Scaffold Homelab Manager foundation

Monorepo (Express+TS+Drizzle/libSQL server, React+Vite+Tabler web) matching
the stack used by ScheduleTaskManager and Sloth Manager. Includes Authentik
OIDC login with local admin/operator/viewer roles (first user becomes admin),
a generalized audit log, encrypted-at-rest storage for future integration API
tokens, the DB schema for all planned modules, and the Tabler-styled app
shell/nav. Also ports the Secrets (expiry tracker) and IP Addresses (IPAM)
modules from Sloth Manager onto the new stack.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
bobbanandClaude Sonnet 5 committed 2026-09-14 21:57:13 +02:00
commit 6bd2ed52c1
52 files changed
+8103

No files matched your search

+39
View File
@@ -0,0 +1,39 @@
export const env = {
port: Number(process.env.PORT ?? 3000),
nodeEnv: process.env.NODE_ENV ?? "development",
appBaseUrl: process.env.APP_BASE_URL ?? "http://localhost:3000",
sessionSecret: process.env.SESSION_SECRET ?? "dev-insecure-session-secret-change-me",
sessionDir: process.env.SESSION_DIR ?? "../data/sessions",
databasePath: process.env.DATABASE_PATH ?? "../data/homelab-manager.sqlite",
credentialsEncryptionKey: process.env.CREDENTIALS_ENCRYPTION_KEY ?? "",
authentik: {
issuerUrl: process.env.AUTHENTIK_ISSUER_URL ?? "",
clientId: process.env.AUTHENTIK_CLIENT_ID ?? "",
clientSecret: process.env.AUTHENTIK_CLIENT_SECRET ?? "",
},
gotify: {
url: process.env.GOTIFY_URL ?? "",
token: process.env.GOTIFY_TOKEN ?? "",
},
get authEnabled() {
return Boolean(this.authentik.issuerUrl && this.authentik.clientId && this.authentik.clientSecret);
},
get credentialsEncryptionEnabled() {
return this.credentialsEncryptionKey.length === 64;
},
};
export function warnIfAuthNotConfigured() {
if (!env.authEnabled) {
console.warn(
"AUTHENTIK_ISSUER_URL / AUTHENTIK_CLIENT_ID / AUTHENTIK_CLIENT_SECRET are not fully set. " +
"The app will boot, but /auth/login and /auth/logout will fail until they are configured.",
);
}
if (!env.credentialsEncryptionEnabled) {
console.warn(
"CREDENTIALS_ENCRYPTION_KEY is not set to a 64-character hex string. " +
"Saving integration credentials (Proxmox/Synology/etc API tokens) will fail until it is configured.",
);
}
}