Skip to content

Docker deployment ​

Official image: uuphy/ipa-harbor:latest.

Local HTTP ​

See Quick Start. Map host port to container PORT (default 3080).

Public network with built-in HTTPS ​

bash
docker run -d \
  -p 80:3080 \
  -p 443:3443 \
  -e KEYCHAIN_PASSPHRASE=$(openssl rand -base64 15 | tr -dc 'A-Za-z0-9' | head -c10) \
  -e ADMIN_INIT_PIN=$(openssl rand -base64 24 | tr -dc '0-9' | head -c8) \
  -e PORT=3080 \
  -e HTTPS_PORT=3443 \
  -e ALLOW_LAN_ACCESS=false \
  -e ALLOWED_DOMAINS=example.com \
  -v ipa_data:/app/data \
  -v ipa_certs:/app/certs \
  --name ipa-harbor \
  --restart unless-stopped \
  uuphy/ipa-harbor:latest

Place server.crt and server.key in the ipa_certs volume (or bind-mount those two files). Visit http:// and https:// on your domain.

Set ALLOW_LAN_ACCESS=true only if you need LAN IP access. For public deployment use false and set ALLOWED_DOMAINS.

Save the ADMIN_INIT_PIN from your command — you need it at /setup and for recovery.

Compose reference ​

See server/docker-compose.example.yml on GitHub for a fuller example including Passkey-related variables.

Building the image yourself ​

Linux ipatool packages must exist under server/bin/ before docker build. Run scripts/dl_latest.sh or ./scripts/build_ipatool.sh --linux-only, then use build.sh at the repository root or your own buildx workflow.