Sign inSign up

hlhd/hubzilla

By hlhd

•Updated 9 days ago

Hubzilla and its official addons, built at a pinned upstream revision.

Image
0

694

hlhd/hubzilla repository overview

⁠hubzilla

A rootless container image for Hubzilla⁠ — the federated social platform built around nomadic identity: a channel is a portable, cryptographically-owned thing that can live on several hubs at once, so an account outlives the server it was created on. Hubzilla speaks its native Zot protocol and ActivityPub (Mastodon, Pixelfed, Lemmy, …), and puts an access-control list on every object — each post, photo, file, wiki page and event. Core and the official addon set are cloned at a pinned upstream ref at build time and baked in.

GitHub GitLab license Open Issues Open PRs Contributors donate sponsor

release build Last Commit StageFreight

GHCR Docker pulls Harbor

latest updated size latest-dev updated size

⁠Documentation
Topic
Configuration⁠Environment reference, writable paths, database, proxy requirements and background jobs
⁠What Hubzilla is
Nomadic identityClone a channel to another hub — both copies stay in sync and either can serve it. Losing a hub does not lose the identity, the connections, or the posts
Permissions per objectEvery item carries its own ACL, addressable to individuals, privacy groups or the public — not a fixed public/followers/DM ladder
Two federation stacksZot natively; ActivityPub through the bundled pubcrawl addon, so the same channel is reachable from Mastodon and friends
Single sign-on, remoteOpenWebAuth recognises visitors from other Zot hubs and grants them exactly what their ACL allows — no account needed here
More than a timelineChannels, forums, WebDAV cloud storage, wikis, published webpages, CalDAV calendars and events — one app, one permission model
Curation-friendlyRegistration policy, per-channel permission roles and connection filters make a small, deliberately-scoped hub practical to run
⁠What this image adds
Pinned buildCore + addons are fetched at a fixed ref during docker build. The running version is the tag you deployed, not whatever upstream master was when the pod last restarted
RootlessRuns as www-data with a read-only root filesystem — the only writable paths are mounts
Mail that leavesAn msmtp sendmail shim reads SMTP_* from the environment at send time, so registration, password resets and notifications work and no relay password lands in a layer
Routing ships with itHubzilla routes on a q= parameter, answers .well-known from index.php, and needs the Authorization header for DAV. Those are the app's rules, so nginx and its config are in the image — not retyped into every deployment, and not left behind by an upgrade
Serves HTTP directlynginx + php-fpm under tini on port 8080. One container, no sidecar, no supervisor

⁠Image contents

Base image & installed components (click to expand)

Base Image:

php 8.3

PHP extensions: gd (freetype + jpeg), pdo, pdo_mysql, zip, exif, intl, bcmath, gmp, imagick

Packages (apt): nginx, tini, imagemagick, msmtp, libzip4

Pinned components — see components.json⁠:


⁠Installation

Pull the image (ghcr primary, Docker Hub mirror):

docker pull ghcr.io/homelabhd/hubzilla:latest
# or
docker pull docker.io/hlhd/hubzilla:latest

Or build it — the refs are required, there is no floating default:

git clone https://github.com/HomeLabHD/hubzilla
cd hubzilla
docker build -t hlhd/hubzilla \
  --build-arg HUBZILLA_REF=11.4 \
  --build-arg ADDONS_REF=11.4 .

Hubzilla needs a MySQL/MariaDB or PostgreSQL database, a mounted .htconfig.php, and persistent storage for store/. The container serves HTTP on 8080 and needs no web server in front of it beyond your TLS terminator — pass X-Forwarded-Proto, or the session cookie is issued without Secure and browsers discard it. All of it is in Configuration⁠.

⁠Contributing

  • Fork the repository
  • Submit Pull Requests / Merge Requests
  • File issues⁠ with image tag, run/compose command, and environment details

⁠Credits

  • Powered by Hubzilla⁠ — the nomadic, permission-first fediverse platform, and the community that keeps it going
  • Builds pull from HomeLabHD mirrors of the upstream repositories; upstream remains framagit.org/hubzilla⁠

⁠Disclaimer

The Software provided hereunder ("Software") is licensed "as-is," without warranties of any kind — express, implied, or federated to you by a hub you have never heard of. The developer makes no promises about functionality, performance, compatibility, security, or availability. Not liable if your nomadic identity wanders off to a hub with better vibes and declines to come back, if an access-control list you set in 2019 is the only reason your relatives cannot see your photos, or if pinning the upstream ref gives you such a smug sense of reproducibility that you forget to back up your database.

Any positive experiences are owed entirely to the brilliant folks behind Hubzilla and the unstoppable force that is the Open Source community. The developer claims no credit for anything that actually goes right.

⁠License

Hubzilla is distributed under the MIT⁠ license. This packaging is maintained by HomeLabHD.

Tag summary

Content type

Image

Digest

sha256:763b3468a…

Size

307.2 MB

Last updated

10 days ago

docker pull hlhd/hubzilla