Monorepo (Express+TS+Drizzle/libSQL server, React+Vite+Tabler web) matching the stack used by ScheduleTaskManager and Sloth Manager. Includes Authentik OIDC login with local admin/operator/viewer roles (first user becomes admin), a generalized audit log, encrypted-at-rest storage for future integration API tokens, the DB schema for all planned modules, and the Tabler-styled app shell/nav. Also ports the Secrets (expiry tracker) and IP Addresses (IPAM) modules from Sloth Manager onto the new stack. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
29 lines
1.3 KiB
Bash
29 lines
1.3 KiB
Bash
# Public URL the app is reachable at (used for OIDC redirect_uri and cookie behavior).
|
|
APP_BASE_URL=https://homelab.example.lan
|
|
|
|
# Random long string used to sign session cookies. Generate with:
|
|
# node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
|
|
SESSION_SECRET=change-me-to-a-random-64-char-hex-string
|
|
|
|
# 32-byte (64 hex char) key used to encrypt stored integration API tokens at
|
|
# rest (AES-256-GCM). Generate the same way as SESSION_SECRET. Losing/changing
|
|
# this key makes previously-stored integration credentials unreadable.
|
|
CREDENTIALS_ENCRYPTION_KEY=change-me-to-a-random-64-char-hex-string
|
|
|
|
# Port docker-compose publishes on the host (container always listens on 3000).
|
|
HOST_PORT=3000
|
|
|
|
# --- Authentik OIDC application/provider ---
|
|
# Create an OAuth2/OIDC "Provider" in Authentik with:
|
|
# Redirect URI: <APP_BASE_URL>/auth/callback
|
|
# Scopes: openid, email, profile
|
|
# then create an "Application" using that provider, and assign the users/groups
|
|
# who should be able to sign in. Copy the provider's values below.
|
|
AUTHENTIK_ISSUER_URL=https://authentik.example.lan/application/o/homelab-manager/
|
|
AUTHENTIK_CLIENT_ID=
|
|
AUTHENTIK_CLIENT_SECRET=
|
|
|
|
# --- Optional: Gotify notifications (secret expiry, integration offline, etc.) ---
|
|
GOTIFY_URL=
|
|
GOTIFY_TOKEN=
|