FileRise
FileRise is a self-hosted web file manager and storage hub with WebDAV, sharing, and per-folder ACLs. Drag & drop uploads, OnlyOffice integration, and optional folder-level encryption at rest — all in one PHP app you control.
Quick links: Website • Docs • Live demo • Install • FileRise Pro
- Built for: anyone who wants a fast, self-hosted file manager, storage hub, client portal, and AI workflow workspace on their own infrastructure.
- Core (MIT): full open-source FileRise feature set (ACLs, folder and file sharing, uploads, tags/search, PDF previews, and more), plus multiple local roots and WebDAV sources for storage-hub workflows.
- Pro: adds user groups, client portals, automation, additional source adapters, gateway shares, search everywhere/audit tooling, and a permissions-aware AI workspace for structured extraction, organization, approvals, and scoped copilots.
- FileRise Pro AI Chat: Organize Files By Type
- FileRise Pro AI Chat: Extract Invoice Fields to JSON and CSV
Table of contents
- Quick links
- Install (Docker – recommended)
- Manual install (PHP web server)
- After install (5 minutes)
- Data & backups
- First-run security checklist
- Optional dependencies
- WebDAV & ONLYOFFICE (optional)
- Security & updates
- Community, support & contributing
- AI Disclosure
- License & third-party code
- Press
Highlights
- 💾 Self-hosted “cloud drive” – Runs on Docker (recommended) or on a standard PHP web server. No external database required.
- 🔐 Granular per-folder ACLs – Manage View (all/own), Upload, Create, Edit, Rename, Move, Copy, Delete, Extract, Share, and more — all enforced consistently across the UI, API, and WebDAV.
- 🔗 Link File (authenticated deep links) – Generate internal links to specific files, require login + ACL checks, and open directly to the target in the app.
- 🤝 Folder and file sharing – Share folders for browsing or upload-only file requests, protect links with passwords/expiration, and share individual files with generated links.
- 📥 File Request links (upload-only) – Share upload-only links so external users can submit files into a folder without browsing existing files.
- 📄 PDF viewing + optional local PDF thumbnails – View PDFs inline in the preview modal, and optionally enable first-page PDF thumbnails for gallery cards and hover previews using
pdftoppm. - 🔐 Folder-level encryption at rest (optional) – Encrypt entire folders (and all descendants) on disk using modern authenticated encryption.
- 🔄 Fast drag-and-drop uploads – Chunked, resumable uploads with pause/resume and progress tracking. If your connection drops, FileRise resumes automatically.
- 🪟 Dual-pane mode + keyboard shortcuts – Optional two-pane file browser for fast workflows (copy/move between panes, compare folders, and operate without the mouse). Shortcut overlay + hotkeys (F3 preview, F4 edit, F5 copy, F6 move, F7 new folder, Del delete,
/search). - 🌳 Scales to huge trees – Tested with 100k+ folders in the sidebar tree without choking the UI.
- 🌈 Visual organization – Color-code folders in the tree, inline list, and folder strip, plus tag files with color-coded labels for fast visual scanning.
- 👀 Hover preview “peek” cards – On desktop, hover files or folders to see thumbnails (images/video), quick metadata (size, timestamps, tags), and effective permissions. Per-user toggle stored in
localStorage. - 🎬 Smart media handling – Track per-file video watch progress with a “watched” indicator, remember last volume/mute state, and reset progress when needed.
- 🧩 OnlyOffice support (optional) – Edit DOCX/XLSX/PPTX using your own Document Server; ODT/ODS/ODP supported as well. PDFs can be viewed inline.
- 🌍 WebDAV (ACL-aware) – Mount FileRise as a drive from macOS, Windows, Linux, or Cyberduck/WinSCP. Listings, uploads, overwrites, deletes, and folder creation all honor the same ACLs as the web UI.
- 🏷️ Tags, search & trash – Tag files, search by name/tag/uploader/content via fuzzy search, and recover mistakes using a Trash with time-based retention.
- 📚 API + live docs – OpenAPI spec served at
api.php?spec=1(fromopenapi.json.dist) with a Redoc UI atapi.php(login required). - 📊 Storage / disk usage summary – CLI scanner with snapshots, total usage, and per-volume breakdowns surfaced in the admin panel.
- 🎨 Polished, responsive UI – Dark/light mode, mobile-friendly layout, in-browser previews, and a built-in code editor powered by CodeMirror.
- 🌐 Internationalization – English, Spanish, French, German, Polish, Russian, Japanese and Simplified Chinese included; community translations welcome.
- 🔑 Login + SSO – Local users, TOTP 2FA, and OIDC (Auth0 / Authentik / Keycloak / etc.) with optional auto-provisioning, IdP-driven admin role assignment, and Pro user-group mapping.
- 🛡️ ClamAV virus scanning (Core) + Pro virus log – Optional ClamAV upload scanning, with a Pro virus detection log in the admin panel and CSV export.
- 🌐 Reverse proxy & subpath aware – Designed to run cleanly behind Nginx, Traefik, Caddy, or Apache:
https://example.com/files)
- Correct URL generation for assets, APIs, portals, PWA, and share links
- If the proxy strips the prefix, set FR_BASE_PATH or send X-Forwarded-Prefix
- Explicit “Published URL” setting for proxy / firewall environments
- Works with X-Forwarded-* headers and Kubernetes ingress setups
- 👥 Pro: user groups, client portals, global search, storage explorer & audit logs –
- ⚙️ Pro: Automation (Webhooks + Jobs) –
- 🤖 Pro: AI workflows + workspace –
- 🌐 Sources (Core + Pro adapters) –
- 🔌 Pro: Gateway Shares v2 (SFTP / S3 / MCP) –
Full list of features: Full Feature Wiki
💡 Looking for FileRise Pro (brandable header, user groups, client upload portals, license handling)?
Check out filerise.net – FileRise Core stays fully open-source (MIT).
Quick links
- 🚀 Live demo: Demo (username:
demo/ password:demo) - 🧩 FileRise Pro: filerise.net
- 📚 Docs & Wiki: Wiki
- 🐳 Docker image:
- ⎈ Community Helm chart (unofficial): dofevine/charts/filerise (community-maintained, not maintained by FileRise core)
- 💬 Discord: Discord
- 📝 Changelog: Changelog
Support checklist (please include)
If you open an issue/discussion, please include:
- FileRise version + install method (Docker tag / release ZIP / git)
- Reverse proxy (Nginx / Traefik / Caddy) + subpath (yes/no)
- Browser console errors (if any)
- Server/container logs around the error
Install (Docker – recommended)
The easiest way to run FileRise is the official Docker image.
✅ Tip: For stability, pin a version tag (example:error311/filerise-docker:vX.Y.Z) instead of:latest. See Releases for current versions.
Option A – Quick start (docker run)
Pristine Docker installs can omit PERSISTENT_TOKENS_KEY. FileRise will generate a unique key on first start and persist it in metadata/persistent_tokens.key.
If you prefer to manage the key yourself, set one before first start:
export PERSISTENT_TOKENS_KEY="$(openssl rand -hex 32)"
docker run -d \
--name filerise \
-p 8080:80 \
-e TIMEZONE="America/New_York" \
-e TOTAL_UPLOAD_SIZE="10G" \
-e SECURE="false" \
-e SCAN_ON_START="true" \
-e CHOWN_ON_START="true" \
-v ~/filerise/uploads:/var/www/uploads \
-v ~/filerise/users:/var/www/users \
-v ~/filerise/metadata:/var/www/metadata \
error311/filerise-docker:latest
Then visit:
http://your-server-ip:8080
On first launch you’ll be guided through creating the initial admin user.
💡 After the first run, you can setCHOWN_ON_START="false"if permissions are already correct and you don’t want a recursivechownon uploads/metadata on every start.
> ⚠️ Uploads folder recommendation
> It’s strongly recommended to bind /var/www/uploads to a dedicated folder
(for example~/filerise/uploadsor/mnt/user/appdata/FileRise/uploads),
not the root of a huge media share.
> 🔐 Persistent tokens key note
> Keep /var/www/metadata persistent. On a pristine install, FileRise writes the
generated persistent tokens key to metadata/persistent_tokens.key. If you
choose to manage the key via env instead, keep that value stable for the life
of the instance.
> If you really want FileRise to sit “on top of” an existing share, use a
subfolder (e.g. /mnt/user/media/filerise_root) instead of the share root,
so scans and permission changes stay scoped to that folder.
Option B – docker-compose.yml
services:
filerise:
image: error311/filerise-docker:latest
container_name: filerise
ports:
- "8080:80"
environment:
TIMEZONE: "America/New_York"
TOTAL_UPLOAD_SIZE: "10G"
SECURE: "false"
PERSISTENT_TOKENS_KEY: "${PERSISTENT_TOKENS_KEY:-}" # optional; blank = pristine installs auto-generate and persist a key in metadata
SCAN_ON_START: "true" # auto-index existing files on startup
CHOWN_ON_START: "true" # fix permissions on uploads/metadata on startup
volumes:
- ./uploads:/var/www/uploads
- ./users:/var/www/users
- ./metadata:/var/www/metadata
Bring it up with:
docker compose up -d
You can leave PERSISTENT_TOKENS_KEY blank for pristine installs, or set it in your shell / .env if you want to manage the key yourself:
export PERSISTENT_TOKENS_KEY="$(openssl rand -hex 32)"
Common environment variables
| Variable | Required | Example | What it does |
|-------------------------|----------|----------------------------------|--------------|
| TIMEZONE | ✅ | America/New_York | PHP / container timezone. |
| TOTAL_UPLOAD_SIZE | ✅ | 10G | Max total upload size per request; also used to set PHP/Apache upload limits. |
| SECURE | ✅ | false | true when running behind HTTPS / a reverse proxy, else false. |
| PERSISTENT_TOKENS_KEY | Optional | openssl rand -hex 32 | Secret used to encrypt stored secrets (tokens, permissions, admin config). If omitted on a pristine install, FileRise auto-generates and persists one in metadata/persistent_tokens.key; existing installs without an explicit key stay on the legacy compatibility path until rotated. |
| SCAN_ON_START | Optional | true | If true, runs a scan once on container start to index existing files. |
| CHOWN_ON_START | Optional | true | If true, recursively normalizes ownership/permissions on uploads/ + metadata/. |
| PUID | Optional | 99 | If running as root, remap www-data user to this UID (e.g. Unraid’s 99). |
| PGID | Optional | 100 | If running as root, remap www-data group to this GID (e.g. Unraid’s 100). |
| FR_PUBLISHED_URL | Optional | https://example.com/files | Public URL when behind proxies/subpaths (share links, portals, redirects). |
| FR_BASE_PATH | Optional | /files | Force a subpath when the proxy strips the prefix (overrides auto-detect). |
| FR_TRUSTED_PROXIES | Optional | 127.0.0.1,10.0.0.0/8 | Comma-separated IPs/CIDRs for trusted proxies; only these can supply the client IP header or proxy-auth identity header. |
| FR_IP_HEADER | Optional | X-Forwarded-For | Header to trust for the real client IP when the proxy is trusted. |
Full list of common env variables: Common Environment variables
Full reference: Environment Variables (Full Reference)
> Other useful env vars (optional):
FR_WEBDAV_MAX_UPLOAD_BYTES(WebDAV upload cap in bytes;0= unlimited),
FR_ENCRYPTION_MASTER_KEY(32-byte key: hex orbase64:...),
VIRUS_SCAN_ENABLED/VIRUS_SCAN_CMD/VIRUS_SCAN_EXCLUDE_DIRS/CLAMAV_AUTO_UPDATE,
LOG_STREAM(error/access/both/none),
HTTP_PORT/HTTPS_PORT/SERVER_NAME,
SHARE_URL(override share endpoint;FR_PUBLISHED_URLpreferred).
> 🧩 Traefik + subpath note (Kubernetes): useStripPrefixand rely onX-Forwarded-Prefix+FR_PUBLISHED_URL.
See: Deployments Wiki
More deployment docs: Install Setup
Manual install (PHP web server)
Short version: FileRise expects data at /var/www/{uploads,users,metadata} and your web server must point to the public/ folder (for example DocumentRoot /var/www/filerise/public).
Docker is the recommended deployment path. Manual installs on a standard PHP web server are supported, but more restrictive shared-hosting environments are best-effort and may not support every feature or background-worker workflow.
On a pristine manual install, FileRise generates a unique key on first request and persists it in metadata/persistent_tokens.key. Keep that file with your backups. Existing installs that previously used the legacy built-in key remain on the compatibility path until an administrator performs a controlled rotation.
Full guide + troubleshooting: Installation & setup • Upgrade & migration • Reverse proxy & subpath
Requirements
- PHP 8.3+
- Web server (Apache / Nginx / Caddy + PHP-FPM)
- PHP extensions:
json,curl,zip(and usual defaults) - No database required
Quick start (release ZIP)
1) Create data directories:
sudo mkdir -p /var/www/uploads /var/www/users /var/www/metadata
sudo chown -R www-data:www-data /var/www/uploads /var/www/users /var/www/metadata # adjust web user if needed
sudo chmod -R 775 /var/www/uploads /var/www/users /var/www/metadata
2) Download a release and extract:
cd /var/www
sudo mkdir -p filerise
sudo chown -R $USER:$USER /var/www/filerise
cd /var/www/filerise
VERSION="vX.Y.Z" # replace with the tag you want
ASSET="FileRise-${VERSION}.zip"
curl -fsSL "https://github.com/error311/FileRise/releases/download/${VERSION}/${ASSET}" -o "${ASSET}"
unzip "${ASSET}"
3) Point your web server at /var/www/filerise/public, then visit http://serverip/.
If you install FileRise outside /var/www/filerise, keep the data dirs in /var/www or update the paths in config/config.php.
After install (5 minutes)
- Log in and create your first admin account (prompted on first run).
- Open Admin → Users to add accounts, then Admin → Folder Access to set permissions.
- If you’re behind a reverse proxy or subpath, set
FR_PUBLISHED_URL(andFR_BASE_PATHif needed). - Optional: enable WebDAV or ONLYOFFICE in Admin and follow the wiki guides.
Data & backups
Back up these paths (Docker volumes or host directories):
/var/www/uploads(file data)/var/www/users(users, ACLs, admin config, Pro license)/var/www/metadata(indexes, tags, logs)
- Logs live in
/var/www/metadata/logand can be rotated or pruned. - If you use the auto-generated key path, back up
/var/www/metadata/persistent_tokens.keywith the rest ofmetadata/. - If you manage the key via env, keep your
PERSISTENT_TOKENS_KEYconsistent when restoring backups.
First-run security checklist
- Persist
/var/www/metadataso the generated persistent tokens key survives container recreation. - Either set your own strong
PERSISTENT_TOKENS_KEYor let a pristine install generate one and then back upmetadata/persistent_tokens.key. - Use HTTPS and set
SECURE="true"when behind TLS/reverse proxy. - If behind a proxy, set
FR_TRUSTED_PROXIESandFR_IP_HEADER; proxy-header login also requiresFR_TRUSTED_PROXIES. - Set
FR_PUBLISHED_URL(andFR_BASE_PATHif needed) so share links are correct. - Block direct HTTP access to
/uploads(serve onlypublic/and deny access to/uploads,/users,/metadata).
Optional dependencies
- FFmpeg – video thumbnails (set
FR_FFMPEG_PATHif not on PATH). - ClamAV – upload scanning (
VIRUS_SCAN_ENABLED=true), optionalVIRUS_SCAN_EXCLUDE_DIRSpath excludes. - PHP sodium (libsodium) – required for encryption-at-rest.
- ONLYOFFICE Document Server – document editing in the browser.
WebDAV & ONLYOFFICE (optional)
WebDAV
Once enabled in the Admin panel, FileRise exposes a WebDAV endpoint (e.g. /webdav.php). Use it with:
- macOS Finder – Go → Connect to Server →
https://your-host/webdav.php/ - Windows File Explorer – Map Network Drive →
https://your-host/webdav.php/ - Linux (GVFS/Nautilus) –
dav://your-host/webdav.php/ - Clients like Cyberduck, WinSCP, etc.
Docs: WebDAV Wiki
ONLYOFFICE integration
If you run an ONLYOFFICE Document Server you can open/edit Office documents directly from FileRise (DOCX, XLSX, PPTX, ODT, ODS, ODP; PDFs view-only).
Configure it in Admin → ONLYOFFICE:
- Enable ONLYOFFICE
- Set your Document Server origin (e.g.
https://docs.example.com) - Configure a shared JWT secret
- Copy the suggested Content-Security-Policy header into your reverse proxy
Security & updates
- FileRise is actively maintained and has published security advisories.
- See SECURITY.md and GitHub Security Advisories for details.
Upgrading
- Docker: pull the new tag and recreate the container with the same volumes.
docker pull error311/filerise-docker:latest
# or pin a specific version from Releases
- Manual: replace app files with the latest release ZIP (keep
/var/www/uploads,/var/www/users,/var/www/metadata, and your config).
Community, support & contributing
Contributions are welcome — from bug fixes and docs to translations and UI polish.
See CONTRIBUTING.md for guidelines.
If FileRise saves you time or becomes your daily driver, a ⭐ on GitHub or sponsorship is hugely appreciated:
- ❤️ GitHub Sponsors
- ☕ Ko-Fi
AI Disclosure
FileRise is my project. I use AI like a tool for some tasks (e.g., translations/snippets), but the architecture, core code, and ongoing maintenance are mine.
License & third-party code
FileRise Core is released under the MIT License – see LICENSE.
It bundles a small set of well-known client and server libraries (Bootstrap, CodeMirror, DOMPurify, Fuse.js, Resumable.js, sabre/dav, etc.). All third-party code remains under its original licenses.
The official Docker image includes the ClamAV antivirus scanner (GPL-2.0-only) for optional upload scanning.
See THIRD_PARTY.md and the licenses/ folder for full details.