From 38be6c13f76e893cf47636257071b440dec0c5b2 Mon Sep 17 00:00:00 2001 From: Robert Günzler Date: Sun, 7 Sep 2025 17:32:13 +0200 Subject: initial commit MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Robert Günzler --- bundles/smb/files/kube.yaml | 46 ++++++++++++++++++++++++++++++++++++++++++++ bundles/smb/files/smb.conf | 39 +++++++++++++++++++++++++++++++++++++ bundles/smb/files/smb.nft | 10 ++++++++++ bundles/smb/files/users.conf | 3 +++ 4 files changed, 98 insertions(+) create mode 100644 bundles/smb/files/kube.yaml create mode 100644 bundles/smb/files/smb.conf create mode 100644 bundles/smb/files/smb.nft create mode 100644 bundles/smb/files/users.conf (limited to 'bundles/smb/files') diff --git a/bundles/smb/files/kube.yaml b/bundles/smb/files/kube.yaml new file mode 100644 index 0000000..3f0e074 --- /dev/null +++ b/bundles/smb/files/kube.yaml @@ -0,0 +1,46 @@ +apiVersion: v1 +kind: Pod +metadata: + name: smb + labels: + traefik.enable: false +spec: + restartPolicy: Never + dnsPolicy: Default + containers: + - name: smb + image: docker.io/dockurr/samba:4.20.2 + volumeMounts: + - name: smb-config + mountPath: /etc/samba + - name: smb-data-scratch + mountPath: /storage/scratch + - name: smb-data-hayasui + mountPath: /storage/hayasui + # - name: smb-data-bigdump + # mountPath: /storage/bigdump + resources: + limits: + cpu: 10m + memory: 50Mi + ports: + - containerPort: 445 + hostPort: 445 + protocol: TCP + volumes: + - name: smb-config + hostPath: + path: /var/lib/smb/config + type: DirectoryOrCreate + - name: smb-data-scratch + hostPath: + path: /var/lib/smb/data + type: DirectoryOrCreate + - name: smb-data-hayasui + hostPath: + path: /media/hayasui + type: Directory + # - name: smb-data-bigdump + # hostPath: + # path: /media/bigdump + # type: Directory diff --git a/bundles/smb/files/smb.conf b/bundles/smb/files/smb.conf new file mode 100644 index 0000000..12c79e2 --- /dev/null +++ b/bundles/smb/files/smb.conf @@ -0,0 +1,39 @@ +[global] + security = user + server min protocol = SMB2 + + # disable printing services + load printers = no + printing = bsd + printcap name = /dev/null + disable spoolss = yes + +[scratch] + path = /storage/scratch + comment = Shared + valid users = @smb + browseable = yes + writable = yes + read only = no + force user = root + force group = root + +[hayasui] + path = /storage/hayasui + comment = Shared + valid users = @smb + browseable = yes + writable = yes + read only = no + force user = root + force group = root + +# [bigdump] +# path = /storage/bigdump +# comment = Shared +# valid users = robert +# browseable = yes +# writable = yes +# read only = no +# force user = root +# force group = root diff --git a/bundles/smb/files/smb.nft b/bundles/smb/files/smb.nft new file mode 100644 index 0000000..98d3bd3 --- /dev/null +++ b/bundles/smb/files/smb.nft @@ -0,0 +1,10 @@ +#!/usr/sbin/nft -f +# vim: set ts=4 sw=4: +table inet filter { + + chain my_filter { + tcp dport { 445 } accept \ + comment "Accept SMB traffic" + } + +} diff --git a/bundles/smb/files/users.conf b/bundles/smb/files/users.conf new file mode 100644 index 0000000..d737757 --- /dev/null +++ b/bundles/smb/files/users.conf @@ -0,0 +1,3 @@ +#username:UID:groupname:GID:password +robert:1001:smb:1000:secret +gonca:1002:smb:1000:secret -- cgit 1.4.1