# NextWorkspace A self-hosted productivity suite for startups. One binary + Caddy + Authelia. ## Architecture ``` Internet :443 ──iptables──> :8443 ──> Caddy container :443 Internet :80 ──iptables──> :8080 ──> Caddy container :80 Caddy (rootless podman, nextwks-net) ├── auth.{DOMAIN} ──> Authelia :9091 (internal) ├── app.{DOMAIN} ──> Launcher :9000 (forward auth via Authelia) └── www.{DOMAIN} ──> static files Authelia :9091 ──> api :8080 (internal) Launcher :9000 ──> /config, /people, /settings, /health ``` - **Caddy**: TLS termination (ZeroSSL/LE), subdomain routing, forward auth to Authelia - **Authelia**: OIDC provider, 2FA, identity store, user management API - **Launcher**: Go binary — app dashboard, people directory, admin panel, settings - **iptables**: Redirects 80→8080 and 443→8443 so Caddy can run rootless ## Quick Start (Bare VM) ```bash # Download the script to your home folder curl -o ~/nextwks.sh https://git.lohmar.co.uk/lexton-it/NextWks/raw/branch/main/tools/nextwks.sh chmod +x ~/nextwks.sh # Run the installer (no sudo — it'll ask only where needed) ./nextwks.sh --install ``` Prompts for domain, TLS email, and admin credentials. Installs deps (Go, Podman, git), clones repo to `/tmp/nextwks-build/`, builds binary, generates configs, deploys stack. The script stays in `~/nextwks.sh` for future updates. ## Directory Layout ``` /opt/nextworkspace/ # Runtime (freshly populated on every deploy) ├── config/ │ ├── caddy/Caddyfile │ ├── authelia/configuration.yml │ ├── authelia/users_database.yml │ └── nextworkspace/{config,apps}.yaml ├── data/ │ ├── caddy/ (certs + runtime) │ └── authelia/ (database) ├── compose/stack.yaml ├── www/ (landing page) ├── lng/ (translations) └── nextworkspace (static Go binary) /opt/backup/ # Secrets vault (survives --destroy) ├── .env └── certificates/ /tmp/nextwks-build/ # Ephemeral build dir (git clone --depth 1) ``` ## Operations ```bash # Smart update (pull, build, copy, restart) ./nextwks.sh --update # Full redeploy (tear down, rebuild from scratch with saved secrets) ./nextwks.sh --destroy ``` ## Workflow (Development) 1. Edit code in your clone. 2. Bump `VERSION`, update `CHANGELOG.md`. 3. `git commit -m "message" && git tag v$(cat VERSION) && git push origin main --tags` 4. On the server: `./nextwks.sh --update` The script clones fresh from git every time — no stale repos, no permissions issues. ## Version Current: 0.1.0.0032 — see [CHANGELOG.md](CHANGELOG.md)