# Changelog ## 0.1.0.0001 — 2026-07-07 ### Fixed - Deploy workflow: start Zoraxy → upload certs via API → stop → write proxy configs → restart - Lego runs per-domain instead of SAN cert - Removed CSRF token issues by separating config phases - `.env` quoting for special chars, email validation in install.sh - Configurable subdomains (hub/noc/www/auth) ### Changed - LE certs backed up to `/opt/backup/certificates/`, persistent across `--destroy` - Helper tool `nextwks-tool` for LE (lego) + BoltDB operations - Binary simplified: no login form, trusts `X-Forwarded-User` from Zoraxy ## 0.1.0 — 2026-07-06 ### Added - Interactive `install.sh` with prompts for domain, TLS email, admin username - `.env` vault at `/opt/nextworkspace/.env` for secrets management - Zoraxy container deployment with automated admin account creation - Let's Encrypt configuration (email, auto-renew) via Zoraxy API - Combined binary with path-based routing, HMAC-session auth, login form, logout - `app.{domain}` subdomain → binary on `:9000` (launcher + auth) - `dns.{domain}` subdomain → Zoraxy admin on `:8000` - Health endpoint at `/health` - `deploy.sh` with `--destroy` (greenfield) and smart update modes ### Fixed - Zoraxy config expansion — configs locked with `chattr +i` to prevent overwrite - CSRF token handling for Zoraxy admin API calls ### Changed - Replaced Go subdomain router + certmagic with Zoraxy reverse proxy - Replaced Authelia OIDC with Zoraxy built-in admin interface - Replaced subdomain-per-app with single `app.{domain}` path-based routing - Deployment target consolidated to `/opt/workspace/`