2.5 KiB
2.5 KiB
Changelog
0.1.0.0007 — 2026-07-08
Added
- Caddy reverse proxy (auto LE TLS, subdomain routing, forward auth)
- Authelia OIDC provider (2FA, identity store, user management)
compose/caddy.yamlandcompose/authelia.yamlconfig/caddy/Caddyfilewith{DOMAIN}templateconfig/authelia/configuration.ymlwith secret injectiontools/hash-password/for bcrypt password hashing- Certificate backup to
/opt/backup/certificates/across destroys - README.md with architecture overview
Changed
- Replaced Zoraxy entirely with Caddy + Authelia
- Binary trusts
Remote-Userheader from Caddy forward auth - deploy.sh rewritten for Caddy/Authelia deployment
- install.sh creates Caddy/Authelia directories
Removed
- Zoraxy compose, configs, proxy rules
tools/nextwks-tool(no longer needed)tools/register-certs(no longer needed)- BoltDB logic,
chattr +i, CSRF handling - All Zoraxy-specific deployment code
0.1.0.0001 — 2026-07-07
Fixed
- Deploy workflow: start Zoraxy → upload certs via API → stop → write proxy configs → restart
- Lego runs per-domain instead of SAN cert
- Removed CSRF token issues by separating config phases
.envquoting for special chars, email validation in install.sh- Configurable subdomains (hub/noc/www/auth)
Changed
- LE certs backed up to
/opt/backup/certificates/, persistent across--destroy - Helper tool
nextwks-toolfor LE (lego) + BoltDB operations - Binary simplified: no login form, trusts
X-Forwarded-Userfrom Zoraxy
0.1.0 — 2026-07-06
Added
- Interactive
install.shwith prompts for domain, TLS email, admin username .envvault at/opt/nextworkspace/.envfor secrets management- Zoraxy container deployment with automated admin account creation
- Let's Encrypt configuration (email, auto-renew) via Zoraxy API
- Combined binary with path-based routing, HMAC-session auth, login form, logout
app.{domain}subdomain → binary on:9000(launcher + auth)dns.{domain}subdomain → Zoraxy admin on:8000- Health endpoint at
/health deploy.shwith--destroy(greenfield) and smart update modes
Fixed
- Zoraxy config expansion — configs locked with
chattr +ito prevent overwrite - CSRF token handling for Zoraxy admin API calls
Changed
- Replaced Go subdomain router + certmagic with Zoraxy reverse proxy
- Replaced Authelia OIDC with Zoraxy built-in admin interface
- Replaced subdomain-per-app with single
app.{domain}path-based routing - Deployment target consolidated to
/opt/workspace/