Skip to content

About

Super simple group chat, without a subscription

Resources

Contributing

Security policy

Stars

4.8k stars

Watchers

28 watching

Forks

Repository files navigation

Campfire

Campfire is a web-based chat application. It supports many of the features you'd expect, including:

  • Multiple rooms, with access controls
  • Direct messages
  • File attachments with previews
  • Search
  • Notifications (via Web Push)
  • @mentions
  • API, with support for bot integrations

Running your own Campfire instance

Campfire's Docker image contains everything needed for a fully-functional, single-machine deployment. This includes the web app, background jobs, caching, file serving, and SSL. You can use our pre-built image at ghcr.io/basecamp/once-campfire:latest, or build your own from this repo.

Deploying with ONCE

The easiest way to self-host Campfire is with ONCE. It will guide you through the initial set up and then keep your instance up to date automatically.

If you don't already have once installed, run this on the machine you want to run Campfire on:

curl https://get.once.com | sh

once will launch as soon as the install is finished.

Choose Campfire from the list of applications, follow the instructions, and ONCE will take care of the rest.

If you prefer the command line to the dashboard, you can deploy directly:

once deploy ghcr.io/basecamp/once-campfire --host chat.example.com

Deploying with Docker

If you'd rather run the Docker image yourself, you can read more about that in the self-hosting guide.

Tip

When you start Campfire for the first time, you'll be guided through a wizard to create an admin account. The email address that you enter for the admin account will be visible on the sign-in page, it's there so that people have someone to contact if they need help with their account. If that bothers you, put in any email address you want and create yourself a new admin account.

Authenticated room, message, sidebar and search pages use a bounded 64 MiB cache per worker. Set CAMPFIRE_RESPONSE_CACHE_MB=0 to disable it. Every request still checks authentication and room access; commits from any SQLite writer invalidate complete cached HTML and gzip bodies. Native HTML, JSON and stream fragments have a separate 64 MiB memory limit per worker; shared rate limits retain their existing store.

Other implementations

Campfire also has implementations in Django, Laravel, Express, Elixir, Go, Rust and C:

HTTP workload (requests/sec) Rails Django Laravel Express Elixir Go Rust C
Room page 4,101 1,507 3,872 42,636 5,350 53,060 106,494 137,524
Messages page 4,115 1,596 3,995 74,362 5,712 54,800 102,697 144,642
Sidebar 4,333 1,873 4,493 94,329 5,949 59,144 120,294 152,002
Search 4,282 1,862 4,172 84,665 5,848 60,509 121,378 149,487
Post a message 330 262 794 2,155 1,278 9,021 8,037 7,530
Backend KLOC 4.4 5.0 3.9 6.5 10.3 22.9 29.8 94.8

KLOC counts backend application code only; excludes frontend, templates, tests, dependencies and generated files.

Shared verification · Detailed results.

Measured with 16 concurrent clients on an AMD Ryzen AI MAX+ 395 with 32 GB RAM, with four hardware cores allocated to each app.

Development

You are welcome - and encouraged - to modify Campfire to your liking. Please see our development guide for how to get Campfire set up for local development.

Security

See SECURITY.md for how to report a vulnerability and a description of our trust model.

Browser writes use Rails’ Sec-Fetch-Site header-only protection and Origin check. HTTPS requires browser metadata; plain HTTP retains the missing-header fallback. Forms contain no CSRF tokens. Existing cookies, bot APIs and signed uploads remain compatible.

About

Super simple group chat, without a subscription

Resources

Contributing

Security policy

Stars

4.8k stars

Watchers

28 watching

Forks

Releases

Packages

Used by

Contributors

Languages