Files
theta-suite/docs/index.md
T
wmantly 5ef3e3fa8c v1.29.0: jump host is core + fix fresh-install setup.sh abort (#125)
Two fresh-install fixes and promote the SSH jump host from opt-in to core.

setup.sh: fix silent abort after "Minting per-app OpenBao tokens". env_get's
grep|cut pipeline returns non-zero under set -euo pipefail when .env exists
(created by the root VAULT_TOKEN env_upsert) but an app-token key is absent
(the normal first-run state); the unguarded existing assignment from env_get
then tripped set -e and killed the script before minting any token. env_get
now always returns 0 (|| true). Reproduced + verified under the exact condition.

jump host is no longer optional:
- docker-compose.yml: drop profiles jump-host from the jump-host service
  (always started); rename the opt-in test fixture profile jump-host to ldap-test.
- setup.sh: SUBMODULES always includes jump-host; build/start/register/summary
  no longer guarded by JUMP_ENABLED; drop the COMPOSE_PROFILES export.
- bootstrap.js: jump provisioning + directory record run unconditionally.
- setup.env.example/docs: drop optional/CFG_JUMP_HOST_ENABLED wording.

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-01 13:48:28 -04:00

3.7 KiB

layout, title, description
layout title description
default Home A unified, one-command SSO Manager + OIDC proxy stack for home labs and small businesses. Wires together a self-hosted identity provider and a reverse proxy with one setup.sh.

theta-env

The whole theta42 identity + access stack in one repo, brought up with a single command — for home labs and small businesses.

It wires together two projects that already work on their own — SSO Manager (OIDC provider + LDAP directory) and Proxy (an OIDC-protected reverse proxy that can also look users up directly in LDAP) — and automates the fiddly part: registering the proxy as an OIDC client of the SSO and pointing it at the right LDAP directory, with hostnames and secrets generated from one setup.env. A third component, the Jump Host, adds directory-driven SSH access to your machines through one public entry point.

Screenshots

The SSO Manager and the proxy it fronts, both stood up by one ./setup.sh run:

SSO Manager dashboard Proxy host list Jump Host dashboard

(click either screenshot to view full size)

Why this over running them separately

Each project works standalone, but they only become useful together once the proxy is registered as an OIDC client of the SSO and pointed at the SSO's LDAP directory — and the domain has to match across half a dozen config fields, or logins silently fail. Doing that by hand is fiddly. setup.sh asks for your domain once, generates both apps' config with it filled in everywhere, registers the proxy as an OIDC client automatically, and snapshots state before every rebuild.

What you get

  • SSO Manager, fronted by the proxy under TLS — manage users, groups, and OAuth clients.
  • Proxy — add the hosts you want to protect with OIDC login.
  • LDAPS for direct binds — Linux hosts (PAM/SSSD, sudo, SSH keys) and LDAP-native apps authenticate against the same directory.
  • SSH Jump Hostssh uid_-_host@jump.<domain> (WinSCP-friendly) or an interactive picker; access is driven by directory group membership, with a web UI for audit + metrics.
  • Self-service API tokens in both apps' UIs, for scripting/CI without a browser session.
  • Multi-Site Support (Geo-Location Scaling) — built-in support for N-Way Multi-Master LDAP replication across physical locations.
  • Multi-target load balancing — built-in proxy support for round-robin load balancing across multiple application servers.

Get it

git clone --recursive https://github.com/theta42/theta-env.git
cd theta-env
cp setup.env.example setup.env     # then edit setup.env: set CFG_DOMAIN to your domain
./setup.sh

You need Docker + Docker Compose. ./setup.sh is idempotent — re-run any time to converge the stack to ./config/. For the full config reference, architecture, and running each project standalone, see the GitHub repository.

  • SSO Manager — the OIDC provider + LDAP directory this stack runs.
  • Proxy — the reverse proxy this stack runs in front of it.
  • Jump Host — the SSH jump host this stack brings up.