All apps · 0 apps
SuperSync
Docker app from BigWebstas' Repository
Overview
Readme
View on GitHubSuperSyncDocker
A public Docker Hub image for Super Productivity's
SuperSync server (packages/super-sync-server in the
super-productivity monorepo).
Upstream only publishes a private image
(issue #6225),
so this repo rebuilds it from source, unmodified, and pushes a public image to
webstas/supersync. There are no upstream release tags — master is the only
source of truth, so each build is tagged with latest, the upstream commit SHA,
and a build date. Pin to a <sha> tag, not latest, for anything you care
about.
Running
cp .env.example .env # fill in JWT_SECRET, POSTGRES_PASSWORD, PUBLIC_URL, SMTP_*
docker compose up -d
docker-compose.yml is a trimmed copy of upstream's — no Caddy/TLS, so front it
with your own reverse proxy. SuperSync needs its own PostgreSQL 16 database; the
compose file does not bundle one. See upstream's
env.example
for every supported variable.
Behind IIS on Windows Server? See
docs/reverse-proxy-iis.md and the ready-made
web.config.
Unraid
Ships a Community Applications template at
templates/supersync.xml. Add this repo as a template
repository (Apps → Settings → Template Repositories):
https://github.com/BigWebstas/SuperSync. Install a separate PostgreSQL 16
container first, then set the Database URL field.
Notes
No Terms of Service / privacy policy is baked in — upstream ships none. Set the
PRIVACY_*variables to generate one for your deployment.latesttracks upstreammaster, which has no stability guarantee.Upstream's sync rate limits are compiled in with no runtime env var. Behind a reverse proxy every client shares one IP, so the per-IP caps bite sooner than the per-user numbers suggest.
build.shrewrites those constants intoprocess.envreads, so this image honours these env vars set at container start — no rebuild needed:SYNC_UPLOAD_RATE_LIMIT_MAX— per-user and per-IPPOST /api/sync/opscap (default 100/min).SYNC_GLOBAL_RATE_LIMIT_MAX— global per-IP cap across all routes (default 500/15min).SYNC_SNAPSHOT_RATE_LIMIT_MAX— per-IPPOST /api/sync/snapshotcap (default 10/15min). Snapshot uploads are full-state and heavy; a client that keeps hitting this is usually stuck in a resync loop worth diagnosing.
Set them in
.env/ your compose file. Unset, empty, or non-numeric falls back to the upstream default, so a stock deployment behaves exactly like upstream.FAITHFUL_REBUILD=true ./build.shskips the rewrite entirely; each rewrite is verified and fails the build if upstream moves the target line.
Requirements
Categories
Download Statistics
Related apps
Explore more like this
Explore allDetails
webstas/supersync:latestRuntime arguments
- Web UI
http://[IP]:[PORT:1900]/- Network
bridge- Shell
sh- Privileged
- false
Template configuration
Port the server listens on.
- Target
- 1900
- Default
- 1900
- Value
- 1900
Persistent app data directory.
- Target
- /app/data
- Default
- /mnt/user/appdata/supersync
- Value
- /mnt/user/appdata/supersync
Postgres 16 connection string for a database you create/manage separately, e.g. postgresql://supersync:PASSWORD@POSTGRES_IP:5432/supersync?connection_limit=60&pool_timeout=10 (the connection_limit param is important, see Overview).
- Target
- DATABASE_URL
Secret used to sign auth tokens, minimum 32 characters. Generate with: openssl rand -base64 32
- Target
- JWT_SECRET
URL your users/devices use to reach this server, with protocol. Used in verification/magic-link emails. MUST start with https:// unless you also set Node Env below to something other than production.
- Target
- PUBLIC_URL
- Default
- http://[IP]:[PORT:1900]
- Value
- http://[IP]:[PORT:1900]
Comma-separated list of origins allowed to call this server (add your self-hosted frontend URL if applicable).
- Target
- CORS_ORIGINS
- Default
- https://app.super-productivity.com
- Value
- https://app.super-productivity.com
Relying-party ID for passkey login: your domain, without protocol or port. Changing later invalidates existing passkeys.
- Target
- WEBAUTHN_RP_ID
- Default
- localhost
- Value
- localhost
Where users reach the auth UI, with protocol. Normally the same as Public URL.
- Target
- WEBAUTHN_ORIGIN
- Default
- http://[IP]:[PORT:1900]
- Value
- http://[IP]:[PORT:1900]
Set to something other than 'production' to allow http:// Public URLs (e.g. for LAN-only/testing use).
- Target
- NODE_ENV
- Default
- production
- Value
- production
Run Prisma database migrations automatically each time the container starts. Disable once your schema is stable if you'd rather run migrations manually.
- Target
- RUN_MIGRATIONS_ON_STARTUP
- Default
- true
- Value
- true
Optional comma-separated allowlist of exact addresses and/or *@domain rules restricting who may register. Leave blank to allow anyone who can reach the server.
- Target
- ALLOWED_EMAILS
Per-user storage quota in bytes applied to accounts created from now on (default 104857600 = 100MB). Existing accounts keep the quota they were created with; raising this does NOT widen anyone's existing quota. To change an existing user's quota, run: UPDATE users SET storage_quota_bytes = bytes WHERE email = 'email'; against your Postgres database.
- Target
- SUPERSYNC_DEFAULT_STORAGE_QUOTA_BYTES
- Default
- 104857600
Max POST /api/sync/ops requests per minute, enforced per user AND per source IP (upstream default 100). Upstream hardcodes this; this image reads it at startup. Behind a reverse proxy every client shares one IP, so the per-IP cap bites sooner than 100/user suggests — raise this if legitimate clients hit 429s. Leave blank for the upstream default.
- Target
- SYNC_UPLOAD_RATE_LIMIT_MAX
Max requests per source IP across ALL routes per 15 minutes (upstream default 500). Upstream hardcodes this; this image reads it at startup. Raise alongside the upload limit when many users share one IP via a reverse proxy. Leave blank for the upstream default.
- Target
- SYNC_GLOBAL_RATE_LIMIT_MAX
Max POST /api/sync/snapshot (full-state upload) requests per source IP per 15 minutes (upstream default 10). Upstream hardcodes this; this image reads it at startup. Behind a reverse proxy that is 10/15min for the whole instance. Snapshot uploads are heavy (large body + full replay), so raise with care; a client repeatedly hitting this is usually stuck in a resync loop worth diagnosing. Leave blank for the upstream default.
- Target
- SYNC_SNAPSHOT_RATE_LIMIT_MAX
SMTP server hostname, required for email verification.
- Target
- SMTP_HOST
SMTP port (587 for TLS/STARTTLS, 465 for SSL).
- Target
- SMTP_PORT
- Default
- 587
- Value
- 587
true for SSL on port 465, false for STARTTLS on 587.
- Target
- SMTP_SECURE
- Default
- false
- Value
- false
SMTP authentication username.
- Target
- SMTP_USER
SMTP authentication password.
- Target
- SMTP_PASS
From address for outgoing emails, e.g. "Super Productivity Sync" noreply@your-domain.com
- Target
- SMTP_FROM