6.6 KiB
6.6 KiB
Changelog
0.1.0.0043 — 2026-07-11
Added
- Edit user button in Access tab — admin can change email and groups (delete + recreate approach)
- Edit user modal with email, groups fields, and new password display
0.1.0.0039 — 2026-07-11
Changed
- Modernized Authelia config format (fixes all deprecation warnings):
server.address: tcp://0.0.0.0:9091(replaceshost+port)identity_validation.reset_password.jwt_secret(replacesjwt_secret)notifier.smtp.address: submission://...(replaceshost+port)authentication_backend.file.watch: true(auto-reload on user changes)session.remember_me(replacesremember_me_duration)
0.1.0.0038 — 2026-07-11
Fixed
- Authelia
authentication_backend.file.watch: true— YAML changes now auto-reload, so new users can log in immediately after creation
Investigation: User Onboarding Emails
- SMTP config is correct (
notifier.smtp→smtp.openxchange.eu:587) - SMTP connection test passed (TLS handshake successful)
- authelia-api does NOT send onboarding emails — returns
placeholder_passwordin API response instead - This is an API feature gap, not a configuration issue
0.1.0.0037 — 2026-07-11
Changed
- Simplified groups model: per-app groups (
drive,office,chat, etc.) replaced withusers+adminsonly config/authelia/configuration.yml— access_control rules reduced from 12 rules to 4config/authelia/users_database.yml— master user groups simplified toadmins,usersconfig/nextworkspace/apps.yaml— all user-facing apps usegroups: ["users"]- Admin panel user creation form — 9 checkboxes replaced with 2 (User + Admin)
0.1.0.0036 — 2026-07-11
Fixed
- Admin panel user management:
apiProxyHandlerwas stripping/apiprefix before forwarding to authelia-api, causing 404 on all/api/userscalls. Removed theTrimPrefix— authelia-api expects the full/api/...path.
0.1.0.0035 — 2026-07-11
Added
AUTHELIA_API_LISTEN=0.0.0.0:8080explicitly set in compose (default already correct)
0.1.0.0034 — 2026-07-11
Added
- Fixed subnet
172.18.0.0/24fornextwks-net - Static IPv4 addresses for all containers (Caddy
.10, Authelia.11, Launcher.12)
Changed
compose/stack.yaml: network config usesipv4_addressinstead of flat listtools/nextwks.sh: network creation now uses--subnet 172.18.0.0/24
0.1.0.0033 — 2026-07-11
Added
tools/firewall-routing.sh— iptables redirects + VM firewallstorage.encryption_keyto Authelia config (required by v4.38+)- Auto-detection of existing install in
--installmode
Changed
- Rootless Podman: all container commands run without sudo
- Ports: Caddy binds to 8080/8443, iptables redirects 80/443
.gitignore:/nextworkspace(root-scoped) to trackconfig/nextworkspace/- Configs regenerated on every mode (install/update/destroy)
.envvalues single-quoted, written viatee -ato preserve$in bcrypt hashes- Admin password: now 24 mixed-case alphanumeric chars (base64)
- Containers stopped before binary copy to avoid "Text file busy"
- Firewall rules persisted via
netfilter-persistent save - Docs: AGENT.md, README.md fully updated
Fixed
SSL_ERROR_INTERNAL_ERROR_ALERT— Authelia now starts with proper config- Password hash corruption —
$2a$...no longer mangled bybash -c - "Text file busy" during
--update— containers stopped before copy --updateskipped config regeneration (now always regenerates)
0.1.0.0032 — 2026-07-11
Added
tools/nextwks.sh— unified install/update/destroy scriptAGENT.md— workflow instructions for agents
Changed
- Replaced
deploy.shandinstall.shwith singletools/nextwks.sh - Build moved from
/opt/NextWks(persistent git repo) to/tmp/nextwks-build(ephemeral clone) - README.md updated for unified script workflow
SESSION_SECRETpersisted in/opt/backup/.envfor idempotent--destroy
Removed
deploy.sh(replaced bytools/nextwks.sh --update / --destroy)install.sh(replaced bytools/nextwks.sh --install)
0.1.0.0007 — 2026-07-08
Added
- Caddy reverse proxy (auto LE TLS, subdomain routing, forward auth)
- Authelia OIDC provider (2FA, identity store, user management)
compose/caddy.yamlandcompose/authelia.yamlconfig/caddy/Caddyfilewith{DOMAIN}templateconfig/authelia/configuration.ymlwith secret injectiontools/hash-password/for bcrypt password hashing- Certificate backup to
/opt/backup/certificates/across destroys - README.md with architecture overview
Changed
- Replaced Zoraxy entirely with Caddy + Authelia
- Binary trusts
Remote-Userheader from Caddy forward auth - deploy.sh rewritten for Caddy/Authelia deployment
- install.sh creates Caddy/Authelia directories
Removed
- Zoraxy compose, configs, proxy rules
tools/nextwks-tool(no longer needed)tools/register-certs(no longer needed)- BoltDB logic,
chattr +i, CSRF handling - All Zoraxy-specific deployment code
0.1.0.0001 — 2026-07-07
Fixed
- Deploy workflow: start Zoraxy → upload certs via API → stop → write proxy configs → restart
- Lego runs per-domain instead of SAN cert
- Removed CSRF token issues by separating config phases
.envquoting for special chars, email validation in install.sh- Configurable subdomains (hub/noc/www/auth)
Changed
- LE certs backed up to
/opt/backup/certificates/, persistent across--destroy - Helper tool
nextwks-toolfor LE (lego) + BoltDB operations - Binary simplified: no login form, trusts
X-Forwarded-Userfrom Zoraxy
0.1.0 — 2026-07-06
Added
- Interactive
install.shwith prompts for domain, TLS email, admin username .envvault at/opt/nextworkspace/.envfor secrets management- Zoraxy container deployment with automated admin account creation
- Let's Encrypt configuration (email, auto-renew) via Zoraxy API
- Combined binary with path-based routing, HMAC-session auth, login form, logout
app.{domain}subdomain → binary on:9000(launcher + auth)dns.{domain}subdomain → Zoraxy admin on:8000- Health endpoint at
/health deploy.shwith--destroy(greenfield) and smart update modes
Fixed
- Zoraxy config expansion — configs locked with
chattr +ito prevent overwrite - CSRF token handling for Zoraxy admin API calls
Changed
- Replaced Go subdomain router + certmagic with Zoraxy reverse proxy
- Replaced Authelia OIDC with Zoraxy built-in admin interface
- Replaced subdomain-per-app with single
app.{domain}path-based routing - Deployment target consolidated to
/opt/workspace/