Z-CMS public site runtime (Next.js) — renders themes in a hardened sandbox.
7.9K
zcms/site-runtime is the public site runtime of Z-CMS, a multi-tenant CMS with a theme engine and a signed plugin marketplace.
Part of a stack. This image runs alongside the other Z-CMS services — not on its own. Use the ready-made Compose stack below.
git clone https://github.com/zscontributor/z-cms-docker-offical-image.git zcms
cd zcms && cp .env.example .env && ./scripts/generate-secrets.sh --write
docker compose up -d && ./scripts/first-run-seed.sh
Reverse-proxy examples (Traefik, Caddy, Nginx, Apache, Portainer) and the full operator guide live in the z-cms-docker-offical-image repository.
The Next.js app that renders every public site with its active theme, on port 3000. Because it evaluates third-party theme code in-process, it is hardened — read_only, cap_drop: ALL, non-root — and is never given the database, Redis or S3 credentials, only a read-only render token. Themes are verified against a pinned public key before they load.
X.Y.Z — an exact, immutable release (pin this in production)X.Y — the latest patch on that minor linelatest — the newest releaseAll tags are multi-arch: linux/amd64 + linux/arm64.
Licensed under MIT · © Z-SOFT Co., Ltd.
Content type
Image
Digest
sha256:7171b15f2…
Size
99.4 MB
Last updated
3 days ago
docker pull zcms/site-runtime