Sign inSign up

keepcoolch/sharecontainer

By keepcoolch

•Updated 30 days ago

Docker image with a responsive web interface for securely creating share links from host folders.

Image
Networking
Internet of things
Databases & storage
1

1.7K

keepcoolch/sharecontainer repository overview

Hero Screenshot

⁠ShareContainer Docker image

ShareContainer is a Docker image with a responsive web interface for securely creating temporary share links from host folders. You run only the admin container, select read-only host paths in the browser-based Admin UI, and ShareContainer automatically starts a separate share container that exposes only the selected folders. Version 1.0.1 Developed by Kevin Tobler 🌐 www.kevintobler.ch⁠


Admin-managed file sharing for Docker:

  • Admin Web UI: http://localhost:10000
  • Share Web UI: http://localhost:11000

The admin container sees the allowed host area read-only under /host. This lets you browse host, macOS, or NAS paths in the Admin UI and create shares from them. The admin container then creates the share container automatically. The share container only receives the folders you selected, mounted read-only under /mnt/shares/....

⁠Start

You only start the admin container. It creates or recreates the share container automatically when you add, update, or remove a share in the Web UI.

On the first visit to the Admin UI, you create the admin username and password. Later visits require login.

⁠Docker Compose

Create a docker-compose.yml like this. This variant stores app data in a Docker volume:

services:
  sharecontainer-admin:
    image: keepcoolch/sharecontainer:latest
    container_name: sharecontainer-admin
    ports:
      - "10000:10000"
    volumes:
      - sharecontainer-data:/data
      - /var/run/docker.sock:/var/run/docker.sock
      - /:/host:ro
    restart: unless-stopped

volumes:
  sharecontainer-data:

Start it:

docker compose up -d
⁠Docker Run

The same setup without Compose:

docker run -d \
  --name sharecontainer-admin \
  -p 10000:10000 \
  -v sharecontainer-data:/data \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v /:/host:ro \
  --restart unless-stopped \
  keepcoolch/sharecontainer:latest

sharecontainer-data stores the admin login, shares, settings, size cache, and thumbnails. Docker creates this volume automatically if it does not exist yet.

⁠Host Path Instead Of Docker Volume

If you want the app data stored in a visible host folder, replace the data volume with an absolute host path. Example for Synology/NAS:

volumes:
  - /volume1/docker/sharecontainer/data:/data
  - /var/run/docker.sock:/var/run/docker.sock
  - /:/host:ro

The app then writes files such as admin.json, shares.json, settings.json, cache data, and thumbnails to /volume1/docker/sharecontainer/data on the host.

As docker run:

docker run -d \
  --name sharecontainer-admin \
  -p 10000:10000 \
  -v /volume1/docker/sharecontainer/data:/data \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v /:/host:ro \
  --restart unless-stopped \
  keepcoolch/sharecontainer:latest

⁠Host Browser Mount

/:/host:ro exposes the host root path / inside the admin container as /host, read-only.

That means:

  • In the container you browse under /host.
  • /host/volume1 maps to the real host path /volume1 on a NAS.
  • :ro means read-only. The admin container can read these host paths, but cannot modify them.
  • /:/host:ro is convenient. A narrower mount such as /volume1:/host:ro or /volume1/photo:/host/photo:ro is more restrictive.

Without a host mount, the admin container cannot show host folders in the path browser. The Docker socket is only used to start and recreate the share container; it does not make the host filesystem browsable.

⁠Security Notes

  • Share mounts are read-only.
  • The admin container can browse the host depending on your mount configuration.
  • The share container only receives the explicitly selected folders.
  • Path traversal is blocked for browsing, previews, downloads, and uploads.
  • Files are served inline only for preview-safe types. Unknown types use application/octet-stream.
  • Passwords are stored as PBKDF2-SHA256 hashes, not as plain text.
  • Folders and selected files are downloaded as ZIP archives.

ā šŸ§‘ā€šŸ’» Developer

Kevin Tobler
🌐 www.kevintobler.ch⁠

Tag summary

Content type

Image

Digest

sha256:14ee9bc53…

Size

50.7 MB

Last updated

30 days ago

docker pull keepcoolch/sharecontainer