A small stack, on your terms
Your own session library.
One application, one persistent volume. No separate search cluster or hosted identity provider required.
01. Run with Docker Compose
Save this as compose.yaml. The published image supports Linux AMD64 and ARM64.
services:
seshshare:
image: "${SESHSHARE_IMAGE:-ghcr.io/splashpad/seshshare:edge}"
pull_policy: always
ports:
- "127.0.0.1:8080:8080"
environment:
SESHSHARE_TOKEN: "${SESHSHARE_TOKEN:?Set a random token of at least 24 characters}"
SESHSHARE_SECURE_COOKIES: "${SESHSHARE_SECURE_COOKIES:-false}"
volumes:
- seshshare-data:/data
restart: unless-stopped
security_opt:
- no-new-privileges:true
cap_drop: [ALL]
volumes:
seshshare-data:
Generate a private .env alongside it:
umask 077 printf 'SESHSHARE_TOKEN=%s\nSESHSHARE_SECURE_COOKIES=false\n' \ "$(openssl rand -hex 32)" > .env
Start Seshshare:
docker compose up -d --wait
Compose downloads the image and starts Seshshare. Your sessions are stored in the persistent seshshare-data volume. Keep .env private.
02. Create local accounts
Open http://localhost:8080/setup. Use any HTTP Basic username and the bootstrap token as its password. Create the administrator, then add members from Accounts. Once configured, the bootstrap token no longer grants access to sessions.
Place the service behind your TLS reverse proxy. Preserve the external Host, disable proxy caching, and set SESHSHARE_SECURE_COOKIES=true when TLS terminates at the proxy. Published sessions are visible to every member of this instance. Drafts belong to their uploader.
03. Bring a session
Upload a supported export through the browser, review its normalized draft, then publish. For a coding-agent workflow, use the publisher CLI or harness skill.
Deployment notes
- Supported structured formats, not arbitrary HTML exports. Harness variants can differ.
- No automated redaction guarantee. Tool inputs, outputs, and metadata may contain sensitive information.
- No SSO, per-session access lists, or account recovery workflow yet.
- Imports are synchronous and SQLite is single-node. Benchmark against your own workload before scaling.
- Back up the persistent data before upgrading. Use the bundled seshshare-admin backup/restore tool; never copy only a live SQLite main file while WAL writes are active.