feat(stack): replace Organizr with Tatlock UI, remove Netdata
Remove Organizr dashboard and Netdata monitoring: - Delete stacks/organizr.yml and stacks/netdata.yml - Delete organizr-widgets/ directory and npm forward-auth config - Remove organizr database references from postgres-shared docs Promote Tatlock UI as primary dashboard: - Move from port 8092 to 9999 (Organizr's port) - Enable external access at home.schweitz.net - Update all documentation references Update service counts: 26 containers across 20 stacks 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
+2
-23
@@ -2,35 +2,14 @@
|
||||
|
||||
This directory contains Nginx configuration snippets for Nginx Proxy Manager (NPM) forward authentication with Authentik.
|
||||
|
||||
## Files
|
||||
|
||||
### `organizr-forward-auth.conf`
|
||||
**Status:** 🧪 Testing
|
||||
**Service:** Organizr (home.schweitz.net)
|
||||
**Purpose:** First test deployment of forward auth to validate standalone outpost functionality
|
||||
|
||||
**DO NOT APPLY TO OTHER SERVICES YET** - This is a proof-of-concept deployment to verify:
|
||||
- Standalone outpost works correctly
|
||||
- No redirect loops occur
|
||||
- SSO functions as expected
|
||||
- Cookie domain settings are correct
|
||||
|
||||
Once proven stable, this configuration can be adapted for other services.
|
||||
|
||||
## Deployment Strategy
|
||||
|
||||
### Phase 1: Single Service Test (Current)
|
||||
- ✅ Deploy to Organizr only
|
||||
- ✅ Test all authentication flows
|
||||
- ✅ Verify no issues for 24-48 hours
|
||||
|
||||
### Phase 2: Gradual Rollout (After Phase 1 Success)
|
||||
Services to protect (in order):
|
||||
Services to protect with forward auth (in order):
|
||||
1. Core API (api.schweitz.net) - Use OIDC instead of forward auth
|
||||
2. Nextcloud (cloud.schweitz.net)
|
||||
3. Gitea (git.schweitz.net)
|
||||
4. Jellyfin (media.schweitz.net)
|
||||
5. Open WebUI, Netdata, etc.
|
||||
5. Open WebUI, etc.
|
||||
|
||||
**Rule:** Deploy to ONE service at a time, test for 24 hours before proceeding to next.
|
||||
|
||||
|
||||
@@ -1,133 +0,0 @@
|
||||
# NPM Forward Auth Configuration for Organizr (home.schweitz.net)
|
||||
# Test deployment - single service only
|
||||
# Date: 2025-11-21
|
||||
# Authentik Version: 2024.8.4
|
||||
# Standalone Outpost: authentik-proxy (port 9445)
|
||||
|
||||
# ===================================================================
|
||||
# IMPORTANT: Apply this ONLY to home.schweitz.net proxy host
|
||||
# DO NOT apply to other services until this is proven stable
|
||||
# ===================================================================
|
||||
|
||||
# Increase buffer size for large headers from Authentik
|
||||
proxy_buffers 8 16k;
|
||||
proxy_buffer_size 32k;
|
||||
|
||||
# Forward authentication via standalone outpost
|
||||
auth_request /outpost.goauthentik.io/auth/nginx;
|
||||
error_page 401 = @goauthentik_proxy_signin;
|
||||
|
||||
# Capture auth response headers
|
||||
auth_request_set $auth_cookie $upstream_http_set_cookie;
|
||||
auth_request_set $authentik_username $upstream_http_x_authentik_username;
|
||||
auth_request_set $authentik_groups $upstream_http_x_authentik_groups;
|
||||
auth_request_set $authentik_email $upstream_http_x_authentik_email;
|
||||
auth_request_set $authentik_name $upstream_http_x_authentik_name;
|
||||
auth_request_set $authentik_uid $upstream_http_x_authentik_uid;
|
||||
|
||||
# Forward auth headers to application
|
||||
add_header Set-Cookie $auth_cookie;
|
||||
proxy_set_header X-authentik-username $authentik_username;
|
||||
proxy_set_header X-authentik-groups $authentik_groups;
|
||||
proxy_set_header X-authentik-email $authentik_email;
|
||||
proxy_set_header X-authentik-name $authentik_name;
|
||||
proxy_set_header X-authentik-uid $authentik_uid;
|
||||
|
||||
# Outpost proxy location
|
||||
location /outpost.goauthentik.io {
|
||||
proxy_pass https://localhost:9445/outpost.goauthentik.io;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header X-Forwarded-Host $http_host;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_pass_request_body off;
|
||||
proxy_set_header Content-Length "";
|
||||
|
||||
# WebSocket support
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
}
|
||||
|
||||
# Signin redirect handler
|
||||
location @goauthentik_proxy_signin {
|
||||
internal;
|
||||
return 302 https://auth.schweitz.net/outpost.goauthentik.io/start?rd=$scheme://$http_host$request_uri;
|
||||
}
|
||||
|
||||
# ===================================================================
|
||||
# DEPLOYMENT INSTRUCTIONS:
|
||||
# ===================================================================
|
||||
#
|
||||
# 1. Open NPM UI: http://192.168.86.149:8000
|
||||
# 2. Navigate to: Hosts → Proxy Hosts
|
||||
# 3. Find "home.schweitz.net" and click Edit
|
||||
# 4. Go to the "Advanced" tab
|
||||
# 5. PASTE THIS ENTIRE CONFIGURATION (lines 11-56) into the text box
|
||||
# 6. Go to the "SSL" tab
|
||||
# 7. Ensure "WebSockets Support" is ENABLED
|
||||
# 8. Click "Save"
|
||||
#
|
||||
# ===================================================================
|
||||
# TESTING PROCEDURE:
|
||||
# ===================================================================
|
||||
#
|
||||
# Step 1: Test in Incognito Window
|
||||
# - Open incognito/private browsing window
|
||||
# - Navigate to: https://home.schweitz.net
|
||||
# - Expected: Redirect to https://auth.schweitz.net
|
||||
# - Login with Google OAuth
|
||||
# - Expected: Redirect back to https://home.schweitz.net
|
||||
# - Expected: Organizr loads successfully
|
||||
#
|
||||
# Step 2: Verify SSO Persistence
|
||||
# - Close incognito window
|
||||
# - Open new incognito window
|
||||
# - Navigate to: https://home.schweitz.net
|
||||
# - Expected: Still logged in (cookie persists)
|
||||
#
|
||||
# Step 3: Check Logs for Errors
|
||||
# docker logs authentik-proxy 2>&1 | tail -50
|
||||
# - Look for any errors or warnings
|
||||
# - Should see successful auth requests
|
||||
#
|
||||
# Step 4: Test Logout
|
||||
# - Navigate to: https://auth.schweitz.net/if/flow/default-invalidation-flow/
|
||||
# - Should log out
|
||||
# - Try accessing https://home.schweitz.net again
|
||||
# - Expected: Redirect to login page
|
||||
#
|
||||
# ===================================================================
|
||||
# ROLLBACK PROCEDURE (if issues occur):
|
||||
# ===================================================================
|
||||
#
|
||||
# 1. Open NPM UI
|
||||
# 2. Edit home.schweitz.net proxy host
|
||||
# 3. Go to "Advanced" tab
|
||||
# 4. DELETE all the configuration
|
||||
# 5. Save
|
||||
# 6. Organizr will be accessible without authentication again
|
||||
#
|
||||
# ===================================================================
|
||||
# TROUBLESHOOTING:
|
||||
# ===================================================================
|
||||
#
|
||||
# Issue: Redirect loop
|
||||
# - Check that auth.schweitz.net does NOT have forward auth enabled
|
||||
# - Verify AUTHENTIK_COOKIE_DOMAIN=.schweitz.net in provider settings
|
||||
#
|
||||
# Issue: 502 Bad Gateway
|
||||
# - Check authentik-proxy container is running: docker ps | grep authentik-proxy
|
||||
# - Check NPM can reach authentik-proxy: docker exec npm ping authentik-proxy
|
||||
#
|
||||
# Issue: 500 Internal Server Error
|
||||
# - Check authentik-proxy logs: docker logs authentik-proxy
|
||||
# - Verify Redis connection is working
|
||||
# - Restart authentik-proxy: docker restart authentik-proxy
|
||||
#
|
||||
# Issue: Authentication works but Organizr doesn't load
|
||||
# - Check buffer sizes are set correctly (lines 13-14)
|
||||
# - Check WebSocket support is enabled in NPM SSL tab
|
||||
#
|
||||
# ===================================================================
|
||||
Reference in New Issue
Block a user