docs: readme + changelog for Caddy/Authelia milestone
This commit is contained in:
parent
a56a485f42
commit
80a5579537
2 changed files with 92 additions and 0 deletions
25
CHANGELOG.md
25
CHANGELOG.md
|
|
@ -1,5 +1,30 @@
|
||||||
# Changelog
|
# Changelog
|
||||||
|
|
||||||
|
## 0.1.0.0007 — 2026-07-08
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- Caddy reverse proxy (auto LE TLS, subdomain routing, forward auth)
|
||||||
|
- Authelia OIDC provider (2FA, identity store, user management)
|
||||||
|
- `compose/caddy.yaml` and `compose/authelia.yaml`
|
||||||
|
- `config/caddy/Caddyfile` with `{DOMAIN}` template
|
||||||
|
- `config/authelia/configuration.yml` with secret injection
|
||||||
|
- `tools/hash-password/` for bcrypt password hashing
|
||||||
|
- Certificate backup to `/opt/backup/certificates/` across destroys
|
||||||
|
- README.md with architecture overview
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- Replaced Zoraxy entirely with Caddy + Authelia
|
||||||
|
- Binary trusts `Remote-User` header from Caddy forward auth
|
||||||
|
- deploy.sh rewritten for Caddy/Authelia deployment
|
||||||
|
- install.sh creates Caddy/Authelia directories
|
||||||
|
|
||||||
|
### Removed
|
||||||
|
- Zoraxy compose, configs, proxy rules
|
||||||
|
- `tools/nextwks-tool` (no longer needed)
|
||||||
|
- `tools/register-certs` (no longer needed)
|
||||||
|
- BoltDB logic, `chattr +i`, CSRF handling
|
||||||
|
- All Zoraxy-specific deployment code
|
||||||
|
|
||||||
## 0.1.0.0001 — 2026-07-07
|
## 0.1.0.0001 — 2026-07-07
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
|
||||||
67
README.md
Normal file
67
README.md
Normal file
|
|
@ -0,0 +1,67 @@
|
||||||
|
# NextWorkspace
|
||||||
|
|
||||||
|
A self-hosted productivity suite for startups. One binary + Caddy + Authelia.
|
||||||
|
|
||||||
|
## Architecture
|
||||||
|
|
||||||
|
```
|
||||||
|
app.nextwks.eu :443 auth.nextwks.eu :443
|
||||||
|
│ │
|
||||||
|
Caddy (TLS + forward auth) Caddy → Authelia :9091
|
||||||
|
│ │
|
||||||
|
├── /home/ → launcher page └── authelia-api :8080
|
||||||
|
├── /drive/* → OpenCloud :9100
|
||||||
|
├── /office/* → Euro Office :9200
|
||||||
|
├── /erp/* → ERPNext :9300
|
||||||
|
├── /chat/* → Matrix :9400
|
||||||
|
├── /meet/* → Jitsi :9500
|
||||||
|
├── /mail/* → Alps :9600
|
||||||
|
├── /ai/* → Open WebUI :9700
|
||||||
|
└── /admin/* → Portainer :9800
|
||||||
|
```
|
||||||
|
|
||||||
|
- **Caddy**: Reverse proxy, TLS (auto LE), subdomain routing, forward auth to Authelia
|
||||||
|
- **Authelia**: OIDC provider, 2FA, identity store
|
||||||
|
- **Binary**: Go launcher + path-based reverse proxy to upstream apps
|
||||||
|
|
||||||
|
## Quick Start
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo ./install.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
Prompts for domain, TLS email, and admin credentials. Installs dependencies, generates configs, deploys Caddy + Authelia + launcher.
|
||||||
|
|
||||||
|
## Directory Layout
|
||||||
|
|
||||||
|
```
|
||||||
|
/opt/nextworkspace/
|
||||||
|
├── config/
|
||||||
|
│ ├── caddy/Caddyfile
|
||||||
|
│ ├── authelia/configuration.yml
|
||||||
|
│ ├── authelia/users_database.yml
|
||||||
|
│ └── nextworkspace/{config,apps}.yaml
|
||||||
|
├── data/
|
||||||
|
│ ├── caddy/ (certs + runtime data)
|
||||||
|
│ └── authelia/ (database)
|
||||||
|
├── compose/
|
||||||
|
│ ├── caddy.yaml
|
||||||
|
│ └── authelia.yaml
|
||||||
|
├── www/ (landing page)
|
||||||
|
└── nextworkspace (binary)
|
||||||
|
|
||||||
|
/opt/backup/
|
||||||
|
├── .env (secrets vault)
|
||||||
|
└── certficates/ (LE cert backup)
|
||||||
|
```
|
||||||
|
|
||||||
|
## Deployment
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo ./deploy.sh # Smart update (swap binary, restart)
|
||||||
|
sudo ./deploy.sh --destroy # Full rebuild (certs backed up)
|
||||||
|
```
|
||||||
|
|
||||||
|
## Version
|
||||||
|
|
||||||
|
Current: 0.1.0.0007 — see [CHANGELOG.md](CHANGELOG.md)
|
||||||
Loading…
Reference in a new issue