The safe approach is to treat an evidence-first ACL audit that maps identities, effective permissions, and inheritance across every access path as a sequence of observable gates, not a single command.
On a home NAS exporting shared data to SMB, NFS, and containers, the practical risk is the same NAS path grants different effective access through SMB, NFS, and container bind mounts. Record the current identity and recovery point, start with the least invasive discriminator, interpret pass and fail results before changing another variable, and stop when storage becomes unstable or the only recoverable copy would be exposed. The workflow below ends only after the original workload succeeds or the evidence reaches an escalation boundary.
Freeze the permission state and map every identity
Choose one representative share and record its dataset or filesystem, export names, SMB share definition, NFS export, container bind mounts, and current ownership. Capture numeric UID and GID values on the NAS and inside each container; matching user names are not evidence that the underlying identities match.
POSIX ACLs add named users, named groups, default entries, and a mask that can limit their effective rights. The POSIX ACL mask behavior explains why the mask shown by getfacl can make an apparently generous entry behave more narrowly, which is essential when comparing a command-line view with SMB or NFS behavior.
Do not run recursive chmod, chown, or ACL replacement during inventory. Save getfacl -p output and service configuration first; the baseline passes when every client identity can be tied to a numeric server-side identity or explicitly marked unmapped.
Test effective access through each protocol
Create a dedicated audit user and a disposable directory below the share. From Windows or macOS over SMB, from a Linux NFS client, and from the target container, test list, read, create, rename, and delete separately. Record the owner, group, mode, ACL, and protocol used after each operation.
Keep authentication and filesystem authorization distinct. An SMB login can succeed while the mapped Unix identity lacks write permission; an NFS client can present a numeric ID that the server accepts but that resolves to the wrong local owner. Change only one identity or ACL variable between tests.
A path passes only when observed rights match the intended access matrix and newly created files receive the expected owner, group, and default ACL. If one protocol differs, stop broad changes and trace that protocolโs mapping layer before touching the shared filesystem.
Inspect inheritance, masks, and container mappings
Compare the parent default ACL with the access ACL on newly created files and directories. Check the ACL mask after group changes, confirm whether the SMB service applies create or directory masks, and identify applications that replace files atomically because replacement can produce different inheritance from in-place edits.
For containers, inspect the runtime user, supplemental groups, user-namespace remapping, and the bind-mounted host path. The related ZimaSpace guide on database access on a network-mounted Docker volume is useful when NFSv4 name mapping is the failing layer; this audit remains focused on proving the end-to-end rights across all three paths.
Do not solve a mapping problem by running the application as root. If the container cannot create the disposable file, align its supported UID, GID, or supplemental group with the NAS policy and repeat the same test before changing any production tree.
Apply the narrowest correction and preserve evidence
Correct one layer at a time: identity mapping first, group membership second, inherited defaults third, and exceptional file ACLs last. Apply changes to the disposable directory, verify all operations again, and only then stage a scoped change for the production subtree with a saved rollback ACL.
After rollout, restart or reconnect clients that cache credentials, remount NFS where required, and restart only containers whose group list is fixed at process start. Repeat the same test matrix and verify that existing files and new files both behave as intended.
The audit closes when every allowed and denied action matches the written matrix, new objects inherit correctly, and the saved ACL can restore the prior state. Escalate instead of recursing blindly when ownership is mixed by design, snapshots or hard links complicate rollback, or the NAS storage reports errors.
Support & Tips
More to Read

NFS Migration Checklist for Renamed Datasets and Stable File Handles
Assume file handles may change when storage identity changes. Quiesce clients, cut over the export deliberately, remount, and verify open and new files.

SMB Client Troubleshooting Guide for Windows, macOS, and Linux
Use the same server, account, share, and file operation on each client so discovery, credentials, policy, and storage faults do not get mixed together.

Home Server Secret Rotation Checklist for Apps, Databases, and Backups
Treat rotation as a dependency migration: map every consumer, overlap credentials where possible, verify the new value, then revoke and test recovery.

