Skip to content

Self-host Seafile

updated Sep 2026prices checked · Jul 2026
We earn commissions when you shop through the links below. Full disclosure →

File sync and share built around libraries: each one syncs separately with delta transfers and resumable uploads, and any library can be encrypted on the desktop client with a password the server never stores. The Community Edition server core is AGPL-3.0 with an Apache-2.0 web UI; the Professional Edition adds full-text search, file locking, audit logs and S3 storage, and is free for up to three users.

Key facts

LicenseAGPL-3.0
StackC, Go, Python
Min RAM2048 MB
Official imageyes
Difficulty
Our recommendation

Pick Seafile when file sync and share is the whole job and you want it done by a dedicated engine: files live in libraries that sync selectively, uploads "only transfer content delta to the server" and resume if interrupted, and any library can be encrypted on the desktop client with a password that "is not stored on the server". The Community Edition's server core is AGPL-3.0 and its Seahub web UI Apache-2.0; the official Docker setup is five containers — `seafileltd/seafile-mc`, MariaDB, Redis, the SeaDoc editor and a Caddy proxy that takes ports 80 and 443 and handles Let's Encrypt. Upstream's floor for the Community Edition is 2 GB of RAM and two cores. If you also want calendar, contacts and calls, Nextcloud is the fit; Seafile is the focused file server.

What you need

  • Any VPS with at least 2048 MB of RAM
  • A domain you control — most self-hosted setups need HTTPS in front of them
  • About an afternoon — budget time for troubleshooting
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + US
Get Hetzner Cloud (opens in new tab)
Kamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + Asia
Start free on Kamatera → (opens in new tab)
DigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + Asia
Deploy on DigitalOcean → (opens in new tab)

Paid link — we earn a commission if you shop through it.

Install

Run these commands on your server:

# Seafile Community Edition — the official Docker setup: Seafile, MariaDB, Redis, SeaDoc and Caddy
mkdir /opt/seafile && cd /opt/seafile
wget -O .env https://manual.seafile.com/13.0/repo/docker/ce/env
wget https://manual.seafile.com/13.0/repo/docker/ce/seafile-server.yml
wget https://manual.seafile.com/13.0/repo/docker/seadoc.yml
wget https://manual.seafile.com/13.0/repo/docker/caddy.yml
# In .env set SEAFILE_SERVER_HOSTNAME, JWT_PRIVATE_KEY (32+ random characters; upstream suggests `pwgen -s 40 1`),
# SEAFILE_MYSQL_DB_PASSWORD, INIT_SEAFILE_MYSQL_ROOT_PASSWORD, and INIT_SEAFILE_ADMIN_EMAIL / _PASSWORD
# (the admin defaults are me@example.com / asecret). SEAFILE_SERVER_PROTOCOL=https gets a Let's Encrypt cert via Caddy.
nano .env
docker compose up -d
# Caddy listens on 80 and 443  →  http(s)://SEAFILE_SERVER_HOSTNAME

What you take on

Seafile's manual is direct about how it stores data and what its encryption does not cover:

non-negotiableFiles are not stored as files. The manual says they "are split to blocks, which means what are stored on your seafile server are not complete files, but blocks", for deduplication. You cannot copy a document out of /opt/seafile-data; seaf-fuse gives a read-only mount for admins (encrypted libraries excluded). Backups must include the three databases — ccnet_db, seafile_db, seahub_db — and the data directory, and upstream recommends dumping the databases first, because the other order can leave libraries corrupted on restore.
non-negotiableDeleting files does not free disk. Blocks may be shared by other files, so Seafile needs its garbage collector: inside the container, /opt/seafile/seafile-server-latest/seaf-gc.sh (with --dry-run to see what it would remove) cleans up blocks from deleted libraries and history beyond each library's retention limit.
non-negotiableEncrypted libraries are end-to-end only when syncing with the desktop client (not in the browser or the client's cloud file explorer). Per the security page, file and folder names, sizes and edit history are not encrypted; opening an encrypted library in the browser sends the password to the server, which caches it in memory for an hour; a library created in the web UI passes its keys through the server; and the iOS and Android clients dropped client-side encryption in 3.0.0. Forget the password and the data cannot be recovered.
non-negotiableEdit .env before the first docker compose up: JWT_PRIVATE_KEY must be at least 32 random characters (upstream suggests pwgen -s 40 1), SEAFILE_SERVER_HOSTNAME is required, and the INIT_SEAFILE_ADMIN_* values — me@example.com / asecret by default — only apply on first start. Set SEAFILE_SERVER_PROTOCOL=https for Caddy to obtain a certificate. Caddy mounts the Docker socket and binds 80 and 443; if another reverse proxy already holds them, upstream's "Use other reverse proxy" page lists the ports to expose instead.
non-negotiableThe Professional Edition is proprietary and free without a license file for up to three users. Seafile's own comparison table reserves full-text search, file locking, fine-grained folder permissions, LDAP/AD user sync, ADFS SSO, audit logs, antivirus, remote wipe, high availability and S3 storage for it, and Pro wants 4 GB and four cores with its default Elasticsearch (2 GB with SeaSearch). Upgrades: a maintenance release is a new image tag; major versions have their own steps in the upgrade guide — 13.0 made Redis the default cache and dropped the bundled Memcached.

An alternative to

Head-to-head

More in File sync & storage

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.