Skip to content

Self-host Ente

updated Sep 2026prices checked · Jul 2026
We earn commissions when you shop through the links below. Full disclosure →

End-to-end encrypted photo and video backup — Ente Photos, with its self-hostable server, museum. Files and metadata are encrypted on your device before upload, and face recognition and natural-language search run on your phone or desktop rather than the server. Apps for iOS, Android, desktop and web.

Key facts

LicenseAGPL-3.0
StackGo, PostgreSQL
Min RAM1024 MB
Official imageyes
Difficulty
Our recommendation

Pick Ente when the reason you are leaving Google Photos is that someone else can see your library — and you want that to stay true on your own server. Files and metadata are end-to-end encrypted on the device, face recognition and magic search run in the mobile and desktop apps, and the server (museum, a Go binary) runs on upstream's 1 GB floor under AGPL-3.0. If you would rather have smart search in the browser and a server that does the indexing for you, Immich is the catalog's other phone-backup pick.

What you need

  • Any VPS with at least 1024 MB of RAM
  • A domain you control — most self-hosted setups need HTTPS in front of them
  • About an afternoon — budget time for troubleshooting
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + US
Get Hetzner Cloud (opens in new tab)
Kamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + Asia
Start free on Kamatera → (opens in new tab)
DigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + Asia
Deploy on DigitalOcean → (opens in new tab)

Paid link — we earn a commission if you shop through it.

Install

Run these commands on your server:

# Ente — official quickstart: writes my-ente/compose.yaml + museum.yaml with generated credentials
sh -c "$(curl -fsSL https://raw.githubusercontent.com/ente/ente/main/server/quickstart.sh)"
# answer n at the start prompt to run it in the background yourself:
cd my-ente && docker compose up -d  #  →  http://localhost:3000 (API on :8080)
# on a VPS, phones and remote browsers need museum (8080) and the bucket (3200) on a reachable address, not localhost — set them in compose.yaml and museum.yaml

What you take on

Ente's self-hosting docs are candid about where a new install goes wrong, and end-to-end encryption adds a rule of its own:

non-negotiableUploads go straight from the client to an S3-compatible bucket through pre-signed URLs, and the quickstart sets the bucket endpoint to localhost:3200. On a phone that address is the phone, so mobile uploads fail silently (museum logs OBJECT_SIZE_FETCH_FAILED). Set the endpoint in museum.yaml to a LAN IP or a domain both museum and your devices can reach, and expect to set bucket CORS if you use the web app over an IP.
non-negotiableKeep museum.yaml safe — upstream says that without the credentials in it, Ente cannot access the data in the volumes. A backup needs the database as well as the bucket: the encrypted files are unusable without the per-file keys the database holds. Upstream recommends keeping a plaintext export of your photos until you have a tested backup and restore.
non-negotiableEnd-to-end encryption means nobody can reset your way back in. If you are logged out of every device and have lost both your password and your 24-word recovery key, the data cannot be decrypted — running the server yourself does not change that. Save the recovery key before you upload anything.
non-negotiableMachine learning is client-side: the web app has no face or magic search, and indexing a large library is best started on the desktop app. The first registered user is treated as admin until you whitelist one in museum.yaml, verification codes appear in the server logs until SMTP is configured, and storage quotas are raised per user with the Ente CLI (ente admin update-subscription).

An alternative to

Head-to-head

More in Photo backup & gallery

Common questions

How much RAM does Ente need?

Ente's requirements page asks for a minimum of 1 GB of RAM and 1 CPU core for the cluster the quickstart script starts. The server is a Go binary, and the heavy work — encryption, face recognition and search indexing — happens on the client devices, not on the server.

Can I self-host Ente with Docker?

Yes — Ente's quickstart script (it needs Docker Compose 2.30 or newer) creates a my-ente folder with compose.yaml and museum.yaml, and offers to start museum (the API on port 8080), the web app (Photos on 3000, public albums on 3002), PostgreSQL and a MinIO-style S3 bucket on 3200. Keep museum.yaml safe: upstream warns that without its credentials Ente cannot access the data in the volumes.

Why do uploads from my phone fail on a fresh Ente install?

The quickstart sets the bucket endpoint to localhost:3200, and museum hands that address to clients inside pre-signed upload URLs. On a phone, localhost is the phone itself, so the upload never reaches the bucket. Set the endpoint in museum.yaml to an address both the server and your devices can reach — a LAN IP or a domain behind a reverse proxy.

Is Ente a good Google Photos alternative?

It is the one to pick if privacy is the reason you are leaving: photos and metadata are end-to-end encrypted, and face recognition and magic search run on your own phone or desktop. The desktop app imports a Google Takeout export and reads its JSON metadata. The trade-offs are no machine-learning search in the web app, and no way back in if you lose both your password and your recovery key.

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.