A containerised alternative ISO encryptor/decryptor for PS3 disc images with a web GUI.
This is started from the modified version of PS3Dec r5, but uses mbedTLS 4.x (via the PSA Crypto API) for AES encryption/decryption and CMake as the build system.
This was built because there are many GUI tools on Windows, but not many on Linux. Additionnaly, the container format makes this fully portable and avoids the headache of compiling PS3Dec which needs very outdated dependencies.
mkdir -p iso keys output # put .iso files in ./iso and their .dkey files in ./keys
docker compose up -d --buildThen open http://localhost:8000. Converted images appear in ./output.
Without compose:
docker build -t ps3dec .
docker run --rm -p 127.0.0.1:8000:8000 --user "$(id -u):$(id -g)" \
-v "$PWD/iso:/data/iso:ro" -v "$PWD/keys:/data/keys:ro" -v "$PWD/output:/data/output" \
ps3decCreate the three folders first: if a bind-mounted folder is missing, Docker creates it as root and the container cannot write to it (the compose file refuses to start instead). --user (or PS3DEC_UID / PS3DEC_GID for compose) makes the files in ./output yours; the image itself runs as UID 1000.
A small local web UI around the PS3Dec tool: pick a disc image and its key, press Start, watch progress. It runs in one container (FastAPI backend serving a React frontend) and works on folders you mount into it. Nothing is uploaded or downloaded through the browser.
Local use only. There is no authentication and one job runs at a time. Keep the port bound to 127.0.0.1 and do not expose it to a network.
Since the PS3Dec binary is compiled inside the container, it's still possible to run it manually inside the container, e.g:
docker compose exec ps3dec ps3dec d key <disc_key_hex> /data/iso/disc.iso /data/output/disc.dec.isoWithout compose:
docker run --rm --user "$(id -u):$(id -g)" \
-v "$PWD/iso:/data/iso:ro" -v "$PWD/keys:/data/keys:ro" -v "$PWD/output:/data/output" \
--entrypoint ps3dec ps3dec \
d d1 <d1_hex> /data/iso/disc.iso /data/output/disc.dec.iso| Container path | Purpose | Mount |
|---|---|---|
/data/iso |
input .iso files (top level only, no subfolders) |
read-only |
/data/keys |
.dkey files |
read-only |
/data/output |
results | read-write |
An existing file in output is only replaced after you confirm, and only once the new one is complete (the tool writes to <name>.iso.ps3dec.part and renames it on success; stale .ps3dec.part files are removed at startup).
- A
.dkeyfile holds the disc's D1 as 32 hex characters (an optional0xprefix and surrounding whitespace are fine), as distributed by redump. - A key is suggested for an ISO when the names match apart from the extension, ignoring case:
Game.iso+game.dkey. You can pick another key by hand. - 3k3y images carry their own key and need none.
- The tool cannot tell whether a key is wrong. With the wrong key a job still finishes "successfully" and writes an image whose encrypted regions are garbage. Check the key if the result does not boot or mount.
All optional; the defaults match the container layout above.
| Variable | Default | |
|---|---|---|
PORT |
8000 |
port inside the container |
PS3DEC_ISO_DIR |
/data/iso |
|
PS3DEC_KEYS_DIR |
/data/keys |
|
PS3DEC_OUTPUT_DIR |
/data/output |
|
PS3DEC_BIN |
/usr/local/bin/ps3dec |
the PS3Dec binary |
PS3DEC_STATIC_DIR |
/app/static |
built frontend |
Job state is held in memory, so the app must run as a single worker (the default python -m app does; do not start it with several).
Four stages, all on Debian trixie: mbedTLS 4.2.0 is built from its release tarball (SHA-256 checked) and linked statically into PS3Dec; the frontend is built with Node and pnpm; the backend's Python dependencies are installed into a venv; the final stage contains only Python, libgomp, the venv, the binary and the built frontend, with no compilers or Node.
Every push to main builds this image and publishes it to GHCR as ghcr.io/tonyp7/ps3dec:latest, so it can be pulled instead of built locally:
docker pull ghcr.io/tonyp7/ps3dec:latestTagging a commit vX.Y.Z (always done against main's current HEAD) promotes that same image to ghcr.io/tonyp7/ps3dec:X.Y.Z and creates a GitHub Release for that version containing both that image tag and the Flatpak bundle (see Flatpak above) — so a release always has one container image and one Flatpak bundle at the same version.
# backend (needs uv); the tests use build/Release/PS3Dec when it exists (see Compilation below)
cd backend && uv sync && uv run pytest
PS3DEC_ISO_DIR=../iso PS3DEC_KEYS_DIR=../keys PS3DEC_OUTPUT_DIR=../output \
PS3DEC_BIN=../build/Release/PS3Dec PS3DEC_STATIC_DIR=/nonexistent uv run python -m app
# frontend (needs pnpm); the dev server proxies /api to localhost:8000
cd frontend && pnpm install && pnpm dev
pnpm test- Visual Studio 2017 (with Visual Studio C++ tools for CMake installed)
- mbedTLS 4.x (e.g. via vcpkg:
vcpkg install mbedtls); pass the vcpkg toolchain file to CMake so it can be found
- A compiler with OpenMP support
- CMake
- Ninja (optional)
- mbedTLS 4.x (e.g.
pacman -S mbedtls)
On macOS, libomp and mbedtls must be installed (available in Homebrew).
git clone https://github.com/tonyp7/PS3Dec- In Visual Studio: Select
File > Open > CMake...and open PS3Dec/CMakeLists.txt - Change the current configuration to
x64-Release - Select
Build > Build Current Document (CMakeLists.txt) - Select
CMake > Cache > Open Cache Folder (x64-Release Only) > PS3Dec - Run the PS3Dec binary (
RelWithDebInfo\PS3Dec.exe)
git clone https://github.com/tonyp7/PS3Dec && cd PS3Decmkdir build && cd buildcmake -G Ninja .. && ninjaif Ninja is installed; otherwise,cmake .. && make- Run the PS3Dec binary (
Release/PS3Dec)
On Linux, the CLI binary is also distributed as a Flatpak bundle, so it can be installed without a compiler or mbedTLS — no cloning or building required:
- Download
PS3Dec.flatpakfrom the latest release. flatpak install PS3Dec.flatpakflatpak run io.github.tonyp7.PS3Dec d key <key_hex> in.iso out.iso
The app is granted --filesystem=host, meaning it can read and write anywhere on your filesystem, the same as the natively compiled binary — this is required so it can reach disc images and key files wherever you keep them, at the cost of most of Flatpak's usual sandboxing.
In the spirit of the original PS3Dec code, this is released as public domain.