SuperSync

SuperSync

Docker app from BigWebstas' Repository

Overview

SuperSync is the self-hostable sync backend for Super Productivity (https://super-productivity.com), letting you sync your tasks/notes across devices without relying on Dropbox/WebDAV or the hosted service. Upstream (super-productivity/super-productivity) only publishes this image to a **private** GHCR registry (see https://github.com/super-productivity/super-productivity/issues/6225), so this is an unofficial public rebuild of the same, unmodified source (packages/super-sync-server), pushed daily to Docker Hub. REQUIRES A SEPARATE POSTGRESQL 16 DATABASE — this template does not bundle one. Install a Postgres container first (e.g. from Community Applications), create a database/user for SuperSync, then point the "Database URL" variable below at it. There are no upstream release tags — this image tracks the `master` branch and has no stability guarantee. Pin to a specific `latest`-alternative sha tag (see the Docker Hub tags list) rather than `latest` for anything you care about staying stable. No Terms of Service / privacy policy is baked in; see the PRIVACY_* variables in upstream's env.example if you need one generated for your deployment.

SuperSyncDocker

A public Docker Hub image for Super Productivity's SuperSync server (packages/super-sync-server in the super-productivity monorepo).

Upstream only publishes a private image (issue #6225), so this repo rebuilds it from source, unmodified, and pushes a public image to webstas/supersync. There are no upstream release tags — master is the only source of truth, so each build is tagged with latest, the upstream commit SHA, and a build date. Pin to a <sha> tag, not latest, for anything you care about.

Running

cp .env.example .env   # fill in JWT_SECRET, POSTGRES_PASSWORD, PUBLIC_URL, SMTP_*
docker compose up -d

docker-compose.yml is a trimmed copy of upstream's — no Caddy/TLS, so front it with your own reverse proxy. SuperSync needs its own PostgreSQL 16 database; the compose file does not bundle one. See upstream's env.example for every supported variable.

Behind IIS on Windows Server? See docs/reverse-proxy-iis.md and the ready-made web.config.

Unraid

Ships a Community Applications template at templates/supersync.xml. Add this repo as a template repository (Apps → Settings → Template Repositories): https://github.com/BigWebstas/SuperSync. Install a separate PostgreSQL 16 container first, then set the Database URL field.

Notes

  • No Terms of Service / privacy policy is baked in — upstream ships none. Set the PRIVACY_* variables to generate one for your deployment.

  • latest tracks upstream master, which has no stability guarantee.

  • Upstream's sync rate limits are compiled in with no runtime env var. Behind a reverse proxy every client shares one IP, so the per-IP caps bite sooner than the per-user numbers suggest. build.sh rewrites those constants into process.env reads, so this image honours these env vars set at container start — no rebuild needed:

    • SYNC_UPLOAD_RATE_LIMIT_MAX — per-user and per-IP POST /api/sync/ops cap (default 100/min).
    • SYNC_GLOBAL_RATE_LIMIT_MAX — global per-IP cap across all routes (default 500/15min).
    • SYNC_SNAPSHOT_RATE_LIMIT_MAX — per-IP POST /api/sync/snapshot cap (default 10/15min). Snapshot uploads are full-state and heavy; a client that keeps hitting this is usually stuck in a resync loop worth diagnosing.

    Set them in .env / your compose file. Unset, empty, or non-numeric falls back to the upstream default, so a stock deployment behaves exactly like upstream. FAITHFUL_REBUILD=true ./build.sh skips the rewrite entirely; each rewrite is verified and fails the build if upstream moves the target line.

Requirements

A separate PostgreSQL 16 (or compatible) database, reachable from this container, is required before starting.

Categories

Download Statistics

1,522
Total Downloads

Related apps

Explore more like this

Explore all

Details

Repository
webstas/supersync:latest
Last Updated2026-09-11
First Seen2026-08-25

Runtime arguments

Web UI
http://[IP]:[PORT:1900]/
Network
bridge
Shell
sh
Privileged
false

Template configuration

WebUIPorttcp

Port the server listens on.

Target
1900
Default
1900
Value
1900
DataPathrw

Persistent app data directory.

Target
/app/data
Default
/mnt/user/appdata/supersync
Value
/mnt/user/appdata/supersync
Database URLVariable

Postgres 16 connection string for a database you create/manage separately, e.g. postgresql://supersync:PASSWORD@POSTGRES_IP:5432/supersync?connection_limit=60&amp;pool_timeout=10 (the connection_limit param is important, see Overview).

Target
DATABASE_URL
JWT SecretVariable

Secret used to sign auth tokens, minimum 32 characters. Generate with: openssl rand -base64 32

Target
JWT_SECRET
Public URLVariable

URL your users/devices use to reach this server, with protocol. Used in verification/magic-link emails. MUST start with https:// unless you also set Node Env below to something other than production.

Target
PUBLIC_URL
Default
http://[IP]:[PORT:1900]
Value
http://[IP]:[PORT:1900]
CORS OriginsVariable

Comma-separated list of origins allowed to call this server (add your self-hosted frontend URL if applicable).

Target
CORS_ORIGINS
Default
https://app.super-productivity.com
Value
https://app.super-productivity.com
WebAuthn RP IDVariable

Relying-party ID for passkey login: your domain, without protocol or port. Changing later invalidates existing passkeys.

Target
WEBAUTHN_RP_ID
Default
localhost
Value
localhost
WebAuthn OriginVariable

Where users reach the auth UI, with protocol. Normally the same as Public URL.

Target
WEBAUTHN_ORIGIN
Default
http://[IP]:[PORT:1900]
Value
http://[IP]:[PORT:1900]
Node EnvVariable

Set to something other than 'production' to allow http:// Public URLs (e.g. for LAN-only/testing use).

Target
NODE_ENV
Default
production
Value
production
Run Migrations On StartupVariable

Run Prisma database migrations automatically each time the container starts. Disable once your schema is stable if you'd rather run migrations manually.

Target
RUN_MIGRATIONS_ON_STARTUP
Default
true
Value
true
Allowed EmailsVariable

Optional comma-separated allowlist of exact addresses and/or *@domain rules restricting who may register. Leave blank to allow anyone who can reach the server.

Target
ALLOWED_EMAILS
Default Storage Quota (Bytes)Variable

Per-user storage quota in bytes applied to accounts created from now on (default 104857600 = 100MB). Existing accounts keep the quota they were created with; raising this does NOT widen anyone's existing quota. To change an existing user's quota, run: UPDATE users SET storage_quota_bytes = bytes WHERE email = 'email'; against your Postgres database.

Target
SUPERSYNC_DEFAULT_STORAGE_QUOTA_BYTES
Default
104857600
Sync Upload Rate Limit (max)Variable

Max POST /api/sync/ops requests per minute, enforced per user AND per source IP (upstream default 100). Upstream hardcodes this; this image reads it at startup. Behind a reverse proxy every client shares one IP, so the per-IP cap bites sooner than 100/user suggests — raise this if legitimate clients hit 429s. Leave blank for the upstream default.

Target
SYNC_UPLOAD_RATE_LIMIT_MAX
Sync Global Rate Limit (max)Variable

Max requests per source IP across ALL routes per 15 minutes (upstream default 500). Upstream hardcodes this; this image reads it at startup. Raise alongside the upload limit when many users share one IP via a reverse proxy. Leave blank for the upstream default.

Target
SYNC_GLOBAL_RATE_LIMIT_MAX
Sync Snapshot Rate Limit (max)Variable

Max POST /api/sync/snapshot (full-state upload) requests per source IP per 15 minutes (upstream default 10). Upstream hardcodes this; this image reads it at startup. Behind a reverse proxy that is 10/15min for the whole instance. Snapshot uploads are heavy (large body + full replay), so raise with care; a client repeatedly hitting this is usually stuck in a resync loop worth diagnosing. Leave blank for the upstream default.

Target
SYNC_SNAPSHOT_RATE_LIMIT_MAX
SMTP HostVariable

SMTP server hostname, required for email verification.

Target
SMTP_HOST
SMTP PortVariable

SMTP port (587 for TLS/STARTTLS, 465 for SSL).

Target
SMTP_PORT
Default
587
Value
587
SMTP SecureVariable

true for SSL on port 465, false for STARTTLS on 587.

Target
SMTP_SECURE
Default
false
Value
false
SMTP UserVariable

SMTP authentication username.

Target
SMTP_USER
SMTP PasswordVariable

SMTP authentication password.

Target
SMTP_PASS
SMTP FromVariable

From address for outgoing emails, e.g. "Super Productivity Sync" noreply@your-domain.com

Target
SMTP_FROM