mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 17:03:17 +00:00
Personal file share — Samba + FileBrowser on EC2
The SnapshotPolicy schedule set both copyTags:true and tagsToAdd file-share-backup=true. Since that tag is already on the data volume, copyTags propagates it to each snapshot and the explicit tagsToAdd of the same key triggers DLM's duplicate-tag error, leaving the policy in ERROR state -- nightly snapshots of the 500 GB NAS volume were silently failing. Dropping the redundant tagsToAdd (copyTags still tags the snapshots) lets the policy run. The live policy was already corrected out-of-band to stop the failing backups; this commit codifies that change so the next clean deploy shows no drift on the policy. |
||
|---|---|---|
| .github/workflows | ||
| bin | ||
| lib | ||
| .gitignore | ||
| cdk.context.json | ||
| cdk.json | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| tsconfig.json | ||
file-share
Personal file share server on AWS — Samba for macOS Finder integration and FileBrowser for web-based file management. Accessible exclusively over the site-to-site VPN.
Architecture
- EC2 —
t4g.small(ARM64, Amazon Linux 2023) in the private subnet - Samba — SMB file share at
/data/share, optimized for macOS (vfs_fruit) - FileBrowser — Web UI on port 8080, backed by the same
/data/sharedirectory - EBS — 500 GiB gp3 data volume (separate from root), encrypted
- DLM — Daily EBS snapshots, 30-day retention
- SSM — Session Manager for instance access (no SSH key)
Access
Requires VPN connection to the office network (10.10.0.0/16).
Finder (SMB)
- Finder > Go > Connect to Server
- Enter
smb://<private-ip>/files - Authenticate with
adamand the password fromfile-share/smb-passwordin Secrets Manager
FileBrowser (Web)
Open http://<private-ip>:8080 in a browser.
Secrets
Both stored in AWS Secrets Manager:
| Secret | Purpose |
|---|---|
file-share/smb-password |
Samba user password |
file-share/filebrowser-password |
FileBrowser admin password |
Create these secrets before deploying the stack:
aws secretsmanager create-secret --name file-share/smb-password --secret-string '<password>'
aws secretsmanager create-secret --name file-share/filebrowser-password --secret-string '<password>'
Deploy
npm install
npx cdk deploy
The stack outputs the instance's private IP for SMB and FileBrowser access.
Expanding Storage
The 500 GiB data volume can be expanded without downtime:
- Modify the volume size in
lib/file-share-stack.ts - Deploy:
npx cdk deploy - SSH into the instance via SSM and resize the filesystem:
sudo growpart /dev/xvdf 1 # if partitioned sudo resize2fs /dev/xvdf