English
Docker deployment
Official image: uuphy/ipa-harbor:latest.
Local HTTP
See Quick Start. Map host port to container PORT (default 3080).
Public network with built-in HTTPS
bash
docker run -d \
-p 80:3080 \
-p 443:3443 \
-e KEYCHAIN_PASSPHRASE=$(openssl rand -base64 15 | tr -dc 'A-Za-z0-9' | head -c10) \
-e ADMIN_INIT_PIN=$(openssl rand -base64 24 | tr -dc '0-9' | head -c8) \
-e PORT=3080 \
-e HTTPS_PORT=3443 \
-e ALLOW_LAN_ACCESS=false \
-e ALLOWED_DOMAINS=example.com \
-v ipa_data:/app/data \
-v ipa_certs:/app/certs \
--name ipa-harbor \
--restart unless-stopped \
uuphy/ipa-harbor:latestPlace server.crt and server.key in the ipa_certs volume (or bind-mount those two files). Visit http:// and https:// on your domain.
Set ALLOW_LAN_ACCESS=true only if you need LAN IP access. For public deployment use false and set ALLOWED_DOMAINS.
Save the ADMIN_INIT_PIN from your command — you need it at /setup and for recovery.
Compose reference
See server/docker-compose.example.yml on GitHub for a fuller example including Passkey-related variables.
Building the image yourself
Linux ipatool packages must exist under server/bin/ before docker build. Run scripts/dl_latest.sh or ./scripts/build_ipatool.sh --linux-only, then use build.sh at the repository root or your own buildx workflow.