Skip to content

About

Self-hosted file management and sharing system, supports multiple storage providers

Resources

Contributing

Security policy

Stars

22 stars

Watchers

0 watching

Forks

 
 

Latest commit

 

History

1,601 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Cloudreve

Community Fork

Self-hosted file management and sharing platform — fully open source, actively maintained.

CI Release GPL-3.0

This is an actively maintained fork of cloudreve/cloudreve. All original work is by the Cloudreve authors (cloudreve.org). This fork exists because upstream development had slowed: it continues the project as a complete, fully open-source distribution — backend, web frontend, desktop clients for Windows/macOS/Linux, and a native Android app — with every "Pro"-class feature reimplemented as free software. See NOTICE for attribution.

Downloads

Server docker run -d -p 5212:5212 -v backend_data:/cloudreve/data ghcr.io/dvorinka/cloudreve:latest — or a standalone binary from Releases
Desktop Windows/macOS/Linux sync client — on-demand files, Explorer share menu, in-app updates: latest desktop release
Android Signed APK (sideload) and AAB (Play): android-v1.1.0

What this fork does differently

  • No Pro tier. The upsell UI (ProChip/ProDialog) is removed. Pro-class capabilities are being reimplemented as open features: share collaboration (upload/edit/preview-only/drop-box shares), OIDC SSO, delegated admin roles — already shipped.
  • Upstream issue backlog triaged and fixed. All 137 migrated upstream issues are tracked in this repo's issue tracker; ~70% are closed. WebDAV mounts/read-only/collision handling, stuck uploads, recycle-bin fail-safes, SQLite WAL, MySQL parseTime, unix-socket migrations, and dozens more.
  • Security hardening on top of upstream's fixes. OAuth public clients no longer ship hardcoded secrets (PKCE only, per RFC 8252); SSRF validation on remote-download URLs; delegated-admin access is audit-logged; auth endpoints are rate-limited; the downloader layer was reviewed for process execution and path-safety.
  • One monorepo. Backend + frontend + desktop + Android live here; no submodules.
  • Tests and CI are real. GitHub Actions run backend tests, frontend typecheck/build, and the desktop matrix (Windows/macOS/Linux) on every PR.

Migrating from upstream Cloudreve

This fork is a drop-in replacement: same schema lineage (4.19.x → 4.20.x), same /cloudreve/data volume layout, same CR_CONF_* env vars, same port 5212. Existing accounts, files, shares, and settings carry over — schema migrations run automatically on first boot. Back up your data volume and database first, as with any upgrade.

Docker Compose — one command (backs up your compose file, swaps the image, restarts):

curl -sSL https://raw.githubusercontent.com/Dvorinka/cloudreve/master/migrate.sh | sh -s -- /path/to/compose/dir

Or edit docker-compose.yml by hand — only the image changes, everything else stays identical to the upstream compose setup:

 services:
   cloudreve:
-    image: cloudreve/cloudreve:v4
+    image: ghcr.io/dvorinka/cloudreve:latest
docker compose pull && docker compose up -d

Plain docker — same flags, new image:

docker stop cloudreve && docker rm cloudreve
docker run -d --name cloudreve --restart unless-stopped \
  -p 5212:5212 -v backend_data:/cloudreve/data \
  ghcr.io/dvorinka/cloudreve:latest

Binary — stop the service, drop in the binary from Releases, start. Your data/ directory (SQLite, uploads, conf.ini) is untouched.

Notes:

  • Tags: latest / slim track the newest release; pin ghcr.io/dvorinka/cloudreve:v4.20.0 for reproducibility. Slim drops aria2, LibreOffice, ffmpeg, and font/media tooling.
  • CR_LICENSE_KEY has no effect — Pro-class features are reimplemented as free features; the key is simply ignored.
  • Migration is supported from upstream ≤ 4.19.x. If you run a newer upstream than our latest release, wait for the next tag rather than downgrading the schema.

Repository layout

.                    Go backend — Gin + ent ORM (SQLite/MySQL/PostgreSQL)
frontend/            Web SPA — React + TypeScript + Vite + MUI (vendored, no submodule)
desktop/             Desktop client — Tauri/Rust sync engine (Windows cfapi, Linux FUSE;
                     macOS hydration on the roadmap)
android/             Native Android client — Kotlin + Jetpack Compose (v1.1.0 shipped)
cli/                 Terminal client — TypeScript CLI on @cloudreve/sdk (vendored from
                     cloudreve/cli; build with `bun install && bun run build`, binary: `cr`)
docs/                Documentation site — VitePress, EN + ZH (vendored from cloudreve/docs;
                     `npm ci && npm run dev`, build with `npm run build`)
.github/workflows/   CI (backend, frontend, desktop matrix) + release pipeline

Features

  • Storage providers: local, remote node, S3-compatible, OneDrive, OSS, COS, Qiniu, Upyun, KS3, OBS.
  • Direct upload/download between client and storage; chunked, resumable, parallel uploads.
  • Remote download: aria2, qBittorrent, and yt-dlp providers, multi-node with per-node settings, group-level concurrent/size quotas.
  • Share links with expiration — plus fork additions: upload-only drop boxes, edit-in-place, preview-only mode, anonymous upload, IP-restricted views.
  • Archive compress/extract, media metadata extraction, metadata/tag search.
  • WebDAV across all storage providers (read-only group enforcement fixed in this fork).
  • SSO: generic OIDC inbound consumer (auth-code + nonce, JWKS-verified, auto-provisioning), OAuth public clients with PKCE, passkeys, TOTP 2FA.
  • Multi-user, multi-group; admin task list with CIDR-capable creator-IP filtering; per-user trash retention; per-group remote-download quotas.
  • Preview: image (progressive thumbnail→full-res), video, audio, ePub, Markdown, diagrams, Office documents (WOPI), 3D models.
  • PWA, dark mode, i18n (en-US, zh-CN, and more), theme customization, custom HTML injection.
  • Desktop client: on-demand placeholder sync (Windows cfapi, Linux FUSE), FileCloud-style share dialog from the Explorer right-click menu, in-app self-updates.
  • Server self-update: admins can upgrade in place from the dashboard.

Build from source

Prereqs: Go ≥ 1.24, Node ≥ 20 + Yarn, (desktop) Rust + platform Tauri deps.

# Frontend
cd frontend && yarn install
NODE_OPTIONS=--max-old-space-size=6144 yarn build   # emits build/ consumed by the Go embed

# Backend (repo root) — the binary serves frontend + API on :5212
go build -o cloudreve .
./cloudreve

Desktop client: see desktop/CLAUDE.md (cargo tauri build, Windows-first; other platforms WIP).

Development

go build ./... && go vet ./... && go test ./...          # backend gate
cd frontend && yarn tsc --noEmit && yarn build           # frontend gate

docker-compose.dev.yml brings up postgres + redis + a source-built backend; yarn dev gives frontend hot reload. PRs land via feature branches — never push to master — and must pass all CI jobs before merge.

Status scorecard

Area State
Backend / frontend Stable — 4.20.x line, all CI green
Upstream issues ~70% of the 137 migrated issues closed; remainder are feature-scale, Pro-surface, or device-bound
Code health desloppify strict score 77.1 (was 18.9); 73 review items dispositioned
Desktop client Shipped for Windows (cfapi sync + Explorer share menu) and Linux (FUSE hydration); in-app updater live
Android client Shipped — v1.1.0 signed APK/AAB on Releases
Pro-free features Share collaboration ✓, OIDC SSO ✓, delegated admins ✓; storage-policy migration, VAS/billing, audit surface in progress

Known limitations and the full plan: ROADMAP.md · issue tracker has honest per-issue status.

Contributing

This project is community-maintained and contributions are genuinely welcome — code, translations, bug reports, ideas, documentation, testing, anything. If something is broken or missing, open an issue — every report gets looked at. If you want to fix it yourself, open a PR against master; CI must pass before merge.

This project only moves forward because people care enough to use it and report what they find. Thank you for being part of that.

Security

Report vulnerabilities privately via GitHub's "Report a vulnerability" on this repo — do not open a public issue. All 16 published upstream GHSAs are patched at our baseline; our own additions are reviewed for SSRF, path traversal, process execution, and session entropy before merge.

Credits

Cloudreve was created by Aaron Liu and the Cloudreve contributors (cloudreve.org). This fork is an independent continuation under the same GPL-3.0 license — attribution, not endorsement. See NOTICE for the full attribution statement.

License

GPL-3.0 — same as upstream. Contributions are licensed identically.

About

Self-hosted file management and sharing system, supports multiple storage providers

Resources

Contributing

Security policy

Stars

22 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages