NextWks/README.md
cclohmar 81e5505f2a Unified install/update/destroy script with ephemeral build dir
- Replace deploy.sh and install.sh with tools/nextwks.sh
- Build in /tmp/nextwks-build (fresh clone every time), no more /opt/NextWks
- Script saves itself to ~/nextwks.sh on --install for easy future access
- Add AGENT.md with workflow rules for the new approach
- Secrets persisted in /opt/backup/.env (JWT, SESSION, password hash)
- Update README and CHANGELOG
2026-07-11 00:02:55 +01:00

86 lines
2.8 KiB
Markdown

# NextWorkspace
A self-hosted productivity suite for startups. One binary + Caddy + Authelia.
## Architecture
```
app.nextwks.eu :443 auth.nextwks.eu :443
│ │
Caddy (TLS + forward auth) Caddy → Authelia :9091
│ │
├── /home/ → launcher page └── authelia-api :8080
├── /drive/* → OpenCloud :9100
├── /office/* → Euro Office :9200
├── /erp/* → ERPNext :9300
├── /chat/* → Matrix :9400
├── /meet/* → Jitsi :9500
├── /mail/* → Alps :9600
├── /ai/* → Open WebUI :9700
└── /admin/* → Portainer :9800
```
- **Caddy**: Reverse proxy, TLS (auto LE), subdomain routing, forward auth to Authelia
- **Authelia**: OIDC provider, 2FA, identity store
- **Binary**: Go launcher + path-based reverse proxy to upstream apps
## Quick Start (Bare VM)
```bash
curl -sL https://git.lohmar.co.uk/lexton-it/NextWks/raw/branch/main/tools/nextwks.sh \
| sudo bash -s -- --install
```
Prompts for domain, TLS email, and admin credentials. Installs deps (Go, Podman, git),
clones repo to `/tmp/nextwks-build/`, builds binary, generates configs, deploys stack.
## Directory Layout
```
/opt/nextworkspace/ # Runtime (freshly populated on every deploy)
├── config/
│ ├── caddy/Caddyfile
│ ├── authelia/configuration.yml
│ ├── authelia/users_database.yml
│ └── nextworkspace/{config,apps}.yaml
├── data/
│ ├── caddy/ (certs + runtime)
│ └── authelia/ (database)
├── compose/stack.yaml
├── www/ (landing page)
├── lng/ (translations)
└── nextworkspace (static Go binary)
/opt/backup/ # Secrets vault (survives --destroy)
├── .env
└── certificates/
/tmp/nextwks-build/ # Ephemeral build dir (git clone --depth 1)
```
## Operations
```bash
# First-time install (download + run — saves itself to ~/nextwks.sh)
curl -sL https://git.lohmar.co.uk/lexton-it/NextWks/raw/branch/main/tools/nextwks.sh \
| sudo bash -s -- --install
# Smart update (pull, build, copy, restart)
sudo bash ~/nextwks.sh --update
# Full redeploy (tear down, rebuild from scratch with saved secrets)
sudo bash ~/nextwks.sh --destroy
```
## Workflow (Development)
1. Edit code in your clone.
2. Bump `VERSION`, update `CHANGELOG.md`.
3. `git commit -m "message" && git tag v$(cat VERSION) && git push origin main --tags`
4. On the server: `sudo bash ~/nextwks.sh --update`
The script clones fresh from git every time — no stale repos, no permissions issues.
## Version
Current: 0.1.0.0032 — see [CHANGELOG.md](CHANGELOG.md)