Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Configuration

Every option is a command-line flag and an environment variable. thencloud-server --help prints the same list.

General

FlagEnvDefault
--bindTHENCLOUD_BIND127.0.0.1:8080
--data-dirTHENCLOUD_DATA_DIR./data. The SQLite database, and the encrypted blobs unless S3 is configured
--web-dirTHENCLOUD_WEB_DIR./web/dist, the built web client
--trust-proxyTHENCLOUD_TRUST_PROXYfalse. Behind a reverse proxy, take the client’s address from the last X-Forwarded-For entry. Only turn it on when clients can’t reach the server directly. The address is used to rate-limit sign-in attempts and never stored
--hstsTHENCLOUD_HSTSfalse. Send Strict-Transport-Security (two years, with subdomains), so browsers only reach the server over HTTPS. Turn it on when the server is only served over HTTPS, unless the reverse proxy already sends the header; not for an onion service
--public-originTHENCLOUD_PUBLIC_ORIGINunset. The address people open the server at, e.g. https://cloud.example.com (comma-separated for several). When set, passkeys only work from pages at one of these, so a passkey made on any other site is refused
--limit-by-addressTHENCLOUD_LIMIT_BY_ADDRESStrue. Rate-limit sign-in attempts by address as well as by account. Turn it off for a Tor onion service

Accounts

FlagEnvDefault
--allow-registrationTHENCLOUD_ALLOW_REGISTRATIONtrue. The first account can always be made (with the setup code). Admins can switch between open, invite only and closed at runtime, which overrides this. Open means anyone who finds the server gets an account and the default quota, and you can’t see what they store; the server warns at start while it’s open. With false, choose invite only in the Admin view to let people in by invite
--admin-usernameTHENCLOUD_ADMIN_USERNAMEunset. The username the first account must have
--default-quotaTHENCLOUD_DEFAULT_QUOTA10 GiB, in bytes of ciphertext
--session-daysTHENCLOUD_SESSION_DAYS30, sliding

Per-user quotas and daily download and upload limits are set in the Admin view.

Files

FlagEnvDefault
--max-versionsTHENCLOUD_MAX_VERSIONS10, versions kept per file, including the current one
--version-thinningTHENCLOUD_VERSION_THINNINGtrue. Keep all versions from the last hour, then one per hour for a day, one per day for 30 days, one per week after that
--trash-daysTHENCLOUD_TRASH_DAYS30
--upload-ttl-hoursTHENCLOUD_UPLOAD_TTL_HOURS24, how long an unfinished upload is kept

Storage

See Storing blobs in S3.

FlagEnvDefault
--s3-endpointTHENCLOUD_S3_ENDPOINTunset
--s3-regionTHENCLOUD_S3_REGIONus-east-1
--s3-bucketTHENCLOUD_S3_BUCKETunset
--s3-access-keyTHENCLOUD_S3_ACCESS_KEYunset
--s3-secret-keyTHENCLOUD_S3_SECRET_KEYunset
--s3-prefixTHENCLOUD_S3_PREFIXempty
--s3-mirrorTHENCLOUD_S3_MIRRORfalse
--s3-snapshot-hoursTHENCLOUD_S3_SNAPSHOT_HOURS24; 0 turns it off
--s3-snapshots-keptTHENCLOUD_S3_SNAPSHOTS_KEPT7

Optional features

FlagEnvDefault
--metrics-tokenTHENCLOUD_METRICS_TOKENunset. See Monitoring
--turnstile-site-keyTHENCLOUD_TURNSTILE_SITE_KEYunset. See Bot check
--turnstile-secretTHENCLOUD_TURNSTILE_SECRETunset
--turnstile-hostnamesTHENCLOUD_TURNSTILE_HOSTNAMESthe host the sign-in request was sent to; comma-separated
--google-client-id, --google-client-secretTHENCLOUD_GOOGLE_CLIENT_ID, THENCLOUD_GOOGLE_CLIENT_SECRETunset. A Google OAuth app, so people can link their Google Drive as a mirror or extra space. See Linked storage
--yt-dlpTHENCLOUD_YT_DLPyt-dlp. See Video downloader
--ffmpegTHENCLOUD_FFMPEGffmpeg
--downloader-max-bytesTHENCLOUD_DOWNLOADER_MAX_BYTES2 GiB per video

Logging

Logging uses RUST_LOG (for example RUST_LOG=thencloud_server=debug). The server never logs keys, names or contents; it can’t, since it never has them.

Subcommands

CommandWhat it does
serveRun the server (the default)
backup DESTSnapshot the database and its blobs; see Backup and restore
checkCheck every blob the database expects is there with the right size
restore-snapshotPut the newest S3 database snapshot into an empty data directory

The Admin view

Admins see accounts and counts, never content: they can change quotas and transfer limits, make other admins, disable, enable and delete accounts, create invite links, switch registration mode, and turn the video downloader on. Every admin action goes into an audit log, kept for a year.