Next Workspace - Self-hosted workspace platform
| compose | ||
| config | ||
| lng | ||
| tools | ||
| .gitignore | ||
| AGENT.md | ||
| CHANGELOG.md | ||
| go.mod | ||
| go.sum | ||
| main.go | ||
| README.md | ||
| VERSION | ||
NextWorkspace
A self-hosted productivity suite for startups. One binary + Caddy + Authelia.
Architecture
Internet :443 ──iptables──> :8443 ──> Caddy container :443
Internet :80 ──iptables──> :8080 ──> Caddy container :80
Caddy (rootless podman, nextwks-net)
├── auth.{DOMAIN} ──> Authelia :9091 (internal)
├── app.{DOMAIN} ──> Launcher :9000 (forward auth via Authelia)
└── www.{DOMAIN} ──> static files
Authelia :9091 ──> api :8080 (internal)
Launcher :9000 ──> /config, /people, /settings, /health
- Caddy: TLS termination (ZeroSSL/LE), subdomain routing, forward auth to Authelia
- Authelia: OIDC provider, 2FA, identity store, user management API
- Launcher: Go binary — app dashboard, people directory, admin panel, settings
- iptables: Redirects 80→8080 and 443→8443 so Caddy can run rootless
Quick Start (Bare VM)
# Download the script to your home folder
curl -o ~/nextwks.sh https://git.lohmar.co.uk/lexton-it/NextWks/raw/branch/main/tools/nextwks.sh
chmod +x ~/nextwks.sh
# Run the installer (no sudo — it'll ask only where needed)
./nextwks.sh --install
Prompts for domain, TLS email, and admin credentials. Installs deps (Go, Podman, git),
clones repo to /tmp/nextwks-build/, builds binary, generates configs, deploys stack.
The script stays in ~/nextwks.sh for future updates.
Directory Layout
/opt/nextworkspace/ # Runtime (freshly populated on every deploy)
├── config/
│ ├── caddy/Caddyfile
│ ├── authelia/configuration.yml
│ ├── authelia/users_database.yml
│ └── nextworkspace/{config,apps}.yaml
├── data/
│ ├── caddy/ (certs + runtime)
│ └── authelia/ (database)
├── compose/stack.yaml
├── www/ (landing page)
├── lng/ (translations)
└── nextworkspace (static Go binary)
/opt/backup/ # Secrets vault (survives --destroy)
├── .env
└── certificates/
/tmp/nextwks-build/ # Ephemeral build dir (git clone --depth 1)
Operations
# Smart update (pull, build, copy, restart)
./nextwks.sh --update
# Full redeploy (tear down, rebuild from scratch with saved secrets)
./nextwks.sh --destroy
Workflow (Development)
- Edit code in your clone.
- Bump
VERSION, updateCHANGELOG.md. git commit -m "message" && git tag v$(cat VERSION) && git push origin main --tags- On the server:
./nextwks.sh --update
The script clones fresh from git every time — no stale repos, no permissions issues.
Version
Current: 0.1.0.0032 — see CHANGELOG.md