Commit Graph

382 Commits

Author SHA1 Message Date
wmantly aeed5b8723 chore(submodules): bump theta-agent to v2.1.3 (fixes v2.1.2 CI failure)
v2.1.2's release build failed on the Windows CI leg (test-only issue --
TestApplyHostsOverride_* didn't skip on non-Linux, where
applyHostsOverride() correctly refuses). v2.1.2's actual code was never
functionally broken, but v2.1.3 is the release whose CI run is actually
green, so that's what theta-suite should point at.
2026-08-10 19:16:22 -04:00
wmantly 6640f8059a Merge pull request #204 from theta42/release-v2.3.0
CI/CD / docker-push (push) Failing after 15s
CI/CD / build-theta-agent (push) Successful in 41s
release(v2.3.0): live replication + gateway-to-gateway WireGuard mesh
v2.3.0
2026-08-10 16:10:10 -07:00
wmantly d6611c7d1b release(v2.3.0): live replication + gateway-to-gateway WireGuard mesh
Rolls up theta-directory v2.4.0, jump-host v2.1.0, theta-agent v2.1.2.

Multi-site directory sync stops being a one-time snapshot (live
fire-and-forget replication, identical agent-signing keys, coordinated
master promotion), and site-to-site networking becomes real
infrastructure (gateway-to-gateway WireGuard mesh, kernel-first with a
userspace wireguard-go fallback, real two-container-verified tunnels)
instead of a documented-but-unbuilt design. Linux mDNS local-discovery
also lands end to end (announcer + agent listener).

See CHANGELOG.md for the full rollup and docs/MULTI_SITE_SPEC.md for
the architecture + explicit TODO list of what's still open.
2026-08-10 19:06:54 -04:00
wmantly 9aaa35fa4e docs(multi-site): mark Linux mDNS local-discovery shipped and verified
Announce (theta-gateway) + discover/apply/revert (theta-agent) confirmed
working end-to-end over real multicast between real containers, including
two real bugs found and fixed along the way (IPv6 query abort, EBUSY on
rename over a bind-mounted /etc/hosts).

Windows/macOS mDNS is now the ONLY unbuilt piece of the original design
this session set out to implement -- and it's blocked on platform access
this environment doesn't have, not on missing design or effort.
2026-08-10 18:10:13 -04:00
wmantly 182787f268 docs(multi-site): add an explicit TODO list, ordered by dependency 2026-08-10 17:31:04 -04:00
wmantly d7698a60e7 docs(multi-site): record no-inbound relay mechanism verification
Confirmed the core idea (master terminates a connection, relays over a
spoke's WG mesh IP to a spoke with zero published/inbound ports of its
own) with a standalone test: an external client hit the master's public
port and got a response that could only have come from the spoke,
which had no reachable port except over the tunnel.

Deliberately did NOT wire this into theta-proxy's actual Lua/Redis
routing engine -- that needs its own dedicated pass to do safely, plus a
real service-to-service credential between sso-manager-node and
theta-proxy/theta-gateway that doesn't exist yet. Recorded as verified
mechanism / unbuilt automation, not conflated with either "done" or
"unknown whether it would even work."
2026-08-10 17:28:45 -04:00
wmantly 484bf0e91d docs(multi-site): reconcile spec with live replication, promotion, WG mesh
Updates the status table and top-of-doc callout to reflect what actually
shipped this pass: live catalog replication, identical-directory signing
key, coordinated master promotion (with two real bugs found + fixed along
the way), and a real, tested gateway-to-gateway WireGuard mesh.

Explicitly calls out what's still NOT true despite all of the above: the
mesh exists as its own transport layer but sso-manager-node's join/
replicate traffic doesn't route over it yet, so the no-inbound-spoke
relay scenario still isn't solved end-to-end. mDNS remains unbuilt.
2026-08-10 17:24:18 -04:00
wmantly f42b69c084 feat(multi-site): wire selfUrl through setup.sh so joins register live
Extends the shipped CFG_MASTER_DIRECTORY_URL/JOIN_KEY join flow with the
selfUrl a spoke needs to register itself for live catalog replication
(theta-directory v2.4.0's POST /api/site/spokes) -- without this, every
spoke was permanently limited to the one-time join snapshot even after
the master gained the ability to push live updates.

setup.sh already computes CFG_SSO_HOST before this point in the script;
passes https://$CFG_SSO_HOST as bootstrap/site-join.js's third argument,
which forwards it as `selfUrl` in the POST /api/site/join body.
2026-08-10 16:50:07 -04:00
wmantly 0367c33542 docs(multi-site): reconcile spec with shipped v1, add mDNS agent handoff spec
MULTI_SITE_SPEC.md described a WireGuard-mesh + live-replication design as
if unbuilt-but-planned; meanwhile theta-directory v2.2.0-v2.3.0 (rolled up
in theta-suite v2.2.0) already shipped a simpler, real join mechanism
(one-time LDIF/catalog export over a site join key, read-only spoke
enforcement, setup.sh wiring) that this doc didn't mention at all. Added a
callout pointing at docs/site-join.md as the actual current behavior, and
corrected the status table so it no longer implies unbuilt features are
implemented.

Also adds AGENT_LOCAL_DISCOVERY_SPEC.md, a standalone handoff spec for the
mDNS "prefer local discovered directory" optimization -- confirmed not
implemented anywhere in theta-agent. Needs Windows/Mac-native investigation
this environment can't do; written so it can be picked up independently.
2026-08-10 15:38:39 -04:00
wmantly ff9c87ff20 Merge pull request #203 from theta42/release-v2.2.0
release(v2.2.0): multi-site join end-to-end
2026-08-10 09:42:04 -07:00
wmantly 423e064147 release(v2.2.0): multi-site join end-to-end (theta-directory v2.3.0 + setup.sh wiring) 2026-08-10 09:40:25 -07:00
wmantly 52c9c30c52 Merge pull request #202 from theta42/feat/multi-site-join-setup
feat(setup): first-run site join via CFG_MASTER_DIRECTORY_URL / CFG_MASTER_DIRECTORY_JOIN_KEY
2026-08-10 09:34:14 -07:00
wmantly ea75e94b3e ci(lint): keep job name 'Syntax check bootstrap.js' for branch protection
Renaming the job broke the master protection rule, which requires a check
named exactly 'Syntax check bootstrap.js'. The job still checks both bootstrap
scripts, just under the protected name.
2026-08-10 09:33:01 -07:00
wmantly 301770321e feat(setup): first-run site join via CFG_MASTER_DIRECTORY_URL / CFG_MASTER_DIRECTORY_JOIN_KEY
Multi-site join wiring (server + UI landed in theta-directory v2.3.0):

- bootstrap/site-join.js: runs inside the sso-manager container (same
  self-contained rule as bootstrap.js); logs in as the bootstrap admin and calls
  /api/site/join. Idempotent: an already-joined node reports 'already a spoke'.
- setup.sh step 5b: if setup.env sets CFG_MASTER_DIRECTORY_URL +
  CFG_MASTER_DIRECTORY_JOIN_KEY, run the join after the bootstrap. Only honored
  on first run (ensure_config reads setup.env once and ignores it once
  ./config/ exists), so an already-populated directory can never be merged.
- setup.env.example documents both vars.
- lint.yml also node --check's site-join.js.
2026-08-10 09:12:47 -07:00
wmantly c6c6f09d48 Merge pull request #201 from theta42/chore/submodules-site-join
chore(submodules): bump theta-directory to v2.2.0
2026-08-10 06:14:21 -07:00
wmantly cccde0792e chore(submodules): bump theta-directory to v2.2.0 (multi-site join endpoints + emoji fix) 2026-08-10 06:12:16 -07:00
wmantly a2afc127c4 Merge pull request #200 from theta42/release-v2.1.1
release(v2.1.1): fresh-install fixes
2026-08-09 20:37:35 -07:00
wmantly ad2f7b7e11 release(v2.1.1): fresh-install fixes (agent silent install, Directory modal/version) 2026-08-09 23:36:19 -07:00
wmantly ec73eae07d Merge pull request #199 from theta42/fix/fresh-install
fix(setup): default org name is Theta Directory; bump theta-agent
2026-08-09 20:29:22 -07:00
wmantly 13aeac059f fix(setup): default org name is Theta Directory; bump theta-agent to the fresh-install fix
- CFG_ORG default was 'SSO Manager', which became the browser tab title / app
  name on fresh installs. Default is now 'Theta Directory' (existing deployments
  keep their operator-owned ./config/sso-secrets.js name).
- Records theta-agent d937f8d (silent-install server_url + tray autostart +
  self-update 404 fixes).
2026-08-09 23:26:33 -07:00
wmantly 349d3d4cd0 Merge pull request #198 from theta42/release-v2.1.0
release(v2.1.0): theta-agent Windows client + theta-directory install commands
2026-08-09 18:45:44 -07:00
wmantly d8725990b3 release(v2.1.0): theta-agent Windows client + theta-directory install commands 2026-08-09 21:44:26 -07:00
wmantly de2d65fe8f Merge pull request #197 from theta42/chore/submodules-theta-agent-v2.1.0
chore(submodules): bump theta-agent to v2.1.0
2026-08-09 18:35:22 -07:00
wmantly e5446b2cfe chore(submodules): bump theta-agent to v2.1.0 (Windows agent: platform ops, WireGuard, IAM, tray, installer, CI) 2026-08-09 20:49:02 -07:00
wmantly 0c87c79f06 release(v2.0.4): bump theta-directory for the OpenLDAP base-image speedup (#196)
Dockerfile.openldap now pulls ghcr.io/theta42/openldap-nestgroup instead of
compiling from source on every build (~5-6min -> ~1.5min per CI matrix run,
and removes the runtime dependency on git.openldap.org).

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-09 17:10:35 -07:00
wmantly c7bf1d0edd release(v2.0.3): bump theta-directory to fix Directory tab managed-filter bug (#195)
Directory tab admitted every kind:'host' resource regardless of promotion
status (every discovery plugin creates its finds as kind:'host'), and
site-status 500'd on a nonexistent Resource.subType column.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-09 16:30:28 -07:00
wmantly a917915037 release(v2.0.2): unify component docs, bump theta-directory/proxy/jump-host (#194)
Unifies the GitHub Pages docs site: the SSO/Proxy/Jump Host pages, their
nav labels, and each component's own README now consistently say Theta
Directory / Theta Proxy / Theta Gateway, drop marketing sections ("Why this
over the alternatives", "Get it", "Related projects") that don't apply to a
suite component, remove every standalone/bare-metal install path, and link
to theta42.github.io/theta-suite/... instead of the old per-repo Pages sites.

Bumps submodules: theta-directory v2.0.2, proxy v2.0.1, jump-host v2.0.1.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-09 16:14:23 -07:00
wmantly 141e5e14f0 Merge pull request #193 from theta42/release-v2.0.1-submodules
release(v2.0.1): sync submodules with updated binaries and package.json version
2026-08-09 12:40:30 -07:00
wmantly f09d38d00b release(v2.0.1): sync submodules with updated binaries and package.json version 2026-08-09 15:39:28 -04:00
wmantly 8632798735 Merge pull request #192 from theta42/release-v2.0.1
release(v2.0.1): rollup sso-manager-node v2.0.1 and theta-agent v2.0.1
2026-08-09 11:51:32 -07:00
wmantly 17f488e2e2 release(v2.0.1): rollup sso-manager-node v2.0.1 and theta-agent v2.0.1 2026-08-09 14:50:31 -04:00
wmantly 3ec641c426 fix(submodules): update sso-manager-node with bundled v2.0.0 agent binaries (#191) 2026-08-09 01:12:26 -04:00
wmantly 69a7843dca docs(changelog): update CHANGELOG.md and submodules for v2.0.0 (#190) 2026-08-09 00:19:13 -04:00
wmantly 4db87de240 chore: sync sso-manager-node submodule pointer (#189) 2026-08-09 00:11:29 -04:00
wmantly 9c521b0d08 chore(release): update submodules to v2.0.0 release commits (#188) 2026-08-09 00:10:05 -04:00
wmantly e091ca406c feat: WireGuard UI in Theta Gateway and Theta Agent desktop tray companion with Theta logo (#187)
- Theta Gateway: Add WireGuard peer management UI (/wireguard) with QR code generator, .conf download, and per-client exit node selection
- Theta Agent: Add desktop tray companion app (theta-agent-tray) with Theta 42 logo, color-coded status (red, yellow, green, blue), and home LAN detection
- Suite Rebuild: Local stack initialized with CFG_DOMAIN=suite.vm42.us and CFG_SITE_NAME=718it
2026-08-08 23:19:47 -04:00
wmantly 3c40c66636 chore: update submodules to v2.0.0 (#186) 2026-08-08 21:46:00 -04:00
wmantly 2a0d194cae docs: audit docs and READMEs for Theta Suite 2.0, Theta Directory, Theta Gateway, and Docker-only deployment (#185) 2026-08-08 21:22:40 -04:00
wmantly 656c2ed8c8 docs: update sso-manager-node submodule commit (#184) 2026-08-08 20:59:14 -04:00
wmantly 282071abca docs: update README to reflect Theta Directory, Theta Gateway, Theta Agent, and Theta Suite 2.0 (#183) 2026-08-08 20:53:29 -04:00
wmantly 1d742c51eb docs: finalize v2.0 multi-site spec with theta-gateway, NETMAP, and policy routing (#182) 2026-08-08 20:49:10 -04:00
wmantly 85a822eb36 docs: add multi-site architecture and replication specification (#181) 2026-08-08 20:35:38 -04:00
wmantly 489fe7b127 feat(suite): release v1.8.0 - sso-manager v1.33.0, theta-agent v1.8.0, preset templates & system telemetry (#180) 2026-08-08 19:40:07 -04:00
wmantly ad6f17515b Merge pull request #179 from theta42/release-v1.48.0
Release v1.48.0 - Directory Key Badges, Discovered Inventory Merge/Ignore & Desktop Operations
2026-08-08 18:17:02 -04:00
wmantly eca92f3f37 release: v1.48.0 - Directory Key Badges, Discovered Inventory Merge/Ignore & Desktop Operations 2026-08-08 18:16:33 -04:00
wmantly acea5217ac Merge pull request #178 from theta42/release-v1.47.0
Release v1.47.0 - Subtype Management & Metrics Drivers Engine, Explicit Secret Inheritance & Cross-Platform Agents
2026-08-08 16:13:22 -04:00
wmantly 47ceb63049 release: v1.47.0 - Subtype Management & Metrics Drivers Engine, Explicit Secret Inheritance & Cross-Platform Agents 2026-08-08 16:12:47 -04:00
wmantly 86d1601069 Merge release branch release-v1.47.0 2026-08-08 15:39:16 -04:00
wmantly 8bfde63684 release: v1.47.0 - Subtype Management & Metrics Drivers Engine, Explicit Secret Inheritance & Cross-Platform Agents 2026-08-08 15:39:16 -04:00
wmantly 603156cbfe Merge pull request #177 from theta42/docs/update-secrets-doc
docs: update secrets documentation
2026-08-07 23:47:00 -04:00