Skip to content

Self-host OpenCloud

updated Sep 2026prices checked · Jul 2026
We earn commissions when you shop through the links below. Full disclosure →

A Go file sync and share server built on ownCloud Infinite Scale's code and developed since 2025 by OpenCloud GmbH, part of Berlin's Heinlein Group. It runs with no database: files are stored as a normal folder tree on disk and their metadata in extended attributes. Spaces, share links, desktop and mobile apps, and Collabora for office editing through an optional compose module.

Key facts

LicenseApache-2.0
StackGo
Min RAM512 MB
Official imageyes
Difficulty
Our recommendation

Pick OpenCloud when file sync and share is the whole job and you want it without a database: it is an Apache-2.0 Go server built on ownCloud Infinite Scale's code and developed since 2025 by OpenCloud GmbH (Heinlein Group), and its default PosixFS driver stores files in the same folder tree users see, with metadata in extended attributes — backups are a snapshot of a stopped instance. The recommended install is the `opencloud-compose` repository, with Traefik for Let's Encrypt and switch-on modules for Collabora, Keycloak, Apache Tika search, ClamAV and a Radicale CalDAV/CardDAV server. Upstream's floor is 512 MB of RAM for up to 10 users. If you want calendar, contacts, calls and an app store in the same product, Nextcloud is the fit; if you already run oCIS with a lot of sharing on it, see ownCloud vs OpenCloud before moving.

What you need

  • Any VPS with at least 512 MB of RAM
  • A domain you control — most self-hosted setups need HTTPS in front of them
  • About an afternoon — budget time for troubleshooting
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + US
Get Hetzner Cloud (opens in new tab)
Kamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + Asia
Start free on Kamatera → (opens in new tab)
DigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + Asia
Deploy on DigitalOcean → (opens in new tab)

Paid link — we earn a commission if you shop through it.

Install

Run these commands on your server:

# OpenCloud — official opencloud-compose, stable branch (production image), Traefik + Let's Encrypt, per docs.opencloud.eu
# main tracks the rolling release; production uses the current stable-* branch (the name changes with each stable release)
git clone -b stable-7.2 https://github.com/opencloud-eu/opencloud-compose.git
cd opencloud-compose
cp .env.example .env
sudo mkdir -p /opt/opencloud/{config,data}
sudo chown -R 1000:1000 /opt/opencloud && sudo chmod -R 0700 /opt/opencloud
# In .env: comment out INSECURE=true; set OC_DOMAIN, COLLABORA_DOMAIN, TRAEFIK_DOMAIN, TRAEFIK_ACME_MAIL,
# INITIAL_ADMIN_PASSWORD, OC_CONFIG_DIR=/opt/opencloud/config, OC_DATA_DIR=/opt/opencloud/data, and
# COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml
# (or docker-compose.yml:traefik/opencloud.yml without Collabora). Each domain needs a DNS record.
nano .env
docker compose up -d
# open https://OC_DOMAIN — user admin, password from INITIAL_ADMIN_PASSWORD

What you take on

OpenCloud's docs are direct about the release streams, the storage rules and the limits of the built-in login:

non-negotiablePick the release stream on purpose. Rolling releases (opencloudeu/opencloud-rolling) ship every three weeks and are community-supported; production releases (opencloudeu/opencloud) come about every six months; LTS is only for subscription customers. The docs' single-container quick start uses the rolling image, and opencloud-compose's main branch tracks rolling — production deployments should check out the current stable-* branch, and moving between stable branches is an upgrade. Stop and back up config and data before every upgrade.
non-negotiableSet OC_CONFIG_DIR and OC_DATA_DIR to host directories owned by UID 1000 before the first start. Without them the compose file uses Docker's internal volumes, which upstream says "may be removed when containers are deleted". Any host account with UID 1000 can read those directories.
non-negotiablePosixFS needs a filesystem with extended attributes, and network storage must be fully POSIX-compliant (NFS v4.2+, mounted with noac). In the default mode the tree belongs to OpenCloud: change files by hand only while it is stopped, keep the extended attributes, and keep ownership correct. Installs made on the older DecomposedFS driver cannot be converted to PosixFS; the data has to be copied into a new instance.
non-negotiableThe built-in identity provider is aimed at up to 500 users and has "no Multifactor Authentication (MFA) and no migration path to other IDPs"; upstream recommends Keycloak for production. Login is OpenID Connect, so WebDAV and CalDAV clients that cannot do OIDC need an app token, or basic auth, which the compose file leaves off by default.
non-negotiableCalendar and contacts come from the Radicale module, with no web UI, and upstream supports them on a best-effort basis only, outside its enterprise support. Migration from oCIS or Nextcloud is an rclone copy of personal-space files — shares, public links, project spaces, trash, versions and metadata are not carried over. The 512 MB floor is upstream's bare-metal minimum for up to 10 users; it asks for 8 GB for up to 1,000 users, and Collabora, search and antivirus add to both.

An alternative to

Head-to-head

More in File sync & storage

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.