NextWks/README.md
cclohmar 81e5505f2a Unified install/update/destroy script with ephemeral build dir
- Replace deploy.sh and install.sh with tools/nextwks.sh
- Build in /tmp/nextwks-build (fresh clone every time), no more /opt/NextWks
- Script saves itself to ~/nextwks.sh on --install for easy future access
- Add AGENT.md with workflow rules for the new approach
- Secrets persisted in /opt/backup/.env (JWT, SESSION, password hash)
- Update README and CHANGELOG
2026-07-11 00:02:55 +01:00

2.8 KiB

NextWorkspace

A self-hosted productivity suite for startups. One binary + Caddy + Authelia.

Architecture

app.nextwks.eu :443                    auth.nextwks.eu :443
       │                                         │
   Caddy (TLS + forward auth)          Caddy → Authelia :9091
       │                                         │
       ├── /home/       → launcher page          └── authelia-api :8080
       ├── /drive/*     → OpenCloud :9100
       ├── /office/*    → Euro Office :9200
       ├── /erp/*       → ERPNext :9300
       ├── /chat/*      → Matrix :9400
       ├── /meet/*      → Jitsi :9500
       ├── /mail/*      → Alps :9600
       ├── /ai/*        → Open WebUI :9700
       └── /admin/*     → Portainer :9800
  • Caddy: Reverse proxy, TLS (auto LE), subdomain routing, forward auth to Authelia
  • Authelia: OIDC provider, 2FA, identity store
  • Binary: Go launcher + path-based reverse proxy to upstream apps

Quick Start (Bare VM)

curl -sL https://git.lohmar.co.uk/lexton-it/NextWks/raw/branch/main/tools/nextwks.sh \
  | sudo bash -s -- --install

Prompts for domain, TLS email, and admin credentials. Installs deps (Go, Podman, git), clones repo to /tmp/nextwks-build/, builds binary, generates configs, deploys stack.

Directory Layout

/opt/nextworkspace/            # Runtime (freshly populated on every deploy)
├── config/
│   ├── caddy/Caddyfile
│   ├── authelia/configuration.yml
│   ├── authelia/users_database.yml
│   └── nextworkspace/{config,apps}.yaml
├── data/
│   ├── caddy/ (certs + runtime)
│   └── authelia/ (database)
├── compose/stack.yaml
├── www/ (landing page)
├── lng/ (translations)
└── nextworkspace (static Go binary)

/opt/backup/                   # Secrets vault (survives --destroy)
├── .env
└── certificates/

/tmp/nextwks-build/            # Ephemeral build dir (git clone --depth 1)

Operations

# First-time install (download + run — saves itself to ~/nextwks.sh)
curl -sL https://git.lohmar.co.uk/lexton-it/NextWks/raw/branch/main/tools/nextwks.sh \
  | sudo bash -s -- --install

# Smart update (pull, build, copy, restart)
sudo bash ~/nextwks.sh --update

# Full redeploy (tear down, rebuild from scratch with saved secrets)
sudo bash ~/nextwks.sh --destroy

Workflow (Development)

  1. Edit code in your clone.
  2. Bump VERSION, update CHANGELOG.md.
  3. git commit -m "message" && git tag v$(cat VERSION) && git push origin main --tags
  4. On the server: sudo bash ~/nextwks.sh --update

The script clones fresh from git every time — no stale repos, no permissions issues.

Version

Current: 0.1.0.0032 — see CHANGELOG.md