oom",{"path":459,"title":5,"description":441,"excerpt":442,"author":6,"date":440,"category":439,"localeGroup":456},{"path":549,"title":550,"description":551,"excerpt":442,"author":6,"date":440,"category":552,"localeGroup":463},"\u002Fguides\u002Fset-up-automatic-minecraft-backups-docker-mc-backup","Set Up Automatic Minecraft Backups with docker-mc-backup","Back up your Minecraft world automatically with itzg\u002Fmc-backup. This guide shows a safe sidecar setup, retention defaults, and how to validate that backups really work.","backups",{"path":554,"title":555,"description":556,"excerpt":442,"author":6,"date":440,"category":552,"localeGroup":557},"\u002Fguides\u002Frestore-minecraft-world-backup-docker","Restore a Minecraft World from Backup in Docker: A Safe Runbook","A backup is only useful if you can restore it safely. This guide shows how to restore a Minecraft world in Docker, avoid overwriting live data accidentally, and validate the result before reopening the server.","docker-minecraft-restore-runbook",{"path":559,"title":560,"description":561,"excerpt":442,"author":6,"date":440,"category":552,"localeGroup":562},"\u002Fguides\u002Fhetzner-snapshots-minecraft-world-volumes","Why Hetzner Snapshots Do Not Fully Protect Your Minecraft World","Hetzner Cloud Backups and Snapshots are useful, but they do not include attached Volumes. This guide explains the risk, the operational consequences, and the safer backup pattern for Minecraft.","hetzner-snapshots-volumes",{"path":564,"title":565,"description":566,"excerpt":442,"author":6,"date":567,"category":503,"localeGroup":568},"\u002Fguides\u002Fminecraft-crossplay-geyser-floodgate","Set Up Java and Bedrock Crossplay with Geyser and Floodgate","Want Bedrock players on phones or consoles to join your Java server? This guide shows a direct Paper-based Geyser and Floodgate setup without introducing a separate proxy layer.","2026-04-04","geyser-floodgate-crossplay",{"path":570,"title":571,"description":572,"excerpt":442,"author":6,"date":573,"category":493,"localeGroup":574},"\u002Fguides\u002Fpaper-vs-vanilla-vs-fabric-vs-forge","Paper vs Vanilla vs Fabric vs Forge: Which Minecraft Server Software Should You Choose?","Choosing the wrong server software creates avoidable pain later. This guide compares Vanilla, Paper, Fabric, Quilt, Forge, and NeoForge based on plugins, mods, performance, and operational complexity.","2026-04-03","minecraft-server-software-choice",{"path":576,"title":577,"description":578,"excerpt":442,"author":6,"date":579,"category":545,"localeGroup":580},"\u002Fguides\u002Fpaper-view-distance-vs-simulation-distance","View Distance vs Simulation Distance: Safe Starting Values for Paper","Paper exposes view-distance and simulation-distance separately, which makes them one of the safest first levers for performance tuning. This guide explains what each setting changes and which starting values are sensible.","2026-04-02","paper-view-distance-simulation-distance",{"path":582,"title":583,"description":584,"excerpt":442,"author":6,"date":585,"category":545,"localeGroup":586},"\u002Fguides\u002Fspark-profiler-paper-docker","Use Spark Profiler to Find Minecraft Lag in Paper and Docker","Paper bundles Spark starting with 1.21, which makes it the preferred profiler for diagnosing lag. This guide shows how to capture a useful report and how to read the first findings without guesswork.","2026-04-01","spark-profiler-paper-docker",{"path":588,"title":589,"description":590,"excerpt":442,"author":6,"date":591,"category":545,"localeGroup":592},"\u002Fguides\u002Fminecraft-server-lag-tps-mspt-cant-keep-up","Minecraft Server Lag Explained: TPS, MSPT, and 'Can’t Keep Up'","This guide explains what TPS and MSPT actually mean, why “Can’t keep up” appears in the console, and which checks help you separate CPU, chunk, entity, and plugin problems quickly.","2026-03-31","minecraft-lag-tps-mspt",{"path":594,"title":595,"description":596,"excerpt":442,"author":6,"date":597,"category":514,"localeGroup":598},"\u002Fguides\u002Ffix-permission-denied-itzg-docker-minecraft-server","Fix Permission Denied in itzg\u002Fminecraft-server with UID\u002FGID and Bind Mounts","Seeing permission errors in \u002Fdata or files that Docker cannot write? This guide explains why itzg\u002Fminecraft-server defaults to UID 1000:GID 1000 and how to fix ownership safely.","2026-03-09","itzg-permission-denied",{"path":600,"title":601,"description":602,"excerpt":442,"author":6,"date":603,"category":514,"localeGroup":604},"\u002Fguides\u002Fadminister-docker-minecraft-server-rcon-console","Administer a Docker Minecraft Server Safely with RCON and Console Access","Need to op a player, manage the whitelist, or stop the server cleanly? This guide shows how to use RCON and interactive console access with itzg\u002Fminecraft-server without exposing extra risk.","2026-03-08","docker-minecraft-rcon-console",{"path":606,"title":607,"description":608,"excerpt":442,"author":6,"date":609,"category":503,"localeGroup":610},"\u002Fguides\u002Fminecraft-domain-without-port-srv-record","Minecraft Domain Without a Port: How to Set Up an SRV Record","Want players to join via example.com instead of an IP and port? This guide shows how SRV records work for Minecraft Java Edition and how to configure them correctly.","2026-03-07","minecraft-srv-record-domain",{"path":612,"title":613,"description":614,"excerpt":442,"author":6,"date":615,"category":503,"localeGroup":616},"\u002Fguides\u002Fopen-port-25565-minecraft-server-hetzner-linux","How to Open Port 25565 for a Minecraft Server on Hetzner and Linux","Players cannot join even though the container is running? This guide checks Docker port publishing, the Linux firewall path, and the Hetzner Cloud Firewall without relying on misleading UFW assumptions.","2026-03-05","open-port-25565-hetzner-linux",{"path":618,"title":619,"description":620,"excerpt":442,"author":6,"date":621,"category":493,"localeGroup":622},"\u002Fguides\u002Fdetermining-correct-java-version-for-operating-minecraft-server","Determining the Correct Java Version for Operating a Minecraft Server","If you want to set up a Minecraft server, you may encounter an error message related to the Java version when starting the server. In this article, you will learn how to determine the correct Java version for your Minecraft server.","2025-01-31","java-version-minecraft-server",{"path":624,"title":625,"description":626,"excerpt":442,"author":6,"date":627,"category":493,"localeGroup":628},"\u002Fguides\u002Fminecraft-server-with-docker-on-hetzner-cloud","Setting up a Minecraft Server on a Hetzner Cloud Server with Docker Compose","In this article, we will show you how to set up a server for Minecraft: Java Edition on a Hetzner Cloud server. We will go through the steps of creating the cloud server, installing Debian, setting up an SSH key, and configuring Docker Compose for easy server management.","2025-01-28","hetzner-docker-setup",[630,631,632,633,634,635,636,637,638,639,640,641,642,643,644,645,646,647,648,649,650,651,652,653,654,655,624,588,582,576,570,564,511,517,522,527,532,618,537,542,459,489,496,500,506,612,606,600,594,549,554,559],"\u002Fde\u002Fguides\u002Fminecraft-server-with-docker-on-hetzner-cloud","\u002Fde\u002Fguides\u002Fminecraft-server-lag-tps-mspt-cant-keep-up","\u002Fde\u002Fguides\u002Fspark-profiler-paper-docker","\u002Fde\u002Fguides\u002Fpaper-view-distance-vs-simulation-distance","\u002Fde\u002Fguides\u002Fpaper-vs-vanilla-vs-fabric-vs-forge","\u002Fde\u002Fguides\u002Fminecraft-crossplay-geyser-floodgate","\u002Fde\u002Fguides\u002Fupdate-minecraft-server-docker-compose-rollback","\u002Fde\u002Fguides\u002Finstall-paper-plugins-docker-compose","\u002Fde\u002Fguides\u002Fmodrinth-modpack-itzg-minecraft-server-docker","\u002Fde\u002Fguides\u002Fmigrate-existing-minecraft-server-to-docker","\u002Fde\u002Fguides\u002Fminecraft-container-keeps-restarting-docker-compose","\u002Fde\u002Fguides\u002Fdetermining-correct-java-version-for-operating-minecraft-server","\u002Fde\u002Fguides\u002Fcurseforge-modpack-itzg-minecraft-server-docker","\u002Fde\u002Fguides\u002Fminecraft-docker-exit-code-137-oomkilled","\u002Fde\u002Fguides\u002Fsecure-minecraft-server-docker-compose","\u002Fde\u002Fguides\u002Fvelocity-proxy-docker-compose-itzg-mc-proxy","\u002Fde\u002Fguides\u002Fvelocity-modern-forwarding-paper-docker","\u002Fde\u002Fguides\u002Fvelocity-proxy-cannot-connect-backend-docker","\u002Fde\u002Fguides\u002Fgeyser-floodgate-velocity-proxy-docker","\u002Fde\u002Fguides\u002Fopen-port-25565-minecraft-server-hetzner-linux","\u002Fde\u002Fguides\u002Fminecraft-domain-without-port-srv-record","\u002Fde\u002Fguides\u002Fadminister-docker-minecraft-server-rcon-console","\u002Fde\u002Fguides\u002Ffix-permission-denied-itzg-docker-minecraft-server","\u002Fde\u002Fguides\u002Fset-up-automatic-minecraft-backups-docker-mc-backup","\u002Fde\u002Fguides\u002Frestore-minecraft-world-backup-docker","\u002Fde\u002Fguides\u002Fhetzner-snapshots-minecraft-world-volumes",1786636763603]