7de9ee2a7ce0fa109814bc6ea5dc48522dcc66ef
5-char slugs over a 32-char alphabet are ~25 bits; brute-forceable at HTTP speeds once the endpoint is public. 8 chars = 40 bits (~10^12 combinations), infeasible to scan within useful timescales. Existing 5-char slugs still resolve; only new artifacts use the longer form.
Artifacto
Self-hosted drop-and-share for HTML artifacts. Paste HTML → get a link → share. Single-binary Go service, SQLite metadata, HTML bodies on disk, behind a reverse proxy.
Features
- Paste or upload HTML, auto-generated slug (or custom)
- Optional per-artifact password (bcrypt), rate-limited unlock
- Optional expiration (time or view-count)
- Admin dashboard with view counts, sparklines, per-artifact 30-day chart
- Privacy-preserving visitor hash (daily-rotated salt, no cookies on viewers)
- One container, one SQLite file, one data directory
Quick start
cp .env.example .env # set ADMIN_PASSWORD + SESSION_SECRET
docker compose up -d
open http://localhost:3100
Then put a reverse proxy (Caddy, nginx, Traefik) in front for HTTPS.
Configuration
| Env var | Default | Purpose |
|---|---|---|
ADMIN_PASSWORD |
— (required) | Admin login password |
SESSION_SECRET |
— (required, 32+ bytes hex) | Cookie HMAC key |
BASE_URL |
http://localhost:3000 |
Used when building share links |
DATA_DIR |
/data |
SQLite DB + artifact files |
BIND_ADDR |
:3000 |
Listen address |
MAX_UPLOAD_MB |
5 |
Per-artifact upload cap |
LOG_LEVEL |
info |
info or debug |
SSO_GATEWAY_SECRET |
— | Optional: enables auto-login from a trusted reverse proxy forwarding Authentik headers plus a matching X-Artifacto-Gateway header |
License
MIT
Description
Languages
Go
66.8%
HTML
31.6%
Dockerfile
0.9%
Makefile
0.7%