Sign inSign up

varavel/nsqlite

By varavel

•Updated 5 months ago

SQLite over the network with optional Litestream integration

Image
2

718

varavel/nsqlite repository overview

NSQLite logo

SQLite over the network.

CI Status ⁠ Go Report Card ⁠ Release Version ⁠ License ⁠ ⁠

A Varavel project ⁠

⁠Overview

nsqlite runs a docker-first SQLite-backed HTTP server and ships with a container image that can optionally wrap the process with litestream for continuous replication to any S3-compatible object store.

Container images are published to both Docker Hub and GitHub Container Registry with matching tags:

  • Docker Hub: varavel/nsqlite:<tag>
  • GHCR: ghcr.io/varavelio/nsqlite:<tag>

For the full documentation site (including an interactive API explorer), visit nsqlite.varavel.com⁠.

⁠Quick Start

Run NSQLite without Litestream using Docker Compose:

services:
  nsqlite:
    image: varavel/nsqlite:latest
    ports:
      - "9876:9876"
    volumes:
      - ./data:/data
    ulimits:
      nofile:
        soft: 65536
        hard: 65536

Run NSQLite with Litestream and an S3-compatible replica using Docker Compose:

services:
  nsqlite:
    image: varavel/nsqlite:latest
    ports:
      - "9876:9876"
    volumes:
      - ./data:/data
    environment:
      NSQLITE_LITESTREAM_ENABLED: "true"
      NSQLITE_LITESTREAM_S3_BUCKET: my-backups
      NSQLITE_LITESTREAM_S3_PATH: db-backup/database.sqlite
      NSQLITE_LITESTREAM_S3_ENDPOINT: https://minio.example.com:9000
      NSQLITE_LITESTREAM_S3_REGION: us-east-1
      NSQLITE_LITESTREAM_S3_ACCESS_KEY_ID: your-access-key
      NSQLITE_LITESTREAM_S3_SECRET_ACCESS_KEY: your-secret-key
    ulimits:
      nofile:
        soft: 65536
        hard: 65536

⁠NSQLite Configuration

The container always configures NSQLite through environment variables and it has sane default values.

VariableContainer defaultDescription
NSQLITE_AUTH_TOKENunsetAdmin token list. Use space-separated plaintext tokens or bcrypt/argon2id hashes for full access.
NSQLITE_AUTH_TOKEN_RWunsetRead/write token list. Use space-separated plaintext tokens or bcrypt/argon2id hashes for query read/write access only.
NSQLITE_AUTH_TOKEN_ROunsetRead-only token list. Use space-separated plaintext tokens or bcrypt/argon2id hashes for query read access only.
NSQLITE_DATA_DIR/dataDirectory used by NSQLite to store its SQLite files. The main database file is always ${NSQLITE_DATA_DIR}/database.sqlite.
NSQLITE_LISTEN_HOST0.0.0.0Host/interface NSQLite binds to inside the container.
NSQLITE_LISTEN_PORT9876TCP port used by the HTTP server.
NSQLITE_TX_IDLE_TIMEOUT10sMaximum idle time for an open transaction before it is rolled back.
NSQLITE_MAX_READ_CONNS10Maximum number of read-only SQLite connections.
NSQLITE_CACHE_SIZE_KB20000SQLite cache size in KB per connection.
NSQLITE_BUSY_TIMEOUT5sHow long SQLite waits when the database is locked by another writer.
NSQLITE_MAX_REQUEST_SIZE_MB100Maximum HTTP body size accepted by the /query endpoint.

⚠️ Important: Auth tokens security

Always prefer using token hashes over plaintext tokens. The recommended algorithm is Argon2ID, followed by Bcrypt as a secondary option. Plaintext tokens are discouraged, as they can be exposed if environment variables or the container are compromised.

Browser access: NSQLite is designed to run on servers. If browser-based access is needed (e.g. for a web based DB explorer), place NSQLite behind a reverse proxy like Nginx or Caddy and configure CORS headers there.

⁠rqlite Compatibility

NSQLite is compatible with the rqlite HTTP API⁠ request and response format. However, whenever possible, use NSQLite's native RPC format.

⁠Litestream Configuration

When NSQLITE_LITESTREAM_ENABLED=true, the container writes a Litestream config that uses the explicit S3-compatible configurations.

Credentials are intentionally not written to the generated YAML file. The entrypoint translates the S3 credential variables into the runtime environment that Litestream expects.

⁠Required Litestream Variables

These variables are required when NSQLITE_LITESTREAM_ENABLED=true.

VariableDescription
NSQLITE_LITESTREAM_ENABLEDSet to true to run NSQLite under Litestream.
NSQLITE_LITESTREAM_S3_BUCKETBucket or container name used for the replica.
NSQLITE_LITESTREAM_S3_PATHObject path inside the bucket for the replica data.
NSQLITE_LITESTREAM_S3_ENDPOINTS3-compatible endpoint. Examples: s3.us-east-1.wasabisys.com, https://minio.example.com:9000, http://localhost:9000.
NSQLITE_LITESTREAM_S3_REGIONReplica region. Use the provider value that matches the target bucket.
NSQLITE_LITESTREAM_S3_ACCESS_KEY_IDAccess key used by Litestream.
NSQLITE_LITESTREAM_S3_SECRET_ACCESS_KEYSecret key used by Litestream.
⁠Optional Litestream Variables
VariableDefaultDescription
NSQLITE_LITESTREAM_S3_SESSION_TOKENunsetOptional session token when temporary credentials are used.
NSQLITE_LITESTREAM_CONFIG_PATH/tmp/litestream.ymlWhere the container writes the generated Litestream config file.
NSQLITE_LITESTREAM_LOG_LEVELinfoLitestream log level written into the generated config.
NSQLITE_LITESTREAM_LOG_FORMATtextLitestream log format written into the generated config.
NSQLITE_LITESTREAM_SNAPSHOT_INTERVAL24hSnapshot creation interval.
NSQLITE_LITESTREAM_SNAPSHOT_RETENTION168hSnapshot retention period.
NSQLITE_LITESTREAM_SYNC_INTERVAL1sHow often Litestream syncs changes to the replica.
NSQLITE_LITESTREAM_VALIDATION_INTERVAL5mHow often Litestream validates replica state.

⁠Notes for S3-Compatible Providers

  • If your provider accepts an endpoint without a scheme, you can pass it directly. Litestream assumes HTTPS by default.
  • For local development, an explicit http:// endpoint is valid.
  • The endpoint and region must match the target provider and bucket configuration.
  • This image keeps the configuration surface intentionally small. Advanced provider-specific settings should be added only when there is a concrete need.

⁠License

This project is released under the MIT License. See LICENSE⁠.

Tag summary

Content type

Image

Digest

sha256:1ddd3499d…

Size

47.1 MB

Last updated

5 months ago

docker pull varavel/nsqlite