SMB proxy that serves shares of many Windows and Samba servers under one host, with its own logins
3.3K
An SMB server that gathers shares from remote Windows and Samba servers, each reached with its own account, and serves them under one host to SMB clients such as Windows Explorer, which log in to the proxy with logins of its own.
SMB clients ──local logins──▶ smbproxy ──each target's account──▶ target servers
(Explorer, net use, …) \\proxy\share \\fs01\Projects, \\nas\media, …
Source, documentation and issues: https://github.com/vnxme/smbproxy
docker run -d --name smbproxy --restart unless-stopped \
-p 445:445 \
-v /etc/smbproxy:/etc/smbproxy:ro \
vnxme/smbproxy
Then, from a client:
\\docker-host\projects
net use P: \\docker-host\projects /user:alice
Windows clients connect only to port 445, so publish the container on the host's port 445 (on a Windows host it is normally taken by Windows' own file sharing).
The image is also published as ghcr.io/vnxme/smbproxy.
The container reads /etc/smbproxy/smbproxy.yaml. Mount the directory that
holds it and any password files it names. Without your own configuration, the
container runs the
example,
whose users and targets are made up: its shares are listed but cannot be
opened, and its logins are public, so do not leave it reachable.
A minimal configuration: one local user, one target and one share.
server:
listen: 0.0.0.0:445 # keep port 445; map the host port with -p
local:
users:
alice:
password_file: alice.pass # first line: alice's password
targets:
fs:
host: fs01.corp.example
user: svc_proxy
domain: CORP
password_file: fs.pass # relative to the configuration file
shares:
- name: projects # \\docker-host\projects
target: fs
path: Projects/2026 # the target's share, then a folder in it
A credential, for a local user or a target, is exactly one of password,
password_file or password_hash (the NT hash). Shares are read-only unless
read_only: false is set; read_access and write_access list the users and
@groups that may open and change each one. The
example configuration
describes every setting and its default.
services:
smbproxy:
image: vnxme/smbproxy
restart: unless-stopped
ports:
- "445:445"
volumes:
- /etc/smbproxy:/etc/smbproxy:ro
| Base | Alpine Linux |
| Platforms | linux/386, linux/amd64, linux/arm/v6, linux/arm/v7, linux/arm64, linux/ppc64le, linux/riscv64, linux/s390x |
| Port | 445/tcp |
| Configuration | /etc/smbproxy/smbproxy.yaml |
| Entrypoint | smbproxy -config /etc/smbproxy/smbproxy.yaml |
smbproxy runs as root inside the container, so it can read a configuration
kept at mode 600. To run it as another user, pass --user and make the files
readable by that user.
docker run --rm vnxme/smbproxy -version prints the version and the commit the
image was built from.
| Tag | Contents |
|---|---|
latest | the latest release |
1.2.3, 1.2, 1 | releases, by version |
main | the latest commit on the main branch |
weekly | the weekly rebuild, picking up base image updates |
sha-<commit> | a specific commit |
\\proxy, the share's Network tab, volume size
and free space, and the Security tab with the target's permissionsdebug: true logs every SMB exchange and file system callpassword_file.Content type
Image
Digest
sha256:4d21ac47f…
Size
6 MB
Last updated
1 day ago
docker pull vnxme/smbproxy