Samba
Container
Samba has provided secure, stable and fast file and print services for all clients using the SMB/CIFS protocol, such as all versions of DOS and Windows, OS/2, Linux and many others.
Image details
Source details
Configuration
TypeContainerlinuxdperson/samba:latestYes139:139/tcp445:445/tcp/share : /portainer/DownloadsPUID=1000PGID=1000USERID=1000GROUPID=1000USER=guest;guestPERMISSIONS=trueSHARE=portainer;/share;yes;no;yes;guestunless-stoppedTemplate by novaspirit
Notes
Check our Github page: https://github.com/pi-hosted/pi-hosted
Official Webpage: https://www.samba.org/
Official Docker Documentation: https://github.com/dperson/samba
Youtube Videos:
- Novaspirit Tech - Setting up Raspberry Pi Samba Server For File Sharing on Docker
- Novaspirit Tech - Building NAS with Container
Standalone Install
Select an install method, to see config/commands for deploying Samba
Install on Portainer
Import all app templates into your Portainer instance, for easy 1-click deploys
- Ensure both Docker and Portainer are installed, and up-to-date
- Log into your Portainer web UI
- Under Settings → App Templates, paste the below URL
- Head to Home → App Templates, and the list of apps will show up
- Select Samba, fill in any config options, and hit Deploy
Template Import URL
https://raw.githubusercontent.com/Lissy93/portainer-templates/main/templates.json
Show Me
More install options in our documentation, or see dperson/samba for app-specific guidance.

Samba
Samba docker containerWhat is Samba?
Since 1992, Samba has provided secure, stable and fast file and print services for all clients using the SMB/CIFS protocol, such as all versions of DOS and Windows, OS/2, Linux and many others.How to use this image
By default there are no shares configured, additional ones can be added.Hosting a Samba instance
sudo docker run -it -p 139:139 -p 445:445 -d dperson/samba -pOR set local storage:sudo docker run -it --name samba -p 139:139 -p 445:445 \
-v /path/to/directory:/mount \
-d dperson/samba -pConfiguration
sudo docker run -it --rm dperson/samba -h
Usage: samba.sh [-opt] [command]
Options (fields in '[]' are optional, '<>' are required):
-h This help
-c "<from:to>" setup character mapping for file/directory names
required arg: "<from:to>" character mappings separated by ','
-G "<section;parameter>" Provide generic section option for smb.conf
required arg: "<section>" - IE: "share"
required arg: "<parameter>" - IE: "log level = 2"
-g "<parameter>" Provide global option for smb.conf
required arg: "<parameter>" - IE: "log level = 2"
-i "<path>" Import smbpassword
required arg: "<path>" - full file path in container
-n Start the 'nmbd' daemon to advertise the shares
-p Set ownership and permissions on the shares
-r Disable recycle bin for shares
-S Disable SMB2 minimum version
-s "<name;/path>[;browse;readonly;guest;users;admins;writelist;comment]"
Configure a share
required arg: "<name>;</path>"
<name> is how it's called for clients
<path> path to share
NOTE: for the default values, just leave blank
[browsable] default:'yes' or 'no'
[readonly] default:'yes' or 'no'
[guest] allowed default:'yes' or 'no'
NOTE: for user lists below, usernames are separated by ','
[users] allowed default:'all' or list of allowed users
[admins] allowed default:'none' or list of admin users
[writelist] list of users that can write to a RO share
[comment] description of share
-u "<username;password>[;ID;group;GID]" Add a user
required arg: "<username>;<passwd>"
<username> for user
<password> for user
[ID] for user
[group] for user
[GID] for group
-w "<workgroup>" Configure the workgroup (domain) samba should use
required arg: "<workgroup>"
<workgroup> for samba
-W Allow access wide symbolic links
-I Add an include option at the end of the smb.conf
required arg: "<include file path>"
<include file path> in the container, e.g. a bind mount
The 'command' (if provided and valid) will be run instead of sambaENVIRONMENT VARIABLESCHARMAP - As above, configure character mapping
GENERIC - As above, configure a generic section option (See NOTE3 below)
GLOBAL - As above, configure a global option (See NOTE3 below)
IMPORT - As above, import a smbpassword file
NMBD - As above, enable nmbd
PERMISSIONS - As above, set file permissions on all shares
RECYCLE - As above, disable recycle bin
SHARE - As above, setup a share (See NOTE3 below)
SMB - As above, disable SMB2 minimum version
TZ - Set a timezone, IE EST5EDT
USER - As above, setup a user (See NOTE3 below)
WIDELINKS - As above, allow access wide symbolic links
WORKGROUP - As above, set workgroup
USERID - Set the UID for the samba server's default user (smbuser)
GROUPID - Set the GID for the samba server's default user (smbuser)
INCLUDE - As above, add a smb.conf includeNOTE: if you enable nmbd (via
-n or the NMBD environment variable), you
will also want to expose port 137 and 138 with -p 137:137/udp -p 138:138/udp.NOTE2: there are reports that
-n and NMBD only work if you have the
container configured to use the hosts network stack.NOTE3: optionally supports additional variables starting with the same name, IE
SHARE also will work for SHARE2, SHARE3... SHAREx, etc.Examples
Any of the commands can be run at creation withdocker run or later with
docker exec -it samba samba.sh (as of version 1.3 of docker).Setting the Timezone
sudo docker run -it -e TZ=EST5EDT -p 139:139 -p 445:445 -d dperson/samba -pStart an instance creating users and shares:
sudo docker run -it -p 139:139 -p 445:445 -d dperson/samba -p \
-u "example1;badpass" \
-u "example2;badpass" \
-s "public;/share" \
-s "users;/srv;no;no;no;example1,example2" \
-s "example1 private share;/example1;no;no;no;example1" \
-s "example2 private share;/example2;no;no;no;example2"User Feedback
Troubleshooting
- You get the error
Access is denied(or similar) on the client and/or see
change_to_user_internal: chdir_current_service() failed! in the container
logs.Add the
-p option to the end of your options to the container, or set the
PERMISSIONS environment variable.sudo docker run -it --name samba -p 139:139 -p 445:445 \
-v /path/to/directory:/mount \
-d dperson/samba -pIf changing the permissions of your files is not possible in your setup you
can instead set the environment variables USERID and GROUPID to the
values of the owner of your files.- High memory usage by samba. Multiple people have reported high memory usage
Add the
-m 512m option to docker run command, or mem_limit: in
dockercompose.yml files, IE:sudo docker run -it --name samba -m 512m -p 139:139 -p 445:445 \
-v /path/to/directory:/mount \
-d dperson/samba -p- Attempting to connect with the
smbclientcommandline tool. By default samba
smbclient -m SMB3, then
any other options you would specify.Issues
If you have any problems with or questions about this image, please contact me through a GitHub issue.Serve Samba on your own domain behind Caddy, Nginx or Traefik. Fill in your domain and copy the result. It's a starting point, some apps need their own base URL or extra headers set too.
Proxying samba.example.com to http://Samba:139
Add this to your Caddyfile
samba.example.com {
reverse_proxy http://Samba:139
}Check the logs first
Nine times out of ten the logs tell you exactly what went wrong.
- In Portainer, go to Containers, click the container, then Logs. Or run
docker logs Samba - Exit codes help too:
137means killed, usually out of memory.126or127means the command inside the image is broken.
Port already in use
If deployment fails with "Bind for 0.0.0.0:139 failed: port is already allocated", something else on your server is using that port.
- Find what's using it:
sudo ss -tlnp | grep :139 - Stop the other service, or pick a different host port. In
139:139only the left number is yours to change, the right one belongs to the app.
Running but the page won't load
The container is up but nothing appears in your browser.
- Use your server's real IP:
http://your-server-ip:139. The 0.0.0.0 link Portainer shows isn't a real address. - Give it a minute after first deploy, Samba can take a while to initialise.
- Make sure your firewall allows the port, e.g.
sudo ufw allow 139
Permission denied on volumes
If the logs show "permission denied", the app can't write to its data folder on the host.
- Fix the ownership:
sudo chown -R 1000:1000 /portainer/Downloads - Or set the
PUIDandPGIDvariables (defaults 1000:1000) to match your own user, found withid $USER
Image won't pull
Test the pull directly on the host: docker pull dperson/samba:latest
- "manifest unknown" means the tag no longer exists. This template uses
latest, so try pinning a specific version instead. - "toomanyrequests" is the Docker Hub rate limit. Log in with
docker loginto raise it. - "no space left on device" means a full disk. Reclaim space with
docker system prune
"exec format error"
This means the image was built for a different CPU architecture than your server.
- This image supports:
amd64, arm64, arm/v6, arm, arm64/v8 - Check yours with
uname -m: x86_64 is amd64, aarch64 is arm64. Raspberry Pi and other ARM boards are the usual culprits.
Container keeps restarting
The unless-stopped restart policy relaunches the app after every crash, so the real error can scroll past.
- Check the logs right after a restart, the last few lines before it died are the useful ones.
- Get the exit code with
docker inspect Samba --format '{{.State.ExitCode}}' - Still stuck? Redeploy once with the restart policy set to
noso the failure stays visible.
Privileged mode
This template runs the container in privileged mode, giving it full access to your host.
- Only deploy it if you trust the app.
- If deployment is blocked, your Portainer security settings or hardened host may not allow privileged containers.
Raise an issue
Found something which isn't working as it should? Here's how to report it.
- Bug within the app: Open an issue on dperson/samba
- Template not working: Open an issue on novaspirit/pi-hosted
- This website not working: Open an issue on lissy93/portainer-templates
A single container
Samba runs as one container, the simplest kind of app here. Just the one image to pull and nothing else wired up alongside it.
The app image
An image is the app packed up ready to go, everything Samba needs bundled into one download. This template pulls dperson/samba:latest, which Docker fetches once (about 20 MB) and then starts your own copy from.
Where the image comes from
Docker pulls its images from registries, public libraries of ready-built apps. Samba's comes from Docker Hub, published by dperson.
Version tags
The bit after the colon in the image name is the version tag. Here it's latest, which always points at the newest build, so a redeploy can bump you to a newer release without you asking. Pin a specific tag if you would rather stay on one version.
Which machines it runs on
Every image is built for particular CPU types. This one ships for amd64, arm64, arm/v6, arm, arm64/v8, so it runs on both regular x86 servers and ARM boards like a Raspberry Pi.
Ports
A port is the door the app answers on. A mapping like 139:139 means it's reachable on port 139 of your server, where the left number is yours to change and the right one belongs to the app. It opens:
139:139445:445
Volumes
A volume is where Samba keeps its files so they survive an update or a restart. Without one, anything it saves would sit inside the container and vanish the moment it's recreated. This template mounts:
/sharefrom/portainer/Downloadson the host
Environment variables
Environment variables are the settings you hand over when you deploy, things like a password or a timezone. Samba takes 7 of them, all with defaults you can leave alone or tweak:
PUID, defaults to1000PGID, defaults to1000USERID, defaults to1000GROUPID, defaults to1000USER, defaults toguest;guestPERMISSIONS, defaults totrueSHARE, defaults toportainer;/share;yes;no;yes;guest
Restart policy
The restart policy here is unless-stopped, so Docker restarts Samba after a crash or reboot, but leaves it off when you stop it on purpose. You can change this on the deploy screen. The choices are no (never restart), on-failure (only after a crash), unless-stopped (restart unless you stop it), and always (bring it back no matter what).
Users and permissions
The PUID and PGID settings tell it which user and group to act as on your host. Point them at your own account (find yours with id $USER) so the files it writes into your mounted folders come out owned by you rather than root.
Networking
Nothing custom is set, so Samba sits on Docker's default bridge network: its own private space that reaches the outside world only through the ports it publishes.
Container name
Once it's deployed, Portainer names the container Samba. That's what you'll spot in the containers list and use in commands like docker logs Samba.
Privileged mode
This template runs Samba in privileged mode, which gives it nearly as much access to your server as the system itself. Some apps genuinely need it to reach hardware or manage the host, so it's one to run only if you trust the source.
Platform
The platform is linux, the kind of system the container is built to run on. Docker and Portainer handle this on a normal Linux server.
Open source license
Samba is open source, released under the AGPL-3.0 license. In plain terms the code is out in the open, so you're free to run it and change it to fit what you need.
Portainer app templates
Zooming out, this whole page comes from a Portainer app template: a short recipe telling Portainer how to set Samba up. Add the template list to Portainer once, then deploying Samba is a click rather than a wall of config.