Self-Hosting a Secure File-Sharing Platform with Pingvin Share on a Docker VPS: The Ultimate WeTransfer Alternative
Introduction: The Cost and Risks of Public File Sharing
In today's digital-first business environment, data exchange is a fundamental operation. Every day, enterprises share contract drafts, high-resolution media files, software builds, and proprietary financial reports. For years, public third-party platforms like WeTransfer, Dropbox, and Google Drive have been the default solutions. However, relying on public cloud providers introduces significant vulnerabilities, including strict file size caps on free tiers, soaring premium subscription fees, and a critical lack of data sovereignty.
When you upload a file to a public platform, you lose absolute control over where that data resides and who can access it. For organizations dealing with strict regulatory compliance (such as GDPR or HIPAA) or intellectual property, this is a risk too high to ignore. The solution? Transitioning to a self-hosted infrastructure. By deploying Pingvin Share on your own Docker-enabled Virtual Private Server (VPS), you can establish a completely private, highly secure, and restriction-free file-sharing platform that serves as the ultimate alternative to WeTransfer.
What is Pingvin Share?
Pingvin Share is an open-source, self-hosted file-sharing application designed with simplicity, security, and modern web standards in mind. Built as a direct competitor to commercial services, it allows individuals and organizations to upload files and generate shareable links with total control over the underlying infrastructure. Unlike traditional FTP setups or bloated cloud suites, Pingvin Share focuses entirely on doing one thing exceptionally well: fast, secure, and seamless file distribution.
Key Features for Business Infrastructure
- No Artificial File Size Limits: Your only limitation is the actual storage capacity of your VPS.
- Advanced Security Controls: Protect shared links with robust password authentication and precise expiration dates.
- Reverse Share Functionality: Allow external clients to securely upload files directly to your server via temporary invite links.
- Comprehensive Audit Logs: Track link visits, download frequencies, and system access logs for compliance and security auditing.
- Email Notifications: Seamlessly integrate with SMTP servers to notify recipients when a file is ready or when a download occurs.
Why Choose a Docker VPS for Deployment?
Deploying application stacks can traditionally be a complex process involving conflicting dependencies, runtime environments, and configuration drift. Utilizing a Virtual Private Server (VPS) paired with Docker containerization solves these pain points entirely.
Docker isolates the Pingvin Share application inside a lightweight container, ensuring it runs identically regardless of the underlying host operating system. This architecture simplifies backups, enables rapid updates, and isolates the application from other services on your server, significantly reducing your security attack surface. Furthermore, a VPS provides dedicated resources and a static public IP, guaranteeing consistent uptime and high upload/download speeds for your global team and clients.
Step-by-Step Deployment Guide
Follow this technical walkthrough to provision your VPS, configure Docker, and launch your secure instance of Pingvin Share.
Prerequisites
Before proceeding, ensure you have the following components ready:
- A Linux VPS (Ubuntu 22.04 LTS or 24.04 LTS recommended) with root or sudo access.
- A registered domain or subdomain (e.g.,
share.yourcompany.com) pointed to your VPS IP address via an A Record. - Docker and Docker Compose installed on the host machine.
Step 1: System Update and Docker Installation
Connect to your VPS via SSH and execute the following commands to ensure your package repository is up to date and Docker is correctly installed:
sudo apt update && sudo apt upgrade -y
sudo apt install curl docker.io docker-compose-v2 -y
sudo systemctl enable --now dockerStep 2: Preparing the Application Directory
Create a dedicated directory to house your configuration and persistent data volumes. This keeps your server clean and makes future migrations straightforward:
mkdir -p ~/pingvin-share
cd ~/pingvin-shareStep 3: Creating the Docker Compose Configuration
Create a docker-compose.yml file using your preferred text editor (such as nano):
nano docker-compose.ymlPaste the following optimized configuration into the file. This definition sets up the Pingvin Share backend, configures persistent data mapping, and exposes the service internally:
version: '3.8'
services:
pingvin-share:
image: stonith404/pingvin-share:latest
container_name: pingvin-share
restart: unless-stopped
ports:
- "3000:3000"
volumes:
- ./data:/opt/app/backend/data
- ./images:/opt/app/frontend/public/imgSave the file and exit the editor (in Nano, press Ctrl+O, Enter, then Ctrl+X).
Step 4: Launching the Application
Execute the Docker Compose command in detached mode to pull the latest image and spin up the container infrastructure:
sudo docker compose up -dVerify that the container is running successfully by checking its status:
sudo docker psSecuring Your Instance with a Reverse Proxy and SSL
Running Pingvin Share directly on port 3000 over unencrypted HTTP is highly insecure for production environments. To protect user credentials and file payloads in transit, you must implement a reverse proxy like Nginx, Caddy, or Nginx Proxy Manager combined with a Let's Encrypt SSL/TLS Certificate.
Example: Nginx Configuration with Let's Encrypt
Install Nginx on your host system:
sudo apt install nginx -yConfigure a new virtual host blocks by creating a configuration file for your subdomain:
sudo nano /etc/nginx/sites-available/pingvin-shareInsert the following configuration, replacing share.yourcompany.com with your actual domain:
server {
listen 80;
server_name share.yourcompany.com;
location / {
proxy_pass [http://127.0.0.1:3000](http://127.0.0.1:3000);
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
client_max_body_size 0; # Allows unlimited file upload size
}
}Enable the site configuration and restart Nginx:
sudo ln -s /etc/nginx/sites-available/pingvin-share /etc/nginx/sites-enabled/
sudo systemctl restart nginxFinally, secure the connection with an SSL certificate using Certbot:
sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d share.yourcompany.comPost-Installation: Essential Production Hardening
Once you access your freshly deployed instance via [https://share.yourcompany.com](https://share.yourcompany.com), you will be prompted to create the initial administrator account. To make this platform enterprise-grade, proceed immediately to the admin settings panel to configure the following hardening measures:
- Disable Public Registration: Prevent unauthorized external actors from discovering your URL and utilizing your server storage. Ensure that only accounts manually created by administrators can generate upload links.
- Enforce Minimum Password Complexity: Require that all internal users leverage strong, unique cryptographic keys for access.
- Set Global Default Expirations: Implement a data lifecycle management rule—such as automatically deleting shared files after 7 or 14 days—to prevent your VPS storage from filling up over time.
- Configure SMTP Settings: Hook the platform into your corporate email relay (such as Amazon SES, SendGrid, or Microsoft 365) to enable verified email delivery for shared links.
Conclusion: Ultimate Data Sovereignty
Transitioning from a restrictive public utility like WeTransfer to a dedicated, self-hosted Pingvin Share instance on a Docker VPS is a major milestone in optimizing your organization's digital workflow. It simultaneously eliminates recurring subscription fees, removes arbitrary file size boundaries, and dramatically reinforces your cybersecurity posture. By maintaining 100% ownership of your data storage and transport layers, you provide clients and internal stakeholders with a fast, modern, and unequivocally secure ecosystem for file distribution.
