85 lines
2.6 KiB
Markdown
85 lines
2.6 KiB
Markdown
# NextWorkspace
|
|
|
|
A self-hosted productivity suite for startups. One binary + Caddy + Authelia.
|
|
|
|
## Architecture
|
|
|
|
```
|
|
Internet :443 ──iptables──> :8443 ──> Caddy container :443
|
|
Internet :80 ──iptables──> :8080 ──> Caddy container :80
|
|
|
|
Caddy (rootless podman, nextwks-net)
|
|
├── auth.{DOMAIN} ──> Authelia :9091 (internal)
|
|
├── app.{DOMAIN} ──> Launcher :9000 (forward auth via Authelia)
|
|
└── www.{DOMAIN} ──> static files
|
|
|
|
Authelia :9091 ──> api :8080 (internal)
|
|
Launcher :9000 ──> /config, /people, /settings, /health
|
|
```
|
|
|
|
- **Caddy**: TLS termination (ZeroSSL/LE), subdomain routing, forward auth to Authelia
|
|
- **Authelia**: OIDC provider, 2FA, identity store, user management API
|
|
- **Launcher**: Go binary — app dashboard, people directory, admin panel, settings
|
|
- **iptables**: Redirects 80→8080 and 443→8443 so Caddy can run rootless
|
|
|
|
## Quick Start (Bare VM)
|
|
|
|
```bash
|
|
# Download the script to your home folder
|
|
curl -o ~/nextwks.sh https://git.lohmar.co.uk/lexton-it/NextWks/raw/branch/main/tools/nextwks.sh
|
|
chmod +x ~/nextwks.sh
|
|
|
|
# Run the installer (no sudo — it'll ask only where needed)
|
|
./nextwks.sh --install
|
|
```
|
|
|
|
Prompts for domain, TLS email, and admin credentials. Installs deps (Go, Podman, git),
|
|
clones repo to `/tmp/nextwks-build/`, builds binary, generates configs, deploys stack.
|
|
The script stays in `~/nextwks.sh` for future updates.
|
|
|
|
## Directory Layout
|
|
|
|
```
|
|
/opt/nextworkspace/ # Runtime (freshly populated on every deploy)
|
|
├── config/
|
|
│ ├── caddy/Caddyfile
|
|
│ ├── authelia/configuration.yml
|
|
│ ├── authelia/users_database.yml
|
|
│ └── nextworkspace/{config,apps}.yaml
|
|
├── data/
|
|
│ ├── caddy/ (certs + runtime)
|
|
│ └── authelia/ (database)
|
|
├── compose/stack.yaml
|
|
├── www/ (landing page)
|
|
├── lng/ (translations)
|
|
└── nextworkspace (static Go binary)
|
|
|
|
/opt/backup/ # Secrets vault (survives --destroy)
|
|
├── .env
|
|
└── certificates/
|
|
|
|
/tmp/nextwks-build/ # Ephemeral build dir (git clone --depth 1)
|
|
```
|
|
|
|
## Operations
|
|
|
|
```bash
|
|
# Smart update (pull, build, copy, restart)
|
|
./nextwks.sh --update
|
|
|
|
# Full redeploy (tear down, rebuild from scratch with saved secrets)
|
|
./nextwks.sh --destroy
|
|
```
|
|
|
|
## Workflow (Development)
|
|
|
|
1. Edit code in your clone.
|
|
2. Bump `VERSION`, update `CHANGELOG.md`.
|
|
3. `git commit -m "message" && git tag v$(cat VERSION) && git push origin main --tags`
|
|
4. On the server: `./nextwks.sh --update`
|
|
|
|
The script clones fresh from git every time — no stale repos, no permissions issues.
|
|
|
|
## Version
|
|
|
|
Current: 0.1.0.0032 — see [CHANGELOG.md](CHANGELOG.md)
|