Self-hosted service
sigoden/dufs avatar
sigoden/dufs

Dufs: A Single-Binary File Server with WebDAV, Access Control, and curl API

A file server that supports static serving, uploading, searching, accessing control, webdav...

10,800 stars591 forksRustApache-2.0

At a glance

What is it?
Dufs is a Rust file server that serves, uploads, searches, and manages files through a web interface and a curl-friendly HTTP API. It ships as a single binary with no runtime dependencies, supports WebDAV, TLS, and per-path access control.
Who is it for?
Dufs is well suited for developers and sysadmins who need a file server that can be started with a single command and configured entirely via CLI flags. The zero-dependency single binary makes it easy to drop into a container or a script.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 93 days ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Dufs Solves and Who It Is For

Dufs is described in its README as a distinctive utility file server. It runs as a single binary, listens on a configurable port, and serves a directory through a web interface that supports browsing, downloading, uploading, creating, editing, searching, and deleting files. Drag-and-drop upload is included in the web interface, and folders can be uploaded as a unit.

The default configuration starts Dufs in read-only mode. A single flag enables all write operations:

bash
dufs -A

This makes it useful for quickly sharing a directory over a local network, for container-based file exchange, or for giving a remote team access to a specific folder with controlled permissions. The README lists curl as a first-class client, meaning all operations can be scripted without a browser.

Dufs supports resumable and partial uploads and downloads. Folders can be downloaded as zip archives. The web interface includes a file editor and a search function that behaves like a recursive find-by-name. The built-in log format is customisable through the option, which accepts variables like , , , , and any request header field via prefix. A YAML configuration file can be used in place of command-line flags for more complex deployments via the flag.

Installation and First Run

Dufs installs via Cargo:

bash
cargo install dufs

Via Docker:

bash
docker run -v `pwd`:/data -p 5000:5000 --rm sigoden/dufs /data -A

Via Homebrew:

bash
brew install dufs

Binary releases for macOS, Linux, and Windows are also available on the GitHub Releases page. The default port is 5000. To serve a specific directory:

bash
dufs Downloads

To serve a single file:

bash
dufs linux-distro.iso

To serve a single-page application:

bash
dufs --render-spa

To require a username and password:

bash
dufs -a admin:123@/:rw

All configuration is done through command-line flags. There is no configuration file required for basic use, though Dufs accepts a config file via `-c`. The Cargo.toml confirms the version is 0.46.0.

Access Control: Per-Path Permissions and Hashed Passwords

Dufs implements account-based access control through the `-a` flag. The syntax uses `@` to separate the account from the paths, `:` to separate username and password, and `,` to list multiple paths. The README gives these examples:

bash
dufs -a admin:admin@/:rw -a guest:guest@/
dufs -a user:pass@/:rw,/dir1 -a @/

The `@/` pattern without an account name means anonymous access. Path suffixes `:rw` and `:ro` set read-write and read-only permissions respectively. Auth permissions are bounded by Dufs global permissions, so an account granted `:rw` cannot upload if Dufs was started without `--allow-upload`.

Dufs supports sha-512 hashed passwords via OpenSSL:

bash
openssl passwd -6 123456

The resulting hash string starts with `$6$` and must be wrapped in single quotes in the shell to prevent variable expansion. The README notes that digest authentication does not work with hashed passwords; only basic authentication works when using the sha-512 hash format.

The curl API and WebDAV Support

Dufs exposes an HTTP API that works directly with curl. To upload a file:

sh
curl -T path-to-file http://127.0.0.1:5000/new-path/path-to-file

To download a folder as a zip:

sh
curl -o path-to-folder.zip http://127.0.0.1:5000/path-to-folder?zip

To search for files:

sh
curl http://127.0.0.1:5000?q=Dockerfile

The search behaves like `find -name`. The `?simple` query parameter outputs filenames only, like `ls -1`, and `?json` returns directory contents as JSON. A health check endpoint is available at `/__dufs__/health`. Resumable uploads are supported via the `X-Update-Range: append` header and a PATCH request. Both basic and digest authentication work with curl via the `--user` flag.

Dufs also implements the WebDAV protocol, which means it can be mounted as a network drive in Windows Explorer, macOS Finder, or any WebDAV-compatible client. The WebDAV support enables file management through existing desktop tools without a custom client. MOVE, MKCOL, and DELETE operations are available both via WebDAV and directly via curl.

Limitations and What Dufs Does Not Cover

Dufs hides paths from directory listings via the `--hidden` flag, accepting glob patterns:

bash
dufs --hidden '.*'
dufs --hidden '*.log,*.lock'

The glob matches file and directory names only, not full paths. The README explicitly states that `--hidden dir1/file` is invalid.

Dufs does not implement WebDAV locking. Applications that require WebDAV LOCK and UNLOCK requests for collaborative editing, such as Microsoft Office editing over WebDAV, will not work correctly. This is a standard WebDAV feature that many full WebDAV server implementations provide but Dufs does not.

The Dockerfile in the repository builds a minimal scratch-based image from scratch with only the Dufs binary and no shell, which is appropriate for containerised deployments but means no debugging utilities are available inside the container.

Dufs also does not support virtual hosting or serving multiple domains from one instance. Each Dufs process serves exactly one root directory. Teams that need to serve multiple unrelated directories with separate hostnames must run multiple Dufs instances.

The option allows mounting the server under a path prefix, which is useful when Dufs runs behind a reverse proxy at a non-root path. Listening on a Unix socket is also supported via the flag with a file path, useful for proxied deployments where the socket is shared with the upstream server.

Dufs Compared to Caddy and nginx for Simple Sharing

Caddy and nginx are general-purpose web servers that can serve static files and, with additional configuration, support file uploads. They are the most common alternatives for static file serving. The difference in approach is significant. Both require configuration files with specific syntax. nginx does not support file uploads or WebDAV without additional modules. Caddy supports WebDAV via a plugin but not in the base binary.

Dufs is designed from the start for interactive file management. The web interface includes drag-and-drop upload, file editing, and search out of the box. The `-A` flag enables all operations with no additional configuration. For teams that need to share or exchange files quickly over a local network or container, Dufs requires far less setup than either nginx or Caddy.

The trade-off is that Dufs is not a production HTTP server for arbitrary web applications. It does not support virtual hosts, complex routing, or reverse proxy functions. Caddy or nginx are better choices when the use case goes beyond file serving.

The last push to the repository was on 2026-06-29, and v0.46.0 shipped on 2026-05-07. The project is dual-licensed under MIT and Apache-2.0, giving adopters flexibility to choose the more permissive option for their context. The Cargo.toml lists the project under the command-line-utilities and web-programming::http-server categories on crates.io.

Editorial conclusion

Dufs is well suited for developers and sysadmins who need a file server that can be started with a single command and configured entirely via CLI flags. The zero-dependency single binary makes it easy to drop into a container or a script. The access control model is expressive enough for most sharing scenarios. The last push to the repository was on 2026-06-29. The main limitation is that Dufs does not implement WebDAV locking, so it is not suitable for collaborative editing workflows where clients expect the full WebDAV locking protocol. Check that your WebDAV clients do not require LOCK/UNLOCK before deploying Dufs in that role.

Frequently asked questions

What is Dufs and how does it differ from a standard file server?

Dufs is a single-binary Rust file server that combines static serving, file uploads, search, WebDAV, and access control in one tool started with a single command. Unlike nginx or Apache, it needs no configuration file for basic use and supports interactive file management through a built-in web interface.

How does Dufs handle access control for multiple users?

Dufs uses the -a flag to define per-path permissions for each user. Each rule specifies a username, password, and one or more paths with :rw or :ro suffixes. An @/ pattern without a username enables anonymous read-only access. Sha-512 hashed passwords are supported for storing credentials more securely.

Can Dufs be run in Docker?

Yes. The Docker image sigoden/dufs is available on Docker Hub. Running `docker run -v $(pwd):/data -p 5000:5000 --rm sigoden/dufs /data -A` serves the current directory on port 5000 with all write operations enabled. A docker-compose.yml is also provided in the repository.

Official sources

  1. Issues
  2. License: Apache-2.0
  3. README
  4. Releases
  5. sigoden/dufs on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/sigoden-dufs.svg)](https://hysenlabs.com/projects/sigoden-dufs)