Personal file share — Samba + FileBrowser on EC2
Find a file
Adam Moussa ea9ab1c463 fix(infra): adopt existing data volume + cache AMI to stop replacement churn
- Import vol-04d951cccacc435b5 (the real 500GiB data volume, orphaned by
  the 2026-06-05 redeploy) via Volume.fromVolumeAttributes — unmanaged,
  so CloudFormation can attach but never create/replace/delete it.
- Remove the inline /dev/xvdf blockDevice (this is what created the
  empty volume that shadowed the data).
- cachedInContext: true + committed cdk.context.json so AMI updates are
  deliberate (uncached lookup replaced the instance on every new AL2023
  release).
- Includes the previously-deployed-but-uncommitted 2026-05-27 work:
  standalone volume pattern, volume-wait userdata, SFTP access.

Deploy replaces the instance once; userdata's blkid guard mounts the
existing filesystem without formatting.
2026-06-05 13:36:45 -04:00
.github/workflows Add dependency-review caller workflow (#3) 2026-06-05 12:27:07 -04:00
bin Initial file-share stack 2026-05-14 15:23:38 -04:00
lib fix(infra): adopt existing data volume + cache AMI to stop replacement churn 2026-06-05 13:36:45 -04:00
.gitignore Add .env to gitignore 2026-05-14 17:48:10 -04:00
cdk.context.json fix(infra): adopt existing data volume + cache AMI to stop replacement churn 2026-06-05 13:36:45 -04:00
cdk.json Initial file-share stack 2026-05-14 15:23:38 -04:00
package-lock.json fix(deps): bump aws-cdk-lib pin to 2.257.0 (#4) 2026-06-05 13:07:29 -04:00
package.json fix(deps): bump aws-cdk-lib pin to 2.257.0 (#4) 2026-06-05 13:07:29 -04:00
README.md Initial file-share stack 2026-05-14 15:23:38 -04:00
tsconfig.json Initial file-share stack 2026-05-14 15:23:38 -04:00

file-share

Personal file share server on AWS — Samba for macOS Finder integration and FileBrowser for web-based file management. Accessible exclusively over the site-to-site VPN.

Architecture

  • EC2 — t4g.small (ARM64, Amazon Linux 2023) in the private subnet
  • Samba — SMB file share at /data/share, optimized for macOS (vfs_fruit)
  • FileBrowser — Web UI on port 8080, backed by the same /data/share directory
  • EBS — 500 GiB gp3 data volume (separate from root), encrypted
  • DLM — Daily EBS snapshots, 30-day retention
  • SSM — Session Manager for instance access (no SSH key)

Access

Requires VPN connection to the office network (10.10.0.0/16).

Finder (SMB)

  1. Finder > Go > Connect to Server
  2. Enter smb://<private-ip>/files
  3. Authenticate with adam and the password from file-share/smb-password in Secrets Manager

FileBrowser (Web)

Open http://<private-ip>:8080 in a browser.

Secrets

Both stored in AWS Secrets Manager:

Secret Purpose
file-share/smb-password Samba user password
file-share/filebrowser-password FileBrowser admin password

Create these secrets before deploying the stack:

aws secretsmanager create-secret --name file-share/smb-password --secret-string '<password>'
aws secretsmanager create-secret --name file-share/filebrowser-password --secret-string '<password>'

Deploy

npm install
npx cdk deploy

The stack outputs the instance's private IP for SMB and FileBrowser access.

Expanding Storage

The 500 GiB data volume can be expanded without downtime:

  1. Modify the volume size in lib/file-share-stack.ts
  2. Deploy: npx cdk deploy
  3. SSH into the instance via SSM and resize the filesystem:
    sudo growpart /dev/xvdf 1  # if partitioned
    sudo resize2fs /dev/xvdf