---
title: "Self-Hosting an FTP Server with Web UI Using Docker and Cloudflare Tunnel: SFTPGo"
description: "Quickly spin up SFTPGo with Docker and expose it externally via Cloudflare Tunnel, giving your FTP server a Web UI with SFTP and WebDAV support."
canonical_url: "https://blog.markkulab.net/en/post/docker-web-ui-ftp-server-sftpgo"
author: "Mark Ku"
author_url: "https://blog.markkulab.net/en/author/mark-ku"
site: "Mark Ku's Tech Notes"
date_published: "2023-12-20 01:01:35 +0800"
category: "DevOps"
tags: ["ftp", "sftp", "sftpgo", "docker", "cloudflare tunnel", "webdav", "self-hosted", "devops"]
language: "en"
license: "CC BY 4.0"
license_url: "https://creativecommons.org/licenses/by/4.0/"
attribution: "when reusing or quoting, credit the author and link back to the original"
---

# Self-Hosting an FTP Server with Web UI Using Docker and Cloudflare Tunnel: SFTPGo

## Background

Our Germany and US sites needed a brand new FTP server. After spending some time researching and trying a few Docker-based FTP solutions, I finally found SFTPGo — an open-source SFTP server with a proper Web UI.

## SFTPGo — Official Overview

A fully-featured, highly configurable SFTP server with optional HTTP/S, FTP/S, and WebDAV support. Supported storage backends include: local filesystem, encrypted local filesystem, S3-compatible object storage, Google Cloud Storage, Azure Blob Storage, and other SFTP servers. It ships with both a WebAdmin and a WebClient interface and supports configuration backup through the UI.

[SFTPGo official website](https://sftpgo.com/)
[GitHub](https://github.com/drakkan/sftpgo)

## A Quick Overview of Common FTP Protocols

Since we are talking about FTP, here is a brief comparison of the common protocols:

### 1. SFTP

SFTP (Secure File Transfer Protocol) provides encrypted file transfer over SSH (port 22). It only needs a single port, making firewall configuration much simpler.

### 2. FTP / FTPS

FTP is the classic file transfer protocol. FTPS is the SSL/TLS-encrypted variant. There are two connection modes:

- **Active mode (PORT):** The client opens a random port to receive data, then tells the server that port number via the PORT command (control port 21). The server connects from its port 20 to the client-specified port. This can cause issues when the client's firewall blocks inbound connections from the FTP server.
- **Passive mode (PASV):** The client requests a passive connection from the server, which opens a random port and notifies the client. The client then initiates the data connection.

In summary, the key difference is who initiates the data connection and how, which affects firewall requirements. Passive mode is generally better suited to modern network environments, especially when the client is behind a restrictive firewall.

> Note: SFTPGo currently only reliably supports SFTP. I tried FTP/S for quite a while and could not get it working. For now, SFTP is the way to go — it only needs a single port.

## Prerequisites

- Install Docker Desktop on the host machine.
- Set up and configure Cloudflare Tunnel, binding it to the ports required by SFTPGo. (SFTPGo's web UI is exposed through Cloudflare Tunnel so users can upload files via the browser. For SFTP, Cloudflare Tunnel still has some bugs, so I use a direct firewall rule to expose the SFTP port instead.)

![image](https://blog.markkulab.net/content/markku/posts/docker-web-ui-ftp-server-sftpgo/images/1.png)

## Step 1: Create and Start the FTP Docker Container

```
docker run -d --name sftpgo --restart always -p 8080:8080 -p 2022:2022 -p 8090:8090 -e TZ=America/Los_Angeles -e SFTPGO_HTTPD__BINDINGS__0__PORT=8080  -e SFTPGO_WEBDAVD__BINDINGS__0__PORT=8090 -v E:\ftp\:/srv/sftpgo drakkan/sftpgo
```

### SFTPGo Default Directories

- SFTP/FTP/WebDAV default directory: `/srv/sftpgo`
- User default directory: `/srv/sftpgo/data/{UserName}`
- Host key directory: `/var/lib/sftpgo`

### SFTPGo TCP Ports

- `2022` — SFTP service
- `8080` — Web Admin UI
- `8090` — WebDAV

## Step 2: Access the Web Admin UI and Create an Admin Account

[http://localhost:8080/web/admin/setup](http://localhost:8080/web/admin/setup)

![image](https://blog.markkulab.net/content/markku/posts/docker-web-ui-ftp-server-sftpgo/images/2.png)

## Step 3: Log In, Then Navigate to Users > Click "+" to Create an FTP Account

[http://localhost:8080/web/admin/login](http://localhost:8080/web/admin/login)

![image](https://blog.markkulab.net/content/markku/posts/docker-web-ui-ftp-server-sftpgo/images/3.png)

> Note: The default home directory is `/srv/sftpgo/data/{your-username}`. If you want all accounts to share the same root — for example `/srv/sftpgo/cdn` — set that in the Home Dir field.

## Step 4: Test the Account via Web Client

[http://localhost:8080/web/client/login](http://localhost:8080/web/client/login)

## Step 5: Test with FileZilla Client

### 1. [Download and install FileZilla Client](https://filezilla-project.org/)

### 2. File > Site Manager > New Site > Set protocol to "SFTP - SSH File Transfer Protocol"

![image](https://blog.markkulab.net/content/markku/posts/docker-web-ui-ftp-server-sftpgo/images/4.png)

## Step 6: Mount WebDAV as a Network Drive on Windows

### 1. Configure the registry path with an elevated PowerShell session

```
// Configure
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\WebClient\Parameters" -Name "BasicAuthLevel" -Value 2

// Check BasicAuthLevel
Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\WebClient\Parameters" -Name "BasicAuthLevel"

// Restart WebClient
net stop webclient
net start webclient
```

### 2. Open This PC > click "..." > Add a network location

![image](https://blog.markkulab.net/content/markku/posts/docker-web-ui-ftp-server-sftpgo/images/5.png)

### 3. Enter the WebDAV host address, IP, and credentials

![image](https://blog.markkulab.net/content/markku/posts/docker-web-ui-ftp-server-sftpgo/images/6.png)

### 4. Continue

![image](https://blog.markkulab.net/content/markku/posts/docker-web-ui-ftp-server-sftpgo/images/7.png)

### 5. Done

![image](https://blog.markkulab.net/content/markku/posts/docker-web-ui-ftp-server-sftpgo/images/8.png)

## Closing Thoughts

The open-source ecosystem keeps producing remarkably capable and easy-to-use tools. For anyone with some technical background, these projects offer enormous flexibility — you can adapt and extend them to fit your exact needs. This post aimed to provide a concise guide to spinning up a Docker-based FTP server with a Web UI using Cloudflare Tunnel and SFTPGo. I hope it helps you get up and running with these powerful open-source tools more easily.

## References

[Reference](https://blog.csdn.net/networken/article/details/133963932)

---

## About this article and its author

Originally published on [Mark Ku's Tech Notes](https://blog.markkulab.net/en/post/docker-web-ui-ftp-server-sftpgo)

License: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/) — when reusing or quoting, credit the author and link back to the original

### About the author

**[Mark Ku](https://blog.markkulab.net/en/author/mark-ku)** — Software Solution Provider

- 10+ years senior software engineer, now an AI Builder
- Focused on large-platform architecture — North-American e-commerce, AI SaaS subscription billing
- Combining AI Agents and automation to build evolvable product foundations

### Free tools built by the author

All of these are free to use:

- [Free PDF Sign Tool](https://blog.markkulab.net/en/tools/pdf-sign): Online PDF sign tool — draw, type, or upload a signature, then drag, resize, and download. Everything runs in your browser; nothing is uploaded.
- [VS Code Refactory](https://blog.markkulab.net/en/tools/refactory): Refactory is a VS Code refactoring extension: 34 actions plus a 37-rule code-smell inspection layer with a Code Health dashboard, across 18 languages, backed by 534 tests. It learns your repo's conventions: where interfaces live, where DI is registered, whether 'use client' belongs. It ranks files by git churn × complexity so you know what to fix first, and hands any smell to the Claude Code already on your machine. Free to use, and your source never leaves your computer.
- [DB-Kit Database Manager](https://blog.markkulab.net/en/tools/db-kit): DB-Kit is a lightweight, cross-platform database manager built with Tauri + Rust + React. Manage MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, MongoDB, Redis, Kafka, Elasticsearch and RabbitMQ from one consistent interface: passwords encrypted in the OS keychain, SSH tunnels, full CRUD, a visual query builder, stacked multi-statement result sets, cross-connection data transfer and compare/sync, Excel / CSV import & export, visualized execution plans, ER diagrams, scheduled backups, SQL stress testing with p50–p99 latency percentiles, a 15-rule SQL review engine, Kafka message browsing with monitoring & alerts, a bilingual UI (Traditional Chinese / English), a built-in AI assistant (natural-language SQL, AI review and tuning advice) and the dbk CLI. Free and open source (MIT), with installers for Windows, macOS and Linux.
- [VS Code Super Mermaid](https://blog.markkulab.net/en/tools/super-mermaid): Super Mermaid is a VS Code extension for beautiful Mermaid diagrams out of the box: auto-colored live preview, mouse pan & zoom, high-res PNG / SVG export, 21 templates and multiple themes. Free and open source (MIT).
- [React Super Mermaid](https://blog.markkulab.net/en/tools/react-super-mermaid): react-super-mermaid is an open-source React component library: render beautiful Mermaid diagrams with a single <MermaidViewer>, with built-in colorful / sketch themes, pan & zoom, in-diagram search, and high-res SVG / PNG export. Lightweight, SSR-safe, fully typed. Free and open source (MIT).
- [Jira / Confluence Super Mermaid](https://blog.markkulab.net/en/tools/jira-super-mermaid): An Atlassian Forge app: write Mermaid syntax directly inside a Jira issue or a Confluence page and get flowcharts, sequence diagrams, state machines and Gantt charts. 11 diagram types, SVG / PNG export, light and dark themes, full CJK support. Runs on Atlassian: your diagrams live in your own site and the app calls no third-party service. Free, coming soon to the Atlassian Marketplace.
- [Mermaid Live Preview](https://blog.markkulab.net/en/tools/mermaid-preview): Write Mermaid in your browser, see it render instantly, and share the whole diagram as a single link. No sign-up, nothing uploaded to a server, and mermaid.live share links work as-is.
- [React Intl Phone Number](https://blog.markkulab.net/en/tools/react-intl-phone-number): react-intl-phone-number is an open-source React component: framework-agnostic and antd-free, with E.164 in/out, a searchable flag / country-code dropdown, configurable validation levels (strict / mobile-strict / loose), themeable CSS, and i18n — phone logic powered by google-libphonenumber. Lightweight and fully typed. Free and open source (MIT).
- [Uptime Kuma Cluster](https://blog.markkulab.net/en/tools/uptime-kuma-cluster): Turn single-node Uptime Kuma into a highly available cluster: OpenResty + Lua smart load balancing, shared MariaDB state, health checks and automatic failover, plus cluster-management REST APIs. One Docker Compose command to start. Free and open source (MIT).
- [Special Education](https://blog.markkulab.net/en/education): Learning materials crafted for special education students

### Daily podcasts

- [Mark's Tech Insights — Daily AI News](https://blog.markkulab.net/en/category/tech-news): Daily curated AI and tech trends. Catch the latest developments via audio summaries — covering AI applications, software architecture, DevOps, and engineering practice. — RSS: https://blog.markkulab.net/feed.xml
- [AI股市蝦聊](https://blog.markkulab.net/en/category/ai-stock-chat): Every trading day, an AI-analyzed take on the Taiwan stock market, delivered as a two-host conversation covering the session and the next-day outlook. — RSS: https://blog.markkulab.net/ai-stock-chat/feed.xml
- [開源好物週報](https://blog.markkulab.net/en/category/open-source-weekly): A weekly two-host pick of free open-source tools surfaced from real Hacker News, GitHub, and Reddit buzz — what pain they solve and the fastest way to get started. — RSS: https://blog.markkulab.net/open-source-weekly/feed.xml

### Newsletter

[Subscribe to the newsletter](https://blog.markkulab.net/en/subscribe) — Be the first to know about new posts. No spam, unsubscribe anytime.
