# AList mounts one data directory and publishes two ports, 5244 and 5245

> A Go and SolidJS file listing program that puts dozens of storage backends behind one WebDAV and web interface. The shipped compose file runs as root, forwards traffic to upstream providers rather than storing data itself, and makes no promise about your account surviving the traffic.

**AlistGo/alist** — GitHub describes it as 🗂️A file list/WebDAV program that supports multiple storages, powered by Gin and Solidjs. / 一个支持多存储的文件列表/WebDAV程序，使用 Gin 和 Solidjs。. The repository metadata lists Go as its primary language. The metadata lists the AGPL-3.0 license. This article stays within the project description and details documented in the GitHub repository README.

- Repository: https://github.com/AlistGo/alist
- Website: https://alistgo.com
- Stars: 50,246 · Forks: 7,939
- Language: Go
- License: AGPL-3.0
- Published: 2026-08-13 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/alistgo-alist

## The shipped compose file runs as root and publishes two ports

The container definition in the repository is the shortest way to see the deployment assumptions:

```yaml
    volumes:
      - '/etc/alist:/opt/alist/data'
    ports:
      - '5244:5244'
      - '5245:5245'
    environment:
      - PUID=0
      - PGID=0
      - UMASK=022
      - TZ=UTC
```

PUID and PGID both being 0 means the process runs as root unless you change them, and the two published ports are both bound on the host, not restricted to localhost. The data volume is the other half: configuration and the SQLite-style state the program keeps sit under /opt/alist/data inside the container, which is /etc/alist on the host, a path that reads like system configuration and is worth renaming before you rely on a backup of it.

The image is xhofe/alist:latest, so a compose file with no tag pinning tracks whatever is newest. Combined with the restart: always setting and the host root directory in the volume path, the defaults are built for a quick private install rather than a reviewed one.

## ffmpeg and aria2 are build arguments, so the image you pull is not the one you build

The Dockerfile has two build arguments, both defaulting to false:

```dockerfile
ARG INSTALL_FFMPEG=false
ARG INSTALL_ARIA2=false
```

With INSTALL_FFMPEG set to true the runtime layer adds ffmpeg, which is what the video and audio preview features would need. With INSTALL_ARIA2 set to true the build installs aria2, then downloads a configuration archive from a third-party repository at github.com/P3TERX/aria2.conf, unpacks it into /opt/aria2/.aria2, and rewrites the paths in aria2.conf and script.conf with a chain of sed commands so nothing points back at /root. The rpc-secret line is commented out in the same pass.

That detail matters more than it looks. The image on Docker Hub was built by whoever ran the Dockerfile with those flags as they chose, and a configuration file from another project is baked in at build time, not fetched at runtime. If you care which flags went into the image you run, build it yourself with the arguments set deliberately rather than assuming the published tag matches your needs, and read the sed chain before you enable the download acceleration path.

## Drivers live in their own directory, and the module path is alist-org/alist/v3

The Go module declares itself as github.com/alist-org/alist/v3 on Go 1.25.0, while the repository this article covers sits under a different owner. The /v3 suffix in the module path is the part with lasting consequences: any Go program importing AList as a library has to write that path, and the major version is baked into every import line rather than being resolved by a tag.

The layout is a conventional Go split. drivers/ holds the storage backends, which is where the per-provider SDK calls live, and the go.mod dependency list shows what that costs: the Azure SDK, the AWS SDK, the Aliyun OSS SDK, an FTP server library with passive port mapping, an SFTP library forked for this project, an SMB client, WebAuthn and OIDC packages, plus ProtonMail's crypto and OpenPGP libraries for credential handling.

Around that sit server/ for the HTTP side, public/ for the SolidJS front end, internal/ and pkg/ for shared code, cmd/ for entry points, and a main.go at the root. .air.toml is a live-reload config for local Go work, Dockerfile.ci is a separate image, and renovate.json says dependency bumps are automated. Two web frameworks appear in the module path: Gin for the server and SolidJS for the interface named in the project description.

## WebDAV reaches OneDrive and SharePoint without their API

The parenthetical on the WebDAV line is the most interesting claim in the feature list: WebDav (Support OneDrive/SharePoint without API). Elsewhere in the same list, OneDrive and SharePoint appear as ordinary storage drivers with separate endpoints for the global, cn, de and us clouds, which implies API credentials. The WebDAV route is offered as the alternative when you would rather not hand over API access, and the project points at a separate guide page for the details.

That gives AList two distinct ways to expose a file. The web interface handles preview, upload, delete, mkdir, rename, move and copy, with web upload described as something that can be allowed for visitors. The WebDAV interface is what a file manager or a backup tool mounts. Protected routes sit in front of both, described as password protection and authentication, so a deployment that opens visitor uploads still has an access control to configure.

The API surface is documented through Apifox at a public address, and the CLI and automation story is not documented in the repository at all, so a reader planning to script against AList is working from the published API reference rather than from anything in the tree.

## The disclaimer says it forwards 302 redirects and nothing more

Three lines in the disclaimer set the boundary of what the program is, and they are the most consequential text in the repository. It is implemented by calling the official sdk and interface without destroying the official interface behavior. It only does 302 redirect and traffic forwarding, and does not intercept, store or tamper with any user data. And before using it you should understand and bear the corresponding risks, including but not limited to account ban and download speed limit, which is explicitly none of the program's business.

Read together, those lines mean your files stay with their providers and AList sits in the request path. A mount that goes through AList is a mount whose throughput is bound by an upstream provider's rate limits, and whose account is bound by that provider's terms. If a provider decides an account is being used in a way it does not like, the ban lands on the account, not on the proxy, and the program's own text says it will not help you with that.

The corollary for anyone treating AList as a backup or an archive is blunt. A forwarding layer is not a copy of your data, and the storage it lists is not storage it owns.

## Thirty-odd storage checkboxes, and one of them is marked differently

The feature list opens with a checked box per storage backend, and the count is around thirty: local storage, Aliyundrive, OneDrive and Sharepoint across four clouds, 189cloud, GoogleDrive, 123pan, FTP and SFTP, PikPak, S3, Seafile, UPYUN, Teambition in two regions, MediaFire, Mediatrack, ProtonDrive, 139yun, YandexDisk, BaiduNetdisk, Terabox, UC, Quark, Thunder, Lanzou, ILanzou, SMB, 115, Dropbox, FeijiPan, dogecloud and Azure Blob Storage, plus photo libraries from Google, Baidu and Mega.nz.

Every one of those lines is prefixed with a checked lowercase x, except Cloudreve, which carries a capital X. The repository does not explain the difference, so treat that entry as unverified rather than as a disabled or pending feature.

The breadth is the product and also its cost. Each backend is an independent integration against a third-party API, which is why the go.mod file lists SDKs from several clouds at once, and each one inherits that provider's rate limits and account rules. Adding a storage is adding a maintenance relationship, not adding a line of configuration.

## Preview and download are the features that need the optional build flags

Beyond listing, the program previews PDF, markdown, code and plain text, renders README.md previews, shows images in a gallery mode, and handles video and audio with lyrics and subtitles. Office documents get their own preview path for docx, pptx and xlsx. Files and folders can be downloaded as a package, there is a permalink copy and a direct file download, and downloading is accelerated by running multiple threads against a single-thread download or stream.

Some of that machinery needs what the Dockerfile makes optional. Video and audio preview is where ffmpeg earns its place, and multi-thread download acceleration is the aria2 path, the one that pulls in a third-party configuration and rewrites its paths during the image build. Offline download and copying files between two storages are the two features that reach across the abstraction rather than sitting on top of it, which is also where the driver's assumptions about paths, permissions and rate limits are most likely to differ between providers.

A gallery that renders and a multi-threaded download that stalls are two different subsystems, and the README does not say which of them a given storage backend supports. That gap is worth probing with a throwaway folder before you point a client at a directory that matters.

## Version tags are frequent, and one release is still called AList Beta Version

The last push to the default branch main is dated 2026-09-29, and the release list shows v3.64.0 published on 2026-09-03 and v3.63.0 on 2026-08-05. That cadence is a project shipping changes often, and it is also an argument for pinning rather than tracking a branch.

Alongside those tags sits a release whose name is AList Beta Version, dated 2024-08-17. The repository does not say whether that beta channel is still cut, so a reader who wants a pre-release has no documented way to tell whether it is current or abandoned.

The licence is AGPL-3.0, stated in the README and in the LICENSE file at the root. For a program intended to sit on a network and serve files to other people, that choice has teeth: the copyleft obligations attach to network use, not only to distribution of the source, so an organisation that modifies AList and runs it for others is in a different position from one running it unmodified. The project is maintained by a single named maintainer who asks for sponsorship, and translations run through Crowdin, with the repository itself carrying English, Chinese and Japanese READMEs.

## Conclusion

Adopt AList when you have files spread across providers that do not speak to each other and you want one address, one WebDAV mount and one set of credentials in front of them, because the WebDAV path even reaches OneDrive and SharePoint without their API. Do not adopt it as durable storage or as a backup: the disclaimer states the program only does 302 redirect and traffic forwarding without intercepting, storing or tampering with data, and that account bans and download speed limits are the user's risk. Two things to check before you point a client at it. Read the compose file rather than trusting the defaults, since PUID and PGID are both 0 and the data directory lives at /etc/alist on the host. And read the licence before you modify it, because AGPL-3.0 attaches obligations to network use that a permissive licence would not.

## FAQ

### What is AList?

A file list and WebDAV program that supports multiple storages, powered by Gin and SolidJS. It puts around thirty storage backends behind one web interface and one WebDAV endpoint.

### Does AList store my files or just forward requests?

It only does 302 redirect and traffic forwarding, and does not intercept, store or tamper with any user data. Your files stay with the provider whose storage you mounted.

### How do I deploy AList with Docker Compose?

The repository ships a compose file using the xhofe/alist:latest image with ports 5244 and 5245 published and /etc/alist mounted to /opt/alist/data. Note that it sets PUID=0 and PGID=0, so the process runs as root unless you change those values.

### Can AList mount OneDrive or SharePoint over WebDAV?

Yes. The feature list marks WebDAV as supporting OneDrive and SharePoint without their API, as an alternative to the OneDrive and Sharepoint storage drivers, which are listed separately with global, cn, de and us endpoints.

### What licence is AList released under?

AGPL-3.0. The README states that AList is open-source software licensed under the AGPL-3.0 license, and a LICENSE file sits at the root of the repository.

## Sources

- [Official documentation](https://alistgo.com)
- [Official README](https://github.com/AlistGo/alist#readme)
- [Project repository](https://github.com/AlistGo/alist)
- [Release notes](https://github.com/AlistGo/alist/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/alistgo-alist
