Skip to content

Repository files navigation

go-samba4

Web Administration Panel for Samba 4 Active Directory

Status: 🔴 Under Development (v1.1.2) Stack: Golang, Echo Framework, GORM, Tailwind CSS (Neo-Brutalism), jQuery, DataTables, Lucide Icons, LDAP, Kerberos.

Overview

The Samba4 AD Web Admin Panel is a modern web administration tool to manage Samba 4 Active Directory environments. Built to replace legacy interfaces (such as SWAT or manual samba-tool commands), it offers a fast, secure, and extensible solution under modern, high-performance technologies.

The interface focuses on functional clarity (Neo-Brutalist style) aimed at IT teams and systems administrators managing Samba domains without Microsoft's infrastructure and tools (RSAT). The panel operates as a modular monolith, where the backend and frontend (templates and static assets) are unified into a single self-sufficient binary via go:embed.

Key Features 🚀

  • Comprehensive User and Group Management: Full CRUD operations in AD (LDAP), disable accounts, reset passwords.
  • OU Tree Navigation: Hierarchical view and movement of AD objects.
  • Secure Authentication: Login via LDAP bind, support for Kerberos (SSO), and Two-Factor Authentication (TOTP).
  • Access Control (RBAC): Conditional permissions (Admin, Operator, Helpdesk) based on AD groups.
  • Auditing and Monitoring: Detailed tracking with local change logs and searchable DataTables views.
  • Advanced Search: Find objects with advanced customizable LDAP filters.
  • Independent Local Database: Embedded SQLite by default (or configurable MySQL/MariaDB via GORM) for audit logs, sessions, and settings.
  • Internationalization: UI fully translated in English, Portuguese (pt_BR), and Spanish, including table controls.
  • Active Navigation: Sidebar highlights the current section, preserving context across nested routes.

Technology & Architecture 🛠️

The architecture guarantees zero dependency on external assets in production.

  • Backend: Go (1.26+), Echo (HTTP), GORM (Data Modeling)
  • AD/Samba Integration: go-ldap/ldap and gokrb5 (Kerberos)
  • Frontend: Server-Side Rendering (SSR) via html/template, TailwindCSS 4.2+, jQuery 4, DataTables 2.3.7, Lucide Icons
  • i18n: Portuguese (pt_BR), English (en), Spanish (es) — including DataTables localization
  • CLI Tooling: Cobra & Viper (config.toml Configurations)

Build ⚙️

# Compile Tailwind CSS
make css

# Build the binary (runs css + go build + UPX compression)
make build

# Run the server after building
make run

CLI Usage ⚙️

Because the application is structured around a powerful cobra CLI, it provides helper commands alongside starting the server:

# Start the Web Admin Server (Default Port 8080)
./go-samba4 serve --port 8080

# Run local application database migrations (Sessions and Logs)
./go-samba4 migrate

# Use the emergency CLI for skeleton tasks (local bypass users)
./go-samba4 user

# Print the current version and build date
./go-samba4 version

Note: The core application configuration, including LDAP and TLS communication, is managed externally via a config.toml file pointed by the --config flag if needed (defaults to ./config.toml).

Security Requirements 🔒

The environment should implement the following mandatory production practices:

  • Transport Security: Active Server HTTPS/TLS certificates along with encrypted LDAPS communication (port 636) to the native Domain Controller.
  • Immutable Auditing: Appended local files recording the access and delegations performed on the interface.

Reference

For further architectural and deep roadmap details, please refer to the Application PRD.

About

Samba4 AD Web Admin Panel

Resources

Stars

7 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages