Commit graph

22 commits

Author SHA1 Message Date
eabbcdaa2d fix: request LE certs for all subdomains (app + dns) on greenfield 2026-07-07 10:47:38 +01:00
22471e479b fix: unlock immutable files before destroy, timeout LE cert request 2026-07-07 10:34:36 +01:00
8ee09fb229 chore: version 0.1.0 with changelog 2026-07-07 10:29:59 +01:00
d2fa6c7365 fix: robust Zoraxy admin creation + LE automation with proper CSRF 2026-07-07 10:21:24 +01:00
47efc2e62d fix: lock Zoraxy proxy configs with immutable flag (chattr +i) 2026-07-07 09:56:39 +01:00
4416f15797 fix: Zoraxy config expansion — use full schema with origin IP 2026-07-07 09:53:29 +01:00
f9b1b3aa7b fix: preserve .env across greenfield destroy 2026-07-07 09:16:12 +01:00
8366164155 fix: restore dns config, Zoraxy admin, LE automation 2026-07-07 09:13:07 +01:00
49ac348694 feat: combined launcher + auth-proxy with path-based routing 2026-07-06 20:58:33 +01:00
c54c01d609 fix: write SSO redirect URL directly to BoltDB 2026-07-06 19:55:10 +01:00
9bc8310db1 fix: CSRF token handling with follow redirects and cookie jar 2026-07-06 19:04:39 +01:00
57defd7a63 feat: automated LE + ZorxAuth SSO via deploy API 2026-07-06 18:57:12 +01:00
91232a7beb fix: dns.nextwks.eu use AuthMethod 0 (no SSO) 2026-07-06 18:12:51 +01:00
7a4328040b feat: interactive install, .env secrets, Zoraxy admin API 2026-07-06 18:06:09 +01:00
2798485a2c fix: Zoraxy config path (conf/proxy/), origin IP, filename 2026-07-06 16:57:34 +01:00
7fdf6692df feat: Zoraxy proxy + launcher rewrite 2026-07-06 16:49:57 +01:00
29b9f3c159 feat(deploy): add --destroy flag and smart update modes 2026-07-06 15:36:48 +01:00
cd15d294a1 feat: subdomain router with certmagic integration 2026-07-06 15:25:21 +01:00
2d3832df0b feat: hello world pipeline proof 2026-07-06 10:28:20 +01:00
e575b4eeb0 feat: self-signed TLS fallback on :443 + proxy as central router
- Add CertFile/KeyFile fields to TLSConfig (config.go)
- File-based TLS fallback: when cert_file+key_file set, ListenAndServeTLS on :443
  while keeping HTTP on configured port (certmagic ACME is non-fallback path)
- deploy.sh: enable TLS by default, generate self-signed cert during deploy
- deploy.sh: change default port 8080 → 80 (reverse proxy standard)
- deploy.sh: add cert_file/key_file to config template
- proxy as central router fix (handler.go: ServeHTTP + StaticHandler methods)
2026-07-06 08:59:12 +01:00
b069cab1e3 fix(deploy): default server port to 80 (reverse proxy standard)
- Change config template in deploy.sh from port 8080 to port 80
- A reverse proxy must listen on port 80 for public HTTP traffic
- CAP_NET_BIND_SERVICE allows non-root binding to low ports
2026-07-06 08:54:58 +01:00
1efeb05f4f deploy: production deploy script + path alignment to /opt/nextworkspace/
- Add deploy.sh: idempotent production deploy (scaffold, build, systemd, health check)
- Fix update.sh: align all paths from /opt/nextwks/ to /opt/nextworkspace/ (blueprint-compliant)
- deploy.sh safe for first-time setup and subsequent updates
- Creates full blueprint directory tree: config/, data/, logs/, src/core/
2026-07-05 18:19:33 +01:00