Self-Hosting Filestash on Docker VPS: Centralize S3, SFTP, and WebDAV into a Unified Web UI
Introduction: The Challenge of Fragmented Cloud Storage
In modern enterprise environments, data is rarely stored in a single location. Organizations routinely distribute assets across various storage protocols: legacy systems rely on SFTP, collaborative platforms leverage WebDAV, and scalable applications utilize object storage like Amazon S3 or MinIO. Managing these disparate systems often requires switching between multiple desktop clients, command-line interfaces, and web consoles.
This fragmentation introduces operational inefficiencies and security risks. Filestash solves this problem by acting as a lightweight, web-based frontend that unifies your entire storage infrastructure into a single, modern user interface. By self-hosting Filestash on a virtual private server (VPS) using Docker, you retain full ownership of your data, eliminate vendor lock-in, and provide your team with a seamless, browser-accessible file manager. This guide provides a step-by-step blueprint for deploying Filestash in a production-ready environment.
Why Filestash? Key Architecture and Benefits
Unlike traditional cloud storage solutions like Nextcloud or Owncloud, Filestash does not include an internal database to index your files. Instead, it operates as a stateless proxy client. When a user interacts with the Filestash UI, the platform translates those actions into native protocol commands (e.g., S3 API calls or SFTP commands) in real time. This architectural choice offers distinct advantages:
- Zero Storage Overhead: Filestash doesn't duplicate your files or require local storage expansion on your VPS.
- High Performance: Written in Go and optimized for speed, the application features an incredibly low memory footprint.
- Universal Compatibility: It supports S3, SFTP, WebDAV, FTP, Git, MinIO, and Google Drive out of the box.
- Built-in Previews: Users can view images, stream videos, read PDFs, and edit text documents directly within the browser.
Prerequisites for Deployment
Before initiating the deployment process, ensure your infrastructure meets the following baseline requirements:
- A Dedicated VPS: A server with at least 1 vCPU, 1GB RAM, and a Linux distribution (Ubuntu 22.04 LTS or newer recommended).
- Docker Ecosystem: Docker Engine and Docker Compose installed on the host machine.
- Domain and DNS: A fully qualified domain name (FQDN) with an A record pointing to your VPS public IP address.
- Network Accessibility: Ports 80 and 443 open on your firewall to facilitate SSL/TLS termination.
Step-by-Step Guide: Deploying Filestash via Docker Compose
Deploying Filestash via Docker Compose ensures configuration consistency and simplifies future upgrades. Follow these steps to configure your stack with an automated Nginx reverse proxy and Let's Encrypt SSL certificates.
Step 1: Directory Setup and Environment Configuration
Connect to your VPS via SSH and establish a structured directory layout for your deployment artifacts:
mkdir -p /opt/filestash/data
cd /opt/filestash
Step 2: Crafting the Docker Compose File
Create a docker-compose.yml file within the directory. This configuration defines the Filestash application service along with an Nginx proxy companion to automate SSL certificate management.
Execute the following command to create and open the file:
nano docker-compose.yml
Populate the file with the configuration block below:
Note: Replace
filestash.yourdomain.comand[email protected]with your actual domain and administrative email address before deploying.
version: '3.8'
services:
filestash:
image: machines/filestash:latest
container_name: filestash
restart: always
environment:
- APPLICATION_URL=[https://filestash.yourdomain.com](https://filestash.yourdomain.com)
volumes:
- ./data:/app/data
networks:
- proxy-tier
nginx-proxy:
image: nginxproxy/nginx-proxy:latest
container_name: nginx-proxy
restart: always
ports:
- "80:80"
- "443:443"
volumes:
- /var/run/docker.sock:/tmp/docker.sock:ro
- certs:/etc/nginx/certs
- vhost:/etc/nginx/vhost.d
- html:/usr/share/nginx/html
networks:
- proxy-tier
acme-companion:
image: nginxproxy/acme-companion:latest
container_name: nginx-proxy-acme
restart: always
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- certs:/etc/nginx/certs
- vhost:/etc/nginx/vhost.d
- html:/usr/share/nginx/html
environment:
- [email protected]
depends_on:
- nginx-proxy
networks:
- proxy-tier
volumes:
certs:
vhost:
html:
networks:
proxy-tier:
driver: bridge
Step 3: Launching the Application
With the configuration file established, initialize the multi-container application stack in detached mode:
docker-compose up -d
Verify that all containers are operating successfully by checking their runtime status:
docker-compose ps
Initial Configuration and Security Best Practices
Once the containers are online, navigate to [https://filestash.yourdomain.com](https://filestash.yourdomain.com) in your browser. Upon your initial visit, Filestash will prompt you to initialize an administrative password. Ensure this password is robust and securely stored, as it grants full access to the backend configuration console.
Connecting Storage backends
From the administrative dashboard, you can define the exact storage backends available to your users:
- Amazon S3 / S3-Compatible: Input your Access Key, Secret Key, Endpoint URL, and Target Bucket name. This works seamlessly with AWS, Backblaze B2, Wasabi, and self-hosted MinIO clusters.
- SFTP: Provide the host IP or hostname, port (default 22), and authentication credentials (either username/password or a private SSH key).
- WebDAV: Enter the target URL of your WebDAV server along with the necessary access credentials.
Security Hardening for Production Environments
To safely run Filestash in an enterprise setting, implement the following security configurations:
1. Enforce Two-Factor Authentication (2FA)
Navigate to the security tab within the Filestash admin panel and mandate 2FA for all users to prevent unauthorized access stemming from credential leaks.
2. Implement Rate Limiting
Protect your deployment from brute-force authentication attempts by configuring rate limits on your Nginx proxy for the /api/login endpoints.
3. Restrict Allowed Host Protocols
If your organization exclusively utilizes S3 and SFTP, explicitly disable alternative protocols (such as FTP or WebDAV) within the administrative panel to reduce the application's attack surface.
Conclusion
Self-hosting Filestash on a Docker VPS balances control, flexibility, and user experience. By centralizing S3, SFTP, and WebDAV into a single responsive web interface, you remove friction for end-users while retaining complete authority over your infrastructure. Deploying via Docker Compose ensures your storage platform remains scalable, easily maintainable, and simple to upgrade as your organizational data needs evolve.
