added phpipam and tailscale integration

This commit is contained in:
bobban committed 2026-09-14 21:05:04 +02:00
1 parent 812c8e5016
commit b5a64fdeac
12 files changed
+846 -66

No files matched your search

+50
View File
@@ -86,6 +86,47 @@ SSO is disabled (and the button is hidden) when any of the three `AUTHENTIK_*` v
---
## phpIPAM
Import IP addresses and devices from a self-hosted [phpIPAM](https://phpipam.net/) instance (optional). When configured, the IPAM page gains a **Sync External** button and shows a phpIPAM source badge on synced entries. Addresses can be edited or deleted with write-back to phpIPAM.
| Variable | Required | Description |
|----------|----------|-------------|
| `PHPIPAM_URL` | Yes | Base URL of your phpIPAM instance, e.g. `https://ipam.example.com` |
| `PHPIPAM_APP_ID` | Yes | API application ID created in phpIPAM → Administration → API |
| `PHPIPAM_TOKEN` | Yes | Static app token (token-based auth, no username/password needed) |
**Setup steps in phpIPAM:**
1. Go to **Administration → phpIPAM Settings** and enable the REST API.
2. Go to **Administration → API** and click **+ Create API key**.
3. Set **App identifier** to any slug (e.g. `sloth-manager`), **App permissions** to `Read/Write`, and **App security** to `SSL with App code token`.
4. Copy the **App code** — this is your `PHPIPAM_TOKEN`.
5. Set `PHPIPAM_APP_ID` to the same slug you chose as the App identifier.
phpIPAM integration is disabled when any of the three `PHPIPAM_*` variables are missing.
---
## Tailscale
Import devices from a [Tailscale](https://tailscale.com/) tailnet (optional). When configured, the IPAM page shows devices with their Tailscale IPs. Devices can be authorized/de-authorized or removed from the tailnet directly from Sloth Manager.
| Variable | Required | Description |
|----------|----------|-------------|
| `TAILSCALE_API_KEY` | Yes | API key generated at [tailscale.com/settings/keys](https://login.tailscale.com/admin/settings/keys) |
| `TAILSCALE_TAILNET` | Yes | Tailnet name, e.g. `yourorg.github` — use `-` to target your default tailnet |
**Setup steps:**
1. Go to **tailscale.com → Settings → Keys → Generate access token**.
2. Grant the token **Devices: Read** and **Devices: Write** (write is needed for authorize and delete actions).
3. Set `TAILSCALE_TAILNET` to your tailnet name (visible in the Admin console URL: `login.tailscale.com/admin/machines/<tailnet>`), or use `-` for the default.
Tailscale integration is disabled when either variable is missing.
---
## Authentication
| Variable | Required | Description |
@@ -139,6 +180,15 @@ AUTHENTIK_URL=https://auth.example.com/application/o/sloth-manager
AUTHENTIK_CLIENT_ID=your_client_id
AUTHENTIK_CLIENT_SECRET=your_client_secret
# phpIPAM (optional)
PHPIPAM_URL=https://ipam.example.com
PHPIPAM_APP_ID=sloth-manager
PHPIPAM_TOKEN=your_app_token
# Tailscale (optional)
TAILSCALE_API_KEY=tskey-api-xxxxxxxxxxxxxxxx
TAILSCALE_TAILNET=yourorg.github
# Auth
JWT_SECRET=your-long-random-secret-here
JWT_EXPIRES_IN=24h