Back to articles
Technology Insight

Self-Hosting FileStash on Docker VPS: Centralizing S3, SFTP, and Cloud Storage into a Single Unified Interface

June 4, 2026

The Challenge of Modern Data Silos

In the contemporary digital landscape, enterprises and developers face a significant operational hurdle: storage fragmentation. Crucial business data is frequently scattered across disparate environments, including Amazon S3 buckets for application assets, legacy SFTP servers for client data exchanges, and private network-attached storage (NAS) protocols like WebDAV or FTP. Navigating these fragmented repositories often requires toggling between multiple specialized desktop clients, command-line utilities, and web consoles.

This tool fatigue not only degrades productivity but also introduces compliance and security vulnerabilities. Managing separate access credentials, updating various client applications, and ensuring audit logs are maintained across scattered endpoints is an administrative burden. The solution lies in establishing a secure, centralized data management layer that unifies access without replicating or moving the underlying files. This is precisely where self-hosting FileStash on a Docker-equipped Virtual Private Server (VPS) offers a compelling, enterprise-grade solution.

What is FileStash?

FileStash is an open-source, web-based cloud file manager designed to act as a centralized hub for virtually any backend storage provider. Unlike traditional cloud management software that requires duplicating data onto a new server, FileStash operates as a lightweight client-side proxy. It communicates directly with your existing storage endpoints, rendering a modern, responsive, and highly intuitive user interface in any web browser.

Key architectural advantages of FileStash include:

  • Universal Protocol Support: Native compatibility with AWS S3, Backblaze B2, Google Cloud Storage, MinIO, SFTP, FTP, WebDAV, Git, and even database systems like MySQL.
  • High Performance: Written in Go, FileStash boasts a minimal resource footprint, enabling rapid file transfers and responsive navigation even on budget-friendly VPS configurations.
  • Advanced Document Handling: Seamless integration with OnlyOffice or Collabora allows users to view, edit, and collaborate on office documents, spreadsheets, and presentations directly within the browser.
  • Media Transcoding: Real-time on-the-fly transcoding for video and image files, facilitating efficient media previews without downloading massive source files.

Architecture Overview & Prerequisites

Before initiating the deployment, it is vital to understand the structural layout of this setup. The FileStash container will run on your isolated VPS. It handles authentication and user requests, translating web actions into specific storage protocols. When a user requests a file from an S3 bucket or an SFTP server, FileStash fetches it and streams it securely to the client browser.

To follow this comprehensive implementation guide, ensure you have the following prerequisites prepared:

  1. A Linux VPS: A virtual machine running Ubuntu 22.04 LTS or 24.04 LTS with at least 1 vCPU and 1GB of RAM.
  2. Docker and Docker Compose: Installed and verified on the server engine.
  3. A Registered Domain/Subdomain: An A record pointing to your VPS public IP address (e.g., filestash.yourcompany.com).
  4. Reverse Proxy Configured: Access to Nginx, Caddy, or Traefik to handle SSL/TLS termination via Let's Encrypt, securing all administrative data transit.

Step-by-Step Deployment Guide via Docker Compose

Deploying FileStash via Docker Compose is the most maintainable and production-ready method, ensuring isolated configurations and simple system upgrades. Follow the structured process below to initialize your instance.

Step 1: System Directory and File Structure Creation

Connect to your VPS via SSH and establish a dedicated directory architecture to persist your FileStash configuration parameters outside the lifecycle of the containerized application:

mkdir -p /opt/filestash/data
cd /opt/filestash

Step 2: Crafting the Docker Compose File

Utilize a text editor like nano to generate a production-ready docker-compose.yml file:

nano docker-compose.yml

Populate the file with the following configuration block, ensuring correct formatting:

version: '3.8'

services:
  filestash:
    image: mickaelperrin/filestash:latest
    container_name: filestash
    restart: always
    ports:
      - "8334:8334"
    volumes:
      - ./data:/app/data
    environment:
      - APPLICATION_URL=https://filestash.yourcompany.com
      - ONLYOFFICE_URL=http://onlyoffice:80

  onlyoffice:
    image: onlyoffice/documentserver:latest
    container_name: filestash_onlyoffice
    restart: always
    expose:
      - "80"
Note: The application URL environment variable is essential for ensuring correct CORS handling and generating secure share links later. The optional inclusion of OnlyOffice enables collaborative enterprise document processing.

Step 3: Orchestrating the Containers

Execute the command to pull the required image layers and initialize your unified cloud storage daemon in a detached background state:

docker compose up -d

Verify that both containers are running successfully and mapping the system ports efficiently by invoking docker compose ps.

Securing Traffic with a Reverse Proxy

To guarantee that login credentials and data streams are encrypted end-to-end, a reverse proxy must manage HTTPS requests. Below is a sample configuration snippet for an Nginx virtual host deployment:

server {
    listen 80;
    server_name filestash.yourcompany.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl;
    server_name filestash.yourcompany.com;

    ssl_certificate /etc/letsencrypt/live/filestash.yourcompany.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/filestash.yourcompany.com/privkey.pem;

    location / {
        proxy_pass http://127.0.0.1:8334;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        
        # Websocket support
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "Upgrade";
    }
}

Consolidating Storage backends: S3, MinIO, and SFTP

With your environment operational and accessible via https://filestash.yourcompany.com, navigate to the setup page to establish an administrative password. Once inside the administrative panel, you can begin provisioning storage endpoints.

1. Integrating Object Storage (Amazon S3 / MinIO)

To bind an S3 bucket into your consolidated environment, select "S3" from the backend provider list. Fill in the required parameters: Access Key ID, Secret Access Key, Bucket Name, and Region. For self-hosted enterprise alternatives like MinIO, you must also specify the custom endpoint URI (e.g., https://minio.internal.net). Once verified, your objects are rendered instantly as files and directories.

2. Unifying SFTP Systems

Connecting legacy infrastructure is equally streamlined. Select "SFTP", provide the target hostname, port (typically 22), the target username, and upload the private SSH identity key or input the associated password securely. FileStash maps the secure shell file transfer sub-system flawlessly, allowing system administrators to read and write blocks to servers deep inside the enterprise perimeter.

Enterprise Security Best Practices

Operating a centralized data gateway necessitates rigid adherence to robust security operational models:

  • Enable Multi-Factor Authentication (MFA): Enforce strict MFA policies for all administrative accounts accessing the console.
  • Restrict Administrative Access: Lock down access to the /admin routing paths via firewall rules or reverse proxy IP restrictions, allowing only verified corporate IPs to make system-level changes.
  • Audit Data Actions: Monitor host system logs regularly to identify unusual access patterns or massive extraction operations.

Conclusion

Self-hosting FileStash on a Docker VPS transforms how modern digital businesses interact with disparate storage vectors. By abstracting away protocol complexities, it provides an elegant, scalable single pane of glass for object storage, secure shell transfers, and internal network drives. Implementing this framework eliminates software fragmentation, reinforces secure asset orchestration, and scales operational velocity across your entire enterprise architecture.

Self-Hosting FileStash on Docker VPS: Centralizing S3, SFTP, and Cloud Storage into a Single Unified Interface | DPTCloud