mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 12:23:17 +00:00
64 lines
1.8 KiB
Markdown
64 lines
1.8 KiB
Markdown
|
|
# file-share
|
||
|
|
|
||
|
|
Personal file share server on AWS — Samba for macOS Finder integration and FileBrowser for web-based file management. Accessible exclusively over the site-to-site VPN.
|
||
|
|
|
||
|
|
## Architecture
|
||
|
|
|
||
|
|
- **EC2** — `t4g.small` (ARM64, Amazon Linux 2023) in the private subnet
|
||
|
|
- **Samba** — SMB file share at `/data/share`, optimized for macOS (`vfs_fruit`)
|
||
|
|
- **FileBrowser** — Web UI on port 8080, backed by the same `/data/share` directory
|
||
|
|
- **EBS** — 500 GiB gp3 data volume (separate from root), encrypted
|
||
|
|
- **DLM** — Daily EBS snapshots, 30-day retention
|
||
|
|
- **SSM** — Session Manager for instance access (no SSH key)
|
||
|
|
|
||
|
|
## Access
|
||
|
|
|
||
|
|
Requires VPN connection to the office network (10.10.0.0/16).
|
||
|
|
|
||
|
|
### Finder (SMB)
|
||
|
|
|
||
|
|
1. Finder > Go > Connect to Server
|
||
|
|
2. Enter `smb://<private-ip>/files`
|
||
|
|
3. Authenticate with `adam` and the password from `file-share/smb-password` in Secrets Manager
|
||
|
|
|
||
|
|
### FileBrowser (Web)
|
||
|
|
|
||
|
|
Open `http://<private-ip>:8080` in a browser.
|
||
|
|
|
||
|
|
## Secrets
|
||
|
|
|
||
|
|
Both stored in AWS Secrets Manager:
|
||
|
|
|
||
|
|
| Secret | Purpose |
|
||
|
|
|---|---|
|
||
|
|
| `file-share/smb-password` | Samba user password |
|
||
|
|
| `file-share/filebrowser-password` | FileBrowser admin password |
|
||
|
|
|
||
|
|
Create these secrets before deploying the stack:
|
||
|
|
|
||
|
|
```bash
|
||
|
|
aws secretsmanager create-secret --name file-share/smb-password --secret-string '<password>'
|
||
|
|
aws secretsmanager create-secret --name file-share/filebrowser-password --secret-string '<password>'
|
||
|
|
```
|
||
|
|
|
||
|
|
## Deploy
|
||
|
|
|
||
|
|
```bash
|
||
|
|
npm install
|
||
|
|
npx cdk deploy
|
||
|
|
```
|
||
|
|
|
||
|
|
The stack outputs the instance's private IP for SMB and FileBrowser access.
|
||
|
|
|
||
|
|
## Expanding Storage
|
||
|
|
|
||
|
|
The 500 GiB data volume can be expanded without downtime:
|
||
|
|
|
||
|
|
1. Modify the volume size in `lib/file-share-stack.ts`
|
||
|
|
2. Deploy: `npx cdk deploy`
|
||
|
|
3. SSH into the instance via SSM and resize the filesystem:
|
||
|
|
```bash
|
||
|
|
sudo growpart /dev/xvdf 1 # if partitioned
|
||
|
|
sudo resize2fs /dev/xvdf
|
||
|
|
```
|