Friendica is a decentralised communications platform that integrates social communication. Our platform links to independent social projects and corporate services.
The images are designed to be used in a micro-service environment. There are two types of the image you can choose from.
The apache tag contains a full Friendica installation including an apache web server.
It is designed to be easy to use and gets you running pretty fast.
This is also the default for the latest tag and version tags that are not further specified.
The second option is a fpm container.
It is based on the php-fpm image and runs a fastCGI-Process that serves your Friendica server.
To use this image it must be combined with any Webserver that can proxy the http requests to the FastCGI-port of the container.
 (Admin-E-Mail: 
[email protected])
You need at least one other mariadb/mysql-container to link it to Friendica.
The apache image contains a webserver and exposes port 80. To start the container type:
$ docker run -d -p 8080:80 --network some-network friendicaNow you can access the Friendica installation wizard at http://localhost:8080/ from your host system.
To use the fpm image you need an additional web server that can proxy http-request to the fpm-port of the container.
For fpm connection this container exposes port 9000.
In most cases you might want use another container or your host as proxy.
If you use your host you can address your Friendica container directly on port 9000.
If you use another container, make sure that you add them to the same docker network (via docker run --network <NAME> ... or a docker-compose file).
In both cases you don't want to map the fpm port to you host.
$ docker run -d friendica:fpmAs the fastCGI-Process is not capable of serving static files (style sheets, images, ...) the webserver needs access to these files.
This can be achieved with the volumes-from option.
You can find more information in the docker-compose section.
Friendica requires background tasks to fetch and send all kind of messages and maintain the complete instance. This setup is crucial for the Friendica node. There are two options to enable background tasks for Friendica:
- Using the default Image and manually setup background tasks (see Friendica Install)
- Using the default image (apache, fpm, fpm-alpine) and starting a dedicated croninstance and usecron.shas startup command (like this Example)
Friendica Settings
- FRIENDICA_URLThe Friendica complete URL including protocol, domain and subpath (example: https://friendica.local/sub/ ).
- FRIENDICA_TZThe default localization of the Friendica server.
- FRIENDICA_LANGThe default language of the Friendica server.
- FRIENDICA_SITENAMEThe Sitename of the Friendica server.
- FRIENDICA_NO_VALIDATIONIf set to- true, the URL and E-Mail validation will be disabled.
- FRIENDICA_DATASet the name of the storage provider (e.g- Filesystemto use filesystem), default is the DB backend.
- FRIENDICA_DATA_DIRThe data directory of the Friendica server (Default: /var/www/data).
- FRIENDICA_UPGRADEForce starting the Friendica update even it's the same version (Default:- false).
Friendica Logging
- FRIENDICA_DEBUGGINGIf set to- true, the logging of Friendica is enabled.
- FRIENDICA_LOGFILE(optional) The path to the logfile (Default: /var/www/friendica.log).
- FRIENDICA_LOGLEVEL(optional) The loglevel to log (Default: notice).
- FRIENDICA_LOGGER(optional) Set the type - stream, syslog, monolog (Default: stream).
- FRIENDICA_SYSLOG_FLAGS(optional) In case syslog is used, set the corresponding flags (Default:- LOG_PID | LOG_ODELAY | LOG_CONS | LOG_PERROR).
- FRIENDICA_SYSLOG_FACTORY(optional) In case syslog is used, set the corresponding factory (Default:- LOG_USER).
Database (required at installation)
- MYSQL_USERUsername for the database user using mysql / mariadb.
- MYSQL_PASSWORDPassword for the database user using mysql / mariadb.
- MYSQL_DATABASEName of the database using mysql / mariadb.
- MYSQL_HOSTHostname of the database server using mysql / mariadb.
- MYSQL_PORTPort of the database server using mysql / mariadb (Default:- 3306)
Lock Driver (Redis)
- REDIS_HOSTThe hostname of the redis instance (in case of locking).
- REDIS_PORT(optional) The port of the redis instance (in case of locking).
- REDIS_PW(optional) The password for the redis instance (in case of locking).
- REDIS_DB(optional) The database instance of the redis instance (in case of locking).
PHP limits
- PHP_MEMORY_LIMIT(default- 512M) This sets the maximum amount of memory in bytes that a script is allowed to allocate. This is meant to help prevent poorly written scripts from eating up all available memory, but it can prevent normal operation if set too tight.
- PHP_UPLOAD_LIMIT(default- 512M) This sets the upload limit (- post_max_sizeand- upload_max_filesize) for big files. Note that you may have to change other limits depending on your client, webserver or operating system.
Because Friendica links the administrator account to a specific mail address, you have to set a valid address for MAILNAME.
The binary msmtp is used for the mail support of Friendica.
The mail functionality is e.g. used for sending confirmation emails for registration (including the password for newly registered users).
To make use of the mail functionality you need a working email account with which you can send emails. This may be an account on GMail, GMX or any other provider of public email. If you have your own email server you can use it as well. It is recommended to not use your personal email account for this. But you may use it if you just want to test Friendica or during the installation. You can change it afterwards by simply changing the following environment variables.
The example is based on sending emails via SMTP submission as this is the standard for sending email with nearly all providers of public email accounts. We use the server for outgoing emails.
The setup uses STARTTLS with authentication by default. It is possible to use plain TLS connection (usually using port 465) or even unencrypted connections by setting the environment variables accordingly. Using unencrypted connections is not recommended though.
The following environment define the Mail-Gateway and its connection for the SMTP setup.
- SMTPrequired Address of the SMTP Mail-Gateway, e.g. smtp.gmx.net
- SMTP_PORTPort of the SMTP Mail-Gateway. (Default: 587)
- SMTP_TLSUse TLS for connecting the SMTP Mail-Gateway. (Default:- on, shall also be- onwhen using STARTTLS)
- SMTP_STARTTLSUse STARTTLS for connecting the SMTP Mail-Gateway. (Default:- on,- offwhen- SMTP_PORTis 465)
Sending emails usually requires authentication or login to the Mail-Gateway. This is controlled by
- SMTP_AUTH_USERusually necessary Username for the SMTP Mail-Gateway. (Default: empty)
- SMTP_AUTH_PASSusually necessary Password for the SMTP Mail-Gateway. (Default: empty)
- SMTP_AUTHAuth mode for the SMTP Mail-Gateway. (Optional: Default- onwhen- SMTP_AUTH_USERand- SMTP_AUTH_PASSare set)
The user used for sending emails is controlled by
- SMTP_DOMAINrequired The sender domain. This is the part after the @ in the email address.
- SMTP_FROMSender user-part of the address. (Default:- no-reply- e.g. [email protected])
If a public email provider is used it may most certainly reject your emails if you use the default no-reply for SMTP_FROM.
You should then use a different name.
A minimum setup for using a gmx.de account would look like this:
  environment:
    - SMTP=smtp.gmx.net
    - SMTP_DOMAIN=gmx.de
    - SMTP_AUTH_USER=<your account login or user>
    - SMTP_AUTH_PASS=<your account password>
You have to add the Friendica container to the same network as the running database container, e. g. --network some-network, and then use mysql as the database host on setup.
The Friendica installation and all data beyond what lives in the database (file uploads, etc) is stored in the unnamed docker volume volume /var/www/html.
The docker daemon will store that data within the docker directory /var/lib/docker/volumes/....
That means your data is saved even if the container crashes, is stopped or deleted.
To make your data persistent to upgrading and get access for backups is using named docker volume or mount a host folder.
To achieve this you need one volume for your database container and Friendica.
Friendica:
- /var/www/html/folder where all Friendica data lives
$ docker run -d \
  -v friendica-vol-1:/var/www/html \
  --network some-network
  friendicaDatabase:
- /var/lib/mysqlMySQL / MariaDB Data
$ docker run -d \
  -v mysql-vol-1:/var/lib/mysql \
  --network some-network
  mariadbThe Friendica image supports auto configuration via environment variables. You can preconfigure everything that is asked on the install page on first run. To enable the automatic installation, you have to the following environment variables:
- FRIENDICA_URLThe Friendica complete URL including protocol, domain and subpath (example: https://friendica.local/sub/ ).
- FRIENDICA_ADMIN_MAILE-Mail address of the administrator.
- MYSQL_USERUsername for the database user using mysql / mariadb.
- MYSQL_PASSWORDPassword for the database user using mysql / mariadb.
- MYSQL_DATABASEName of the database using mysql / mariadb.
- MYSQL_HOSTHostname of the database server using mysql / mariadb.
As an alternative to passing sensitive information via environment variables, _FILE may be appended to the previously listed environment variables, causing the initialization script to load the values for those variables from files present in the container. In particular, this can be used to load passwords from Docker secrets stored in /run/secrets/<secret_name> files. For example:
version: '3.2'
services:
  db:
    image: mariadb
    restart: always
    volumes:
      - db:/var/lib/mysql
    environment:
       - MYSQL_DATABASE_FILE=/run/secrets/mysql_db
       - MYSQL_USER_FILE=/run/secrets/mysql_user
       - MYSQL_PASSWORD_FILE=/run/secrets/mysql_password
    secrets:
      - mysql_database
      - mysql_password
      - mysql_user
  app:
    image: friendica
    restart: always
    volumes:
      - friendica:/var/www/html
    ports:
      - "8080:80"
    environment:
      - MYSQL_HOST=db
      - MYSQL_DATABASE_FILE=/run/secrets/mysql_db
      - MYSQL_USER_FILE=/run/secrets/mysql_user
      - MYSQL_PASSWORD_FILE=/run/secrets/mysql_password
      - FRIENDICA_ADMIN_MAIL_FILE=/run/secrets/friendica_admin_mail
    depends_on:
      - db
    secrets:
      - friendica_admin_mail
      - mysql_database
      - mysql_password
      - mysql_user
volumes:
  db:
  friendica:
secrets:
  friendica_admin_mail:
    file: ./friendica_admin_mail.txt # put admin email to this file
  mysql_database:
    file: ./mysql_database.txt # put mysql database name to this file
  mysql_password:
    file: ./mysql_password.txt # put mysql password to this file
  mysql_user:
    file: ./mysql_user.txt # put mysql username to this fileCurrently, this is only supported for FRIENDICA_ADMIN_MAIL, MYSQL_DATABASE, MYSQL_PASSWORD, MYSQL_USER.
You have to pull the latest image from the hub (docker pull friendica).
The stable branch gets checked at every startup and will get updated if no installation was found or a new image is used.
The easiest way to get a fully featured and functional setup is using a docker-compose file.
There are too many different possibilities to setup your system, so here are only some examples what you have to look for.
At first make sure you have chosen the right base image (fpm or apache) and added the features you wanted (see below). In every case you want to add a database container and docker volumes to get easy access to your persistent data. When you want your server reachable from the internet adding HTTPS-encryption is mandatory! See below for more information.
This version will use the apache image and add a mariaDB container. The volumes are set to keep your data persistent. This setup provides no ssl encryption and is intended to run behind a proxy.
Make sure to set the variable MYSQL_PASSWORD before run this setup.
version: '2'
services:
  db:
    image: mariadb
    restart: always
    volumes:
      - db:/var/lib/mysql
    environment:
      - MYSQL_USER=friendica
      - MYSQL_PASSWORD=
      - MYSQL_DATABASE=friendica
      - MYSQL_RANDOM_ROOT_PASSWORD=yes
  app:
    image: friendica
    restart: always
    volumes:
      - friendica:/var/www/html
    ports:
      - "8080:80"
    environment:
      - MYSQL_HOST=db
      - MYSQL_USER=friendica
      - MYSQL_PASSWORD=
      - MYSQL_DATABASE=friendica
      - [email protected]      
    depends_on:
      - db
volumes:
  db:
  friendica:Then run docker-compose up -d, now you can access Friendica at http://localhost:8080/ from your system.
When using the FPM image you need another container that acts as web server on port 80 and proxies requests to the Friendica container.
In this example a simple nginx container is combined with the Friendica-fpm image and a MariaDB database container.
The data is stored in docker volumes.
The nginx container also need access to static files from your Friendica installation.
It gets access to all the volumes mounted to Friendica via the volumes_from option.
The configuration for nginx is stored in the configuration file nginx.conf that is mounted into the container.
An example can be found in the examples section.
As this setup does not include encryption it should to be run behind a proxy.
Prerequisites for this example:
- Make sure to set the variable MYSQL_PASSWORDandMYSQL_USERbefore you run the setup.
- Create a nginx.confin the same directory as the docker-compose.yml file (take it from example)
version: '2'
services:
  db:
    image: mariadb
    restart: always
    volumes:
      - db:/var/lib/mysql
    environment:
      - MYSQL_USER=friendica
      - MYSQL_PASSWORD=
      - MYSQL_DATABASE=friendica
      - MYSQL_RANDOM_ROOT_PASSWORD=yes
  app:
    image: friendica:fpm
    restart: always
    volumes:
      - friendica:/var/www/html    
    environment:
      - MYSQL_HOST=db
      - MYSQL_USER=friendica
      - MYSQL_PASSWORD=
      - MYSQL_DATABASE=friendica
      - [email protected]
    networks:
      - proxy-tier
      - default 
  web:
    image: nginx
    ports:
      - 8080:80
    links:
      - app
    volumes:
      - ./nginx.conf:/etc/nginx/nginx.conf:ro    
    restart: always
    networks:
      - proxy-tier  
volumes:
  db:
  friendica:
networks:
  proxy-tier:Then run docker-compose up -d, now you can access Friendica at http://localhost:8080/ from your system.
The *-dev and *-rc branches are directly downloaded and verified at each docker start to ensure that the latest sources are used.
The parameter FRIENDICA_UPGRADE is required to be true (Default: false) to activate this behavior.
If you got any questions or problems using the image, please visit our Github Repository and write an issue.