
自托管健身追踪器,安全记录健身数据。
数据安全意识提升,健身爱好者需求增加。
提供安全的数据记录方案,适合国内用户需求。
个人健身数据记录与管理。

A self-hosted gym and body-weight tracker you actually own.
Plan your week, run guided workouts, log every set and your body weight —
on your phone, synced across your devices, behind your own passkey login.
Website · Live demo · Android APK · Self-hosting guide · Roadmap · Changelog
![]() Home · today's workout and weight |
![]() Guided workout · demos and sets |
![]() Stats · heatmap, charts and PRs |
Most workout apps keep your data on their servers, push you towards a subscription, or vanish when the company does. openGym runs on your own box, keeps your data in a folder you control, and is yours to fork. It still behaves like a modern app: installable on the home screen, passkey sign-in, works offline, syncs between your phone and your laptop.
No account on someone else's server, no subscription, no ads, no telemetry. One
docker compose up and it's running.
The in-browser demo is the real app with example data, if you want to try it before installing anything.
Planning
Training
Progress
Accounts and data
Optional extras, off by default
The full list of what changed release by release is in the changelog.
You need Docker with Compose.
git clone https://github.com/DuarteSantos8/openGym
cd openGym
cp .env.example .env
docker compose pull # prebuilt images, amd64 + arm64 (skip this to build from source)
docker compose up -d
Open http://localhost:8080, tap Create profile, and you're in. The first start downloads the exercise media (about 140 MB) once.
To reach it from your phone with passkeys you need HTTPS on a domain; that's a two-line change in
.env. The self-hosting guide walks through Cloudflare Tunnel, Caddy,
Traefik and nginx, and there are separate guides for
HTTPS on a LAN and Kubernetes.
[!NOTE] Images are published from the same tag to
registry.gitlab.com/duartesantos8/opengym/{api,web}(whatdocker-compose.ymlpulls) andghcr.io/duartesantos8/opengym-{api,web}. Swap theimage:lines if you prefer GHCR, or rundocker compose up -d --buildto build locally. Either way you don't need Node on the host.
.env)| Variable | What it does | Default |
|---|---|---|
RP_ID |
Hostname passkeys are bound to | localhost |
ORIGIN |
Full URL the app is served from | http://localhost:8080 |
WEB_PORT |
Host port for the web UI | 8080 |
NGINX_PORT |
Port the web container listens on inside the container | 80 |
BACKEND |
Name of the API service that /api is proxied to |
api |
PORT |
Port the API listens on; the web container proxies to the same value | 3000 |
RP_NAME |
Name shown in the passkey prompt | openGym |
SESSION_DAYS |
How long a sign-in lasts, in days | 90 |
ADMIN_UIDS |
User ids that get the admin dashboard, comma-separated | (none) |
INVITE_ONLY |
Require an invite code to create a profile | (off) |
ALLOW_GUEST |
Offer "Continue without account"; 0 requires a profile |
(on) |
PASSWORD_LOGIN |
Offer name-and-password sign-in next to passkeys | (off) |
TRUST_PROXY |
Let the sign-in throttle read the client address from proxy headers | 1 in docker-compose.yml |
AUDIT_LOG |
Record sign-ins and admin actions; 0 records nothing |
(on) |
AUDIT_MAX |
Events kept in the activity log; 0 for no limit |
5000 |
AUDIT_DAYS |
Days kept in the activity log; 0 keeps until AUDIT_MAX |
90 |
AUDIT_IP |
Record the caller's address: off, net (network only) or full |
off |
VAPID_SUBJECT |
Contact URL sent with push notifications | your ORIGIN |
API_TARGET |
API image to build: default, or coach with the Claude Agent SDK and Codex CLI |
default |
COACH_DISABLED |
1 forces the AI coach off instance-wide |
(unset) |
Push-notification keys are generated on first run into ./data/vapid.json. DATA_DIR is pinned to
/data inside the container and mapped to ./data on the host; change the volume, not the
variable. The self-hosting guide covers every option in detail.
The same codebase builds a standalone app with Capacitor: no account, no server, everything stays on the phone, with native reminders and a rest countdown in the notification shade.
.sha256, and
the app checks for updates itself. openGym is deliberately not on the Play Store.Details and build instructions: docs/MOBILE.md.
frontend/ is React 19 and Vite (React Router, Zustand), built to static files inside Docker.api/ is plain node:http with two dependencies: @simplewebauthn/server for passkeys and
web-push for notifications. Everything is stored as JSON under ./data.web/ builds the frontend and serves it with nginx, proxying /api so the whole app sits on
one origin, which passkeys require.The training logic (progression rules, 1RM, how a logged session is read back) lives in pure
functions under frontend/src/lib/ with tests beside them. The HTTP API is documented as an
OpenAPI spec in api/openapi.yaml, browsable at
opengym.duarte-santos.ch/api.html.
Each profile's data is one document with a server revision. A device sends the revision it last saw along with its changes; if another device wrote in between, the server refuses and returns the current document so the device can merge and retry.
Nothing that hasn't reached the server is discarded on disconnect or sign-out, and the app shows a banner whenever it's working offline.
Everything lives in ./data on your host:
| File | Contents |
|---|---|
db.json |
Profiles and public passkey data |
state-<user>.json |
Each user's plan, workouts, body weight and settings |
audit.log |
Admin activity log (no IP addresses unless you turn that on) |
secret |
Session-cookie signing key |
Back up ./data and you've backed up everything. Passkey private keys never reach the server; they
stay in your phone's secure hardware or your password manager.
The documentation index sorts every guide by who it's for. The most used ones:
| I want to | Read |
|---|---|
| Get a quick answer | FAQ |
| Set up my own instance | Self-hosting |
| Use the Android or iPhone app | Phone app |
| Bring my history from another app | Importing data |
| Turn on the AI coach | AI coach |
| Contribute code | Contributing |
| Report a security problem | Security |
A release roughly every two weeks, each small and themed. The full plan is in ROADMAP.md, and the issues sit in the GitHub milestones.
| Release | Planned | Theme |
|---|---|---|
| v1.3.10 | Oct 2026 | Session queue and rotation |
| v1.3.11 | Nov 2026 | Programmes and phases |
| v1.3.12–13 | Nov–Dec 2026 | Progression engine: AMRAP, %1RM, 5/3/1 |
| v1.3.14 | Dec 2026 | Cardio, exercise alternatives, groups |
| v1.4.0 | Jan 2027 | Database storage (the one compatibility break) |
| v1.4.1–3 | Jan–Feb 2027 | Search, OIDC login, trainer role |
| v1.4.4–7 | Mar–Apr 2027 | iOS app, Health Connect, catalogue, skins |
RP_ID/ORIGIN mismatch; the
self-hosting guide covers it.GitHub is the home of the project. gitlab.com/DuarteSantos8/opengym
is a mirror, updated by a GitHub Actions workflow on every push to main and every release tag. It
exists because its CI builds the release artifacts: the signed APK, the multi-arch images and the
SBOMs. Nothing is merged there by hand. In the changelog, !NN refers to a GitLab merge request
from the weeks in August and September 2026 when the project lived there.
People have asked about this, so plainly: openGym is developed with
Claude Code, Anthropic's coding agent. A large share of the
code, tests and documentation is drafted in Claude Code sessions, and the repository carries a
CLAUDE.md with the project context those sessions start from.
What that does and doesn't mean:
Community pull requests are written by their authors, with whatever tools they like, and reviewed the same way.
openGym is free and stays free: AGPL, no paid tier, nothing held back for sponsors. If it replaced a paid tracker for you and you'd like to chip in, there's a coffee button below. A star, a bug report or a pull request helps just as much.
openGym's own code is licensed under the GNU AGPL v3.0. You can self-host, use, modify and share it; if you run a modified version as a network service, you have to offer that version's source under the same license.
[!IMPORTANT] The exercise media is not covered by that license. Exercise metadata and instruction text come from ExerciseDB v1 through hasaneyldrm/exercises-dataset under MIT. The images and animations are third-party content under neither MIT nor the AGPL, and their ownership is disputed: the dataset attributes them to Gym visual, while ExerciseDB/AscendAPI claims to own them. openGym doesn't redistribute them (your instance downloads them on first start) and doesn't relicense them. To reuse that media, clear it with the rights holder first.
Full third-party notices, including the body-diagram geometry, are in NOTICE.md.
同属 UI/应用 类型 · 适合同类用户的其他选择