Sign inSign up

vnxme/smbproxy

By vnxme

•Updated 1 day ago

SMB proxy that serves shares of many Windows and Samba servers under one host, with its own logins

Image
Networking
Security
Databases & storage
0

3.3K

vnxme/smbproxy repository overview

⁠smbproxy

An SMB server that gathers shares from remote Windows and Samba servers, each reached with its own account, and serves them under one host to SMB clients such as Windows Explorer, which log in to the proxy with logins of its own.

SMB clients  ──local logins──▶  smbproxy  ──each target's account──▶  target servers
(Explorer, net use, …)          \\proxy\share                         \\fs01\Projects, \\nas\media, …
  • Aggregation: shares spread across several servers and accounts appear as ordinary shares of one host.
  • Indirect access: the proxy ends the client's connection and makes its own to the target, so routing, firewalling and dialect or signing differences are dealt with once, at the proxy.
  • Credential confinement: clients never see the targets' credentials; they log in to the proxy with separate local logins.

Source, documentation and issues: https://github.com/vnxme/smbproxy⁠

⁠Quick start

docker run -d --name smbproxy --restart unless-stopped \
  -p 445:445 \
  -v /etc/smbproxy:/etc/smbproxy:ro \
  vnxme/smbproxy

Then, from a client:

\\docker-host\projects
net use P: \\docker-host\projects /user:alice

Windows clients connect only to port 445, so publish the container on the host's port 445 (on a Windows host it is normally taken by Windows' own file sharing).

The image is also published as ghcr.io/vnxme/smbproxy.

⁠Configuration

The container reads /etc/smbproxy/smbproxy.yaml. Mount the directory that holds it and any password files it names. Without your own configuration, the container runs the example⁠, whose users and targets are made up: its shares are listed but cannot be opened, and its logins are public, so do not leave it reachable.

A minimal configuration: one local user, one target and one share.

server:
  listen: 0.0.0.0:445             # keep port 445; map the host port with -p

local:
  users:
    alice:
      password_file: alice.pass   # first line: alice's password

targets:
  fs:
    host: fs01.corp.example
    user: svc_proxy
    domain: CORP
    password_file: fs.pass        # relative to the configuration file

shares:
  - name: projects                # \\docker-host\projects
    target: fs
    path: Projects/2026           # the target's share, then a folder in it

A credential, for a local user or a target, is exactly one of password, password_file or password_hash (the NT hash). Shares are read-only unless read_only: false is set; read_access and write_access list the users and @groups that may open and change each one. The example configuration⁠ describes every setting and its default.

⁠Docker Compose
services:
  smbproxy:
    image: vnxme/smbproxy
    restart: unless-stopped
    ports:
      - "445:445"
    volumes:
      - /etc/smbproxy:/etc/smbproxy:ro

⁠Image details

BaseAlpine Linux
Platformslinux/386, linux/amd64, linux/arm/v6, linux/arm/v7, linux/arm64, linux/ppc64le, linux/riscv64, linux/s390x
Port445/tcp
Configuration/etc/smbproxy/smbproxy.yaml
Entrypointsmbproxy -config /etc/smbproxy/smbproxy.yaml

smbproxy runs as root inside the container, so it can read a configuration kept at mode 600. To run it as another user, pass --user and make the files readable by that user.

docker run --rm vnxme/smbproxy -version prints the version and the commit the image was built from.

⁠Tags

TagContents
latestthe latest release
1.2.3, 1.2, 1releases, by version
mainthe latest commit on the main branch
weeklythe weekly rebuild, picking up base image updates
sha-<commit>a specific commit

⁠Features

  • SMB 2.0.2 to 3.1.1, with signing, encryption, compression and durable handles
  • Any number of targets, one connection each, made on first use and remade after a drop; a share maps to a target's share or a folder inside it, which clients cannot leave
  • Local users and groups, optional guest and anonymous access, per-share read and write access lists, and optional hiding of inaccessible shares
  • Directory listings, reads with read-ahead, and, on writable shares, creating, writing, renaming, deleting and truncating files and folders
  • Windows Explorer: browsing \\proxy, the share's Network tab, volume size and free space, and the Security tab with the target's permissions
  • debug: true logs every SMB exchange and file system call

⁠Limitations

  • No byte-range locks: applications that lock files, such as Microsoft Office, may open documents read-only
  • Permissions can be viewed but not changed
  • No change notifications, so Explorer does not refresh a folder by itself
  • Opportunistic locks, leases and Previous Versions are not available
  • The proxy logs in to targets with NTLM, and everything clients do on a target is done as the target's account

⁠Security

  • The configuration holds the targets' credentials: keep it readable only by the account running smbproxy, or use password_file.
  • Every client acts on a target as the account configured for it, so give that account only the rights the shares need.
  • Use smbproxy only with servers and accounts you own or are allowed to use.

⁠License

Apache License 2.0⁠

Tag summary

Content type

Image

Digest

sha256:4d21ac47f…

Size

6 MB

Last updated

1 day ago

docker pull vnxme/smbproxy