Sign inSign up

ssiroos/chaparkhoneh

By ssiroos

•Updated 13 days ago

private, self-hosted communication app that brings your mailbox, messaging together in one workspace

Image
Web servers
Databases & storage
0

637

ssiroos/chaparkhoneh repository overview

⁠ChaparKhoneh

ChaparKhoneh is a private, self-hosted communication app that brings your mailbox, messaging, contacts, and calendar together in one workspace. It can be installed on desktop and mobile as a PWA and includes optional private AI tools powered by a local GGUF model.

PWAApps⁠ ·

⁠Features

  • Mailbox client for Inbox, Sent, Outbox, Drafts, and custom mail folders
  • Compose, reply, reply all, forward, search, tags, stars, and bulk mail actions
  • Direct messaging plus private groups and channels with encrypted file attachments
  • Private contact management and address book
  • Day, week, and month calendar views for events received by email
  • Notifications for newly received mail and messages
  • Installable desktop and mobile PWA with light and dark themes
  • Optional private AI assistant and selected-email summaries using a local GGUF model
  • Administrator controls for users, mail servers, messaging, AI, and registration
  • Persistent database, object storage, and encryption-key storage

AI is inactive until the installation has a valid ChaparKhoneh licence. After registration, an administrator can enable the internal GGUF provider from the Admin panel. Mail and AI data stay on the deployed server when the internal provider is used.

⁠Quick start with Docker Compose

Create an empty directory, save the following as compose.yaml, and create an llm-models directory beside it. The model directory may remain empty when AI is not needed.

services:
  app:
    image: ${CHAPARKHONEH_IMAGE:-ssiroos/chaparkhoneh:latest}
    restart: unless-stopped
    depends_on:
      db:
        condition: service_healthy
      minio:
        condition: service_healthy
    environment:
      ASPNETCORE_ENVIRONMENT: Production
      ASPNETCORE_URLS: http://+:8080
      ConnectionStrings__DefaultConnection: Server=db;Port=3306;Database=chaparkhone;User=chaparkhone;Password=${DB_PASSWORD}
      DataProtection__KeysPath: /keys
      SeedUser__Enabled: "true"
      SeedUser__UserName: ${ADMIN_USERNAME:-sa}
      SeedUser__Email: ${ADMIN_EMAIL}
      SeedUser__Password: ${ADMIN_PASSWORD}
      SeedUser__FullName: ${ADMIN_FULL_NAME:-System Administrator}
      Minio__Endpoint: minio:9000
      Minio__AccessKey: ${MINIO_ACCESS_KEY}
      Minio__SecretKey: ${MINIO_SECRET_KEY}
      Minio__Bucket: chaparkhone-messaging
      Minio__UseSsl: "false"
      InternalLlm__ModelPath: /models/Qwen3-1.7B-GGUF/Qwen3-1.7B-Q4_K_M.gguf
    ports:
      - "8080:8080"
    volumes:
      - data-protection-keys:/keys
      - ./llm-models:/models:ro

  db:
    image: mariadb:11.4
    restart: unless-stopped
    environment:
      MARIADB_DATABASE: chaparkhone
      MARIADB_USER: chaparkhone
      MARIADB_PASSWORD: ${DB_PASSWORD}
      MARIADB_ROOT_PASSWORD: ${DB_ROOT_PASSWORD}
    volumes:
      - database:/var/lib/mysql
    healthcheck:
      test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
      interval: 5s
      timeout: 5s
      retries: 20

  minio:
    image: minio/minio:RELEASE.2025-09-07T16-13-09Z
    restart: unless-stopped
    command: server /data
    environment:
      MINIO_ROOT_USER: ${MINIO_ACCESS_KEY}
      MINIO_ROOT_PASSWORD: ${MINIO_SECRET_KEY}
    volumes:
      - object-storage:/data
    healthcheck:
      test: ["CMD", "wget", "--spider", "-q", "http://localhost:9000/minio/health/live"]
      interval: 5s
      timeout: 5s
      retries: 20

volumes:
  database:
  data-protection-keys:
  object-storage:

Create .env in the same directory and replace every example secret:

DB_PASSWORD=replace-with-a-long-random-password
DB_ROOT_PASSWORD=replace-with-a-different-random-password
[email protected]
ADMIN_PASSWORD=replace-with-a-strong-admin-password
MINIO_ACCESS_KEY=chaparkhone
MINIO_SECRET_KEY=replace-with-a-long-random-secret

Start the stack:

docker compose up -d

Open http://localhost:8080, sign in with the administrator values from .env, and change SeedUser__Enabled to "false" after the initial administrator has been created. Existing administrator passwords are not overwritten by the seeder.

⁠Registration and local AI

Register the installation from Admin panel → Register. Licence tokens are accepted only when signed with RSA-SHA256 and issued for the installation's device UUID. The verification public key is embedded in the application image and cannot create licences.

To use local AI, place a compatible GGUF model at the path configured by InternalLlm__ModelPath, restart the app, then select Admin panel → AI Integration → Self — internal GGUF. Model files are mounted read-only and are not included in this image. Choose a quantization that fits the host's available RAM.

⁠Updating

docker compose pull
docker compose up -d

Back up all three named volumes before upgrades. In particular, losing the encryption keys makes previously encrypted contact and messaging data unreadable.

⁠Reverse proxy

Expose ChaparKhoneh through an HTTPS reverse proxy for internet-facing deployments. Keep MariaDB and MinIO private; only the application port needs to be published.

For product information and other PWA applications, visit pwaapps.com⁠.

Tag summary

Content type

Image

Digest

sha256:d2bae9a58…

Size

159.6 MB

Last updated

13 days ago

docker pull ssiroos/chaparkhoneh