Deploy
Dropkiln runs as a single container without an external database by default. Artifacts are stored as plain files under /data, so copying that directory backs up the entire instance. Requires Node.js ≥ 22 with no build step.
docker compose (recommended)
git clone https://github.com/anvilnine/artifacts && cd artifacts
cp .env.example .env # set ARTIFACTS_API_KEY and BASE_URL
docker compose up -d
Generate a key with openssl rand -hex 32. Compose reads .env from the project directory.
docker
docker run -d -p 3000:3000 -v artifacts-data:/data \
-e ARTIFACTS_API_KEY=$(openssl rand -hex 32) \
-e BASE_URL=https://artifacts.example.com \
ghcr.io/anvilnine/artifacts:latest
Configuration
| Env var | Required | Default | Purpose |
|---|---|---|---|
ARTIFACTS_API_KEY |
yes | — | Bootstrap admin bearer, the break-glass key; also mints scoped keys |
BASE_URL |
recommended | http://localhost:3000 |
Public origin in returned URLs; an https:// value marks the session cookie Secure |
ARTIFACTS_ADMIN_USERNAME / ARTIFACTS_ADMIN_PASSWORD |
no | — | Seed the admin account instead of using the first-run setup screen |
STORAGE_BACKEND |
no | local |
local, s3, git, postgres, or sqlite |
PORT |
no | 3000 |
Listen port |
TRUST_PROXY |
no | none |
Client-IP source for rate limiting: none, cloudflare, or xff |
Storage backends
Local storage under /data works well when backed by persistent storage (such as a mounted volume or persistent PaaS disk). On ephemeral hosts without persistent volumes, set STORAGE_BACKEND to persist state externally:
s3: S3-compatible object storage (R2, B2, MinIO, Spaces, Wasabi). Buckets must be private because Dropkiln applies security headers on response.git: Commits each change to a private Git remote for version history and container state rehydration. Requires a single writer.postgres: Stores one row per object for deployments with an existing PostgreSQL database.sqlite: Uses Node’s built-innode:sqlitesingle-file database. Durability depends on host disk persistence.
Any Dockerfile PaaS
Dropkiln runs on container platforms such as Coolify, CapRover, Dokploy, and Railway. Expose port 3000, mount a persistent volume at /data, and set ARTIFACTS_API_KEY and BASE_URL. A health check endpoint is available at GET /healthz.
Serve artifacts from a separate origin
Because uploaded HTML executes directly in the browser under its serving origin, host artifact routes (/a/…) on a dedicated domain separate from the management dashboard. This origin isolation prevents user-submitted scripts from accessing admin session cookies or making authenticated requests to /api/*. See Security.