# Dufs: A Single-Binary File Server with WebDAV, Access Control, and curl API

> Dufs is a Rust file server that serves, uploads, searches, and manages files through a web interface and a curl-friendly HTTP API. It ships as a single binary with no runtime dependencies, supports WebDAV, TLS, and per-path access control.

**sigoden/dufs** — A file server that supports static serving, uploading, searching, accessing control, webdav...

- Repository: https://github.com/sigoden/dufs
- Stars: 10,800 · Forks: 591
- Language: Rust
- License: Apache-2.0
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/sigoden-dufs

## What Dufs Solves and Who It Is For

Dufs is described in its README as a distinctive utility file server. It runs as a single binary, listens on a configurable port, and serves a directory through a web interface that supports browsing, downloading, uploading, creating, editing, searching, and deleting files. Drag-and-drop upload is included in the web interface, and folders can be uploaded as a unit.

The default configuration starts Dufs in read-only mode. A single flag enables all write operations:

```bash
dufs -A
```

This makes it useful for quickly sharing a directory over a local network, for container-based file exchange, or for giving a remote team access to a specific folder with controlled permissions. The README lists curl as a first-class client, meaning all operations can be scripted without a browser.

Dufs supports resumable and partial uploads and downloads. Folders can be downloaded as zip archives. The web interface includes a file editor and a search function that behaves like a recursive find-by-name. The built-in log format is customisable through the  option, which accepts variables like , , , , and any request header field via  prefix. A YAML configuration file can be used in place of command-line flags for more complex deployments via the  flag.

## Installation and First Run

Dufs installs via Cargo:

```bash
cargo install dufs
```

Via Docker:

```bash
docker run -v `pwd`:/data -p 5000:5000 --rm sigoden/dufs /data -A
```

Via Homebrew:

```bash
brew install dufs
```

Binary releases for macOS, Linux, and Windows are also available on the GitHub Releases page. The default port is 5000. To serve a specific directory:

```bash
dufs Downloads
```

To serve a single file:

```bash
dufs linux-distro.iso
```

To serve a single-page application:

```bash
dufs --render-spa
```

To require a username and password:

```bash
dufs -a admin:123@/:rw
```

All configuration is done through command-line flags. There is no configuration file required for basic use, though Dufs accepts a config file via `-c`. The Cargo.toml confirms the version is 0.46.0.

## Access Control: Per-Path Permissions and Hashed Passwords

Dufs implements account-based access control through the `-a` flag. The syntax uses `@` to separate the account from the paths, `:` to separate username and password, and `,` to list multiple paths. The README gives these examples:

```bash
dufs -a admin:admin@/:rw -a guest:guest@/
dufs -a user:pass@/:rw,/dir1 -a @/
```

The `@/` pattern without an account name means anonymous access. Path suffixes `:rw` and `:ro` set read-write and read-only permissions respectively. Auth permissions are bounded by Dufs global permissions, so an account granted `:rw` cannot upload if Dufs was started without `--allow-upload`.

Dufs supports sha-512 hashed passwords via OpenSSL:

```bash
openssl passwd -6 123456
```

The resulting hash string starts with `$6$` and must be wrapped in single quotes in the shell to prevent variable expansion. The README notes that digest authentication does not work with hashed passwords; only basic authentication works when using the sha-512 hash format.

## The curl API and WebDAV Support

Dufs exposes an HTTP API that works directly with curl. To upload a file:

```sh
curl -T path-to-file http://127.0.0.1:5000/new-path/path-to-file
```

To download a folder as a zip:

```sh
curl -o path-to-folder.zip http://127.0.0.1:5000/path-to-folder?zip
```

To search for files:

```sh
curl http://127.0.0.1:5000?q=Dockerfile
```

The search behaves like `find -name`. The `?simple` query parameter outputs filenames only, like `ls -1`, and `?json` returns directory contents as JSON. A health check endpoint is available at `/__dufs__/health`. Resumable uploads are supported via the `X-Update-Range: append` header and a PATCH request. Both basic and digest authentication work with curl via the `--user` flag.

Dufs also implements the WebDAV protocol, which means it can be mounted as a network drive in Windows Explorer, macOS Finder, or any WebDAV-compatible client. The WebDAV support enables file management through existing desktop tools without a custom client. MOVE, MKCOL, and DELETE operations are available both via WebDAV and directly via curl.

## Limitations and What Dufs Does Not Cover

Dufs hides paths from directory listings via the `--hidden` flag, accepting glob patterns:

```bash
dufs --hidden '.*'
dufs --hidden '*.log,*.lock'
```

The glob matches file and directory names only, not full paths. The README explicitly states that `--hidden dir1/file` is invalid.

Dufs does not implement WebDAV locking. Applications that require WebDAV LOCK and UNLOCK requests for collaborative editing, such as Microsoft Office editing over WebDAV, will not work correctly. This is a standard WebDAV feature that many full WebDAV server implementations provide but Dufs does not.

The Dockerfile in the repository builds a minimal scratch-based image from scratch with only the Dufs binary and no shell, which is appropriate for containerised deployments but means no debugging utilities are available inside the container.

Dufs also does not support virtual hosting or serving multiple domains from one instance. Each Dufs process serves exactly one root directory. Teams that need to serve multiple unrelated directories with separate hostnames must run multiple Dufs instances.

The  option allows mounting the server under a path prefix, which is useful when Dufs runs behind a reverse proxy at a non-root path. Listening on a Unix socket is also supported via the  flag with a file path, useful for proxied deployments where the socket is shared with the upstream server.

## Dufs Compared to Caddy and nginx for Simple Sharing

Caddy and nginx are general-purpose web servers that can serve static files and, with additional configuration, support file uploads. They are the most common alternatives for static file serving. The difference in approach is significant. Both require configuration files with specific syntax. nginx does not support file uploads or WebDAV without additional modules. Caddy supports WebDAV via a plugin but not in the base binary.

Dufs is designed from the start for interactive file management. The web interface includes drag-and-drop upload, file editing, and search out of the box. The `-A` flag enables all operations with no additional configuration. For teams that need to share or exchange files quickly over a local network or container, Dufs requires far less setup than either nginx or Caddy.

The trade-off is that Dufs is not a production HTTP server for arbitrary web applications. It does not support virtual hosts, complex routing, or reverse proxy functions. Caddy or nginx are better choices when the use case goes beyond file serving.

The last push to the repository was on 2026-06-29, and v0.46.0 shipped on 2026-05-07. The project is dual-licensed under MIT and Apache-2.0, giving adopters flexibility to choose the more permissive option for their context. The Cargo.toml lists the project under the command-line-utilities and web-programming::http-server categories on crates.io.

## Conclusion

Dufs is well suited for developers and sysadmins who need a file server that can be started with a single command and configured entirely via CLI flags. The zero-dependency single binary makes it easy to drop into a container or a script. The access control model is expressive enough for most sharing scenarios. The last push to the repository was on 2026-06-29. The main limitation is that Dufs does not implement WebDAV locking, so it is not suitable for collaborative editing workflows where clients expect the full WebDAV locking protocol. Check that your WebDAV clients do not require LOCK/UNLOCK before deploying Dufs in that role.

## FAQ

### What is Dufs and how does it differ from a standard file server?

Dufs is a single-binary Rust file server that combines static serving, file uploads, search, WebDAV, and access control in one tool started with a single command. Unlike nginx or Apache, it needs no configuration file for basic use and supports interactive file management through a built-in web interface.

### How does Dufs handle access control for multiple users?

Dufs uses the -a flag to define per-path permissions for each user. Each rule specifies a username, password, and one or more paths with :rw or :ro suffixes. An @/ pattern without a username enables anonymous read-only access. Sha-512 hashed passwords are supported for storing credentials more securely.

### Can Dufs be run in Docker?

Yes. The Docker image sigoden/dufs is available on Docker Hub. Running `docker run -v $(pwd):/data -p 5000:5000 --rm sigoden/dufs /data -A` serves the current directory on port 5000 with all write operations enabled. A docker-compose.yml is also provided in the repository.

## Sources

- [Issues](https://github.com/sigoden/dufs/issues)
- [License: Apache-2.0](https://github.com/sigoden/dufs/blob/main/LICENSE)
- [README](https://github.com/sigoden/dufs/blob/main/README.md)
- [Releases](https://github.com/sigoden/dufs/releases)
- [sigoden/dufs on GitHub](https://github.com/sigoden/dufs)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/sigoden-dufs
