Learn how to install and configure Zulip on AWS with our step-by-step deployment guide. This resource walks you through provisioning your cloud environment, deploying Zulip securely, creating your first organization, and operating it reliably in a self-hosted AWS environment. Whether you're moving your team off a hosted chat subscription or want your conversations to stay inside your own AWS account, this guide will help you set up and run Zulip efficiently in the cloud.

Zulip takes a different approach from most team chat tools. Every message belongs to a channel and a topic, so conversations stay threaded and easy to catch up on. If you are still weighing your options, our Rocket.Chat vs Mattermost comparison and Mattermost vs Slack breakdown cover the other popular self-hosted choices. Let's get started deploying Zulip on AWS.

Prerequisites

Before you get started with the Zulip AMI, ensure you have the following prerequisites:

  • Basic knowledge of AWS services, including EC2 instances and CloudFormation.
  • An active AWS account with appropriate permissions.
  • SMTP credentials (host, port, username and password) so Zulip can send sign-up and invitation emails.
  • If you encounter a vCPU quota error when launching the stack, follow https://meetrix.io/blogs/increase-aws-vcpu-quota/ to increase your vCPU limit.

Launching the AMI

Step 1: Find and Select the Zulip AMI

  1. Log in to your AWS Management Console.
  2. Navigate to 'Zulip' in AWS Marketplace.

Step 2: Initial Setup & Configuration

  1. Click the "Continue to Subscribe" button.
  2. After subscribing, accept the terms and click "Accept Terms".
  3. Wait a few minutes until processing completes, then click "Continue to Configuration".
  4. Select "CloudFormation script to deploy Zulip" as the fulfillment option and choose your region. Click "Continue to Launch".
  5. From the "Choose Action" dropdown, select "Launch CloudFormation" and click "Launch".

Create CloudFormation Stack

Step 1: Create a stack

  1. Ensure the "Template is ready" option is selected under "Prepare template".
  2. Click "Next".

Step 2: Specify stack options

  1. Provide a unique "Stack name".
  2. Enter the "AdminEmail" used for SSL certificate generation.
  3. Enter a value for "DeploymentName".
  4. Provide a public domain for "DomainName". Zulip will automatically try to set up SSL if the domain is hosted on Route53. If unsuccessful, you must set up SSL manually.
  5. Enter your SMTP server for "EmailHost" (for example, smtp.gmail.com).
  6. Enter the SMTP password for "EmailHostPassword". For Gmail, use an app password rather than your account password.
  7. Enter the SMTP username for "EmailHostUser", usually the full sending email address.
  8. Enter the SMTP port for "EmailPort" (587 for STARTTLS).
  9. Choose an instance type "InstanceType" (Recommended: t3a.small for small teams, larger as usage grows).
  10. Select your preferred "KeyName".
  11. Provide an S3 bucket name for "S3Bucket", used for storing backups.
  12. Set "SSHLocation" to 0.0.0.0/0.
  13. Keep "SubnetCidrBlock" as 10.0.0.0/24.
  14. Keep "VpcCidrBlock" as 10.0.0.0/16.
  15. Click "Next".

Step 3: Configure stack options

  1. Choose "Roll back all stack resources" and "Delete all newly created resources" under "Stack failure options".
  2. Click "Next".

Step 4: Review

Review and verify the details you've entered. Here's an example of a completed set of stack parameters:

CloudFormation Parameters tab listing the 14 Zulip stack parameters including AdminEmail, DomainName, EmailHost, EmailPort 587, InstanceType t3a.small, KeyName, and S3Bucket
  1. Tick "I acknowledge that AWS CloudFormation might create IAM resources with custom names".
  2. Click "Submit".
AWS CloudFormation capabilities notice for AWS::IAM::Policy and AWS::IAM::Role with the IAM acknowledgement checkbox ticked

Afterward, you'll be directed to the CloudFormation stacks page. Please wait for 5-10 minutes until the stack has been successfully created.

Zulip CloudFormation stack Outputs tab showing DashboardUrl, DashboardUrlIp, and PublicIp

Update DNS

Step 1: Copy IP Address

Copy the public IP labeled "PublicIp" in the "Outputs" tab.

PublicIp value highlighted in the Zulip CloudFormation Outputs tab

Step 2: Update DNS

  1. Go to AWS Route 53 and navigate to "Hosted Zones".
  2. Click Create record.
  3. Add a record name and paste the copied PublicIp into the value textbox.
  4. Click "Save".
Route 53 quick create record form with an A record named zulip pointing at the instance public IP

Access Zulip

Access Zulip using the "DashboardUrl" or "DashboardUrlIp" provided in the Outputs tab.

Note

If you receive a "502 Bad Gateway" error, wait approximately 5 minutes and refresh the page. The application may still be initializing.
502 Bad Gateway error page shown by nginx while Zulip is still starting up

A fresh Zulip server has no organization yet, so the first page you see is "No organization found". This is expected.

Zulip No organization found page on a freshly deployed server

Clicking "New organization" will not help yet either. Zulip requires a secure, single-use link before anyone can create an organization on the server.

Zulip Organization creation link required page at the /new/ URL

Step 1: Log in to the server

  1. Open the terminal and go to the directory where your private key is located.
  2. Run the SSH command below.
  3. Type "yes" and press Enter to confirm.
ssh -i <your key name> ubuntu@<Public IP address>
Logging into the Zulip server via SSH and confirming the host key fingerprint

Step 2: Generate an organization creation link

Run Zulip's management command to generate the link:

sudo -u zulip /home/zulip/deployments/current/manage.py generate_realm_creation_link
Terminal output of generate_realm_creation_link showing a secure single-use link to register a new Zulip organization

Step 3: Create your organization

Open the link in your browser. Enter the Organization name, choose the Organization type and language, enter your email, and click "Create organization". Zulip sends a confirmation email to finish creating your admin account, which is why the SMTP parameters need to be correct.

Create a new Zulip organization form with organization name, type, language, URL and email fields

The link works once. If you need another organization or the link expires, run the command again. If your team already uses a central identity provider, Zulip also supports SAML and OpenID Connect login - our Authentik developer guide shows how to run one on AWS.

Generate SSL Manually

Zulip will automatically try to set up SSL when a Route53-hosted domain is provided. If it fails, follow these steps to generate SSL manually.

Step 1: Copy IP Address

Follow the Update DNS steps above, if not already done, and copy the Public IP indicated as "PublicIp" in the "Outputs" tab.

Step 2: Log in to the server

ssh -i <your key name> ubuntu@<Public IP address>
SSH session to the Zulip server with the host key confirmation prompt answered yes

Step 3: Generate SSL

Run Zulip's certbot setup script, replacing the admin email and domain with your own:

sudo /home/zulip/deployments/current/scripts/setup/setup-certbot --email=<admin-email> --agree-tos <your-domain>

Check Server Logs

Step 1: Log in to the server

ssh -i <your key name> ubuntu@<Public IP address>

Step 2: Check the logs

Check that Zulip's services are running, then read the server and error logs:

sudo supervisorctl status

sudo tail -n 100 /var/log/zulip/server.log

sudo tail -n 100 /var/log/zulip/errors.log

Shutting Down Zulip

  1. In CloudFormation, click the link labeled "Instance" in the "Resources" tab to open the EC2 instance.
  2. Stop the Zulip instance from the Instance state dropdown. You can restart it later as needed.
CloudFormation Resources tab with the EC2 Instance physical ID link highlighted Stopping the Zulip EC2 instance from the instance state dropdown

Remove Zulip

Delete the CloudFormation stack from the AWS Management Console under "CloudFormation Stacks" by clicking "Delete".

Upgrades

When a new version is available in AWS Marketplace, remove the previous deployment after backing up necessary server data, and relaunch with the new version.

Troubleshoot

  1. If you face vCPU quota limits, request an increase: How to increase AWS quota.
CloudFormation events showing CREATE_FAILED with a VcpuLimitExceeded error
  1. If you face insufficient capacity errors while creating the stack, try another region or time.
CloudFormation events showing CREATE_FAILED with an InsufficientInstanceCapacity error
  1. If new users never receive their confirmation or invitation emails, check the EmailHost, EmailPort, EmailHostUser and EmailHostPassword values, then look for SMTP errors in /var/log/zulip/errors.log.

Check whether the instance storage is full - uploaded files and message history grow steadily on an active Zulip server.

  • Log into the server and run:
df -h
Checking disk usage on the Zulip server with df -h
  • If the root volume is between 90-100%, resize the EBS volume (per AWS docs), then reboot and restart the service.

Conclusion

The Meetrix Zulip Deployment Guide helps you bring a self-hosted, topic-based team chat into your AWS environment. Whether you're a DevOps engineer, team lead, or IT administrator, this guide gives you step-by-step instructions for a secure and reliable setup. For other self-hosted tools on AWS, see our Rocket.Chat developer guide, our Zammad help desk guide, or the roundup of collaboration tools on AWS Marketplace.

Technical Support

Reach out to Meetrix Support (aws@meetrix.io) for assistance with Zulip issues.

For questions about Zulip itself rather than the AWS deployment, the Zulip server documentation, the Zulip GitHub repository, and zulip.com are the best starting points.

Frequently Asked Questions

What is Zulip?

Zulip is an open-source team chat application. Its conversations are organized into channels and topics, so each discussion stays in its own thread and people can catch up on what matters to them without scrolling through one long stream of messages.

What are the prerequisites for installing Zulip on AWS?

You need basic knowledge of AWS services (EC2, CloudFormation), an active AWS account with appropriate permissions, a sufficient vCPU limit to launch the required instance type, and SMTP credentials so Zulip can send invitation and sign-up emails.

Which instance type is recommended?

t3a.small is a workable baseline for a small team. Move up to t3a.medium or larger as your user count and message history grow.

Why does my Zulip URL say "No organization found"?

A fresh Zulip server has no organization yet, and it will not let anyone create one without a secure link. SSH into the instance, run the generate_realm_creation_link command, and open the link it prints to create your first organization.

Why do I need to provide SMTP settings?

Zulip sends email for account confirmation, invitations, and password resets. Without working SMTP settings, new users cannot finish signing up. If you use Gmail, create an app password for the EmailHostPassword field instead of using your normal account password.

What if the automatic SSL setup fails?

Zulip tries to provision SSL automatically when the domain is hosted on Route53. If that fails, SSH into the instance and run Zulip's setup-certbot script manually - see the Generate SSL Manually section.

How do I get technical support?

Reach out to Meetrix Support at aws@meetrix.io for assistance with Zulip issues.

Ready to Deploy Your Own Zulip Server?

Get started in minutes with our pre-configured AMI and give your team threaded, topic-based chat on infrastructure you control.

Deploy Zulip from AWS Marketplace