ANVILNINE
On this page

Deploy

Dropkiln runs as a single container without an external database by default. Artifacts are stored as plain files under /data, so copying that directory backs up the entire instance. Requires Node.js ≥ 22 with no build step.

git clone https://github.com/anvilnine/artifacts && cd artifacts
cp .env.example .env   # set ARTIFACTS_API_KEY and BASE_URL
docker compose up -d

Generate a key with openssl rand -hex 32. Compose reads .env from the project directory.

docker

docker run -d -p 3000:3000 -v artifacts-data:/data \
  -e ARTIFACTS_API_KEY=$(openssl rand -hex 32) \
  -e BASE_URL=https://artifacts.example.com \
  ghcr.io/anvilnine/artifacts:latest

Configuration

Env var Required Default Purpose
ARTIFACTS_API_KEY yes — Bootstrap admin bearer, the break-glass key; also mints scoped keys
BASE_URL recommended http://localhost:3000 Public origin in returned URLs; an https:// value marks the session cookie Secure
ARTIFACTS_ADMIN_USERNAME / ARTIFACTS_ADMIN_PASSWORD no — Seed the admin account instead of using the first-run setup screen
STORAGE_BACKEND no local local, s3, git, postgres, or sqlite
PORT no 3000 Listen port
TRUST_PROXY no none Client-IP source for rate limiting: none, cloudflare, or xff

Storage backends

Local storage under /data works well when backed by persistent storage (such as a mounted volume or persistent PaaS disk). On ephemeral hosts without persistent volumes, set STORAGE_BACKEND to persist state externally:

  • s3: S3-compatible object storage (R2, B2, MinIO, Spaces, Wasabi). Buckets must be private because Dropkiln applies security headers on response.
  • git: Commits each change to a private Git remote for version history and container state rehydration. Requires a single writer.
  • postgres: Stores one row per object for deployments with an existing PostgreSQL database.
  • sqlite: Uses Node’s built-in node:sqlite single-file database. Durability depends on host disk persistence.

Any Dockerfile PaaS

Dropkiln runs on container platforms such as Coolify, CapRover, Dokploy, and Railway. Expose port 3000, mount a persistent volume at /data, and set ARTIFACTS_API_KEY and BASE_URL. A health check endpoint is available at GET /healthz.

Serve artifacts from a separate origin

Because uploaded HTML executes directly in the browser under its serving origin, host artifact routes (/a/…) on a dedicated domain separate from the management dashboard. This origin isolation prevents user-submitted scripts from accessing admin session cookies or making authenticated requests to /api/*. See Security.

Last updated