Commit graph

49 commits

Author SHA1 Message Date
c42807d076 refactor: configure Zoraxy via BoltDB + config files, no API/CSRF 2026-07-07 16:19:34 +01:00
90c8c57fbe debug: show login.html response when CSRF fetch fails 2026-07-07 16:12:30 +01:00
b1004e4514 fix: BoltDB fallback for admin creation if CSRF API fails 2026-07-07 16:12:05 +01:00
fd1fa7dbeb fix: CSRF token — clear jar before first fetch, preserve session across calls 2026-07-07 16:08:20 +01:00
710781bc47 fix: surface admin registration result instead of swallowing it 2026-07-07 16:05:31 +01:00
b2e3086e10 fix: upload existing LE certs to Zoraxy via API after deploy 2026-07-07 15:51:25 +01:00
5f46d3c2b8 refactor: rename backup dir to /opt/backup/certificates/ 2026-07-07 15:33:22 +01:00
6d87718b43 refactor: lego outputs to /opt/backup/certs/, one backup directory 2026-07-07 15:27:30 +01:00
c7d25c0107 fix: fallback to lego SAN cert directory if backup missing 2026-07-07 15:24:03 +01:00
5f168d21f1 feat: replace autocert with lego CLI for reliable LE cert issuance 2026-07-07 15:05:41 +01:00
02bab22a5d fix: build tool from script directory (correct go.mod context) 2026-07-07 14:57:30 +01:00
533b6f4137 fix: full service teardown (stop+disable+remove) + port 80 wait 2026-07-07 14:53:00 +01:00
63099703a1 fix: stop Zoraxy before running tool to free port 80 for ACME 2026-07-07 14:44:13 +01:00
360112c7b7 fix: remove old zoraxy container before deploying 2026-07-07 14:33:28 +01:00
2e7a0e3645 refactor: /opt/backup/ vault for .env + certs, clean destroy flow 2026-07-07 14:30:48 +01:00
b0a3cd3206 fix: tool only manages backup, preservation handles cert deployment 2026-07-07 14:14:36 +01:00
25c0e7b9b7 docs: remove --destroy blocker — tool handles cert backup/restore 2026-07-07 12:57:58 +01:00
2398bdce83 feat: nextwks-tool for LE + DB + Zoraxy Auth 2026-07-07 12:53:57 +01:00
d73b67614e fix: proxy www through binary for ACME challenge support 2026-07-07 12:22:11 +01:00
038d923a11 fix: include www in LE cert auto-generation loop 2026-07-07 12:19:17 +01:00
4e50bf15dd fix: www files go to html/ subdirectory (Zoraxy static root) 2026-07-07 12:13:06 +01:00
ddef538795 feat: www landing page with component listing 2026-07-07 12:09:25 +01:00
7b3942658d docs: add 5s safety warning before --destroy 2026-07-07 12:06:12 +01:00
79bf23618d fix: proper Zoraxy CSRF/session handling (login.html + cookie jar) 2026-07-07 12:02:59 +01:00
d0f9854084 fix: bypass global TLS for dns subdomain (HTTP without redirect) 2026-07-07 11:04:12 +01:00
ccd362a964 fix: hoist COOKIE_JAR outside function to avoid unbound variable 2026-07-07 10:56:17 +01:00
acd9671359 fix: preserve Zoraxy certs across greenfield destroy 2026-07-07 10:52:16 +01:00
eabbcdaa2d fix: request LE certs for all subdomains (app + dns) on greenfield 2026-07-07 10:47:38 +01:00
22471e479b fix: unlock immutable files before destroy, timeout LE cert request 2026-07-07 10:34:36 +01:00
8ee09fb229 chore: version 0.1.0 with changelog 2026-07-07 10:29:59 +01:00
d2fa6c7365 fix: robust Zoraxy admin creation + LE automation with proper CSRF 2026-07-07 10:21:24 +01:00
47efc2e62d fix: lock Zoraxy proxy configs with immutable flag (chattr +i) 2026-07-07 09:56:39 +01:00
4416f15797 fix: Zoraxy config expansion — use full schema with origin IP 2026-07-07 09:53:29 +01:00
f9b1b3aa7b fix: preserve .env across greenfield destroy 2026-07-07 09:16:12 +01:00
8366164155 fix: restore dns config, Zoraxy admin, LE automation 2026-07-07 09:13:07 +01:00
49ac348694 feat: combined launcher + auth-proxy with path-based routing 2026-07-06 20:58:33 +01:00
c54c01d609 fix: write SSO redirect URL directly to BoltDB 2026-07-06 19:55:10 +01:00
9bc8310db1 fix: CSRF token handling with follow redirects and cookie jar 2026-07-06 19:04:39 +01:00
57defd7a63 feat: automated LE + ZorxAuth SSO via deploy API 2026-07-06 18:57:12 +01:00
91232a7beb fix: dns.nextwks.eu use AuthMethod 0 (no SSO) 2026-07-06 18:12:51 +01:00
7a4328040b feat: interactive install, .env secrets, Zoraxy admin API 2026-07-06 18:06:09 +01:00
2798485a2c fix: Zoraxy config path (conf/proxy/), origin IP, filename 2026-07-06 16:57:34 +01:00
7fdf6692df feat: Zoraxy proxy + launcher rewrite 2026-07-06 16:49:57 +01:00
29b9f3c159 feat(deploy): add --destroy flag and smart update modes 2026-07-06 15:36:48 +01:00
cd15d294a1 feat: subdomain router with certmagic integration 2026-07-06 15:25:21 +01:00
2d3832df0b feat: hello world pipeline proof 2026-07-06 10:28:20 +01:00
e575b4eeb0 feat: self-signed TLS fallback on :443 + proxy as central router
- Add CertFile/KeyFile fields to TLSConfig (config.go)
- File-based TLS fallback: when cert_file+key_file set, ListenAndServeTLS on :443
  while keeping HTTP on configured port (certmagic ACME is non-fallback path)
- deploy.sh: enable TLS by default, generate self-signed cert during deploy
- deploy.sh: change default port 8080 → 80 (reverse proxy standard)
- deploy.sh: add cert_file/key_file to config template
- proxy as central router fix (handler.go: ServeHTTP + StaticHandler methods)
2026-07-06 08:59:12 +01:00
b069cab1e3 fix(deploy): default server port to 80 (reverse proxy standard)
- Change config template in deploy.sh from port 8080 to port 80
- A reverse proxy must listen on port 80 for public HTTP traffic
- CAP_NET_BIND_SERVICE allows non-root binding to low ports
2026-07-06 08:54:58 +01:00
1efeb05f4f deploy: production deploy script + path alignment to /opt/nextworkspace/
- Add deploy.sh: idempotent production deploy (scaffold, build, systemd, health check)
- Fix update.sh: align all paths from /opt/nextwks/ to /opt/nextworkspace/ (blueprint-compliant)
- deploy.sh safe for first-time setup and subsequent updates
- Creates full blueprint directory tree: config/, data/, logs/, src/core/
2026-07-05 18:19:33 +01:00