Scaffold Homelab Manager foundation

Monorepo (Express+TS+Drizzle/libSQL server, React+Vite+Tabler web) matching
the stack used by ScheduleTaskManager and Sloth Manager. Includes Authentik
OIDC login with local admin/operator/viewer roles (first user becomes admin),
a generalized audit log, encrypted-at-rest storage for future integration API
tokens, the DB schema for all planned modules, and the Tabler-styled app
shell/nav. Also ports the Secrets (expiry tracker) and IP Addresses (IPAM)
modules from Sloth Manager onto the new stack.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
bobbanandClaude Sonnet 5 committed 2026-09-14 21:57:13 +02:00
commit 6bd2ed52c1
52 files changed
+8103

No files matched your search

+28
View File
@@ -0,0 +1,28 @@
# Public URL the app is reachable at (used for OIDC redirect_uri and cookie behavior).
APP_BASE_URL=https://homelab.example.lan
# Random long string used to sign session cookies. Generate with:
# node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
SESSION_SECRET=change-me-to-a-random-64-char-hex-string
# 32-byte (64 hex char) key used to encrypt stored integration API tokens at
# rest (AES-256-GCM). Generate the same way as SESSION_SECRET. Losing/changing
# this key makes previously-stored integration credentials unreadable.
CREDENTIALS_ENCRYPTION_KEY=change-me-to-a-random-64-char-hex-string
# Port docker-compose publishes on the host (container always listens on 3000).
HOST_PORT=3000
# --- Authentik OIDC application/provider ---
# Create an OAuth2/OIDC "Provider" in Authentik with:
# Redirect URI: <APP_BASE_URL>/auth/callback
# Scopes: openid, email, profile
# then create an "Application" using that provider, and assign the users/groups
# who should be able to sign in. Copy the provider's values below.
AUTHENTIK_ISSUER_URL=https://authentik.example.lan/application/o/homelab-manager/
AUTHENTIK_CLIENT_ID=
AUTHENTIK_CLIENT_SECRET=
# --- Optional: Gotify notifications (secret expiry, integration offline, etc.) ---
GOTIFY_URL=
GOTIFY_TOKEN=