GC phase 2 already had the right shape — `ref_count <= 0 AND NOT
EXISTS(manifest lists it) AND NOT EXISTS(file points at it)` — so unlike
phase 1 before 6dc045ea, a stale counter could only delay collection
there, never delete live bytes. What it did not have is any connection
to `BlobReferenceRegistry`: the two cross-checks named
`storage.chunk_manifests` and `storage.files` literally.
That is correct today and one source away from not being. Both
`content_derived_blobs` and `file_attached_blobs` return None at
RefLevel::Chunk, so the registry's chunk union is exactly manifests +
legacy files. The moment anything contributes at that level — a legacy
whole-file derived blob, or file_versions when versioning lands — phase
2 misses it and reaps referenced bytes. That is precisely the failure
the registry was built to prevent, and precisely what the phase 1
comment warns about while phase 2 sat unfixed.
## Why this is additive, not a swap
`no_reference_predicate` is assembled from fragments designed for
COUNTING, and FilesReferenceSource's chunk-level fragment deliberately
excludes files whose blob_hash has a manifest — otherwise a single-chunk
blob, whose file hash and lone chunk hash are the same BLAKE3, would be
counted at both levels. Correct for a recompute; too narrow for a reap
guard.
Concretely: a `storage.blobs` row keyed by a MULTI-chunk file's hash is
not a member of its own manifest's chunk_hashes, and such rows exist
transiently while `rechunk` migrates a legacy blob. Replacing the
hardcoded guards with the registry predicate would have satisfied
"unreferenced" for that row while a live storage.files row still pointed
at it — reaping it mid-migration. So the guards stay and the registry
predicate is ANDed on top. Adding a conjunct can only spare more rows,
never reap more, so this cannot regress; what it buys is that a future
chunk-level source is honoured automatically.
## Also: EXISTS instead of COUNT in the hot path
ChunksReferenceSource had no `ref_exists_sql` override, so the trait
default wrapped its counting fragment as `(SELECT COUNT(*) …) > 0`. That
now runs per candidate row inside the reap guard, and a
heavily-deduplicated chunk is exactly where counting every referrer is
most expensive and least necessary. FilesReferenceSource already carried
this override for the same reason; ChunksReferenceSource now does too.
Semantically identical, so no golden-test drift beyond the shape.
## Tests
`blob_reap_statement_is_stable` pins the assembled statement, and
`empty_registry_refuses_to_build_blob_reap_statement` mirrors the
manifest builder's loud failure on a wiring bug.
`a_new_chunk_level_source_reaches_the_blob_reap_statement` is the one
that earns its keep: since no shipped source contributes at chunk level,
a golden test alone would not notice the registry conjunct being dropped.
It registers a synthetic source and asserts the fragment appears.
Verified 921 passed / 0 failed on a clean database, and again on a second
consecutive run against the same one.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
A fast self-hosted cloud for people who want files, calendars, contacts, and office editing without dragging a heavy stack behind them.
Documentation · Quick Start · Star OxiCloud · Request a Feature · Supported Clients · Project Status
If OxiCloud saves you setup time, RAM, or complexity, give it a star. If something is missing, ask for a feature or request a docs improvement.
Why People Try OxiCloud
OxiCloud is aimed at self-hosters, home labs, and small teams who want the useful parts of a cloud suite without the operational drag of a traditional PHP stack.
What pulls people in:
- Standard protocols first: WebDAV, CalDAV, and CardDAV are built in
- Useful product surface already there: files, previews, sharing, trash, search, favorites, and recent items
- Modern auth and admin basics: OIDC/SSO, quotas, roles, and shared links
- Better interoperability: native desktop and mobile clients work without custom sync tooling for basic access
- Lower deployment friction: Docker Compose, environment-based configuration, Helm chart, and Nix module
OxiCloud is not trying to mirror the full plugin ecosystem of Nextcloud. It is designed for a smaller stack, fast startup, and standards-based interoperability.
Quick Start
Docker Compose
Requires Docker and Docker Compose.
git clone https://github.com/AtalayaLabs/OxiCloud.git
cd OxiCloud
cp example.env .env
# If users will access OxiCloud through a domain or reverse proxy,
# set OXICLOUD_BASE_URL in .env before the first login.
docker compose up -d
Open http://localhost:8086.
Prebuilt binary
Binary releases (Linux musl amd64/arm64, macOS Intel/Apple Silicon)
are attached to every tagged release on GitHub — the whole SPA + all
operator subcommands + migrations bake into a single self-contained
executable. See docs/install/binary.md for
the download / verify / systemd walkthrough.
cargo binstall oxicloud works too once a release is out.
Run from source
Requires Rust 1.93+ and PostgreSQL.
git clone https://github.com/AtalayaLabs/OxiCloud.git
cd OxiCloud
cp example.env .env
# If PostgreSQL runs on your host instead of Docker, update both
# OXICLOUD_DB_CONNECTION_STRING and DATABASE_URL to use localhost:5432.
cargo run
Deployment details: deployment guide · example.env
What You Get
| Area | Included |
|---|---|
| Files | Multi-file upload, folders, inline previews, thumbnails, chunked uploads, deduplication, trash |
| Sync and clients | WebDAV, CalDAV, CardDAV, native OS clients, Thunderbird, DAVx5 |
| Security | JWT auth, Argon2id, OIDC/SSO, shared links, quotas, admin/user roles |
| Integrations | REST API and WOPI for Collabora or OnlyOffice |
| Operations | Docker image, Docker Compose, env-driven config, PostgreSQL backend |
| Project tooling | Architecture docs, Helm chart, Nix module, CI |
Supported Clients
OxiCloud uses standard DAV protocols, so it works with native clients instead of requiring a custom sync stack for basic access.
| Use case | URL |
|---|---|
| Files via WebDAV | https://your-host/webdav/ |
| Calendars via CalDAV | https://your-host/caldav/ |
| Contacts via CardDAV | https://your-host/carddav/ |
Common clients that work well:
- macOS Finder
- Windows Explorer
- GNOME Files and KDE Dolphin
- Thunderbird
- Apple Calendar and Contacts
- DAVx5 on Android
Client setup guides: DAV client setup · WebDAV guide · CalDAV & CardDAV guide
Project Status
OxiCloud is actively developed and already covers the core self-hosted cloud workflow.
| Capability | Status | Notes |
|---|---|---|
| File storage and web UI | Ready | Uploads, previews, sharing, trash, and search |
| WebDAV | Ready | Standard file access for desktop and mobile clients |
| CalDAV and CardDAV | Ready | Working with Thunderbird, Apple clients, and others |
| OIDC / SSO | Ready | Documentation and config examples included |
| WOPI office editing | Ready | Works with Collabora or OnlyOffice |
| DAVx5 Android support | Partial | File sync works well; calendar and contact behavior is still being refined |
| Desktop sync client | Planned | Not yet available |
| Mobile apps | Planned | Not yet available |
| End-to-end encryption | Planned | Roadmap item |
Roadmap: TODO-LIST.md
Help Shape OxiCloud
If you want OxiCloud to get better faster, use the repo like a product feedback loop, not just a code dump.
- Give it a star if you want more people to discover the project: Star OxiCloud
- Propose missing functionality: feature request
- Point out confusing onboarding or weak docs: documentation request
- Report breakage or regressions: bug report
- Build it with us: CONTRIBUTING.md
The best feature ideas usually come from real deployment pain. If you hit friction, open an issue and describe the workflow you want.
Architecture and Deployment
OxiCloud follows a clean, hexagonal architecture so protocol handlers, business logic, and infrastructure stay separated.
- Backend: Rust + Axum
- Database: PostgreSQL
- Configuration: environment variables
- Default deployment: Docker Compose
- Additional packaging: Helm chart and Nix module
Architecture docs: internal architecture · caching architecture · database transactions · storage safety
Configuration and Integrations
Start with example.env. The most important settings are:
OXICLOUD_BASE_URLfor reverse proxies, domains, and external accessOXICLOUD_DB_CONNECTION_STRINGfor PostgreSQLOXICLOUD_OIDC_ENABLEDand related settings for SSOOXICLOUD_WOPI_ENABLEDand discovery URL for office editingMIMALLOC_PURGE_DELAY=0for lower idle RSS in constrained environments
Integration docs: OIDC setup · OIDC architecture · OIDC config examples · WOPI integration
Documentation
- Docs site: AtalayaLabs.github.io/OxiCloud
- Deployment: docs/config/deployment.md
- Batch operations: docs/guide/batch-operations.md
- Search: docs/guide/search.md
- Thumbnails and transcoding: docs/guide/thumbnails-and-transcoding.md
- Deduplication: docs/guide/deduplication.md
Development
cargo fmt --all --check
cargo clippy --all-features --all-targets -- -D warnings
cargo test --workspace
Contributing
Contributions are welcome. Read CONTRIBUTING.md before opening a pull request and CODE_OF_CONDUCT.md for community expectations.
If you are not ready to code yet, starring the project and opening a precise feature request is still a meaningful contribution.
Contributors
OxiCloud is a community-driven project, and we appreciate all contributions. Check out the Contributors page to see the amazing people who have helped make OxiCloud better.
Star History
License
OxiCloud is a trademark of the OxiCloud project. All other trademarks are the property of their respective owners.

