Sign inSign up

frimurare/wulfvault

By frimurare

•Updated about 2 months ago

Self-hosted secure file sharing: branded links, SSO, 2FA, GDPR tools, audit log. v7.2.0

Image
Integration & delivery
Web servers
Databases & storage
0

3.2K

frimurare/wulfvault repository overview

⁠WulfVault — Secure Self-Hosted File Sharing

Current version: 7.2.0 "Grease Monkey" (2026-08-07) · AGPL-3.0 · GitHub⁠ · Changelog⁠

Enterprise file sharing you run yourself: branded download pages, share links with password/expiry/download limits, download-recipient accounts with GDPR self-service, teams, 2FA, SSO (Microsoft Entra ID or any OpenID Connect provider), full audit log — in a single container.

⁠What's new in 7.2.0

  • Smart chunked downloads — 25 MB chunks with progress (speed + ETA), auto-retry, resume after browser restart, SHA-256 verification. 15 GB+ files download without holding the file in RAM.
  • Swedish and English UI — language switcher, per-user preference, server default.
  • Share emails explain the identity check when authentication is required — why it exists, how it works, and that the account can be deleted right after downloading.
  • Security hardening — signed download cookies, share passwords removed from the file list API, cryptographically random initial admin password, irreversible GDPR anonymization (with automatic migration), HTTPS preserved in invitation links, Remember Me fixed for download accounts.
  • First test suite — 250+ test cases.

Upgrading with Docker picks everything up automatically — binary, static files and database migrations are all in the image. See the release notes⁠ for details.

⁠Quick start

docker run -d --name wulfvault \
  -p 8080:8080 \
  -v wulfvault-data:/data \
  -v wulfvault-uploads:/uploads \
  frimurare/wulfvault:latest

Open http://localhost:8080 — the initial admin password is printed in the container log on first start (docker logs wulfvault), or set ADMIN_PASSWORD yourself.

⁠Volumes & environment

/dataDatabase and configuration
/uploadsUploaded files
PORTListen port (default 8080)
SERVER_URLPublic URL used in emails and share links
ADMIN_PASSWORDInitial admin password (otherwise randomly generated and logged)

⁠Tags

  • latest — most recent stable release
  • 7.2.0, 7.1.1, … — pinned versions

Behind a TLS proxy? Set SERVER_URL to your https address — 7.2.0 no longer rewrites invitation links to http.

Tag summary

Content type

Image

Digest

sha256:8b51a44ae…

Size

14.9 MB

Last updated

about 2 months ago

docker pull frimurare/wulfvault