Levelrail
Skip to content

Network shares ​

A network share is a saved record of an NFS export or a CIFS (SMB) share on your network, such as a NAS. You register it once, with the host, remote path and credentials, and test that the host answers. The record is stored by the control plane, and a CIFS password is stored encrypted with the master key, never returned by the API.

Registration only, for now

Today a network share is a managed record plus a reachability test. Nothing in the control plane yet creates a Docker volume from a share or mounts one into an app. The translation to Docker's built-in local driver NFS and CIFS options exists in internal/docker, but no code path calls it. The dashboard page text describes attaching a share as an app volume source; treat that as the intended direction, not a shipped capability. To use a share in an app today, mount it on the node yourself and bind-mount the path with a hostPath volume.

Add a share ​

FieldCLI flagRequiredNotes
Name--nameyesDisplay name. Must be unique; a duplicate returns a conflict error.
Protocol--protocolyesnfs or cifs.
Host--hostyesHostname or IP of the server, for example nas.internal.
Remote path--remote-pathyesThe export or share path, for example /exports/data.
Mount options--mount-optionsnoExtra mount options passed through as given.
Username--usernameCIFS onlyRequired for a CIFS share.
Password--passwordCIFS onlyRequired for a CIFS share. Stored encrypted.

Creating a share with credentials needs the control plane's master key to be configured. Without one, the API refuses with a "not implemented" error. An NFS share carries no credentials.

Test, update and remove ​

bash
levelrail-cli network-shares list
levelrail-cli network-shares get <id>
levelrail-cli network-shares test <id>
levelrail-cli network-shares update <id> --name nas-media --protocol nfs --host nas.internal --remote-path /exports/media
levelrail-cli network-shares delete <id>
  • test opens a TCP connection from the control plane to the share's host on the protocol's standard port (2049 for NFS, 445 for CIFS) with a 10 second timeout. A failure returns the address it could not reach. This is a reachability check only. It does not authenticate and never reads the CIFS password, so a passing test does not prove the credentials or the export path are right.
  • update takes the full set of required fields again. Omit --password to keep the existing password; pass it to rotate it.
  • delete removes the record. The control plane's secrets store has no delete operation yet, so a deleted CIFS share's encrypted password stays in the store, unreferenced.

All subcommands accept the standard --token, --api-url, --profile, --json, --output and --query flags.

API ​

MethodPathAbility
GET/api/v1/network-sharesRead
POST/api/v1/network-sharesSensitive write
GET/api/v1/network-shares/{id}Read
PUT/api/v1/network-shares/{id}Sensitive write
DELETE/api/v1/network-shares/{id}Sensitive write
POST/api/v1/network-shares/{id}/testRead

A share does not appear on the project topology graph, because no stored link ties a share to an app volume.

Released under the Apache 2.0 License.