Personal file share — Samba + FileBrowser on EC2
Find a file
Adam Moussa 01438bd1fd Fix file-share DLM policy duplicate-tag error (audit C-8)
The SnapshotPolicy schedule set both copyTags:true and tagsToAdd
file-share-backup=true. Since that tag is already on the data volume,
copyTags propagates it to each snapshot and the explicit tagsToAdd of
the same key triggers DLM's duplicate-tag error, leaving the policy in
ERROR state -- nightly snapshots of the 500 GB NAS volume were silently
failing. Dropping the redundant tagsToAdd (copyTags still tags the
snapshots) lets the policy run.

The live policy was already corrected out-of-band to stop the failing
backups; this commit codifies that change so the next clean deploy shows
no drift on the policy.
2026-05-29 17:18:15 -04:00
.github/workflows Set node-version to 24 in CI/CD workflows 2026-05-14 15:41:54 -04:00
bin Initial file-share stack 2026-05-14 15:23:38 -04:00
lib Fix file-share DLM policy duplicate-tag error (audit C-8) 2026-05-29 17:18:15 -04:00
.gitignore Add .env to gitignore 2026-05-14 17:48:10 -04:00
cdk.context.json Initial file-share stack 2026-05-14 15:23:38 -04:00
cdk.json Initial file-share stack 2026-05-14 15:23:38 -04:00
package-lock.json Pin aws-cdk-lib to 2.253.1 to fix npm ci 2026-05-14 15:47:21 -04:00
package.json Pin aws-cdk-lib to 2.253.1 to fix npm ci 2026-05-14 15:47:21 -04:00
README.md Initial file-share stack 2026-05-14 15:23:38 -04:00
tsconfig.json Initial file-share stack 2026-05-14 15:23:38 -04:00

file-share

Personal file share server on AWS — Samba for macOS Finder integration and FileBrowser for web-based file management. Accessible exclusively over the site-to-site VPN.

Architecture

  • EC2 — t4g.small (ARM64, Amazon Linux 2023) in the private subnet
  • Samba — SMB file share at /data/share, optimized for macOS (vfs_fruit)
  • FileBrowser — Web UI on port 8080, backed by the same /data/share directory
  • EBS — 500 GiB gp3 data volume (separate from root), encrypted
  • DLM — Daily EBS snapshots, 30-day retention
  • SSM — Session Manager for instance access (no SSH key)

Access

Requires VPN connection to the office network (10.10.0.0/16).

Finder (SMB)

  1. Finder > Go > Connect to Server
  2. Enter smb://<private-ip>/files
  3. Authenticate with adam and the password from file-share/smb-password in Secrets Manager

FileBrowser (Web)

Open http://<private-ip>:8080 in a browser.

Secrets

Both stored in AWS Secrets Manager:

Secret Purpose
file-share/smb-password Samba user password
file-share/filebrowser-password FileBrowser admin password

Create these secrets before deploying the stack:

aws secretsmanager create-secret --name file-share/smb-password --secret-string '<password>'
aws secretsmanager create-secret --name file-share/filebrowser-password --secret-string '<password>'

Deploy

npm install
npx cdk deploy

The stack outputs the instance's private IP for SMB and FileBrowser access.

Expanding Storage

The 500 GiB data volume can be expanded without downtime:

  1. Modify the volume size in lib/file-share-stack.ts
  2. Deploy: npx cdk deploy
  3. SSH into the instance via SSM and resize the filesystem:
    sudo growpart /dev/xvdf 1  # if partitioned
    sudo resize2fs /dev/xvdf