NextWks/CHANGELOG.md

2.5 KiB

Changelog

0.1.0.0007 — 2026-07-08

Added

  • Caddy reverse proxy (auto LE TLS, subdomain routing, forward auth)
  • Authelia OIDC provider (2FA, identity store, user management)
  • compose/caddy.yaml and compose/authelia.yaml
  • config/caddy/Caddyfile with {DOMAIN} template
  • config/authelia/configuration.yml with secret injection
  • tools/hash-password/ for bcrypt password hashing
  • Certificate backup to /opt/backup/certificates/ across destroys
  • README.md with architecture overview

Changed

  • Replaced Zoraxy entirely with Caddy + Authelia
  • Binary trusts Remote-User header from Caddy forward auth
  • deploy.sh rewritten for Caddy/Authelia deployment
  • install.sh creates Caddy/Authelia directories

Removed

  • Zoraxy compose, configs, proxy rules
  • tools/nextwks-tool (no longer needed)
  • tools/register-certs (no longer needed)
  • BoltDB logic, chattr +i, CSRF handling
  • All Zoraxy-specific deployment code

0.1.0.0001 — 2026-07-07

Fixed

  • Deploy workflow: start Zoraxy → upload certs via API → stop → write proxy configs → restart
  • Lego runs per-domain instead of SAN cert
  • Removed CSRF token issues by separating config phases
  • .env quoting for special chars, email validation in install.sh
  • Configurable subdomains (hub/noc/www/auth)

Changed

  • LE certs backed up to /opt/backup/certificates/, persistent across --destroy
  • Helper tool nextwks-tool for LE (lego) + BoltDB operations
  • Binary simplified: no login form, trusts X-Forwarded-User from Zoraxy

0.1.0 — 2026-07-06

Added

  • Interactive install.sh with prompts for domain, TLS email, admin username
  • .env vault at /opt/nextworkspace/.env for secrets management
  • Zoraxy container deployment with automated admin account creation
  • Let's Encrypt configuration (email, auto-renew) via Zoraxy API
  • Combined binary with path-based routing, HMAC-session auth, login form, logout
  • app.{domain} subdomain → binary on :9000 (launcher + auth)
  • dns.{domain} subdomain → Zoraxy admin on :8000
  • Health endpoint at /health
  • deploy.sh with --destroy (greenfield) and smart update modes

Fixed

  • Zoraxy config expansion — configs locked with chattr +i to prevent overwrite
  • CSRF token handling for Zoraxy admin API calls

Changed

  • Replaced Go subdomain router + certmagic with Zoraxy reverse proxy
  • Replaced Authelia OIDC with Zoraxy built-in admin interface
  • Replaced subdomain-per-app with single app.{domain} path-based routing
  • Deployment target consolidated to /opt/workspace/