tui-tools

tui-dc

A Samba Active Directory domain, administered from the terminal

A terminal UI (TUI) for samba-tool on Linux: samba-tool for a machine that is a Samba Active Directory domain controller.

v0.2.1betausersMIT
The domain screen: what the controller answered, what this host is, and the functional levels
The domain screen: what the controller answered, what this host is, and the functional levels

A terminal UI over samba-tool for a machine that is a Samba Active Directory domain controller. It opens read-only: the domain's name and functional levels, the role this host plays in it, the password policy, the accounts, the groups, the machine accounts, the domain's own DNS zone, and the state of replication per naming context.

Every change is one samba-tool command, shown in full and confirmed before it runs — and no password is ever an argument. samba-tool warns about that itself, because a command line is visible in ps to every user on the machine, so creating an account and resetting a password ask samba-tool for a random password and show what it printed — and provisioning omits --adminpass so samba-tool generates the Administrator password itself and prints it exactly once.

On a machine that has samba-tool and no domain, a wizard provisions one: realm, NetBIOS name, DNS backend, optional forwarder, the realm typed back as a second confirmation, then the usual previewed command. It does not join or demote a domain: both touch a trust relationship with another controller, and are worth reading in a shell where they can be checked twice.

Keys

KeyAction
tab / 1…6Move between domain, users, groups, computers, DNS and replication
enterOpen the selected row, reading its detail if it has not been read
nCreate an account, a group or a DNS record
dDelete the selected account, group or record
e / sEnable or suspend the account; on the domain screen, edit the password-policy setting
POn the domain screen of a host with no domain: provision one (wizard, double-confirmed)
pReset the selected account's password to a random one
xSet when the selected account expires
a / mAdd or remove a member of the selected group
/Filter the current screen
r / ctrl+rRe-read the domain
?Help
qQuit

Press ? inside the tool for the full help screen, which is generated from the same action table as the key map.

Compatibility

This tool is a face on the program below, so its version matters.Tested is not a claim: a version lands there only after the tool's own suite passed against it on a real machine in the lab, and the run is kept as evidence in the repository. At startup the tool probes the backend once and says what it found in its header — a version nobody has run against is shown as(untested) in the warning colour, one older than the minimum as (below minimum) in the error colour. Neither stops it: the backend still refuses what it cannot do, in its own words.

samba

samba-tool ≥ 4.13
Binary
samba-tool
Minimum
4.13
Probed with
samba-tool --version
Tested
No recorded run yet. The tool still runs and reports the version it found as untested.

Needs a version this new

  • computer-subcommandsince 4.8

What changes on older versions

  • samba <4.8

    samba-tool computer does not exist, so the computers screen is empty

  • samba <4.13

    untested: the output of domain info, dns query and drs showrepl has changed shape across releases and the parsers are only checked against 4.19 and 4.22

Install

Once per machine, then every tool in the family is one pacman away.

Add the repository
$ curl -fsSL https://pkgs.tui.tools/install.sh | sh
Or run the same thing yourself, one command at a time

A family whose whole promise is preview before you run is not going to insist you pipe a script into a shell. These are the commands that script runs.

The one-time setup, by hand
$ curl -fsSL -o /tmp/tui-tools.asc https://pkgs.tui.tools/pubkey.asc
  sudo pacman-key --add /tmp/tui-tools.asc
  sudo pacman-key --lsign-key \
    "$(gpg --show-keys --with-colons /tmp/tui-tools.asc | awk -F: '/^fpr:/{print $10; exit}')"
  printf '[tui-tools]\nServer = https://pkgs.tui.tools/arch/$arch\n' \
    | sudo tee -a /etc/pacman.conf
  sudo pacman -Sy
Arch Linux · tui-dc
$ sudo pacman -S tui-dc

Not released yet. The channel turns available once the first release lands in pkgs.tui.tools.

What it can do to your machine

  • Preview, then confirm

    Every change is shown as an exact command line and confirmed before it runs. The dialog and the runner receive the same value, so the preview cannot drift from what executes.

  • Escalates for actions

    Everything. samba-tool opens the directory database directly and that database is readable only by root, so even the read path escalates. A machine where escalation is refused says so at startup rather than showing an empty domain.

  • No daemon, no state of its own

    Nothing keeps running after you quit, and nothing is installed to run later. The system is the source of truth; the tool re-reads it after every change.

  • Opens network connections

    samba-tool talks to a controller, and this tool points it at this host. domain info is a CLDAP query, dns query a DNS RPC call and drs showrepl a DRS one, so there is loopback traffic on every read. Nothing leaves the machine and nothing is fetched from the internet.

  • Static binary

    Released statically linked, with no runtime dependencies to install.

  • Signed release, with provenance

    checksums.txt carries a keyless cosign signature from this repository's release workflow, every archive has a CycloneDX SBOM, and every archive, package and the checksum file carry SLSA build provenance. The security page shows the three commands that check it.

Reporting

Report a security issue privately, through GitHub's private vulnerability reporting on the repository's Security tab. The family-wide policy, and what counts as in scope, is on the security page.

Downloads

v0.2.1 · 2026-09-02
FileSizeSHA-256
checksums.txt986 B
checksums.txt.sigstore.json10 KB
provenance.intoto.jsonl12 KB
tui-dc-0.2.1-1-aarch64.pkg.tar.zst1.7 MB30c7c69ebdb6465a78dcd6ccff546b8f46b68126a2c352d06cfe2f14a1b08d00
tui-dc-0.2.1-1-x86_64.pkg.tar.zst1.9 MB846387cd20db8161db878ff8a27932b0adf39547b3ca2339842011b0f69f1cc0
tui-dc-0.2.1-1.aarch64.rpm1.7 MB9b6c1bc64f9fa21e3a51d2276c73994ab92455768972d2d3a581f35b3c68af22
tui-dc-0.2.1-1.x86_64.rpm1.9 MBbe36aeec39001a3c2333b9545ae90cfd825db23eb2dc9736a66db76a65a6b0cf
tui-dc_0.2.1_amd64.deb1.9 MBfc4be7bb4d2bae8aa7b30db1d1baa78cba96ad94c368addf9c2aef212ad6fcd2
tui-dc_0.2.1_arm64.deb1.7 MBa9553b171dd49083b8d28c6231c9f99a385cbbe4a9c502e9bec00225233df1ce
tui-dc_0.2.1_linux_amd64.tar.gz1.9 MB29621d25b7fa67e5efb341ec3deb506d4046779355ddc290dee47725580407d2
tui-dc_0.2.1_linux_amd64.tar.gz.cyclonedx.json23 KB485e484be546a4ecf94508aa911ed16dda2912ec99cbf3a38b461aac5e7a025e
tui-dc_0.2.1_linux_arm64.tar.gz1.7 MB7feb812142479c83c0a276adb252ebd6552f69135eba86b544952bc9e8bbadbb
tui-dc_0.2.1_linux_arm64.tar.gz.cyclonedx.json23 KBa1d6f826c9ce33292e065e7d2c8a49e48704d60cdf5063c6513e644b5023c729

Every release ships a checksums.txt. Download it next to the archive and run sha256sum -c checksums.txt --ignore-missing. See verifying a download.

Releases

v0.2.1

2026-09-02
## tui-dc v0.2.1

tui-kit v0.3.0: the dialogs wrap and scroll instead of clipping the
command preview, and the picker filters as you type.

Built by this repository's CI on the tag itself. Each archive ships a
CycloneDX SBOM, `checksums.txt` carries a keyless cosign signature, and
every file has SLSA build provenance — see the README's "Verify a
download" for the two commands that check them.

The commits in this release:

## Changelog
* bb59e12027bd5aff170577dfbf6a6081302c4420 Bump tui-kit to v0.3.0 (#5)
* 65658796d8867823d2b86275c38fd16dd1f89100 tool.json: released (#4)

v0.2.0

2026-09-01
## tui-dc v0.2.0

Manage, not view: create and edit from the TUI (wave 1), lab-validated on the router image.

Built by this repository's CI on the tag itself. Each archive ships a
CycloneDX SBOM, `checksums.txt` carries a keyless cosign signature, and
every file has SLSA build provenance — see the README's "Verify a
download" for the two commands that check them.

The commits in this release:

## Changelog
* 55abe6ba3af082b21eb07fa42fbf82ce71419d86 Domain provision wizard and password policy — the DC learns to create (#3)

v0.1.0

2026-09-01
## tui-dc v0.1.0

First validated release: the router-1.0 lab ran this tool against real VMs (tui-lab router topology).

Built by this repository's CI on the tag itself. Each archive ships a
CycloneDX SBOM, `checksums.txt` carries a keyless cosign signature, and
every file has SLSA build provenance — see the README's "Verify a
download" for the two commands that check them.

The commits in this release:

## Changelog
* 051ba70e4bde4b77a8923ea01acb5a359d1cba52 Bump anchore/sbom-action/download-syft in the github-actions group (#1)
* 08be222949085e71786a65c17b2b35a2ab8df511 Initial commit
* c7864297f37facc16f1693c4247ff389764b8769 Replace the template with a Samba AD domain controller tool (#2)