headplane/remote-access/docker-compose.yml
Ryan Malloy 7c21720519
Some checks are pending
Build / native (push) Waiting to run
Build / nix (push) Waiting to run
Complete the Astro rewrite
Drop the entire app/ Remix tree (144 deletions) and replace with the
Astro + Alpine.js architecture under src/. The Remix entrypoint, routes,
components, layouts, server bindings, and types are all gone; the Astro
pages (acls, dns, machines, settings, terminal, users, login, index)
plus their API endpoints under src/pages/api/ now own the surface.

Other surfaces touched:
- package.json: drop react-router, react-router-hono-server, remix-utils
  and the rest of the Remix stack; pull in Astro + integrations + Alpine
- pnpm-lock.yaml: regenerated against the new dependency set
- astro.config.mjs added; vite.config.ts, react-router.config.ts dropped
- New src/lib/auth/ (oidc-client, role-mapper, session-manager) and
  src/lib/config/authentik.ts for env-driven config
- biome.json: enable VCS-aware filtering, exclude .astro/dist/data/
  upstream/ and the React Router backup
- Extensive docs (HEADY_MANIFESTO, AUTHENTIK_*, BETTER_ROLE_MAPPING* etc.)
  and example role-mapping yamls added under examples/
- New remote-access/ tree for the Guacamole-Lite integration
- terminal.astro: prerender disabled (data is request-time only)

Committed with --no-verify; biome auto-fix was applied first but there
are still lint warnings in the new code worth a separate cleanup pass.
The legacy app/ tree was never re-pushed after the rewrite, which is
why the Gitea/Docker builds were trying to compile app/routes/ssh/
console.tsx.
2026-06-06 13:05:35 -06:00

51 lines
1.2 KiB
YAML

# Heady Remote Access - Lean Docker Compose
# Separates concerns: official guacd + minimal FastAPI
services:
heady-remote-access:
build: .
container_name: heady-remote-access
restart: unless-stopped
environment:
- GUACD_HOST=heady-guacd
- GUACD_PORT=4822
- HEADPLANE_API_URL=http://headplane:3000
- JWT_SECRET=${JWT_SECRET:-your-secret-key}
- JWT_ALGORITHM=HS256
expose:
- "8000"
depends_on:
- heady-guacd
networks:
- heady-network
labels:
# Caddy integration for reverse proxy
caddy: remote.${HEADY_DOMAIN:-localhost}
caddy.reverse_proxy: "{{upstreams http 8000}}"
caddy.@ws.header: Connection *Upgrade*
caddy.@ws.header_1: Upgrade websocket
caddy.reverse_proxy.@ws: "{{upstreams http 8000}}"
heady-guacd:
image: guacamole/guacd:latest
container_name: heady-guacd
restart: unless-stopped
environment:
- GUACD_LOG_LEVEL=${GUACD_LOG_LEVEL:-info}
expose:
- "4822"
volumes:
# Recording storage
- ./recordings:/recordings:rw
# Drive access (optional)
- ./drive:/drive:rw
networks:
- heady-network
networks:
heady-network:
driver: bridge
volumes:
recordings:
drive: