When developer advocate swyx issued a challenge on X—asking for "an open source Dropbox on Cloudflare R2"—New York City founder Zach Meyer did something unusual. He actually built it.
Within days, Meyer had shipped Locker.dev, an MIT-licensed file storage platform designed to let users plug in their own S3 buckets rather than fork over monthly fees to Dropbox or Google Drive. The timing was April, and the project landed on Hacker News with a title engineered for maximum provocation: "Stop paying for Dropbox/Google Drive, use your own S3 bucket instead."
The response was immediate. GitHub stars climbed past 500, reaching 562 by early April. But alongside the enthusiasm came something more valuable: a sprawling, skeptical debate about what it really takes to replace enterprise file storage services. Turns out, quite a lot.
The Promise: Your Files, Your Cloud, Your Rules
Locker's pitch is straightforward enough. It's a web-based interface that handles the table stakes of file management—upload, organize, rename, move, delete—through a familiar explorer view. Users can generate shareable links with password protection, expiration dates, and download limits. There's an upload link feature allowing anyone to send files without creating an account.
Then Meyer added a twist: OCR-based search. Locker transcribes images and PDFs into searchable text, making every document in your bucket discoverable. For developers, there's a virtual Bash filesystem (labeled beta as of early April 2026) that lets you navigate your workspace using commands like ls, cd, find, cat, and grep through a tRPC API. Write operations fail with EROFS errors—the filesystem stays read-only for now, which is perhaps more cautious than ambitious.
The platform supports workspace teams with role-based access. Authentication happens via email and password or Google OAuth. API keys enable programmatic access. Storage quotas can be configured per-user. Sessions run on encrypted cookies.
Nothing groundbreaking, exactly. But then there's the one-variable trick.
The Architecture of Flexibility

Locker's core selling point is provider agnosticism. According to the documentation, you can run it on local filesystem storage, AWS S3, Cloudflare R2, or Vercel Blob—and swap between them by changing a single environment variable. No code changes required.
The technical stack reads like a checklist of modern web development trends: Next.js 16 with App Router and Turbopack, PostgreSQL 16 paired with Drizzle ORM, tRPC 11 for type-safe APIs, BetterAuth handling authentication, and Tailwind CSS 4 with Radix UI components. The monorepo structure uses Turborepo and pnpm. It requires Node 20 or higher and ships with a docker-compose file for spinning up local Postgres.
Community contributions arrived quickly. One early pull request added support for custom S3 endpoints via environment variables, extending compatibility to S3-like providers beyond what Meyer originally documented. An open issue suggests replacing the AWS SDK entirely with S3mini to broaden the field even further.
The Economics of DIY Storage
Meyer frames the project around a simple economic argument: "free forever, open source, no strings attached; you pay your own infrastructure." For developers already nursing frustration over recurring SaaS bills, the math can be compelling—provided you're already paying for S3 storage anyway.
Cloudflare R2 gets particular attention in the discussion threads, and for good reason. R2 offers S3-compatible APIs with zero egress fees. That matters when you're sharing files frequently. Traditional S3 charges for bandwidth, and those costs accumulate faster than most people expect. The calculus becomes whether managing your own infrastructure—and accepting certain feature trade-offs—justifies the savings.
Several Hacker News commenters ran the numbers and emerged unconvinced. "Storage is the easy part," one noted, cutting to the heart of the matter. The real challenge lies in building sync engines, conflict resolution logic, desktop clients with deep OS integration, and offline mode. Those are the features that make Dropbox feel invisible, the kind of engineering that takes years, not days.
The Feature Gap

The GitHub repository shows the project in its early stages. File versioning and history aren't explicitly documented, though multiple Hacker News users raised the question. Desktop and mobile sync clients don't exist yet. There's no FUSE integration for mounting Locker as a native filesystem on macOS, Windows, or Linux. The documentation emphasizes authentication security but stops short of claiming end-to-end encryption.
These aren't oversights so much as engineering realities. Meyer constructed a functional web interface for S3 storage in roughly a week—an impressive feat. Building the infrastructure to match Dropbox's seamless, cross-platform experience would require substantially more time. Perhaps years.
As of early April 2026, the repository showed three open pull requests and three open issues. One requests an all-in-one docker-compose configuration to simplify deployment. Commit history and forks suggest early momentum, though whether it sustains remains an open question.
Crowded Territory
The discussion threads evolved into something of a catalog session for existing alternatives. Nextcloud offers a comprehensive self-hosted ecosystem with an extensive app marketplace. Seafile provides efficient synchronization and supports external storage locations on certain platforms. Syncthing delivers peer-to-peer file sharing without requiring any central server. The command-line tool rclone handles syncing across dozens of backends.
Each addresses different slices of the file storage problem, and each comes with its own complexity budget.
Locker distinguishes itself through simplicity and that single-variable provider switch. It's not attempting to be Nextcloud with its plugin architecture or Syncthing with its distributed sync protocol. It's a web interface for your S3 bucket, with OCR search and a developer-friendly API thrown in. That narrower scope might be exactly what some teams need—or it might be too narrow to matter.
What Happens Next

Meyer, who lists roles as co-founder and CTO of Zap App and graduated from Washington University in 2022, hasn't published a detailed write-up about Locker's architecture or long-term roadmap. The project's direction will likely depend on community interest and contribution patterns in the coming months.
For developers already managing S3 buckets who want a clean interface without monthly fees, Locker offers a working foundation. For teams expecting Dropbox-level polish and native clients across every platform, it represents a starting point with considerable distance still to travel.
The MIT license means anyone can fork the code, extend it, or run it commercially. But first they'll need to decide something more fundamental: whether controlling their storage infrastructure is worth the burden of managing their storage infrastructure. That trade-off, more than any technical feature, will determine whether projects like Locker remain experiments or evolve into genuine alternatives.
Some founders see a problem on social media and talk about solving it. Meyer built something in a week and put it out there. Whether that week-long sprint becomes something more substantial depends on what happens next—and whether enough people share his willingness to trade convenience for control.
