Sign inSign up

keepcoolch/permissions-manager

By keepcoolch

•Updated about 2 months ago

Permissions Manager is a small Alpine-based web tool for setting or removing POSIX ACLs per user.

Image
Developer tools
Operating systems
Monitoring & observability
1

104

keepcoolch/permissions-manager repository overview

⁠Permissions Manager

A small Alpine-based web tool for browsing files and folders on a mounted path and setting or removing POSIX ACLs per user.

⁠User Listing

The container can list users when it can see the host user database. The example mounts /etc/passwd and /etc/group read-only into the container. On many Linux systems, this is enough to show users with name, UID, and GID.

If users are managed through LDAP, AD, or Samba, those identities must also be available inside the container, or permissions must be mapped through matching UID/GID values. Linux file permissions ultimately depend on UID/GID and ACL entries.

⁠Start

Use the published Docker image:

docker pull keepcoolch/permissions-manager:latest

The app always shows / as the browser root. By default, it detects the correct internal root automatically:

  • Docker Desktop/macOS: /hostroot/host_mnt, so the root view shows host paths instead of Docker's Linux/container filesystem
  • Linux/NAS: /hostroot, so the mounted host root is used directly

Optionally set a different host root:

export HOST_ROOT=/path/to/root

Or set it for a single start:

HOST_ROOT=/path/to/root docker compose up

Start:

docker compose up

Web interface:

http://localhost:8000

The app starts with write access enabled by default. To run in read-only mode:

environment:
  ENABLE_WRITE: "0"

The first level hides typical Docker-internal artifacts. You can override the list if needed:

environment:
  HIDE_ROOT_ENTRIES: "app,containers,oldroot,services"

⁠Docker Compose

services:
  permissions-manager:
    image: keepcoolch/permissions-manager:latest
    container_name: permissions-manager
    ports:
      - "8000:8000"
    volumes:
      - ${HOST_ROOT:-/}:/hostroot
      - /etc/passwd:/etc/passwd:ro
      - /etc/group:/etc/group:ro
    user: "0:0"

⁠Notes

  • The app uses getfacl and setfacl.
  • Recursive changes can affect many files. For testing, switch to read-only mode with ENABLE_WRITE=0.
  • For directories, execute means the user can enter the directory. Read permission alone is not enough for directories.
  • The image does not include authentication. Run it only on a protected local network, behind a VPN, or behind a reverse proxy with authentication.

Tag summary

Content type

Image

Digest

sha256:30e3d0de3…

Size

18.8 MB

Last updated

about 2 months ago

docker pull keepcoolch/permissions-manager