ai-flow improvement / add langchain

This commit is contained in:
2025-11-23 14:51:19 +01:00
parent ade84f34d5
commit 5e734ad27f
25 changed files with 4867 additions and 51 deletions
+42 -6
View File
@@ -46,6 +46,13 @@ This document is a **complete revision** of the Authentik SSO implementation pla
5. Create backup snapshots at every milestone
6. Update this document with progress and issues as we go
**SSO Inclusion Policy:**
- ✅ **Include:** Web-based admin interfaces, dashboards, APIs requiring browser access
- ❌ **Exclude:** Services with native mobile/desktop apps that work better with username/password
- ❌ **Exclude:** Media streaming services (Jellyfin) - app integration priority
- ❌ **Exclude:** Development tools (code-server) - IDE integration priority
- ⏸️ **Defer:** Disabled/inactive services (Nextcloud) - implement when re-enabled
---
## Table of Contents
@@ -870,23 +877,52 @@ curl -I https://auth.schweitz.net # Should return error (Authentik not running)
**Dependencies:** M3 completed successfully
**Configuration:** See original plan Section 5.1.3 for detailed implementation.
**Status:** ✅ **COMPLETE** - Using forward auth (shares Organizr Proxy provider)
**Expected Duration:** 90-120 minutes
**Implementation Decision (2025-11-23):**
- Core API already protected with forward auth via NPM
- Shares "Organizr Proxy" provider with home.schweitz.net
- Authentication working correctly with Google OAuth
- Headers forwarded: X-authentik-username, X-authentik-email, X-authentik-groups, X-authentik-name, X-authentik-uid
- **Decision:** Keep current setup, defer separate admin provider to avoid complexity
- **Rationale:** Current implementation is secure and functional for homelab use case
**Status:** ⏳ Not Started
**Configuration:**
- Provider: Organizr Proxy (shared)
- External host: https://api.schweitz.net
- Outpost: Standalone proxy (port 9445)
- Mode: forward_single
**Expected Duration:** ~~90-120 minutes~~ SKIPPED (already functional)
---
### Milestone 5: Remaining Services (Gradual Rollout)
**Objective:** Enable forward auth on remaining 9 services, one at a time, testing each before proceeding.
**Objective:** Enable forward auth on remaining services, one at a time, testing each before proceeding.
**Dependencies:** M3 and M4 completed successfully
**Services:** Nextcloud, Gitea, Jellyfin, Open WebUI, code-server, Netdata, Uptime Kuma, AMP, Tatlock
**Services to Protect:**
- Gitea (git.schweitz.net)
- Open WebUI (no external domain yet)
- Netdata (no external domain yet)
- Uptime Kuma (no external domain yet)
- AMP (amp.schweitz.net)
- Tatlock (tatlock.schweitz.net)
**Expected Duration:** 4-8 hours (30-60 min per service)
**Services EXCLUDED from SSO (Keep Native Auth):**
- ❌ **Jellyfin (media.schweitz.net)** - Better mobile app integration with native auth
- ❌ **code-server (code.schweitz.net)** - Better VS Code integration with native auth
- ❌ **Nextcloud (cloud.schweitz.net)** - Service disabled, SSO deferred until re-enabled
**Rationale for Exclusions:**
- Jellyfin and code-server have excellent native authentication
- Mobile apps and desktop clients work better with username/password
- SSO adds complexity without significant security benefit for these services
- Nextcloud is not currently in active use
**Expected Duration:** 3-6 hours (30-60 min per service)
**Status:** ⏳ Not Started