- Rewrite docs/index.md as a short landing page (what it is, screenshots, why this over running the two separately, what you get, a minimal "get it" snippet) instead of a full config/architecture reference -- that content still lives in the repo (README, docs/*.md), linked from here. - Cross-link to SSO Manager's and Proxy's own Pages sites. - Screenshots are now clickable (open full size) on both the Pages site and the README. - Disable show_downloads in docs/_config.yml -- the Cayman theme's "Download .zip/.tar.gz" buttons are gone; "View on GitHub" (which links back to the repo) is the only header link now. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2.6 KiB
layout, title
| layout | title |
|---|---|
| default | Home |
theta-env
The whole theta42 identity + access stack in one repo, brought up with a single command — for home labs and small businesses.
It wires together two projects that already work on their own —
SSO Manager (OIDC provider +
LDAP directory) and Proxy (an
OIDC-protected reverse proxy that can also look users up directly in LDAP) —
and automates the fiddly part: registering the proxy as an OIDC client of the
SSO and pointing it at the right LDAP directory, with hostnames and secrets
generated from one setup.env.
Screenshots
The SSO Manager and the proxy it fronts, both stood up by one ./setup.sh run:
(click either screenshot to view full size)
Why this over running them separately
Each project works standalone, but they only become useful together once the
proxy is registered as an OIDC client of the SSO and pointed at the SSO's
LDAP directory — and the domain has to match across half a dozen config
fields, or logins silently fail. Doing that by hand is fiddly. setup.sh
asks for your domain once, generates both apps' config with it filled in
everywhere, registers the proxy as an OIDC client automatically, and
snapshots state before every rebuild.
What you get
- SSO Manager, fronted by the proxy under TLS — manage users, groups, and OAuth clients.
- Proxy — add the hosts you want to protect with OIDC login.
- LDAPS for legacy apps that bind directly.
- Self-service API tokens in both apps' UIs, for scripting/CI without a browser session.
Get it
git clone --recursive https://github.com/theta42/theta-env.git
cd theta-env
cp setup.env.example setup.env # then edit setup.env: set CFG_DOMAIN to your domain
./setup.sh
You need Docker + Docker Compose. ./setup.sh is idempotent — re-run
any time to converge the stack to ./config/. For the full config reference,
architecture, and running each project standalone, see the
GitHub repository.
Related projects
- SSO Manager — the OIDC provider + LDAP directory this stack runs.
- Proxy — the reverse proxy this stack runs in front of it.

