NextWks/CHANGELOG.md

6.4 KiB

Changelog

0.1.0.0039 — 2026-07-11

Changed

  • Modernized Authelia config format (fixes all deprecation warnings):
    • server.address: tcp://0.0.0.0:9091 (replaces host + port)
    • identity_validation.reset_password.jwt_secret (replaces jwt_secret)
    • notifier.smtp.address: submission://... (replaces host + port)
    • authentication_backend.file.watch: true (auto-reload on user changes)
    • session.remember_me (replaces remember_me_duration)

0.1.0.0038 — 2026-07-11

Fixed

  • Authelia authentication_backend.file.watch: true — YAML changes now auto-reload, so new users can log in immediately after creation

Investigation: User Onboarding Emails

  • SMTP config is correct (notifier.smtpsmtp.openxchange.eu:587)
  • SMTP connection test passed (TLS handshake successful)
  • authelia-api does NOT send onboarding emails — returns placeholder_password in API response instead
  • This is an API feature gap, not a configuration issue

0.1.0.0037 — 2026-07-11

Changed

  • Simplified groups model: per-app groups (drive, office, chat, etc.) replaced with users + admins only
  • config/authelia/configuration.yml — access_control rules reduced from 12 rules to 4
  • config/authelia/users_database.yml — master user groups simplified to admins, users
  • config/nextworkspace/apps.yaml — all user-facing apps use groups: ["users"]
  • Admin panel user creation form — 9 checkboxes replaced with 2 (User + Admin)

0.1.0.0036 — 2026-07-11

Fixed

  • Admin panel user management: apiProxyHandler was stripping /api prefix before forwarding to authelia-api, causing 404 on all /api/users calls. Removed the TrimPrefix — authelia-api expects the full /api/... path.

0.1.0.0035 — 2026-07-11

Added

  • AUTHELIA_API_LISTEN=0.0.0.0:8080 explicitly set in compose (default already correct)

0.1.0.0034 — 2026-07-11

Added

  • Fixed subnet 172.18.0.0/24 for nextwks-net
  • Static IPv4 addresses for all containers (Caddy .10, Authelia .11, Launcher .12)

Changed

  • compose/stack.yaml: network config uses ipv4_address instead of flat list
  • tools/nextwks.sh: network creation now uses --subnet 172.18.0.0/24

0.1.0.0033 — 2026-07-11

Added

  • tools/firewall-routing.sh — iptables redirects + VM firewall
  • storage.encryption_key to Authelia config (required by v4.38+)
  • Auto-detection of existing install in --install mode

Changed

  • Rootless Podman: all container commands run without sudo
  • Ports: Caddy binds to 8080/8443, iptables redirects 80/443
  • .gitignore: /nextworkspace (root-scoped) to track config/nextworkspace/
  • Configs regenerated on every mode (install/update/destroy)
  • .env values single-quoted, written via tee -a to preserve $ in bcrypt hashes
  • Admin password: now 24 mixed-case alphanumeric chars (base64)
  • Containers stopped before binary copy to avoid "Text file busy"
  • Firewall rules persisted via netfilter-persistent save
  • Docs: AGENT.md, README.md fully updated

Fixed

  • SSL_ERROR_INTERNAL_ERROR_ALERT — Authelia now starts with proper config
  • Password hash corruption — $2a$... no longer mangled by bash -c
  • "Text file busy" during --update — containers stopped before copy
  • --update skipped config regeneration (now always regenerates)

0.1.0.0032 — 2026-07-11

Added

  • tools/nextwks.sh — unified install/update/destroy script
  • AGENT.md — workflow instructions for agents

Changed

  • Replaced deploy.sh and install.sh with single tools/nextwks.sh
  • Build moved from /opt/NextWks (persistent git repo) to /tmp/nextwks-build (ephemeral clone)
  • README.md updated for unified script workflow
  • SESSION_SECRET persisted in /opt/backup/.env for idempotent --destroy

Removed

  • deploy.sh (replaced by tools/nextwks.sh --update / --destroy)
  • install.sh (replaced by tools/nextwks.sh --install)

0.1.0.0007 — 2026-07-08

Added

  • Caddy reverse proxy (auto LE TLS, subdomain routing, forward auth)
  • Authelia OIDC provider (2FA, identity store, user management)
  • compose/caddy.yaml and compose/authelia.yaml
  • config/caddy/Caddyfile with {DOMAIN} template
  • config/authelia/configuration.yml with secret injection
  • tools/hash-password/ for bcrypt password hashing
  • Certificate backup to /opt/backup/certificates/ across destroys
  • README.md with architecture overview

Changed

  • Replaced Zoraxy entirely with Caddy + Authelia
  • Binary trusts Remote-User header from Caddy forward auth
  • deploy.sh rewritten for Caddy/Authelia deployment
  • install.sh creates Caddy/Authelia directories

Removed

  • Zoraxy compose, configs, proxy rules
  • tools/nextwks-tool (no longer needed)
  • tools/register-certs (no longer needed)
  • BoltDB logic, chattr +i, CSRF handling
  • All Zoraxy-specific deployment code

0.1.0.0001 — 2026-07-07

Fixed

  • Deploy workflow: start Zoraxy → upload certs via API → stop → write proxy configs → restart
  • Lego runs per-domain instead of SAN cert
  • Removed CSRF token issues by separating config phases
  • .env quoting for special chars, email validation in install.sh
  • Configurable subdomains (hub/noc/www/auth)

Changed

  • LE certs backed up to /opt/backup/certificates/, persistent across --destroy
  • Helper tool nextwks-tool for LE (lego) + BoltDB operations
  • Binary simplified: no login form, trusts X-Forwarded-User from Zoraxy

0.1.0 — 2026-07-06

Added

  • Interactive install.sh with prompts for domain, TLS email, admin username
  • .env vault at /opt/nextworkspace/.env for secrets management
  • Zoraxy container deployment with automated admin account creation
  • Let's Encrypt configuration (email, auto-renew) via Zoraxy API
  • Combined binary with path-based routing, HMAC-session auth, login form, logout
  • app.{domain} subdomain → binary on :9000 (launcher + auth)
  • dns.{domain} subdomain → Zoraxy admin on :8000
  • Health endpoint at /health
  • deploy.sh with --destroy (greenfield) and smart update modes

Fixed

  • Zoraxy config expansion — configs locked with chattr +i to prevent overwrite
  • CSRF token handling for Zoraxy admin API calls

Changed

  • Replaced Go subdomain router + certmagic with Zoraxy reverse proxy
  • Replaced Authelia OIDC with Zoraxy built-in admin interface
  • Replaced subdomain-per-app with single app.{domain} path-based routing
  • Deployment target consolidated to /opt/workspace/