暫無描述

Marcus B Spencer 54bb987fae chore(config): remove fallback STUN servers that are CNAMEs to stun.counterpath.com (#10219) 3 月之前
.github 4d92855d76 build: release job needs full checkout with tags 4 月之前
assets 9cc49aea77 assets, gui: Losslessly compress all JPG, PNG, and PDF images (#6265) 5 年之前
cmd ff88430efb feat: add debug commands for folder counts and files (#10206) 4 月之前
etc 40ab668a73 chore(etc): add option dash to upstart config 4 月之前
gui 74367d2f66 chore(gui, man, authors): update docs, translations, and contributors 3 月之前
internal 7c07610ab2 fix: allow deleted files to win conflict resolution (#10207) 3 月之前
lib 54bb987fae chore(config): remove fallback STUN servers that are CNAMEs to stun.counterpath.com (#10219) 3 月之前
man 74367d2f66 chore(gui, man, authors): update docs, translations, and contributors 3 月之前
meta 832fa094a3 Merge branch 'main' into v2 5 月之前
proto 95187bcc64 chore(protocol): minor cleanup of ClusterConfig messages; remove DisableTempIndexes option (#10202) 4 月之前
relnotes 7c07610ab2 fix: allow deleted files to win conflict resolution (#10207) 3 月之前
script e8cfc8acfb build: improve next version calculation for bumped prereleases 3 月之前
test bb91f53641 Merge branch 'main' into v2 5 月之前
.codecov.yml 9e857ed2d4 build: Add test coverage info (#7502) 4 年之前
.deepsource.toml c5ec6cd7ef build: Fix deepsource test & exclude patterns (#7969) 4 年之前
.gitattributes 6809d38cde lib/protocol: Revert protobuf encoder changes in v0.14.17 (fixes #3855) 8 年之前
.gitignore 1a25ae32ca chore: remove abandoned next-gen-gui experiment (#10004) 7 月之前
.golangci.yml ff88430efb feat: add debug commands for folder counts and files (#10206) 4 月之前
.policy.yml 6208c36417 fix(policy): do not require multiple maintainers for build changes 8 月之前
.yamlfmt 8991ecf444 build: Add more GitHub Actions 2 年之前
AUTHORS cf84a260ca chore(gui, man, authors): update docs, translations, and contributors 4 月之前
CONDUCT.md 6df3940c26 conduct: Upgrade to Contributor Covenant 7 年之前
CONTRIBUTING.md 784129e1cf gui: Switch to Weblate for translations (#8777) 2 年之前
Dockerfile 876d056705 build: Fixup Docker changes from previous (#9223) 1 年之前
Dockerfile.builder 876d056705 build: Fixup Docker changes from previous (#9223) 1 年之前
Dockerfile.stcrashreceiver 876d056705 build: Fixup Docker changes from previous (#9223) 1 年之前
Dockerfile.stdiscosrv 876d056705 build: Fixup Docker changes from previous (#9223) 1 年之前
Dockerfile.strelaypoolsrv ba6ac2f604 lib/geoip, cmd/relaypoolsrv, cmd/ursrv: Automatically manage GeoIP updates (#9342) 1 年之前
Dockerfile.strelaysrv 876d056705 build: Fixup Docker changes from previous (#9223) 1 年之前
Dockerfile.stupgrades 876d056705 build: Fixup Docker changes from previous (#9223) 1 年之前
Dockerfile.ursrv 5c65a1bc83 build: Ursrv image for infrastructure 1 年之前
GOALS.md dcafd6ec72 readme: Style fixes, add security note (#9136) 2 年之前
LICENSE f7fc0c1d3e all: Update license url to https (ref #3976) 8 年之前
README-Docker.md 429672e0b4 docs(docker): add healthcheck to docker-compose (#9742) 1 年之前
README.md 99a6f3a5b6 docs: update section on code signing 10 月之前
buf.gen.yaml 77970d5113 refactor: use modern Protobuf encoder (#9817) 11 月之前
buf.yaml 77970d5113 refactor: use modern Protobuf encoder (#9817) 11 月之前
build.go f2a5b62733 build: unset build ID in generated binaries (#10203) 4 月之前
build.ps1 04ff890263 build: Clean up build.sh, add build.ps1 (#6689) 5 年之前
build.sh 93ae30d889 chore(gui): update dependency copyrights, add script for periodic maintenance (#10067) 6 月之前
compat.yaml 20257faf54 build: compat entry for Go 1.25 4 月之前
go.mod 95187bcc64 chore(protocol): minor cleanup of ClusterConfig messages; remove DisableTempIndexes option (#10202) 4 月之前
go.sum 9d425b0588 fix(beacon, osutil, upnp): fix local discovery send and intf detection on Android (#10196) 4 月之前
tools.go e6ed3acf5f build: add dependency for next-version script 4 月之前

README-Docker.md

Docker Container for Syncthing

Use the Dockerfile in this repo, or pull the syncthing/syncthing image from Docker Hub.

Use the /var/syncthing volume to have the synchronized files available on the host. You can add more folders and map them as you prefer.

Note that Syncthing runs as UID 1000 and GID 1000 by default. These may be altered with the PUID and PGID environment variables. In addition the name of the Syncthing instance can be optionally defined by using --hostname=syncthing parameter.

To grant Syncthing additional capabilities without running as root, use the PCAP environment variable with the same syntax as that for setcap(8). For example, PCAP=cap_chown,cap_fowner+ep.

To set a different umask value, use the UMASK environment variable. For example UMASK=002.

Example Usage

Docker cli

$ docker pull syncthing/syncthing
$ docker run -p 8384:8384 -p 22000:22000/tcp -p 22000:22000/udp -p 21027:21027/udp \
    -v /wherever/st-sync:/var/syncthing \
    --hostname=my-syncthing \
    syncthing/syncthing:latest

Docker compose

---
version: "3"
services:
  syncthing:
    image: syncthing/syncthing
    container_name: syncthing
    hostname: my-syncthing
    environment:
      - PUID=1000
      - PGID=1000
    volumes:
      - /wherever/st-sync:/var/syncthing
    ports:
      - 8384:8384 # Web UI
      - 22000:22000/tcp # TCP file transfers
      - 22000:22000/udp # QUIC file transfers
      - 21027:21027/udp # Receive local discovery broadcasts
    restart: unless-stopped
    healthcheck:
      test: curl -fkLsS -m 2 127.0.0.1:8384/rest/noauth/health | grep -o --color=never OK || exit 1
      interval: 1m
      timeout: 10s
      retries: 3

Discovery

Note that Docker's default network mode prevents local IP addresses from being discovered, as Syncthing is only able to see the internal IP of the container on the 172.17.0.0/16 subnet. This will result in poor transfer rates if local device addresses are not manually configured.

It is therefore advisable to use the host network mode instead:

Docker cli

$ docker pull syncthing/syncthing
$ docker run --network=host \
    -v /wherever/st-sync:/var/syncthing \
    syncthing/syncthing:latest

Docker compose

---
version: "3"
services:
  syncthing:
    image: syncthing/syncthing
    container_name: syncthing
    hostname: my-syncthing
    environment:
      - PUID=1000
      - PGID=1000
    volumes:
      - /wherever/st-sync:/var/syncthing
    network_mode: host
    restart: unless-stopped
    healthcheck:
      test: curl -fkLsS -m 2 127.0.0.1:8384/rest/noauth/health | grep -o --color=never OK || exit 1
      interval: 1m
      timeout: 10s
      retries: 3

Be aware that syncthing alone is now in control of what interfaces and ports it listens on. You can edit the syncthing configuration to change the defaults if there are conflicts.

GUI Security

By default Syncthing inside the Docker image listens on 0.0.0.0:8384 to allow GUI connections via the Docker proxy. This is set by the STGUIADDRESS environment variable in the Dockerfile, as it differs from what Syncthing would otherwise use by default. This means you should set up authentication in the GUI, like for any other externally reachable Syncthing instance. If you do not require the GUI, or you use host networking, you can unset the STGUIADDRESS variable to have Syncthing fall back to listening on 127.0.0.1:

$ docker pull syncthing/syncthing
$ docker run -e STGUIADDRESS= \
    -v /wherever/st-sync:/var/syncthing \
    syncthing/syncthing:latest

With the environment variable unset Syncthing will follow what is set in the configuration file / GUI settings dialog.