Files
theta-suite/docs/index.md
T
wmantly 502aba3da6 Redesign docs site: match the projects' own look, add SEO, mobile-ready
Same treatment as the proxy and sso-manager-node companion PRs. This
repo has no app UI of its own (it's a bash orchestrator), so both the
nav logo and favicon use the shared theta42.svg mark -- matching the
family look shown in its own screenshots (the SSO Manager/proxy
dashboards it stands up).

- New cross-page nav (Home/Quickstart/Architecture/Standalone/
  Changelog) -- replaces index.md's old "More docs" section, now
  redundant with the top nav.
- SEO: jekyll-seo-tag + jekyll-sitemap, per-page meta description,
  OG/Twitter card tags, canonical URLs, JSON-LD, sitemap.xml,
  robots.txt.
- Mobile: Bootstrap's responsive grid + collapsible navbar; the
  screenshot pair in index.md stacks to full-width below 576px.
- Added docs/_site to .gitignore (missing entirely before -- the
  other two repos already had it).

Verified with a real Jekyll build (jekyll/jekyll Docker image) +
Playwright: desktop and mobile (375px) screenshots, mobile nav
toggle, active-link highlighting, zero console/page errors, and
confirmed real SEO output (meta description, OG/Twitter tags,
canonical, JSON-LD, sitemap.xml, robots.txt) via curl against the
served site.
2026-07-16 20:20:42 -04:00

2.8 KiB

layout, title, description
layout title description
default Home A unified, one-command SSO Manager + OIDC proxy stack for home labs and small businesses. Wires together a self-hosted identity provider and a reverse proxy with one setup.sh.

theta-env

The whole theta42 identity + access stack in one repo, brought up with a single command — for home labs and small businesses.

It wires together two projects that already work on their own — SSO Manager (OIDC provider + LDAP directory) and Proxy (an OIDC-protected reverse proxy that can also look users up directly in LDAP) — and automates the fiddly part: registering the proxy as an OIDC client of the SSO and pointing it at the right LDAP directory, with hostnames and secrets generated from one setup.env.

Screenshots

The SSO Manager and the proxy it fronts, both stood up by one ./setup.sh run:

SSO Manager dashboard Proxy host list

(click either screenshot to view full size)

Why this over running them separately

Each project works standalone, but they only become useful together once the proxy is registered as an OIDC client of the SSO and pointed at the SSO's LDAP directory — and the domain has to match across half a dozen config fields, or logins silently fail. Doing that by hand is fiddly. setup.sh asks for your domain once, generates both apps' config with it filled in everywhere, registers the proxy as an OIDC client automatically, and snapshots state before every rebuild.

What you get

  • SSO Manager, fronted by the proxy under TLS — manage users, groups, and OAuth clients.
  • Proxy — add the hosts you want to protect with OIDC login.
  • LDAPS for legacy apps that bind directly.
  • Self-service API tokens in both apps' UIs, for scripting/CI without a browser session.

Get it

git clone --recursive https://github.com/theta42/theta-env.git
cd theta-env
cp setup.env.example setup.env     # then edit setup.env: set CFG_DOMAIN to your domain
./setup.sh

You need Docker + Docker Compose. ./setup.sh is idempotent — re-run any time to converge the stack to ./config/. For the full config reference, architecture, and running each project standalone, see the GitHub repository.

  • SSO Manager — the OIDC provider + LDAP directory this stack runs.
  • Proxy — the reverse proxy this stack runs in front of it.