Portainer Templates logo

Portainer Templates

Samba Samba

Container

OtherTools

Samba has provided secure, stable and fast file and print services for all clients using the SMB/CIFS protocol, such as all versions of DOS and Windows, OS/2, Linux and many others.

Image details

Pulls: 93.5M
Architecture: amd64, arm64, arm/v6, arm, arm64/v8
Image size: 20 MB
User: dperson
Created: Jan 02, 2015
Updated: 5 years ago
Status: active

Source details

Stars: 2k
Forks: 523
Language: Shell
License: AGPL-3.0
Updated: 2 years ago

Configuration

Type
Container
Platform
linux
Image
dperson/samba:latest
Privileged
Yes
Ports
139:139/tcp445:445/tcp
Volumes
/share : /portainer/Downloads
Env vars
PUID=1000PGID=1000USERID=1000GROUPID=1000USER=guest;guestPERMISSIONS=trueSHARE=portainer;/share;yes;no;yes;guest
Restart
unless-stopped

Template by novaspirit

Notes

Standalone Install

Select an install method, to see config/commands for deploying Samba

Installation method

Install on Portainer

Import all app templates into your Portainer instance, for easy 1-click deploys

  1. Ensure both Docker and Portainer are installed, and up-to-date
  2. Log into your Portainer web UI
  3. Under Settings → App Templates, paste the below URL
  4. Head to Home → App Templates, and the list of apps will show up
  5. Select Samba, fill in any config options, and hit Deploy

Template Import URL

https://raw.githubusercontent.com/Lissy93/portainer-templates/main/templates.json
Show Me demo

More install options in our documentation, or see dperson/samba for app-specific guidance.

logo

Samba

Samba docker container

What is Samba?

Since 1992, Samba has provided secure, stable and fast file and print services for all clients using the SMB/CIFS protocol, such as all versions of DOS and Windows, OS/2, Linux and many others.

How to use this image

By default there are no shares configured, additional ones can be added.

Hosting a Samba instance

sudo docker run -it -p 139:139 -p 445:445 -d dperson/samba -p
OR set local storage:
sudo docker run -it --name samba -p 139:139 -p 445:445 \
            -v /path/to/directory:/mount \
            -d dperson/samba -p

Configuration

sudo docker run -it --rm dperson/samba -h
Usage: samba.sh [-opt] [command]
Options (fields in '[]' are optional, '<>' are required):
    -h          This help
    -c "<from:to>" setup character mapping for file/directory names
                required arg: "<from:to>" character mappings separated by ','
    -G "<section;parameter>" Provide generic section option for smb.conf
                required arg: "<section>" - IE: "share"
                required arg: "<parameter>" - IE: "log level = 2"
    -g "<parameter>" Provide global option for smb.conf
                required arg: "<parameter>" - IE: "log level = 2"
    -i "<path>" Import smbpassword
                required arg: "<path>" - full file path in container
    -n          Start the 'nmbd' daemon to advertise the shares
    -p          Set ownership and permissions on the shares
    -r          Disable recycle bin for shares
    -S          Disable SMB2 minimum version
    -s "<name;/path>[;browse;readonly;guest;users;admins;writelist;comment]"
                Configure a share
                required arg: "<name>;</path>"
                <name> is how it's called for clients
                <path> path to share
                NOTE: for the default values, just leave blank
                [browsable] default:'yes' or 'no'
                [readonly] default:'yes' or 'no'
                [guest] allowed default:'yes' or 'no'
                NOTE: for user lists below, usernames are separated by ','
                [users] allowed default:'all' or list of allowed users
                [admins] allowed default:'none' or list of admin users
                [writelist] list of users that can write to a RO share
                [comment] description of share
    -u "<username;password>[;ID;group;GID]"       Add a user
                required arg: "<username>;<passwd>"
                <username> for user
                <password> for user
                [ID] for user
                [group] for user
                [GID] for group
    -w "<workgroup>"       Configure the workgroup (domain) samba should use
                required arg: "<workgroup>"
                <workgroup> for samba
    -W          Allow access wide symbolic links
    -I          Add an include option at the end of the smb.conf
                required arg: "<include file path>"
                <include file path> in the container, e.g. a bind mount

The 'command' (if provided and valid) will be run instead of samba
ENVIRONMENT VARIABLES
CHARMAP - As above, configure character mapping GENERIC - As above, configure a generic section option (See NOTE3 below) GLOBAL - As above, configure a global option (See NOTE3 below) IMPORT - As above, import a smbpassword file NMBD - As above, enable nmbd PERMISSIONS - As above, set file permissions on all shares RECYCLE - As above, disable recycle bin SHARE - As above, setup a share (See NOTE3 below) SMB - As above, disable SMB2 minimum version TZ - Set a timezone, IE EST5EDT USER - As above, setup a user (See NOTE3 below) WIDELINKS - As above, allow access wide symbolic links WORKGROUP - As above, set workgroup USERID - Set the UID for the samba server's default user (smbuser) GROUPID - Set the GID for the samba server's default user (smbuser) INCLUDE - As above, add a smb.conf include
NOTE: if you enable nmbd (via -n or the NMBD environment variable), you will also want to expose port 137 and 138 with -p 137:137/udp -p 138:138/udp.
NOTE2: there are reports that -n and NMBD only work if you have the container configured to use the hosts network stack.
NOTE3: optionally supports additional variables starting with the same name, IE SHARE also will work for SHARE2, SHARE3... SHAREx, etc.

Examples

Any of the commands can be run at creation with docker run or later with docker exec -it samba samba.sh (as of version 1.3 of docker).

Setting the Timezone

sudo docker run -it -e TZ=EST5EDT -p 139:139 -p 445:445 -d dperson/samba -p

Start an instance creating users and shares:

sudo docker run -it -p 139:139 -p 445:445 -d dperson/samba -p \
            -u "example1;badpass" \
            -u "example2;badpass" \
            -s "public;/share" \
            -s "users;/srv;no;no;no;example1,example2" \
            -s "example1 private share;/example1;no;no;no;example1" \
            -s "example2 private share;/example2;no;no;no;example2"

User Feedback

Troubleshooting

  • You get the error Access is denied (or similar) on the client and/or see
change_to_user_internal: chdir_current_service() failed! in the container logs.
Add the -p option to the end of your options to the container, or set the PERMISSIONS environment variable.
sudo docker run -it --name samba -p 139:139 -p 445:445 \
            -v /path/to/directory:/mount \
            -d dperson/samba -p
If changing the permissions of your files is not possible in your setup you can instead set the environment variables USERID and GROUPID to the values of the owner of your files.
  • High memory usage by samba. Multiple people have reported high memory usage
that's never freed by the samba processes. Recommended work around below:
Add the -m 512m option to docker run command, or mem_limit: in dockercompose.yml files, IE:
sudo docker run -it --name samba -m 512m -p 139:139 -p 445:445 \
            -v /path/to/directory:/mount \
            -d dperson/samba -p
  • Attempting to connect with the smbclient commandline tool. By default samba
still tries to use SMB1, which is depriciated and has security issues. This container defaults to SMB2, which for no decernable reason even though it's supported is disabled by default so run the command as smbclient -m SMB3, then any other options you would specify.

Issues

If you have any problems with or questions about this image, please contact me through a GitHub issue
.

Serve Samba on your own domain behind Caddy, Nginx or Traefik. Fill in your domain and copy the result. It's a starting point, some apps need their own base URL or extra headers set too.

Proxying samba.example.com to http://Samba:139

Add this to your Caddyfile

samba.example.com {
	reverse_proxy http://Samba:139
}

Check the logs first

Nine times out of ten the logs tell you exactly what went wrong.

  • In Portainer, go to Containers, click the container, then Logs. Or run docker logs Samba
  • Exit codes help too: 137 means killed, usually out of memory. 126 or 127 means the command inside the image is broken.

Port already in use

If deployment fails with "Bind for 0.0.0.0:139 failed: port is already allocated", something else on your server is using that port.

  • Find what's using it: sudo ss -tlnp | grep :139
  • Stop the other service, or pick a different host port. In 139:139 only the left number is yours to change, the right one belongs to the app.

Running but the page won't load

The container is up but nothing appears in your browser.

  • Use your server's real IP: http://your-server-ip:139. The 0.0.0.0 link Portainer shows isn't a real address.
  • Give it a minute after first deploy, Samba can take a while to initialise.
  • Make sure your firewall allows the port, e.g. sudo ufw allow 139

Permission denied on volumes

If the logs show "permission denied", the app can't write to its data folder on the host.

  • Fix the ownership: sudo chown -R 1000:1000 /portainer/Downloads
  • Or set the PUID and PGID variables (defaults 1000:1000) to match your own user, found with id $USER

Image won't pull

Test the pull directly on the host: docker pull dperson/samba:latest

  • "manifest unknown" means the tag no longer exists. This template uses latest, so try pinning a specific version instead.
  • "toomanyrequests" is the Docker Hub rate limit. Log in with docker login to raise it.
  • "no space left on device" means a full disk. Reclaim space with docker system prune

"exec format error"

This means the image was built for a different CPU architecture than your server.

  • This image supports: amd64, arm64, arm/v6, arm, arm64/v8
  • Check yours with uname -m: x86_64 is amd64, aarch64 is arm64. Raspberry Pi and other ARM boards are the usual culprits.

Container keeps restarting

The unless-stopped restart policy relaunches the app after every crash, so the real error can scroll past.

  • Check the logs right after a restart, the last few lines before it died are the useful ones.
  • Get the exit code with docker inspect Samba --format '{{.State.ExitCode}}'
  • Still stuck? Redeploy once with the restart policy set to no so the failure stays visible.

Privileged mode

This template runs the container in privileged mode, giving it full access to your host.

  • Only deploy it if you trust the app.
  • If deployment is blocked, your Portainer security settings or hardened host may not allow privileged containers.

Raise an issue

Found something which isn't working as it should? Here's how to report it.

A single container

Samba runs as one container, the simplest kind of app here. Just the one image to pull and nothing else wired up alongside it.

The app image

An image is the app packed up ready to go, everything Samba needs bundled into one download. This template pulls dperson/samba:latest, which Docker fetches once (about 20 MB) and then starts your own copy from.

Where the image comes from

Docker pulls its images from registries, public libraries of ready-built apps. Samba's comes from Docker Hub, published by dperson.

Version tags

The bit after the colon in the image name is the version tag. Here it's latest, which always points at the newest build, so a redeploy can bump you to a newer release without you asking. Pin a specific tag if you would rather stay on one version.

Which machines it runs on

Every image is built for particular CPU types. This one ships for amd64, arm64, arm/v6, arm, arm64/v8, so it runs on both regular x86 servers and ARM boards like a Raspberry Pi.

Ports

A port is the door the app answers on. A mapping like 139:139 means it's reachable on port 139 of your server, where the left number is yours to change and the right one belongs to the app. It opens:

  • 139:139
  • 445:445

Volumes

A volume is where Samba keeps its files so they survive an update or a restart. Without one, anything it saves would sit inside the container and vanish the moment it's recreated. This template mounts:

  • /share from /portainer/Downloads on the host

Environment variables

Environment variables are the settings you hand over when you deploy, things like a password or a timezone. Samba takes 7 of them, all with defaults you can leave alone or tweak:

  • PUID, defaults to 1000
  • PGID, defaults to 1000
  • USERID, defaults to 1000
  • GROUPID, defaults to 1000
  • USER, defaults to guest;guest
  • PERMISSIONS, defaults to true
  • SHARE, defaults to portainer;/share;yes;no;yes;guest

Restart policy

The restart policy here is unless-stopped, so Docker restarts Samba after a crash or reboot, but leaves it off when you stop it on purpose. You can change this on the deploy screen. The choices are no (never restart), on-failure (only after a crash), unless-stopped (restart unless you stop it), and always (bring it back no matter what).

Users and permissions

The PUID and PGID settings tell it which user and group to act as on your host. Point them at your own account (find yours with id $USER) so the files it writes into your mounted folders come out owned by you rather than root.

Networking

Nothing custom is set, so Samba sits on Docker's default bridge network: its own private space that reaches the outside world only through the ports it publishes.

Container name

Once it's deployed, Portainer names the container Samba. That's what you'll spot in the containers list and use in commands like docker logs Samba.

Privileged mode

This template runs Samba in privileged mode, which gives it nearly as much access to your server as the system itself. Some apps genuinely need it to reach hardware or manage the host, so it's one to run only if you trust the source.

Platform

The platform is linux, the kind of system the container is built to run on. Docker and Portainer handle this on a normal Linux server.

Open source license

Samba is open source, released under the AGPL-3.0 license. In plain terms the code is out in the open, so you're free to run it and change it to fit what you need.

Portainer app templates

Zooming out, this whole page comes from a Portainer app template: a short recipe telling Portainer how to set Samba up. Add the template list to Portainer once, then deploying Samba is a click rather than a wall of config.