Files
theta-suite/docs/standalone.md
T
wmantly 9fb240ff45 theta-env: unified SSO Manager + Proxy stack with one-command setup
Composes theta42/sso-manager-node and theta42/proxy (as git submodules) on a
single Docker network and automates first-run wiring.

- docker-compose.yml: sso-manager (build ./sso-manager-node/Dockerfile.openldap)
  + proxy (build ./proxy/Dockerfile) on theta-net; SSO UI + mgmt port bound to
  localhost, LDAPS published, proxy 80/443/4443 published.
- setup.sh: idempotent one-command bring-up — validates .env, starts SSO, runs
  the bootstrap, writes ./proxy.env, starts the proxy, prints admin login.
- bootstrap/bootstrap.js: runs inside the sso-manager container (self-contained,
  Node built-ins + fetch only) — creates the LDAP service account, first admin
  (+ app_sso_admin/app_sso_oauth_admin membership), registers the proxy as an
  OIDC client via the SSO HTTP API, emits CLIENT_ID/CLIENT_SECRET.
- .env.example: all tunables (LDAP_BASE_DN, LDAP_ADMIN_PASS, JWT_SECRET,
  SSO_HOST, PROXY_HOST, BOOTSTRAP_ADMIN_*, LDAP_SERVICE_PASS, SMTP_*, ports).
- README.md + docs/ (Jekyll site for GitHub Pages): quickstart, architecture,
  standalone usage.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-11 17:04:36 -04:00

3.7 KiB

layout, title
layout title
default Standalone

Running each project standalone

← Back to Home

theta-env composes the two projects but doesn't fork them — both work on their own. The submodules in this repo are normal clones; you can also clone them directly from GitHub.

SSO Manager alone

The all-in-one image (Dockerfile.openldap) bundles the app + OpenLDAP + Redis:

git clone https://github.com/theta42/sso-manager-node.git
cd sso-manager-node
# Option A: configure via app_* env (preferred for Docker):
LDAP_ADMIN_PASS='choose-a-strong-password' \
JWT_SECRET="$(openssl rand -hex 32)" \
docker compose up -d --build

# Option B: configure via a file:
cp secrets.js.example nodejs/conf/secrets.js   # edit it
docker compose up -d --build
  • Web UI: http://localhost:3001
  • Health: http://localhost:3001/health
  • OIDC discovery: http://localhost:3001/.well-known/openid-configuration
  • LDAPS: ldaps://<host>:636

Requires @simpleworkjs/conf >= 1.1.0 for app_* env overrides. Full reference: SSO Manager deployment docs.

Bare metal

sudo ./install.sh -p 'your-ldap-password' -b 'dc=yourdomain,dc=com' -n 'Your Org' -o 3001
sudo systemctl enable --now sso-manager

Idempotent — re-run to update. See the SSO Manager deployment guide.

Proxy alone

The all-in-one image (Dockerfile) bundles OpenResty + the Node app + Redis:

git clone https://github.com/theta42/proxy.git
cd proxy
# Wire it to an external SSO + LDAP via app_* env (or nodejs/conf/secrets.js):
cat > .env <<EOF
app_oidc__issuer=https://sso.example.com
app_oidc__authorizationEndpoint=https://sso.example.com/oauth/authorize
app_oidc__endSessionEndpoint=https://sso.example.com/oauth/logout
app_oidc__tokenEndpoint=https://sso.example.com/oauth/token
app_oidc__userinfoEndpoint=https://sso.example.com/oauth/userinfo
app_oidc__clientId=...
app_oidc__clientSecret=...
app_oidc__redirectUri=https://proxy.example.com/api/auth/oidc/callback
app_ldap__url=ldaps://sso.example.com:636
app_ldap__bindDN=cn=ldapclient,ou=people,dc=example,dc=com
app_ldap__bindPassword=...
app_ldap__searchBase=ou=people,dc=example,dc=com
app_ldap__userFilter=(objectClass=posixAccount)
app_ldap__tlsOptions__rejectUnauthorized=false
EOF
docker compose up -d --build
  • Proxy (public, auto-SSL): https://<host>/
  • Mgmt UI / API: http://127.0.0.1:3000/
  • Health: http://127.0.0.1:3000/health

Requires @simpleworkjs/conf >= 1.1.0. Full reference: proxy deployment docs.

Bare metal

wget -O - https://raw.githubusercontent.com/theta42/proxy/master/ops/install.sh | sudo bash

See the proxy Docker guide / installation guide.

Mixing and matching

theta-env isn't required to use the two together — the four wiring steps are documented in both projects' deployment guides:

  1. One Docker network (or reachable hostnames) so the proxy can reach the SSO internally for token/userinfo + LDAPS.
  2. Set the SSO's OAUTH_ISSUER / app_oauth__issuer to the browser-facing HTTPS URL the proxy serves the SSO at.
  3. Register the proxy as an OIDC client in the SSO, with redirectUri matching the proxy's callback.
  4. Point the proxy's app_ldap__url at the SSO's LDAPS + create a dedicated cn=ldapclient service account.

theta-env just automates those four steps with ./setup.sh. If you prefer to do them by hand (or want the two on separate hosts), follow the standalone guides above.

← Back to Home