This is an actively maintained fork of cloudreve/cloudreve. All original work is by the Cloudreve authors (cloudreve.org). This fork exists because upstream development had slowed: it continues the project as a complete, fully open-source distribution — backend, web frontend, desktop clients for Windows/macOS/Linux, and a native Android app — with every "Pro"-class feature reimplemented as free software. See NOTICE for attribution.
| Server | docker run -d -p 5212:5212 -v backend_data:/cloudreve/data ghcr.io/dvorinka/cloudreve:latest — or a standalone binary from Releases |
| Desktop | Windows/macOS/Linux sync client — on-demand files, Explorer share menu, in-app updates: latest desktop release |
| Android | Signed APK (sideload) and AAB (Play): android-v1.1.0 |
- No Pro tier. The upsell UI (
ProChip/ProDialog) is removed. Pro-class capabilities are being reimplemented as open features: share collaboration (upload/edit/preview-only/drop-box shares), OIDC SSO, delegated admin roles — already shipped. - Upstream issue backlog triaged and fixed. All 137 migrated upstream issues are tracked in this
repo's issue tracker; ~70% are closed. WebDAV mounts/read-only/collision handling, stuck uploads,
recycle-bin fail-safes, SQLite WAL, MySQL
parseTime, unix-socket migrations, and dozens more. - Security hardening on top of upstream's fixes. OAuth public clients no longer ship hardcoded secrets (PKCE only, per RFC 8252); SSRF validation on remote-download URLs; delegated-admin access is audit-logged; auth endpoints are rate-limited; the downloader layer was reviewed for process execution and path-safety.
- One monorepo. Backend + frontend + desktop + Android live here; no submodules.
- Tests and CI are real. GitHub Actions run backend tests, frontend typecheck/build, and the desktop matrix (Windows/macOS/Linux) on every PR.
This fork is a drop-in replacement: same schema lineage (4.19.x → 4.20.x), same /cloudreve/data
volume layout, same CR_CONF_* env vars, same port 5212. Existing accounts, files, shares, and settings
carry over — schema migrations run automatically on first boot. Back up your data volume and
database first, as with any upgrade.
Docker Compose — one command (backs up your compose file, swaps the image, restarts):
curl -sSL https://raw.githubusercontent.com/Dvorinka/cloudreve/master/migrate.sh | sh -s -- /path/to/compose/dirOr edit docker-compose.yml by hand — only the image changes, everything else stays identical to
the upstream compose setup:
services:
cloudreve:
- image: cloudreve/cloudreve:v4
+ image: ghcr.io/dvorinka/cloudreve:latestdocker compose pull && docker compose up -dPlain docker — same flags, new image:
docker stop cloudreve && docker rm cloudreve
docker run -d --name cloudreve --restart unless-stopped \
-p 5212:5212 -v backend_data:/cloudreve/data \
ghcr.io/dvorinka/cloudreve:latestBinary — stop the service, drop in the binary from
Releases, start. Your data/ directory
(SQLite, uploads, conf.ini) is untouched.
Notes:
- Tags:
latest/slimtrack the newest release; pinghcr.io/dvorinka/cloudreve:v4.20.0for reproducibility. Slim drops aria2, LibreOffice, ffmpeg, and font/media tooling. CR_LICENSE_KEYhas no effect — Pro-class features are reimplemented as free features; the key is simply ignored.- Migration is supported from upstream ≤ 4.19.x. If you run a newer upstream than our latest release, wait for the next tag rather than downgrading the schema.
. Go backend — Gin + ent ORM (SQLite/MySQL/PostgreSQL)
frontend/ Web SPA — React + TypeScript + Vite + MUI (vendored, no submodule)
desktop/ Desktop client — Tauri/Rust sync engine (Windows cfapi, Linux FUSE;
macOS hydration on the roadmap)
android/ Native Android client — Kotlin + Jetpack Compose (v1.1.0 shipped)
cli/ Terminal client — TypeScript CLI on @cloudreve/sdk (vendored from
cloudreve/cli; build with `bun install && bun run build`, binary: `cr`)
docs/ Documentation site — VitePress, EN + ZH (vendored from cloudreve/docs;
`npm ci && npm run dev`, build with `npm run build`)
.github/workflows/ CI (backend, frontend, desktop matrix) + release pipeline
- Storage providers: local, remote node, S3-compatible, OneDrive, OSS, COS, Qiniu, Upyun, KS3, OBS.
- Direct upload/download between client and storage; chunked, resumable, parallel uploads.
- Remote download: aria2, qBittorrent, and yt-dlp providers, multi-node with per-node settings, group-level concurrent/size quotas.
- Share links with expiration — plus fork additions: upload-only drop boxes, edit-in-place, preview-only mode, anonymous upload, IP-restricted views.
- Archive compress/extract, media metadata extraction, metadata/tag search.
- WebDAV across all storage providers (read-only group enforcement fixed in this fork).
- SSO: generic OIDC inbound consumer (auth-code + nonce, JWKS-verified, auto-provisioning), OAuth public clients with PKCE, passkeys, TOTP 2FA.
- Multi-user, multi-group; admin task list with CIDR-capable creator-IP filtering; per-user trash retention; per-group remote-download quotas.
- Preview: image (progressive thumbnail→full-res), video, audio, ePub, Markdown, diagrams, Office documents (WOPI), 3D models.
- PWA, dark mode, i18n (en-US, zh-CN, and more), theme customization, custom HTML injection.
- Desktop client: on-demand placeholder sync (Windows cfapi, Linux FUSE), FileCloud-style share dialog from the Explorer right-click menu, in-app self-updates.
- Server self-update: admins can upgrade in place from the dashboard.
Prereqs: Go ≥ 1.24, Node ≥ 20 + Yarn, (desktop) Rust + platform Tauri deps.
# Frontend
cd frontend && yarn install
NODE_OPTIONS=--max-old-space-size=6144 yarn build # emits build/ consumed by the Go embed
# Backend (repo root) — the binary serves frontend + API on :5212
go build -o cloudreve .
./cloudreveDesktop client: see desktop/CLAUDE.md (cargo tauri build, Windows-first; other platforms WIP).
go build ./... && go vet ./... && go test ./... # backend gate
cd frontend && yarn tsc --noEmit && yarn build # frontend gatedocker-compose.dev.yml brings up postgres + redis + a source-built backend; yarn dev gives
frontend hot reload. PRs land via feature branches — never push to master — and must pass all CI
jobs before merge.
| Area | State |
|---|---|
| Backend / frontend | Stable — 4.20.x line, all CI green |
| Upstream issues | ~70% of the 137 migrated issues closed; remainder are feature-scale, Pro-surface, or device-bound |
| Code health | desloppify strict score 77.1 (was 18.9); 73 review items dispositioned |
| Desktop client | Shipped for Windows (cfapi sync + Explorer share menu) and Linux (FUSE hydration); in-app updater live |
| Android client | Shipped — v1.1.0 signed APK/AAB on Releases |
| Pro-free features | Share collaboration ✓, OIDC SSO ✓, delegated admins ✓; storage-policy migration, VAS/billing, audit surface in progress |
Known limitations and the full plan: ROADMAP.md · issue tracker has honest per-issue status.
This project is community-maintained and contributions are genuinely welcome — code, translations,
bug reports, ideas, documentation, testing, anything. If something is broken or missing,
open an issue — every report gets looked at.
If you want to fix it yourself, open a PR against master; CI must pass before merge.
This project only moves forward because people care enough to use it and report what they find. Thank you for being part of that.
Report vulnerabilities privately via GitHub's "Report a vulnerability" on this repo — do not open a public issue. All 16 published upstream GHSAs are patched at our baseline; our own additions are reviewed for SSRF, path traversal, process execution, and session entropy before merge.
Cloudreve was created by Aaron Liu and the Cloudreve contributors (cloudreve.org). This fork is an independent continuation under the same GPL-3.0 license — attribution, not endorsement. See NOTICE for the full attribution statement.
GPL-3.0 — same as upstream. Contributions are licensed identically.