A public Docker Hub image for Super Productivity's
SuperSync server (packages/super-sync-server in the
super-productivity monorepo).
Upstream only publishes a private image
(issue #6225),
so this repo rebuilds it from source, unmodified, and pushes a public image to
webstas/supersync. There are no upstream release tags — master is the only
source of truth, so each build is tagged with latest, the upstream commit SHA,
and a build date. Pin to a <sha> tag, not latest, for anything you care
about.
cp .env.example .env # fill in JWT_SECRET, POSTGRES_PASSWORD, PUBLIC_URL, SMTP_*
docker compose up -ddocker-compose.yml is a trimmed copy of upstream's — no Caddy/TLS, so front it
with your own reverse proxy. SuperSync needs its own PostgreSQL 16 database; the
compose file does not bundle one. See upstream's
env.example
for every supported variable.
Behind IIS on Windows Server? See
docs/reverse-proxy-iis.md and the ready-made
web.config.
Ships a Community Applications template at
templates/supersync.xml. Add this repo as a template
repository (Apps → Settings → Template Repositories):
https://github.com/BigWebstas/SuperSync. Install a separate PostgreSQL 16
container first, then set the Database URL field.
-
No Terms of Service / privacy policy is baked in — upstream ships none. Set the
PRIVACY_*variables to generate one for your deployment. -
latesttracks upstreammaster, which has no stability guarantee. -
Upstream's sync rate limits are compiled in with no runtime env var. Behind a reverse proxy every client shares one IP, so the per-IP caps bite sooner than the per-user numbers suggest.
build.shrewrites those constants intoprocess.envreads, so this image honours these env vars set at container start — no rebuild needed:SYNC_UPLOAD_RATE_LIMIT_MAX— per-user and per-IPPOST /api/sync/opscap (default 100/min).SYNC_GLOBAL_RATE_LIMIT_MAX— global per-IP cap across all routes (default 500/15min).SYNC_SNAPSHOT_RATE_LIMIT_MAX— per-IPPOST /api/sync/snapshotcap (default 10/15min). Snapshot uploads are full-state and heavy; a client that keeps hitting this is usually stuck in a resync loop worth diagnosing.
Set them in
.env/ your compose file. Unset, empty, or non-numeric falls back to the upstream default, so a stock deployment behaves exactly like upstream.FAITHFUL_REBUILD=true ./build.shskips the rewrite entirely; each rewrite is verified and fails the build if upstream moves the target line.