Self-Hosting a Secure, Large-File Sharing Platform for Enterprise: Deploying Pingvin Share on VPS Docker
Introduction: The Enterprise Challenge of Large-File Sharing
In the modern corporate ecosystem, data is one of the most critical assets an enterprise possesses. On a daily basis, businesses must transmit substantial volumes of sensitive data, including high-resolution media, proprietary software builds, architectural blueprints, and confidential legal documents. While mainstream public cloud providers offer convenient sharing solutions, they often present significant challenges for enterprise-grade operations. These challenges include escalating recurring subscription fees, strict file size limitations, and potential compliance liabilities regarding data residency and privacy regulations such as GDPR or HIPAA.
To mitigate these risks, forward-thinking enterprises are increasingly turning toward self-hosted solutions. By deploying a dedicated file-sharing platform on a Virtual Private Server (VPS) utilizing Docker, organizations can retain total ownership of their infrastructure, enforce stringent access controls, and guarantee that confidential assets never pass through unvetted third-party pipelines. This guide provides an end-to-end framework for deploying Pingvin Share—a lightweight, secure, and highly efficient self-hosted alternative to commercial file-sharing platforms.
What is Pingvin Share and Why Choose It?
Pingvin Share is an open-source, minimalist file-sharing application designed specifically for speed, simplicity, and robust security. Unlike bloated enterprise collaboration suites, Pingvin Share focuses entirely on doing one thing exceptionally well: allowing users to upload large files and share them via secure, customizable links.
For enterprise environments, Pingvin Share offers several distinctive advantages over both public clouds and traditional FTP systems:
- No Artificial File Size Limits: The only constraints on file sizes are the physical storage capacity and bandwidth of your chosen VPS.
- Comprehensive Security Controls: Links can be tightly restricted using reverse proxy configurations, access tokens, mandatory password protection, and explicit expiration dates.
- Streamlined User Experience: A clean, intuitive web interface ensures that employees and external clients can transmit and download assets without a steep learning curve.
- Resource Efficiency: Built on a modern technical stack, Pingvin Share requires minimal system overhead, allowing it to run smoothly even on cost-effective VPS configurations.
Prerequisites for Enterprise Deployment
Before initiating the technical installation, ensure your infrastructure meets the necessary foundational requirements for a stable and secure deployment. We recommend provisioning a VPS from a reputable cloud provider (such as DigitalOcean, Linode, AWS, or Vultr) with the following minimum specifications:
- Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS (highly recommended for stability).
- Hardware: Minimum 2 vCPUs, 2GB RAM, and sufficient NVMe/SSD storage tailored to your organization's anticipated file transfer volume.
- Network: A dedicated public IPv4 address and standard ports (80, 443) open on the firewall.
- Domain Name: A fully qualified domain name (FQDN), such as share.yourcompany.com, with its A Record correctly pointed to your VPS IP address.
Additionally, you must ensure that Docker and Docker Compose are pre-installed on the host system to orchestrate the containerized services.
Step-by-Step Deployment Guide via Docker Compose
Utilizing Docker Compose provides a declarative way to define and manage our application stack. This ensures reproducibility, isolated environments, and effortless upgrades. Follow these sequential steps to configure and launch Pingvin Share on your server.
Step 1: Accessing the Server and Directory Architecture
First, authenticate into your VPS via SSH using secure administrative credentials. Once logged in, establish a structured directory layout to maintain configuration files and persistent data volumes outside of the containers.
ssh root@your_vps_ip
mkdir -p /opt/pingvin-share
cd /opt/pingvin-shareStep 2: Constructing the Docker Compose Configuration
Create a new configuration file named docker-compose.yml using a standard command-line text editor like nano:
nano docker-compose.ymlPaste the following optimized configuration block into the file. This setup defines the Pingvin Share service, maps the essential local directories for persistent storage, and configures the container to restart automatically in the event of a system reboot.
version: '3.8'
services:
pingvin-share:
image: stonith404/pingvin-share:latest
container_name: pingvin-share
restart: unless-stopped
ports:
- "3000:3000"
volumes:
- ./data:/opt/app/backend/data
- ./images:/opt/app/frontend/public/imgSave your modifications and exit the editor (in Nano, press Ctrl+O, Enter, then Ctrl+X).
Step 3: Executing the Container Initialization
With the configuration file precisely defined, launch the containerized application in detached mode, which allows it to run silently in the background:
docker compose up -dTo verify that the application has initialized correctly and is listening on the assigned port, execute the following container status command:
docker psYou should observe the pingvin-share container running actively with port 3000 mapped correctly.
Securing the Platform with Nginx and SSL Encryption
Exposing an enterprise file-sharing platform over an unencrypted HTTP connection (port 3000) introduces severe security vulnerabilities, leaving sensitive payloads exposed to interception. To establish a secure architecture, we must implement a reverse proxy using Nginx and obtain an SSL/TLS certificate from Let's Encrypt.
Step 1: Installing and Configuring Nginx
Install the Nginx web server package on the host operating system:
sudo apt update
sudo apt install nginx -yCreate a dedicated server block configuration for your file-sharing subdomain:
sudo nano /etc/nginx/sites-available/pingvin-shareInsert the configuration below, ensuring you replace share.yourcompany.com with your actual domain name. This tells Nginx to capture inbound external web traffic and forward it internally to the Pingvin Share container.
server {
listen 80;
server_name share.yourcompany.com;
client_max_body_size 100G; # Accommodates exceptionally large file uploads
location / {
proxy_pass [http://127.0.0.1:3000](http://127.0.0.1:3000);
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# Essential for real-time upload progress indicators
proxy_buffering off;
proxy_read_timeout 600s;
}
}Activate the configuration by establishing a symbolic link to the enabled sites directory, validate the syntax, and reload Nginx:
sudo ln -s /etc/nginx/sites-available/pingvin-share /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl reload nginxStep 2: Automating SSL/TLS via Certbot
To enforce HTTPS, deploy Certbot to obtain and automatically renew a free, trusted SSL certificate:
sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d share.yourcompany.comFollow the interactive prompts to complete the certificate installation. Certbot will automatically rewrite your Nginx configuration to mandate secure HTTPS traffic, ensuring all data in transit is protected by industry-standard encryption.
Post-Installation: Essential Administrative Configurations
Navigate to your secured domain (e.g., [https://share.yourcompany.com](https://share.yourcompany.com)) via a web browser to complete the initial setup wizard. The first user registration automatically receives full administrative privileges over the entire instance.
Critical Security Reminder: Once the primary administrator account is successfully created, navigate directly to the Admin Settings panel and disable public registration. This prevents unauthorized external parties from utilizing your enterprise infrastructure and storage assets.
Within the administration dashboard, configure these key enterprise settings:
- App URL: Explicitly define your full domain string (including the
https://prefix) to guarantee sharing links are generated accurately. - File Expiration Constraints: Enforce mandatory global retention policies, ensuring uploaded files are automatically purged from the server after a predefined window (e.g., 7 or 14 days) to optimize disk space.
- SMTP Mail Integration: Configure your corporate email relay (such as Microsoft 365, Google Workspace, or SendGrid) to enable automated notification emails to recipients when shares are ready for download.
Conclusion: Embracing Absolute Data Sovereignty
By transitioning from commercial public cloud storage to a self-hosted Pingvin Share platform on Docker, your enterprise achieves an optimal balance between absolute data privacy and operational efficiency. You eliminate unpredictable monthly SaaS overhead, retain complete transparency over your infrastructure, and maintain definitive control over your confidential files. With your newly established reverse proxy and robust SSL configuration, your business is fully equipped to transfer large-scale technical assets safely, reliably, and under your own corporate banner.
