- Go 85.2%
- Shell 14.1%
- Makefile 0.6%
- Dockerfile 0.1%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
* fix(key): restrict overwritten key exports to owner-only permissions Signed-off-by: questfever <questfever@outlook.com> * fix(atomicfile): temp file leak and name limit Both problems surface through `ipfs key export`, which now writes through this helper, but they affect every caller: config writes, repo migrations and `ipfs update`. - remove the temporary file when the rename fails, so one holding private key material is not left next to the target - keep the ".tmp-" prefix and the random suffix within the 255 byte file name limit, so a target with a long name can still be written * fix(key): route key export by target type Choosing the write path with os.Lstat treated /dev/stdout, /dev/stderr and /dev/fd/N as plain paths, because they are symlinks into /proc/self/fd, so the atomic write failed on targets that worked before. Decide by what the path resolves to, and state the whole contract in the command help. - regular file or nothing yet: written to a temporary file and renamed over the target, following symlinks, including one whose target does not exist yet - character device or pipe: streamed in place, confirmed on the open descriptor and without O_TRUNC, so a path swapped for a regular file can neither receive the key nor be emptied - anything else: refused, naming the path - errors name the file the user asked for, and the temporary file is flushed before the rename * fix(key): stop export landing on the wrong file An export could replace a file the target symlink does not point at. resolveSymlink joined a relative link target onto the path as typed, so ".." collapsed lexically. Where a parent component was itself a symlink, the join named a file outside the directory the link resolves to: the key was renamed over that file, and the intended target was never written. The link's parent is now resolved with filepath.EvalSymlinks before the join. * test(key): drop umask dependency in export test os.WriteFile applies the umask, so under umask 077 the fixture was created 0600 and the check that a failed export leaves the file at 0644 failed for reasons unrelated to the code under test. The CLI test already chmods for the same reason. --------- Signed-off-by: questfever <questfever@outlook.com> Co-authored-by: Marcin Rataj <lidel@lidel.org> |
||
| .github | ||
| assets | ||
| bin | ||
| blocks/blockstoreutil | ||
| client/rpc | ||
| cmd | ||
| commands | ||
| config | ||
| core | ||
| coverage | ||
| docs | ||
| fuse | ||
| gc | ||
| internal/fusemount | ||
| misc | ||
| mk | ||
| p2p | ||
| plugin | ||
| profile | ||
| repo | ||
| routing | ||
| test | ||
| thirdparty | ||
| tracing | ||
| .codeclimate.yml | ||
| .cspell.yml | ||
| .dockerignore | ||
| .gitattributes | ||
| .gitignore | ||
| .golangci.yml | ||
| .hadolint.yaml | ||
| .mailmap | ||
| AGENTS.md | ||
| CHANGELOG.md | ||
| codecov.yml | ||
| CONTRIBUTING.md | ||
| doc.go | ||
| docker-compose.yaml | ||
| Dockerfile | ||
| FUNDING.json | ||
| GNUmakefile | ||
| go.mod | ||
| go.sum | ||
| LICENSE | ||
| LICENSE-APACHE | ||
| LICENSE-MIT | ||
| Makefile | ||
| README.md | ||
| Rules.mk | ||
| SECURITY.md | ||
| version.go | ||
| version_test.go | ||
Kubo: IPFS Implementation in Go
The first implementation of IPFS.
What is Kubo? | Quick Taste | Install | Documentation | Development | Getting Help
What is Kubo?
Kubo was the first IPFS implementation and is the most widely used one today. It takes an opinionated approach to content-addressing (CIDs, DAGs) that maximizes interoperability: UnixFS for files and directories, HTTP Gateways for web browsers, Bitswap and HTTP for verifiable data transfer.
Features:
- Runs an IPFS node as a network service (LAN mDNS and WAN Amino DHT)
- Command-line interface (
ipfs --help) - WebUI for node management
- HTTP Gateway for trusted and trustless content retrieval
- HTTP RPC API to control the daemon
- HTTP Routing V1 client and server for delegated routing
- FUSE mounts for mounting
/ipfs,/ipns, and/mfsas local filesystems (experimental) - Content blocking for public node operators
Other IPFS implementations: Helia (JavaScript), more...
Quick Taste
After installing Kubo, verify it works:
$ ipfs init
generating ED25519 keypair...done
peer identity: 12D3KooWGcSLQdLDBi2BvoP8WnpdHvhWPbxpGcqkf93rL2XMZK7R
$ ipfs daemon &
Daemon is ready
$ echo "hello IPFS" | ipfs add -q --cid-version 1
bafkreicouv3sksjuzxb3rbb6rziy6duakk2aikegsmtqtz5rsuppjorxsa
$ ipfs cat bafkreicouv3sksjuzxb3rbb6rziy6duakk2aikegsmtqtz5rsuppjorxsa
hello IPFS
Verify this CID is provided by your node to the IPFS network: https://check.ipfs.network/?cid=bafkreicouv3sksjuzxb3rbb6rziy6duakk2aikegsmtqtz5rsuppjorxsa
See ipfs add --help for all import options. Ready for more? Follow the command-line quick start.
Install
Follow the official installation guide, or choose: prebuilt binary | Docker | package manager | from source.
Prefer a GUI? Try IPFS Desktop and/or IPFS Companion.
Minimal System Requirements
Kubo runs on most Linux, macOS, and Windows systems. For optimal performance, we recommend at least 6 GB of RAM and 2 CPU cores (more is ideal, as Kubo is highly parallel).
Important
Larger pinsets require additional memory, with an estimated ~1 GiB of RAM per 20 million items for reproviding to the Amino DHT.
Caution
Systems with less than the recommended memory may experience instability, frequent OOM errors or restarts, and missing data announcement (reprovider window), which can make data fully or partially inaccessible to other peers. Running Kubo on underprovisioned hardware is at your own risk.
For running Kubo on constrained hardware such as a Raspberry Pi, see Kubo on low-memory devices.
Official Prebuilt Binaries
Download from https://dist.ipfs.tech#kubo or GitHub Releases.
Docker
Official images are published at https://hub.docker.com/r/ipfs/kubo/:
🟢 Release Images
Use these for production deployments.
latestandreleasealways point at the latest stable releasevN.N.Npoints at a specific release tag
$ docker pull ipfs/kubo:latest
$ docker run --rm -it --net=host ipfs/kubo:latest
To customize your node, pass config via -e or mount scripts in /container-init.d.
🟠 Developer Preview Images
For internal testing, not intended for production.
master-latestpoints atHEADofmastermaster-YYYY-DD-MM-GITSHApoints at a specific commit
🔴 Internal Staging Images
For testing arbitrary commits and experimental patches (force push to staging branch).
staging-latestpoints atHEADofstagingstaging-YYYY-DD-MM-GITSHApoints at a specific commit
Build from Source
git clone https://github.com/ipfs/kubo.git
cd kubo
make build # creates cmd/ipfs/ipfs
make install # installs to $GOPATH/bin/ipfs
See the Developer Guide for details, Windows instructions, and troubleshooting.
Package Managers
Kubo is available in community-maintained packages across many operating systems, Linux distributions, and package managers. See Repology for the full list:
Warning
These packages are maintained by third-party volunteers. The IPFS Project and Kubo maintainers are not responsible for their contents or supply chain security. For increased security, build from source.
Linux
| Distribution | Install | Version |
|---|---|---|
| Ubuntu | PPA: sudo apt install ipfs-kubo |
|
| Arch | pacman -S kubo |
|
| Fedora | COPR: dnf install kubo |
|
| Nix | nix-env -i kubo |
|
| Gentoo | emerge -a net-p2p/kubo |
|
| openSUSE | zypper install kubo |
|
| Solus | sudo eopkg install kubo |
|
| Guix | guix install kubo |
|
| other | See Repology for the full list |
Snap no longer supported (#8688)
macOS
| Manager | Install | Version |
|---|---|---|
| Homebrew | brew install ipfs |
|
| MacPorts | sudo port install ipfs |
|
| Nix | nix-env -i kubo |
|
| other | See Repology for the full list |
Windows
| Manager | Install | Version |
|---|---|---|
| Scoop | scoop install kubo |
|
| other | See Repology for the full list |
Chocolatey no longer supported (#9341)
Documentation
| Topic | Description |
|---|---|
| Configuration | All config options reference |
| Environment variables | Runtime settings via env vars |
| Experimental features | Opt-in features in development |
| HTTP Gateway | Path, subdomain, and trustless gateway setup |
| HTTP RPC clients | Client libraries for Go, JS |
| Delegated routing | Multi-router and HTTP routing |
| Metrics & monitoring | Prometheus metrics |
| FUSE mounts | Mount /ipfs, /ipns, /mfs as local filesystems |
| Content blocking | Denylist for public nodes |
| Customizing | Unsure if use Plugins, Boxo, or fork? |
| Debug guide | CPU profiles, memory analysis, tracing |
| Changelogs | Release notes for each version |
| All documentation | Full list of docs |
Development
See the Developer Guide for build instructions, testing, and contribution workflow. AI coding agents should follow AGENTS.md.
Getting Help
- IPFS Forum - community support, questions, and discussion
- Community - chat, events, and working groups
- GitHub Issues - bug reports for Kubo specifically
- IPFS Docs Issues - documentation issues
Security Issues
See SECURITY.md.
Contributing
We welcome contributions. See CONTRIBUTING.md and the Developer Guide.
This repository follows the IPFS Code of Conduct.
Maintainer Info
Note
Kubo is maintained by the Shipyard team.
License
Dual-licensed under Apache 2.0 and MIT:
