Build Your Own Self-Hosted Large File Sharing Server: Replacing WeTransfer and Google Drive with Pingvin Share on a VPS
Introduction: The Cost of Relying on Public Cloud Storage
In the modern business landscape, data mobility is paramount. Organizations and professionals routinely exchange massive datasets, ranging from high-definition video productions to sensitive financial audits. For years, the default solution has been relying on public cloud providers and third-party file-sharing platforms like Google Drive, Dropbox, or WeTransfer.
However, these mainstream platforms present significant drawbacks for enterprise users. Subscription costs escalate rapidly as storage requirements grow, strict file size limits restrict workflow efficiency, and—most importantly—centralized data storage introduces severe privacy and data sovereignty risks. When you upload a confidential file to a third-party server, you surrender a degree of control over that asset.
The ultimate solution to these operational bottlenecks is building your own self-hosted, encrypted file-sharing server. By leveraging Pingvin Share deployed on a Virtual Private Server (VPS), your business can establish an independent, secure, and highly efficient data transit hub that acts as a direct, private alternative to WeTransfer.
What is Pingvin Share?
Pingvin Share is an open-source, self-hosted file-sharing platform designed with simplicity, security, and absolute user control in mind. Unlike resource-heavy enterprise platforms, Pingvin Share focuses entirely on the seamless transmission of files via web links, mirroring the exact user experience of WeTransfer but without the commercial constraints.
Core Features of Pingvin Share
- No Arbitrary File Size Limits: Your only limitation is the actual storage capacity of your underlying VPS hardware.
- End-to-End Control: All files reside on your isolated infrastructure, completely shielded from third-party data mining or unauthorized access.
- Advanced Link Management: Administrators can set custom expiration dates, enforce download limits, and secure links with robust password protection.
- Reverse Proxy & Encryption Compatibility: Seamlessly integrates with modern security protocols to ensure all data in transit is fully encrypted via HTTPS.
- User Management Systems: Built-in functionality to allow specific team members to generate links while restricting public registration.
Prerequisites for Deployment
Before initiating the installation process, ensure that you have gathered the necessary infrastructure components. Operating a production-grade file-sharing server requires reliable, scalable building blocks:
- A Virtual Private Server (VPS): A Linux-based VPS running Ubuntu 22.04 LTS or newer is highly recommended. For basic operations, a server with 2 vCPUs and 2GB of RAM is sufficient. However, optimize your storage allocation (SSD/NVMe) based on the maximum volume of concurrent files you expect to host.
- A Registered Domain Name: A dedicated domain or subdomain (e.g.,
share.yourcompany.com) is mandatory for assigning a professional identity and provisioning SSL certificates. - Docker and Docker Compose: Pingvin Share is containerized, meaning deployment is handled efficiently via Docker, isolating the application from the host operating system.
Step-by-Step Installation Guide
Step 1: System Update and Docker Installation
First, access your VPS via SSH and update the local package index to guarantee all system dependencies are current. Run the following commands sequentially:
sudo apt update && sudo apt upgrade -y
sudo apt install docker.io docker-compose -yVerify that the Docker service is running actively on your host by executing sudo systemctl status docker.
Step 2: Configuring the Directory Structure
To keep the server environment organized, create a dedicated directory for the Pingvin Share configuration and data volumes. This ensures simple backup procedures in the future.
mkdir -p ~/pingvin-share
cd ~/pingvin-shareStep 3: Creating the Docker Compose Configuration
Construct a configuration file that dictates how the Pingvin Share container behaves, mapping external network ports and mounting local directories for persistent storage. Create a file named docker-compose.yml using your preferred text editor:
version: '3.8'
services:
pingvin-share:
image: stonith404/pingvin-share:latest
container_name: pingvin-share
restart: unless-stopped
ports:
- "3000:3000"
volumes:
- ./data:/opt/app/backend/data
environment:
- PORT=3000Save and close the file. This simple composition tells Docker to pull the official Pingvin Share image, route port 3000, and ensure the container auto-restarts if the VPS reboots.
Step 4: Launching the Application
With the configuration file established, initialize the container in detached mode (running seamlessly in the background) with the following command:
sudo docker-compose up -dAt this stage, Pingvin Share is operational and listening locally on port 3000. However, accessing it directly via an unencrypted IP address is highly unsecure for enterprise operations.
Securing Your Server with Nginx and Let's Encrypt HTTPS
To safeguard high-volume business files during transit, you must wrap your deployment in an industry-standard SSL/TLS encryption layer using Nginx as a reverse proxy.
1. Install Nginx
sudo apt install nginx -y2. Configure the Reverse Proxy
Create an Nginx configuration file for your specific subdomain:
sudo nano /etc/nginx/sites-available/share.yourcompany.comInsert the following configuration blocks, substituting your actual domain name:
server {
listen 80;
server_name share.yourcompany.com;
location / {
proxy_pass http://localhost:3000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# Critical for large file uploads
client_max_body_size 0;
}
}Important Technical Note: Setting client_max_body_size 0; removes Nginx's default file upload restrictions, enabling the transfer of massive multi-gigabyte zip files, databases, and media assets without encountering 413 Entity Too Large errors.Activate the configuration and restart Nginx:
sudo ln -s /etc/nginx/sites-available/share.yourcompany.com /etc/nginx/sites-enabled/
sudo systemctl restart nginx3. Automate SSL Certificate Generation
Utilize Certbot to acquire a free, automatically renewing Let's Encrypt SSL certificate, ensuring all web traffic transitions securely over port 443 (HTTPS):
sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d share.yourcompany.comFollow the interactive prompts to enable automatic HTTPS redirection. Your file-sharing network is now fully hardened against external interceptors.
Optimizing Pingvin Share for Enterprise Workflows
Navigate to [https://share.yourcompany.com](https://share.yourcompany.com) to access the intuitive Pingvin Share setup wizard. As the first user, you will register the master administrator account. Once inside the administrative dashboard, implement these critical optimization protocols:
Enforcing Data Security
Go to the Settings panel and deactivate "Public Registration." This ensures that random internet actors cannot discover your portal and abuse your VPS storage capacity. Only accounts manually generated by your IT administrators will possess the authorization to upload and distribute assets.
Customizing Link Expirations
To prevent your storage disks from slowly accumulating obsolete historical data, configure a default link expiration window (e.g., 7 days). Once this lifecycle concludes, Pingvin Share automatically purges the underlying file from your VPS storage array, maintaining optimal system health.
Conclusion: Embracing Data Sovereignty
By migrating from restrictive public platforms like WeTransfer and Google Drive to a self-hosted Pingvin Share instance, your enterprise secures absolute data sovereignty, eliminates recurring subscription ceilings, and ensures that sensitive file distribution remains entirely within your domain of control. Investing an hour into setting up an independent VPS server yields dividends in long-term data security, professional branding, and architectural independence.
