No description
  • Go 63.1%
  • Vue 17.6%
  • TypeScript 12.5%
  • CSS 6.3%
  • Dockerfile 0.2%
  • Other 0.2%
Find a file
nhpro 18829bfb8f
All checks were successful
CI / backend (push) Successful in 35s
CI / frontend (push) Successful in 52s
Release / release (push) Successful in 2m0s
ci(release): publish the container image for arm64 too
The release image was amd64 only, though GoReleaser already compiled the
linux/arm64 binary. Move from the deprecated `dockers` to `dockers_v2`,
which builds both platforms from the prebuilt binaries in one buildx
push and publishes a single multi-arch tag; QEMU only emulates the
runtime layer's `apk add`. SBOM and provenance attestations stay off so
the index lists exactly linux/amd64 and linux/arm64.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-07 10:49:02 +02:00
.gitea/workflows ci(release): publish the container image for arm64 too 2026-10-07 10:49:02 +02:00
application feat(archive): read bzip2, xz and zstd, and choose the format on creation 2026-09-17 11:38:57 +02:00
cmd fix(queue): bound the job map, add graceful shutdown and panic recovery 2026-07-27 12:43:26 +02:00
conf feat(archive): read bzip2, xz and zstd, and choose the format on creation 2026-09-17 11:38:57 +02:00
frontend feat(appearance): replace the favicon and the light/dark banners 2026-10-06 18:31:10 +02:00
middleware feat(ops): enrich request logging with client IP, user and level 2026-07-27 13:17:27 +02:00
migrations feat(appearance): replace the favicon and the light/dark banners 2026-10-06 18:31:10 +02:00
model feat(appearance): replace the favicon and the light/dark banners 2026-10-06 18:31:10 +02:00
packaging ci(rpm): build an RPM with GoReleaser and push to the Forgejo registry 2026-07-21 11:19:43 +02:00
pkg feat(archive): cancel a running task, pick the level, and create tar.xz 2026-09-17 12:39:13 +02:00
repository perf(appearance): answer a branding revalidation without reading the image 2026-10-06 18:37:55 +02:00
routers perf(appearance): answer a branding revalidation without reading the image 2026-10-06 18:37:55 +02:00
service/share feat(livedoc): relay for collaborative Markdown editing 2026-09-16 10:58:53 +02:00
.dockerignore build: add Docker image (multi-stage) and docker-compose 2026-07-13 12:01:04 +02:00
.gitignore ci: correct the pnpm store comment 2026-09-17 10:19:33 +02:00
.goreleaser.yaml ci(release): publish the container image for arm64 too 2026-10-07 10:49:02 +02:00
conf.ini.example feat(archive): cancel a running task, pick the level, and create tar.xz 2026-09-17 12:39:13 +02:00
docker-compose.yml feat(security): response security headers, CSP and a dedicated WOPI secret 2026-07-27 12:27:00 +02:00
Dockerfile build(frontend): move the toolchain to pnpm 2026-09-16 11:25:38 +02:00
Dockerfile.release ci(release): publish the container image for arm64 too 2026-10-07 10:49:02 +02:00
go.mod feat(archive): read bzip2, xz and zstd, and choose the format on creation 2026-09-17 11:38:57 +02:00
go.sum feat(archive): read bzip2, xz and zstd, and choose the format on creation 2026-09-17 11:38:57 +02:00
LICENSE chore: scaffold project (CLI, config loader, license) 2026-07-12 22:39:38 +02:00
main.go chore: scaffold project (CLI, config loader, license) 2026-07-12 22:39:38 +02:00
README.md build(frontend): move the toolchain to pnpm 2026-09-16 11:25:38 +02:00

OrionDrive

Self-hosted file management, in a single binary.

A Go backend serving an embedded Vue 3 SPA — files, sharing, WebDAV/SFTP, previews, Office editing and multi-backend storage, with SSO-only authentication.

CI License: MIT Go Vue


OrionDrive is a clean-room, self-hosted drive: one static binary that embeds the web app, talks to SQLite / PostgreSQL / MySQL, and stores objects on local disk, S3-compatible storage or a remote node. Authentication is OIDC / SSO only — there are no local password accounts.

Not affiliated with, and containing no code from, any GPL-licensed project. Licensed under MIT.

Features

  • Files — explorer with folders, resumable chunked upload, rename/move, trash & restore, versioning, file locking, and per-group quotas.
  • Search — recursive, filterable (type, category, starred, modified date), with each hit's location.
  • Storage backends — local, S3-compatible and remote (slave-node) drivers, with direct/presigned downloads and per-group speed limits. Optional AES-256-CTR encryption at rest.
  • Sharing — file & folder links with permission levels (view / edit / blind deposit), passwords, expiry and download limits; rich OpenGraph unfurls on paste.
  • Access protocols — WebDAV over /dav and SFTP (resumable), both with dedicated per-user credentials independent of SSO; personal access tokens for API clients.
  • Preview & editing — image, video, audio, PDF, text, Markdown and ePub previews; an image editor; and collaborative Office editing via WOPI (OnlyOffice / Collabora) with document locking.
  • Archives — background compress/extract (zip / tar / 7z) and grouped ZIP downloads.
  • Administration — admin panel; groups with granular permissions and per-group storage policies; SSO-group → group/admin mapping; scheduled maintenance (trash purge, upload cleanup).
  • Platform — SQLite / PostgreSQL / MySQL, optional Redis-backed shared cache for multi-node deployments, an installable PWA, dark/light themes and full i18n (English & French).

Quick start (Docker)

docker run -p 5212:5212 -v orion-data:/app/data \
  -e OD_CONF_System_SessionSecret="$(openssl rand -hex 32)" \
  -e OD_CONF_System_SiteURL="https://drive.example.com" \
  -e OD_CONF_OIDC_Issuer="https://id.example.com" \
  -e OD_CONF_OIDC_ClientID="orion" \
  -e OD_CONF_OIDC_ClientSecret="…" \
  git.nhsoul.fr/nhpro/orion-drive:latest

Or with Compose (bundles PostgreSQL, Redis and OnlyOffice behind opt-in profiles):

docker compose up -d          # http://localhost:5212

Configuration

Every setting is an INI key (conf.ini) overridable by an OD_CONF_<Section>_<Key> environment variable — see conf.ini.example for the full, documented set. At minimum set System.SessionSecret, System.SiteURL and the OIDC.* values. The published image runs in release mode, so the debug dev-login is compiled out.

Development

cp conf.ini.example conf.ini      # configure OIDC (or use dev-login in debug mode)

# Backend — API + embedded SPA on :5212 (runs pending migrations on startup)
go run . server

# Frontend — Vite dev server with API proxy + hot reload
cd frontend && pnpm install && pnpm dev

Useful CLI: go run . migrate up, go run . group …, go run . policy add-s3|add-local.

Production build

cd frontend && pnpm build         # emits application/statics/dist (embedded by the binary)
cd .. && go build -o orion-drive .
./orion-drive server

The multi-stage Dockerfile does both steps and ships a minimal Alpine runtime (with ffmpeg for thumbnails); the binary is static (CGO_ENABLED=0).

Tech stack

Backend Go 1.26 · Gin · GORM (SQLite / PostgreSQL / MySQL, pure-Go) · goose migrations · cobra · coreos/go-oidc · x/net/webdav · pkg/sftp · aws-sdk-go-v2 · optional Redis
Frontend Vue 3 · Vite · TypeScript · Pinia · vue-router · vue-i18n · vite-plugin-pwa · lucide · a custom "Nebula" CSS design system (oklch tokens, dark/light)
Release GoReleaser · Forgejo Actions · Docker

Project layout

cmd/            CLI commands (server, migrate, version, group, policy)
conf/           configuration (INI + env overrides)
application/    bootstrap (DI container) and embedded SPA
migrations/     goose SQL migrations, per dialect (embedded)
model/          GORM models
repository/     data-access layer
service/        business logic
pkg/            filemanager (drivers/encrypt), auth, cache, queue, crontab,
                archive, thumb, wopi, webdav, sftpserver, serializer
middleware/     Gin middleware
routers/        HTTP routes and controllers
frontend/       Vue 3 SPA

License

MIT.