Self-hosted alternatives to popular cloud services
liminality.xyz
liminality.xyz
Here's 43 self-hosted alternatives to popular cloud services, with one-click demos you can try yourself!
Tiny Tiny RSS, Ghost, Gitlab, and Rocket.Chat are in there.
ownCloud is missing, but you can try Davros, which is compatible with the ownCloud client apps. https://apps.sandstorm.io/app/8aspz4sfjnp8u89000mh2v1xrdyx97...
Ampache is missing, but you could try Groove Basin for music -- it's neat in that you can share control of the playback with other people, to implement a communal music player. https://apps.sandstorm.io/app/wfg1r0qra2ewyvns05r0rddqttt57q...
(But also someone should package ownCloud and Ampache for Sandstorm! https://docs.sandstorm.io)
For any help regarding ownCloud internals, everyone is very welcome in our IRC channel #owncloud-dev (on freenode).
- A web IDE
- A container to run web stuff I'm working on (ie hook it up to the ide through rsync or something)
Eventually, we plan to support logging in using a PGP key.
We see "internal user stores" (e.g. basic username/password with no connected email address) as problematic because a major design goal of Sandstorm is the ability to move data between hosts easily. Say you and five friends have been using Rocket.Chat on Sandstorm Oasis, and then you decide to transfer it to a self-hosted Sandstorm server -- or vice versa. It would be nice if after moving, Rocket.Chat can still recognize your five friends and being the same people, so that you don't lose your PM history and such. This is only possible by using some form of federated identities which all Sandstorm servers can independently authenticate. Username/password is inherently per-server so doesn't provide that.
FWIW we're currently working on a change that will allow you to attach multiple such "identities" to a single account, after which we plan to open up the door to a lot more authentication providers, including other "open" federated options like OpenID or Shibboleth (as well as popular proprietary services like Twitter, Facebook, etc. -- again, it's up to each user to decide what's most convenient for them).
Probably at some point you'll be able to host your own IDP as a Sandstorm app, if that's what you want. Other Sandstorm servers would be able to rely on that IDP as well, so it meets the federated requirement.
Of course, we have a lot on our plate, so I can't guarantee anything. Happy to accept pull requests. :)
I would like to read the reasoning behind the individual choices OR the reasoning behind the overall choice of moving a way from big corp products.
It feels to much like a "look at my setup" posts, which are nice to read but it could be much better.
But, my input now:
OwnCloud is wonderful for file syncing but where it really shines is the contact and calendar sync. It is the easiest to install and best accessable web interface Cal/CardDAV software out there. Radicale is a wonderfull little python Cal/CardDAV server but it hasn't got a web interface which is a feature I do miss when I don't have it. OwnCloud is really pulling through on the whole "google replacement", work has been started on a mail client which looks very nice and works decently (for now).
Ampache is cool but I found the installation to be too fiddly and easy to break. It could be my incompetence with that product but I prefer subsonic. A java product which just runs and it runs well. The webinterface desperately needs a good UIoverall but it works and it doesn't get in the way.
RocketChat I don't know and I should look into but I do feel that XMPP should be the chat replacement for all. The fedearation, the gazillion clients and the maturity of the software is just so so nice that I am sad that it isn't more popular. I feel it's a huge shame google and facebook stopped fedarating their xmpp services.
It took more work to set up but I have Seafile self-hosted on the smallest DigitalOcean VPS and it works beautifully. $5/month, plenty of space for the amount of files I need to sync across machines, and my data is in Germany which is great (I'm in Europe). Native client-side encryption is built-in to the client so I have an easier configuration on local machines, and it does most of what I need.
I'm still looking for a good self-hosted CalDAV/CardDAV option that doesn't require PHP or MySQL, but as this data is less sensitive I'm happy to trust it to FastMail for now.
Did you host OwnCloud yourself? But you didn't trust the software with your files? In what way is the SeaFile solution you are running now more trustworthy?
> I'm still looking for a good self-hosted CalDAV/CardDAV option that doesn't require PHP or MySQL, but as this data is less sensitive I'm happy to trust it to FastMail for now.
http://radicale.org/ is exactly what you are looking for.
Yes, I prefer to self-host anything I can. I'm lucky to have a gigabit FTTH connection and moving lots of data around is no problem. I still prefer to use a remote VPS because some things are best left to the pros.
> But you didn't trust the software with your files? In what way is the SeaFile solution you are running now more trustworthy?
Seafile has a much smaller attack surface (no PHP, MySQL not required, etc) and handles the client-side encryption itself. We are discussing degrees of trust here, so while I was happy to trust ownCloud and the VPS to be there for a request, and to not corrupt my data, I didn't trust that my sensitive data was safe if the server was compromised. EncFS was a workaround, but it cluttered up Nautilus with extra drives since every encrypted directory had to be mounted as a drive. Now I'm comfortable trusting Seafile to do all that because an attacker would need to compromise both my VPS and my local machine to gain access to sensitive data. This is orders of magnitude less likely and for me is an acceptable risk, especially considering the simpler software stack.
And I'm definitely checking out radicale, thanks for the tip. If it does contact photo sync (annoyingly not currently supported my FastMail CardDAV) I'll give it a try.
I'm not sure how seriously to take this.
Development on Seafile is very active and they are transparent about security issues. I don't think it is poorly written but maybe a third-party audit like Truecrypt did is a good idea.
Here's their 'Records of security issues' page: https://seacloud.cc/group/3/wiki/security-records/
Just take a look who reported their recent issue allowing a lot of attack vectors. (more than they mentioned though) :)
Actually if somebody had a local user account themselves they could bruteforce the secret key in seconds. And SeaFile has additionally modified the default Django components making it more insecure: https://github.com/haiwen/seahub/commit/7cdb70368aa7acbf0546...
By the way, ownCloud does run a Bug Bounty: https://hackerone.com/owncloud
The constant time comparison is pretty irrelevant here. Check https://github.com/haiwen/seahub/commit/7cdb70368aa7acbf0546..., basically a valid password reset token in default Django requires an attacker to know:
- Primary Key of the user (User ID)
- Hashed version of the user password
- Timestamp of the last login (1 second accuracy)
- Number of days since 2001-1-1 converted to base 36
- The configured SECRET_KEY
Basically except the configured SECRET_KEY and the hashed version of the password everything is known to an attacker. And even if an attacker knows the SECRET_KEY they would not be able to generate a valid token as the old password hash is required.
However, Seafile has removed the hashed password out of their version of "tokens.py". This means that if somebody knows the SECRET_KEY they could create valid password reset tokens. That the initial SECRET_KEY was basically generated by `str(random.randint(0,100000))` did make this all much more worse… (https://github.com/haiwen/seahub/blob/b6f8935c0f355cc70145f9...)
Bad thing about this is that this basically makes a lot of old Seafile instances insecure unless they get a new SECRET_KEY. They did somewhat tell users to regenerate it within a forum post and some wiki page (https://seacloud.cc/group/3/wiki/whats-new-in-the-next-versi...) but that's not really a good way to spread awareness…
your original comment pointing to the commit said
> And SeaFile has additionally modified the default Django components making it more insecure
So I was under the impression that this commit was making things worse, not better. Thanks for clarifying that this was already fixed in this commit, rather than introduce a vulnerability. It looks like they added the hashed password on the diff to mitigate this issue - unless I am missing something here? Can you explain why they "partially mitigated the vulnerability" here? is there still some gap that they've missed?
I'm not underestimating the vulnerability, or the fact that it was there in the first place. Just trying to get a full(er) picture.
I've had a read through this, and some other places where insecurity of Seafile is exposed/discussed/fixed. I agree that the overall impression I'm getting is that they're not security experts, and security could have definitely been better designed or taken into account in the first place.
I still think they're trying to do their best, and fix problems and improve. I hope for their and their users' sake that they can get some security-dedicated contributors (mostly to prevent bad things in the first place rather than fixing them later on). There's always more that can be done, but I'd like to give them the benefit of the doubt here and have faith that things will be better in the long run. Having a (robustly) secure, open-source dropbox replacement is a good thing. I think that's their aim, even if they are some times misguided.
disclaimed: I'm not even a user of Seafile, let alone know much about its codebase. It's the first time I hear about it. I was just curious about the security aspects of their product in light of some criticism here and on github etc.
ownCloud does run a successful Bug Bounty program and is paying for security bugs: https://hackerone.com/owncloud
Also I have published a blog post elaborating why CVEs are not everything when it comes to comparing the security of products: https://statuscode.ch/2015/09/ownCloud-security-development-...
Furthermore please take a look at https://seacloud.cc/group/3/wiki/security-records/. Not using PHP doesn't make everything more secure magically, neither does using PHP make things more secure.
The ownCloud Android client required duplicate copies of all the photos & videos (the original plus a copy in the ownCloud folder) which filled up storage on my phone too quickly. Once this is sorted I might try it again, even if only for the calendar and contacts. It has many features but I just don't need most of them.
ownCloud does run a bug bounty program (https://hackerone.com/owncloud) and the company supporting the project also employs internal security experts.
You might also want to read https://statuscode.ch/2015/09/ownCloud-security-development-... which covers why comparing CVEs is not a reliably way to compare the security of products.
Baikal is PHP, but can run on sqlite instead of MySQL : http://baikal-server.com/
My compromise for the most part is having all of those services walled off behind vpn.
Agreed. Given that there are multiple, open source servers, several good open source Web clients and literally hundreds of native libraries/clients, XMPP seems like the obvious choice here.
What irks me even more - Rocket Chats homepage: > Native client applications available for download on Linux, Windows and OSX.
Rocket Chat's GitHub Repo for the "Native" desktop Apps: https://github.com/RocketChat/Rocket.Chat.Electron
Call it a desktop app, sure. I won't use it, but I won't begrudge you the term desktop app. If you're bundling NodeJS and using a webview, your app isn't native.
Firefox is pretty "native", yet practically all of the UI is powered by JS.
Hell some of the built in programs in windows 10 are using html/js/css and if you are going to argue that the built-in "part of the OS" programs aren't native, then what is?
If you can see performance issues or problems with how it works then point those out, don't just blanket knock an entire application because you don't like the languages it uses.
For instance, in Slack, which is more or less an Electron app / browser in a box, I can easily get it down to <5 fps just by posting a snippet or going too far in scrollback. Resizing the window is beyond painful, etc., etc. It all seems unbelievably unnecessary - why should a chat program, literally text on a screen, perform like this on a top-of-the-line quad-core i7 system?
web rendering doesn't automatically make an app slow. And in my experience choosing a "common" platform like the web allows an app to run everywhere. I'm not suddenly going to be able to triple my development speed, so without the common platform that means that i'd only be able to support one major platform, or all platforms but with a small fraction of the development speed, and most likely many more bugs.
And to be fair, saying slack is nothing more than "text on a screen" is really oversimplifying it. There are tons of formatting options, code highlighting, embedded HTML, embedded video and images, attachments, coloring, emojis, and more.
It seems like a pretty obvious choice to go with a web rendering engine seeing as it supports almost all of that "natively".
Firefox honestly is a terrible choice to defend non-native UI conventions. You might as well have picked Java apps as your argument.
Also, I’m glad you like the Mail app although it’s in a very early stage! If you experience any issues or have feature requests, please let us know at https://github.com/owncloud/mail/issues :)
Is there any way I can set up just the features I want, and disable the rest? I have very briefly looked over how to do this, but haven't found anything.
As a really dirty hack, meanwhile you could just hide the Files icon from the menu via CSS. But, well … ;)
I donated years ago to the project and I'm grandfathered into the 'premium' app.
I use ampache, but you are absolutely correct: it is fiddly, and breaks easy. Subsonic also does "just work". I personally like ampache because it's much less resource-intensive on my webserver, and easier to fiddle with (I'm also a java-hater), but Subsonic is much more approachable.
(Note of course that self-hosting is free...)
WordPress - https://wordpress.org/ - because "WordPress is the Kalashnikov of the web." (https://t.co/QgsYYUFTbo)
Syncthing - https://syncthing.net/ - for distributed file syncing
Baikal - http://baikal-server.com/ - for contact & calendar syncing
rss2email - https://pypi.python.org/pypi/rss2email - because email is stable, solid, and not going anywhere
Tox - https://tox.chat/ - p2p, encrypted instant messaging w/ video & audio
Regarding contact & calendar syncing, I just wish more apps could just use files instead of always setting a new server and reinventing the wheel to sync data. I still have not found a good way to export my calcurse calendar to my Android phone via files only.
I'm not quite sure what you'd gain by doing this process manually (export on one device, import on the other) rather than just using a {cal/card}dav server?
Moreover, it's much easier to set up, I share stuff with family and they didn't have problems setting it up.
https://bitnami.com/stack/ghost
https://bitnami.com/stack/owncloud
https://wiki.bitnami.com/Applications/BitNami_GitLab#How_to_...
We are working on verifying the upgrade instructions with the new major version recently released.
Happy to address any concerns or issues we missed
Unfortunately it's not open source but alone the fact that it can run on a peer to peer basis without the need of any external out of control cloud host is very appealing to me. With small devices such as raspberry pi or NUC becoming more powerful the approach has a bright future.
The idea is discussed for syncthing, https://github.com/syncthing/syncthing/issues/109
There is a 880 USD bounty on it at https://www.bountysource.com/issues/1474343-support-for-file...
[0] - http://www.mopidy.com
Also OwnCloud DOES NOT support "delta sync" (i.e. uploading file chunks when tiny portions of files are changed, instead of, for example, needing to upload the ENTIRE gigabytes-large file when only 10KB have changed). The core devs have kicked the can down the road at every opportunity (for example take a look at the huge BountySource bug for that issue, it's like USD 1200 or something, in addition to the issue being locked to contributors because of all the +1s). This means for any use case involving large files (e.g. TrueCrypt/VeraCrypt volumes), you will quickly find yourself in a messy situation of continually uploading gigabytes of data. It was painful to experience even on a gigabit LAN.
About the delta sync: There’s plans being made and work being done on it. It’s locked because all people get notified on every »+1« comment and that doesn’t help to focus and get actual work done. Besides, do you really believe that USD 1200 will swiftly take care of implementing this feature?
Your VPN provider can probably MITM that much like your ISP could but not without messing with the certificates that you're pinning.
You shouldn't have to do that but given the circumstances it'll work. Whether you can be bothered is another discussion.
I'm not ISP locked, but no other ISP offers me anything else since: "we don't offer worse service since we can offer you faster connection via TV cable".
Self-hosted WebRTC audio/video conferencing: https://github.com/jitsi/jitsi-meet
The Omnibus packages allow you to quickly install GitLab without having to do a lot of setup. The installation from source is also official, see https://about.gitlab.com/installation/
Its understandable why you wanted to bundle everything, and I bet it makes installation much easier for beginners and/or lazy sysadmins.
That said, it would be even better if the installation worked with existing software instead of installing its own copy of everything. It seems like apt package dependencies would be more elegant than bundling everything together.
Its great to have the installation from source as a supported option. But lets be honest, that's a world of pain that's simply unnecessary for a standard deployment.
- A happy GitLab user
The focus is on highlighting one (the best) alternative in a given field, and limit the ones listed to those which are well-designed, open source of course, and also have a hosted instance so it’s ready to use for anyone without a server.
I’m sure you already know of https://prism-break.org/ ?
Anyhow, there is really lots of good stuff that turned up in this entire thread.
GitHub: https://enterprise.github.com/home
NPM: https://www.npmjs.com/onsite
Travis CI: https://enterprise.travis-ci.com/
Circle CI: https://circleci.com/enterprise
Sysdig: https://sysdig.com/pricing/
CodeClimate: https://codeclimate.com/enterprise
Waffle.io: https://takeout.waffle.io
Coveralls: https://enterprise.coveralls.io/
Sense.io: https://sense.io/enterprise
RollBar: https://rollbar.com/enterprise/
BugSnag: https://bugsnag.com/enterprise
HipChat: https://www.hipchat.com/server
Docker Hub: https://www.docker.com/enterprise/hub/
Upverter: https://upverter.com/enterprise/
CoreOS Registry: https://tectonic.com/quay-enterprise/
Looker: http://www.looker.com/docs/admin/on-premise/installation
RedBooth: https://redbooth.com/en/enterprise/
OwnCloud - I just don't trust an American company to host my data. Now, is my small UK based host as likely to be as effective at protecting my data as DropBox? Maybe not - but they don't have a proponent of torture on their board, so it's swings and roundabouts.
TT-RSS - I couldn't find a decent RSS manager which I liked. TT does the job - and I'm not worried that someone will decide that Google+ is better and force me off.
Ampache - all of my music is stored as FLAC, which can be a PITA to transcode and/or stream. This sits on a box at home and I can listen to my music wherever I am. I'm not reliant on a corporation who might decide that my music isn't licensed correctly, or they don't want to support my hardware, etc.
Personally I use WordPress rather than Ghost - it's more flexible for my needs.
It’s pretty cool, basically like TT-RSS but it looks more modern and is integrated in ownCloud. There are also apps for almost all platforms, like apps for Android & iOS which download all articles (and even podcasts) for offline reading.
The reason I selfhost is this. We are on a rapid path towards home computing devices being nothing more than dumb terminals where some server in the distance hosts your OS, files and apps. All, of course, proprietary so as to make switching painful. I DO NOT WANT THIS. So, I use and root for the technologies that I want to see win. I want complete and unfettered access to my files.
There’s apps for Android & iOS which download all items for offline reading. The Android app can even download podcasts and videos of Youtube channels.
There’s also apps for OS X, Linux, Firefox OS, Blackberry and Jolla as far as I know.
Sadly, there's no good replacement for Office365 (Word, Excel, Powerpoint).
It works with odt files and you can edit collaboratively, even with people not on ownCloud. Spreadsheets and presentations are not there yet because that’s really difficult. :)
Ampache is cool but is really heavy for a simple hosting. Plex does movies and tv shows sort too. Place a Transmission / Deluge torrent client behind, you have a true media center, on a little server.
Owncloud is cool but very buggy !
There's also BitTorrent Sync which is cool, but sadly proprietary.
Sorry that you experienced bugs. Just to ensure that we fix any potential bug: Could you file those as described at https://github.com/owncloud/core/blob/master/CONTRIBUTING.md? Thanks a lot!
Thanks! :)
That's not my experience at all. It's been running solid for a year now, on a lowly VPS and two MacBooks. It's got very nice Debian packages and an excellent iOS client.
I think it's rude to just say "very buggy" and leave it at that.
[1]: https://gogs.io