When SSO_GATEWAY_SECRET is set and an incoming request carries both X-Artifacto-Gateway (matching the secret) and X-Authentik-Username, the admin middleware mints a session automatically so Authentik-authenticated users skip the password form. Missing or wrong gateway header falls back to the password-login flow, so peers that can reach the container directly (bypassing the reverse proxy) cannot spoof Authentik identities.
1.9 KiB
1.9 KiB
Artifacto
Self-hosted drop-and-share for HTML artifacts. Paste HTML → get a link → share. Single-binary Go service, SQLite metadata, HTML bodies on disk, behind a reverse proxy.
Features
- Paste or upload HTML, auto-generated slug (or custom)
- Optional per-artifact password (bcrypt), rate-limited unlock
- Optional expiration (time or view-count)
- Admin dashboard with view counts, sparklines, per-artifact 30-day chart
- Privacy-preserving visitor hash (daily-rotated salt, no cookies on viewers)
- One container, one SQLite file, one data directory
Quick start
cp .env.example .env # set ADMIN_PASSWORD + SESSION_SECRET
docker compose up -d
open http://localhost:3100
Then put a reverse proxy (Caddy, nginx, Traefik) in front for HTTPS.
Configuration
| Env var | Default | Purpose |
|---|---|---|
ADMIN_PASSWORD |
— (required) | Admin login password |
SESSION_SECRET |
— (required, 32+ bytes hex) | Cookie HMAC key |
BASE_URL |
http://localhost:3000 |
Used when building share links |
DATA_DIR |
/data |
SQLite DB + artifact files |
BIND_ADDR |
:3000 |
Listen address |
MAX_UPLOAD_MB |
5 |
Per-artifact upload cap |
LOG_LEVEL |
info |
info or debug |
SSO_GATEWAY_SECRET |
— | Optional: enables auto-login from a trusted reverse proxy forwarding Authentik headers plus a matching X-Artifacto-Gateway header |
License
MIT