Self-host Element with Docker Compose
Messagerie chiffrée, voix et vidéo pour équipes et communautés sur Matrix.
element
matrix
ghcr.io/matrix-construct/tuwunel:latest
The steps below take a few minutes end to end.
Requirements
You'll need these installed on the machine you're deploying to:
Docker
Packages Element and everything it depends on into an isolated container, so it runs the same way on your machine as it does everywhere else.
Install guideDocker Compose
Reads docker-compose.ymland starts everything in it together. Ships with Docker Desktop. On Linux servers it's usually a separate install.
Install guide1. Docker compose setup and file
Create a folder for Element and save the file below into it as docker-compose.yml. It describes every container the stack needs — Elementitself and any supporting services, such as its database — along with the ports, volumes and environment variables each one uses. You'll also need an empty .env file in the same folder; Docker Compose reads it automatically and uses it to fill in the ${VARIABLE}references you'll see in the file below.
docker-compose.yml
version: "3.9"
services:
element:
image: vectorim/element-web:latest
restart: unless-stopped
ports:
- 8080:8080
environment:
ELEMENT_BASE_URL: http://element.localhost:8080
MATRIX_PUBLIC_HOSTNAME: element-matrix.localhost:8008
volumes:
- tmp:/tmp
configs:
- source: element-default.conf
target: /etc/nginx/conf.d/default.conf
command:
- /bin/sh
- -c
- 'mkdir -p /tmp/element-web-config && jq --arg url "$${ELEMENT_BASE_URL%%:*}://$${MATRIX_PUBLIC_HOSTNAME}" --arg name "$${MATRIX_PUBLIC_HOSTNAME}" ''.default_server_config = {"m.homeserver": {"base_url": $$url, "server_name": $$name}} | .room_directory = {"servers": [$$name]}'' /app/config.json > /tmp/element-web-config/config.json && exec nginx -g "daemon off;"'
matrix:
image: ghcr.io/matrix-construct/tuwunel:latest
restart: unless-stopped
network_mode: service:element
environment:
TUWUNEL_ADDRESS: 0.0.0.0
TUWUNEL_ADMIN_EXECUTE: '["users create-user demo Admin123"]'
TUWUNEL_ADMIN_EXECUTE_ERRORS_IGNORE: "true"
TUWUNEL_ALLOW_FEDERATION: "false"
TUWUNEL_ALLOW_REGISTRATION: "true"
TUWUNEL_DATABASE_PATH: /var/lib/tuwunel
TUWUNEL_PORT: "8008"
TUWUNEL_REGISTRATION_TOKEN: ${SETUP_ADMIN_KEY}
TUWUNEL_SERVER_NAME: element-matrix.localhost:8008
volumes:
- data:/var/lib/tuwunel
volumes:
data: null
tmp: null
configs:
element-default.conf:
content: |
server {
listen 8080;
server_name localhost;
root /usr/share/nginx/html;
index index.html;
location = /index.html {
add_header Cache-Control "no-cache";
}
location = /version {
add_header Cache-Control "no-cache";
}
location /i18n/ {
add_header Cache-Control "no-cache";
}
location /config {
root /tmp/element-web-config;
add_header Cache-Control "no-cache";
}
location /modules {
alias /modules;
}
error_page 500 502 503 504 /50x.html;
}
Volumes
Element stores its data in named Docker volumes, so it survives container restarts and updates:
- tmp mounted at /tmp: The generated config.json and nginx's temporary paths. Nothing here needs to survive a restart.
2. Secret generation
Element needs a few randomly generated secrets — for example, database passwords or an internal session key — before it can start. These are referenced from docker-compose.ymlabove but don't live in it, so they need to end up in your .env file. Pick one of the two options below.
Generating secrets…
3. Start Element with Docker Compose
From the folder with docker-compose.yml and .env, run:
Terminal
Start Element and all its supporting services in the background.
docker compose up -dThe -d flag runs the stack in the background so it keeps running after you close the terminal. Docker will pull the images the first time, which can take a minute or two.
To check on it afterwards: docker compose ps shows whether containers are healthy, and docker compose logs -f follows their logs if something looks wrong. Once it's running, open http://localhost:8080 in your browser.