# DoraCMS: an EggJS 3.x + Vue 3 CMS managed as a pnpm monorepo

> DoraCMS splits a content management system into an EggJS 3.x server, a Vue 3 user front end and a Vue 3 + TypeScript admin console, wired together with pnpm workspaces and shipped with Docker Compose profiles for MongoDB or MariaDB. The architecture is the product here, and that cuts both ways.

**doramart/DoraCMS** — DoraCMS 是一个基于 EggJS 3.x + Vue 3 + TypeScript 的现代化内容管理系统，采用 pnpm monorepo 架构管理。它不仅仅是一个 CMS 系统，更是一个优秀的企业级应用架构实践。

- Repository: https://github.com/doramart/DoraCMS
- Website: https://www.doracms.net
- Stars: 3,545 · Forks: 1,031
- Language: JavaScript
- License: MIT
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/doramart-doracms

## What DoraCMS solves, and for whom

Most content management systems give you a running site and hide the seams. DoraCMS does the opposite. The README describes it as a content management system built on EggJS 3.x, Vue 3 and TypeScript and managed as a pnpm monorepo, and the repository layout backs that up: server/ holds the EggJS backend, client/user-center/ and client/admin-center/ hold two separate Vue 3 front ends, and packages/ holds independently published npm packages. The stated audience is teams that treat the project as an enterprise application architecture example as much as a CMS.

That framing matters when you evaluate it. If you want a drop-in blog engine with a single install command, the multi-package split is overhead you will pay for and never use. If you are building a content product and want a reference for how an EggJS service, a public front end and a typed admin console share types and tooling through pnpm workspaces, the split is the reason to look. The demo at demo.doracms.net, with the admin console at /admin-center and the published credentials doracms / Hello985, is the fastest way to see which of those two situations you are in.

## The monorepo layout and the request path through it

The workspace is declared in pnpm-workspace.yaml and driven from a root package.json whose scripts fan out with pnpm --filter. The backend runs on EggJS 3.x and talks to MongoDB through Mongoose or to MariaDB through Sequelize; the README describes this as dual database support, and the compose file selects between them with a DATABASE_TYPE environment variable set to mongodb or mariadb. A repository layer under server/app/repository/ is documented separately as the database adaptation layer, which is the mechanism that lets one application serve two engines.

A request to the public site hits the EggJS server, which renders Nunjucks templates and reads the current locale from ctx.locale. The README states that a localeDetector middleware picks the language from the URL, a cookie and the Accept-Language header, then syncs it to the session, and that Nunjucks filters and date helpers read the same value so page rendering and API responses agree. The admin console is a separate Vue 3 + TypeScript application built on Vite 6.x and derived from SoybeanAdmin, with Element Plus, Pinia, UnoCSS and Echarts. Authentication is JWT. Redis is listed as optional in the technology stack, but the compose file labels it as required, a contradiction worth resolving before you plan a small deployment.

## Installing DoraCMS and starting the three services

The README targets Node.js >= 14.0.0 with 18.x recommended and pnpm >= 8.0.0, plus MongoDB or MariaDB and optional Redis. The root package.json enforces the package manager with a preinstall hook that runs npx only-allow pnpm, so npm and yarn installs will be rejected. Clone and install from the repository root:

```bash
git clone https://github.com/doramart/DoraCMS.git
cd DoraCMS
pnpm install
```

Development is split by target. The README documents pnpm dev for the server plus the user front end, pnpm dev:all to start every project in parallel, and single targets for when you only want one process. Ports are fixed in the documentation: 7001 for the backend API, 3000 for the user front end and 5173 for the admin console.

```bash
pnpm dev:server
pnpm dev:user-center
pnpm dev:admin-center
```

For a container deployment the README points at docker-quickstart.sh or a plain compose up. The compose file defines the application service with profiles, so the database choice is a profile rather than an edit. The app listens on 8080 inside the container, mapped to 8080 on the host, with the admin console at /admin and the API under /api.

```bash
docker compose up -d
docker compose --profile mariadb up -d
docker compose --profile redis up -d
```

Before exposing any of this, the README is explicit that APP_KEYS, SESSION_SECRET and database passwords must be changed in production, and it offers two ways to generate a key. Copy docker.env.example to .env first, then edit it.

```bash
cp docker.env.example .env
node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
openssl rand -hex 32
```

The Dockerfile builds on node:18-alpine in two stages, installs pnpm@9 in the builder, copies the server into the production image, runs as a non-root eggcms user and declares a health check against http://localhost:8080/api/health. That health endpoint is the concrete thing to poll after a first start.

## Where DoraCMS will disappoint you

The release history is the first problem. The most recent release listed is 2.1.6, a zip file dated 2020-08-01, while the default branch is 3.1 and the root package.json declares version 3.0.0. There is no published 3.x artifact in the release list, so anyone who wants a tagged, downloadable build is working with code from six years earlier or tracking a branch. The last push to the repository was on 2026-07-12, so the branch is not stale, but the release channel and the branch have diverged.

The second problem is the documentation boundary. The README links to a Docker deployment guide on doracms.net and to local files including DOCKER_DEPLOYMENT.md and DATABASE_MIGRATION.md, but nothing in what the README shows describes rollback, downgrade or what happens when a migration between MongoDB and MariaDB fails partway. If you plan to switch engines in production, that gap is yours to close by reading the migration document and testing on a copy.

The third is the Redis contradiction. The technology stack calls Redis optional; the compose file comments call it required. One of those statements is wrong for your deployment, and only a trial run will tell you which.

Finally, the monorepo is a cost. Three applications, a shared root, a workspace filter for every dependency addition, and an admin console that needs Node.js >= 18.20.0 even though the root engines field says >= 14.0.0. The README addresses that mismatch directly with an nvm instruction, which is a fair sign the constraint has bitten people.

## DoraCMS against Strapi and Directus

Strapi and Directus are the obvious alternatives, and the difference is architectural rather than feature-level. Both are Node.js content platforms that ship a single application with an admin interface generated from your content model, and both distribute versioned releases. You install one package, define content types in the admin UI, and get REST or GraphQL endpoints. The content model lives in the tool.

DoraCMS inverts that. The content model is expressed in the EggJS application and its repository layer, the admin console is a separate Vue 3 application you build and deploy yourself, and the public site is a third application rendering Nunjucks templates on the server. Nothing generates an API from a schema you define in a browser. If you want to change how content is stored, you edit the server. That is more work and more control.

The practical consequence is deployment shape. A Strapi or Directus instance is one service plus a database. DoraCMS in development is three processes on three ports, and in Docker it is one container plus MongoDB or MariaDB plus optionally Redis and Nginx. Choose DoraCMS when you want to own the rendering layer and the data layer in one codebase; choose the other two when you want the tool to own them.

## Licence, maintenance and the cost of upgrading

DoraCMS is MIT licensed, per the LICENSE file and the badge in the README. MIT permits commercial use and modification and requires that the copyright notice and permission notice travel with copies or substantial portions of the software. That is the general shape of the licence; whether a specific redistribution satisfies it is a question for your own counsel, not for this article.

Upgrade cost is where the monorepo shape shows. The root package.json pins pnpm >= 8 in engines while the Dockerfile installs pnpm@9, and the admin console requires Node.js >= 18.20.0 against a root engines field of >= 14.0.0. Any dependency bump goes through pnpm --filter against the specific workspace, and the README's own troubleshooting entry for dependency conflicts is to run pnpm clean followed by pnpm install. That is a full reinstall of every workspace, which is the realistic recovery path when a lockfile change goes wrong.

The last push was on 2026-07-12. The repository is not archived. Judging maintenance from those two facts alone, the branch is current but the release channel is not, and the README does not describe a supported upgrade path between major versions.

## Verifying a DoraCMS checkout before you commit

Start with the demo, then reproduce it locally. The README publishes the admin console at https://demo.doracms.net/admin-center with the account doracms and password Hello985, which lets you inspect the content, model and AI publishing screens before installing anything. Then clone the repository, run pnpm install, and start the three development targets on 7001, 3000 and 5173 to confirm your Node and pnpm versions satisfy every workspace rather than just the root.

After that, decide your database before you write content. MongoDB is the default profile; MariaDB is the alternative, and the README links a migration guide for moving between them. Whichever you pick, set APP_KEYS and SESSION_SECRET in .env from generated values, not from the example file, and check that /api/health responds once the container is up. Those three checks, a local start, a chosen database and rotated secrets, are the ones the README itself treats as non-negotiable.

## Conclusion

Adopt DoraCMS if you want a working CMS that doubles as a reference layout for a pnpm monorepo and an EggJS service, and you are comfortable reading the repository because the README does not document rollback or migration failure handling. Do not adopt it if you need a versioned release artifact: the newest release entry is 2.1.6 from 2020-08-01, while the default branch is 3.1 and package.json reports 3.0.0, so branch tracking is the only path to current code. Before committing, clone the repository, run pnpm install, and confirm that server, client/user-center and client/admin-center all start on their documented ports.

## FAQ

### How do I install DoraCMS?

Clone the repository, then run pnpm install from the root; the root package.json has a preinstall hook running npx only-allow pnpm, so npm and yarn are rejected. Node.js >= 14.0.0 with 18.x recommended and pnpm >= 8.0.0 are the stated requirements.

### Which database does DoraCMS use, MongoDB or MariaDB?

Both are supported. The README describes dual database support through Mongoose and Sequelize, and Docker Compose selects between them with the DATABASE_TYPE environment variable set to mongodb or mariadb. MongoDB is the default profile.

### What ports does DoraCMS run on?

In development the README lists the backend API on 7001, the user front end on 3000 and the admin console on 5173. In the Docker deployment the application is exposed on 8080, with the admin console at /admin and the API under /api.

### Is DoraCMS free to use commercially?

It is MIT licensed according to the LICENSE file and the README badge. MIT permits commercial use and modification and requires the copyright and permission notice to be included with copies or substantial portions of the software.

## Sources

- [doramart/DoraCMS on GitHub](https://github.com/doramart/DoraCMS)
- [License: MIT](https://github.com/doramart/DoraCMS/blob/3.1/LICENSE)
- [Project website](https://www.doracms.net)
- [README](https://github.com/doramart/DoraCMS/blob/3.1/README.md)
- [Releases](https://github.com/doramart/DoraCMS/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/doramart-doracms
