Self-host AFFiNE with Docker Compose
Open-source Notion & Miro alternative combining docs, whiteboards, and databases.
affine
postgres
postgres:18.3-alpine3.23
redis
redis:7
The steps below take a few minutes end to end.
Requirements
You'll need these installed on the machine you're deploying to:
Docker
Packages AFFiNE and everything it depends on into an isolated container, so it runs the same way on your machine as it does everywhere else.
Install guideDocker Compose
Reads docker-compose.ymland starts everything in it together. Ships with Docker Desktop. On Linux servers it's usually a separate install.
Install guide1. Docker compose setup and file
Create a folder for AFFiNE and save the file below into it as docker-compose.yml. It describes every container the stack needs — AFFiNEitself and any supporting services, such as its database — along with the ports, volumes and environment variables each one uses. You'll also need an empty .env file in the same folder; Docker Compose reads it automatically and uses it to fill in the ${VARIABLE}references you'll see in the file below.
docker-compose.yml
version: "3.9"
services:
affine:
image: ghcr.io/toeverything/affine:stable
restart: unless-stopped
ports:
- 3010:3010
environment:
AFFINE_INDEXER_ENABLED: "false"
AFFINE_SERVER_EXTERNAL_URL: http://localhost
AFFINE_SERVER_HTTPS: "true"
DATABASE_URL: postgresql://app:${RANDOM_PG_PASSWORD}@localhost:5432/app
RANDOM_PG_PASSWORD: ${RANDOM_PG_PASSWORD}
REDIS_SERVER_HOST: localhost
REDIS_SERVER_PASSWORD: ${RANDOM_REDIS_PASSWORD}
REDIS_SERVER_PORT: "6379"
volumes:
- storage:/home/node/.affine
- tmp:/tmp
- graphql-schema:/app/src
command:
- sh
- -c
- node ./scripts/self-host-predeploy.js && exec node ./dist/main.js
healthcheck:
test:
- CMD
- curl
- -f
- http://localhost:3010/api/health
interval: 10s
timeout: 5s
retries: 5
postgres:
image: postgres:18.3-alpine3.23
restart: unless-stopped
network_mode: service:affine
environment:
POSTGRES_PASSWORD: ${RANDOM_PG_PASSWORD}
POSTGRES_USER: app
redis:
image: redis:7
restart: unless-stopped
network_mode: service:affine
environment:
REDIS_PASSWORD: ${RANDOM_REDIS_PASSWORD}
entrypoint:
- sh
- -c
command:
- redis-server --requirepass $$REDIS_PASSWORD
volumes:
graphql-schema: null
storage: null
tmp: null
Volumes
AFFiNE stores its data in named Docker volumes, so it survives container restarts and updates:
- storage mounted at /home/node/.affine: Config (private key) plus uploaded files, images, and blobs. Mounted at the "node" user's home ($HOME/.affine, resolved via os.homedir()) since AFFiNE runs as a non-root user, not root — /root/.affine was never actually written to once the pod stopped running as root.
- tmp mounted at /tmp: Scratch space for yarn's cache directory, needed by the predeploy script's `yarn prisma migrate deploy` step (yarn falls back to /tmp/.yarn-cache* when $HOME/.cache isn't writable, and under a read-only root filesystem /tmp itself isn't writable either unless declared as its own volume).
- graphql-schema mounted at /app/src: NestJS's GraphQLModule generates its schema to src/schema.gql at startup (@nestjs/graphql's FileSystemHelper.writeFile), unrelated to AFFiNE's own data — this path doesn't exist in the image at all, it's purely a runtime scratch target, so mounting an empty volume here is safe and doesn't shadow anything.
2. Secret generation
AFFiNE needs a few randomly generated secrets — for example, database passwords or an internal session key — before it can start. These are referenced from docker-compose.ymlabove but don't live in it, so they need to end up in your .env file. Pick one of the two options below.
Generating secrets…
3. Start AFFiNE with Docker Compose
From the folder with docker-compose.yml and .env, run:
Terminal
Start AFFiNE and all its supporting services in the background.
docker compose up -dThe -d flag runs the stack in the background so it keeps running after you close the terminal. Docker will pull the images the first time, which can take a minute or two.
To check on it afterwards: docker compose ps shows whether containers are healthy, and docker compose logs -f follows their logs if something looks wrong. Once it's running, open http://localhost:3010 in your browser.