Container images for cal.diy, the MIT community fork of Cal.com.
docker pull zenjoy/cal-diy:main
docker pull ghcr.io/zenjoy/cal-diy:mainCal.com went closed-source in April 2026 and its official image is frozen at v6.2.0. cal.diy
continues as an MIT fork but publishes no container image of its own, so we build it ourselves.
This repo holds no application code. It pins an upstream commit and builds upstream's unmodified
Dockerfile with calcom/cal.diy as the build context.
versions.env is the single source of truth:
CAL_DIY_REF=<40-char commit sha of calcom/cal.diy>
Renovate watches main of the upstream repo (git-refs datasource) and opens a PR to bump the sha.
To bump by hand:
gh api repos/calcom/cal.diy/commits/main --jq .shaMerging a change to versions.env on main triggers a build. You can also run the
Build and push container images workflow manually; its optional ref input overrides
versions.env for that run (handy to test an upstream branch without committing).
| Tag | Meaning |
|---|---|
<yyyymmdd>-<sha7> |
Immutable build tag — use this in Kubernetes |
sha-<sha7> |
Alias for the upstream commit |
main |
Latest successful build |
amd64 only. Builds take ~45-60 min (Next.js monorepo, MAX_OLD_SPACE_SIZE=6144).
Upstream's entrypoint is scripts/start.sh, which on every boot:
- Rewrites the baked-in URL placeholder with the runtime
NEXT_PUBLIC_WEBAPP_URL(static Next.js output is patched in place, so the container filesystem must be writable). - Waits for
DATABASE_HOST(set it, orwait-for-it.shhangs/errors). - Runs
prisma migrate deploy— deploy one replica at a time, strategyRecreate. - Seeds the app store (
seed-app-store.ts), thenyarn start.
Because of step 1, NEXT_PUBLIC_WEBAPP_URL is not a build arg here — set it at runtime.
Other facts from upstream's Dockerfile: listens on port 3000, runs as root (node:20 base, no
USER), and has a HEALTHCHECK hitting http://localhost:3000. Required runtime env includes
DATABASE_URL, DATABASE_DIRECT_URL, NEXTAUTH_SECRET, NEXTAUTH_URL,
CALENDSO_ENCRYPTION_KEY (never rotate this one) and NEXT_PUBLIC_WEBAPP_URL.
All images are signed with Cosign keyless signatures:
cosign verify \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-identity-regexp https://github.com/zenjoy/docker-cal-diy/.github/workflows/ \
zenjoy/cal-diy:mainThis repo is MIT (LICENSE). The image content is calcom/cal.diy, also MIT.