feat!: remove rathole package - superseded by netbird [#650]
Founder ruling: "we will use netbird for all enterprise network
access." Package dir deleted (11th package, f918a90, is hereby
retired); GitUrlList 41->40; counts 19->18; completed tables
renumbered; JOURNAL section retained as history with a superseding
addendum. Standing policy recorded: netbird for network access.
This commit is contained in:
@@ -3,25 +3,23 @@
|
||||
> **Human read-only. Agents maintain this file automatically after each work
|
||||
> session.** Do not edit by hand — the next agent run will overwrite it.
|
||||
>
|
||||
> **Last updated:** 2026-09-06 by ZCode (GLM-5.3) — GoAlert packaged (18th; rulings synced:
|
||||
> GitUrlList 56→46, no-Node policy live)
|
||||
> (#648, Infrastructure, 16th package); auth gate verdict: native OIDC via
|
||||
> python-social-auth (OpenIdConnectAuth + SOCIAL_AUTH_OIDC_*) wired to the
|
||||
> platform provider; official-image wrapper of netboxcommunity/netbox
|
||||
> v4.6.10 (netbox-docker 5.0.2), full-stack verified (migrations, Granian,
|
||||
> gated RQ worker, OIDC login button). Session also finished #685's apply
|
||||
> pass (memlimits script repairs + photos floor-limit).
|
||||
> **Last updated:** 2026-09-06 by ZCode (GLM-5.3) — rathole REMOVED by founder
|
||||
> ruling ("we will use netbird for all enterprise network access"): package dir
|
||||
> deleted, GitUrlList 46→40, completed count 19→18. Landed tickets sit in
|
||||
> **Feedback** (awaiting live-Cloudron UAT); builds ON HOLD pending the
|
||||
> founder's queue review. Standing policies: no-Node, no-open-core, no-SSO-tax,
|
||||
> netbird for network access, RustFS makes S3 a non-blocker.
|
||||
|
||||
## Current State: STABLE (packaging phase, ongoing)
|
||||
|
||||
Cloudron packaging pipeline is operational. 19 of 46 remaining-set applications are
|
||||
Cloudron packaging pipeline is operational. 18 of 40 remaining-set applications are
|
||||
packaged, committed, and pushed. Packaging templates exist for the core
|
||||
patterns. The gardening protocol (this file + AGENTS.md) keeps docs in sync.
|
||||
All remaining apps now carry build tickets (#633-#678) under umbrella
|
||||
[#632](https://projects.knownelement.com/issues/632) in Redmine project 55 —
|
||||
ready for the sequential grind-driver pattern.
|
||||
|
||||
## Completed Packages (19)
|
||||
## Completed Packages (18)
|
||||
|
||||
| # | Application | Category | Pattern | Port(s) | Addons |
|
||||
|---|-------------|----------|---------|---------|--------|
|
||||
@@ -35,12 +33,11 @@ ready for the sequential grind-driver pattern.
|
||||
| 8 | draw.io | Documentation-Tools | Official-image wrapper + auth proxy | 8080 | none (stateless) |
|
||||
| 9 | Windmill | Automation | Official-image wrapper + start.sh | 8000 | localstorage, postgresql |
|
||||
| 10 | Easy-Gate | Infrastructure | Multi-stage (Go) + auth proxy | 8080 | localstorage |
|
||||
| 11 | Rathole | Infrastructure | Pre-compiled binaries + auth proxy | 8000, 2333, 5200-5299 | localstorage |
|
||||
| 12 | Database Gateway | Infrastructure | Multi-stage (Go, CGO) | 8080 | localstorage, postgresql |
|
||||
| 13 | FX | DevOps-Tools | Pre-compiled binaries + auth proxy | 8000 | localstorage |
|
||||
| 14 | ChirpStack | Infrastructure | Official-image wrapper | 8080 | localstorage, postgresql, redis |
|
||||
| 15 | eLabFTW | Business-Apps | Official-image wrapper | 443 | localstorage, mysql, ldap |
|
||||
| 16 | NetBox | Infrastructure | Official-image wrapper + start.sh | 8080 | localstorage, postgresql, redis |
|
||||
| 11 | Database Gateway | Infrastructure | Multi-stage (Go, CGO) | 8080 | localstorage, postgresql |
|
||||
| 12 | FX | DevOps-Tools | Pre-compiled binaries + auth proxy | 8000 | localstorage |
|
||||
| 13 | ChirpStack | Infrastructure | Official-image wrapper | 8080 | localstorage, postgresql, redis |
|
||||
| 14 | eLabFTW | Business-Apps | Official-image wrapper | 443 | localstorage, mysql, ldap |
|
||||
| 15 | NetBox | Infrastructure | Official-image wrapper + start.sh | 8080 | localstorage, postgresql, redis |
|
||||
|
||||
Each package lives in `Package-Workspace/<Category>/<app>/` and contains a
|
||||
`Dockerfile`, `CloudronManifest.json`, `README.md`, `CHANGELOG.md`, `logo.png`,
|
||||
@@ -73,7 +70,6 @@ GitUrlList pruned 56 → 46 accordingly.
|
||||
| #647 | Fleet | Monitoring | GO-with-risk (SAML first-class; build parked pending ruling) |
|
||||
| #648 | NetBox | Infrastructure | DONE (16th package) |
|
||||
| #649 | SeaTunnel | Data-Management | disposition: OUT OF SCOPE (job engine) — ruling pending |
|
||||
| #650 | Rathole | Infrastructure | DONE (11th package) |
|
||||
| #651 | Easy-Gate | Infrastructure | DONE (10th package) |
|
||||
| #653 | ConsulDemocracy | Collaboration | DONE (17th package, grind-verified) |
|
||||
| #654 | BOINC | Scientific-Computing | disposition: OUT OF SCOPE — ruling pending |
|
||||
@@ -118,7 +114,7 @@ Full write-ups of each pattern + challenges are in [`JOURNAL.md`](JOURNAL.md).
|
||||
| Automation | 2 | 1/2 | windmill done (huginn, runme removed) |
|
||||
| Business-Apps | 4 | 2/4 | elabftw, inventree done (midday, openboxes, pimcore removed) |
|
||||
| Collaboration | 2 | 1/2 | consuldemocracy done |
|
||||
| Infrastructure | 6 | 5/6 | easy-gate, rathole, database-gateway, chirpstack, netbox done |
|
||||
| Infrastructure | 5 | 4/5 | easy-gate, database-gateway, chirpstack, netbox done (rathole removed) |
|
||||
| Data-Management | 2 | 0/2 | datahub, seatunnel |
|
||||
| Security | 2 | 0/2 | tirreno pending ruling (gophish, sniperphish, sat, comply removed) |
|
||||
| System-Administration | 1 | 0/1 | slurm (mender removed) |
|
||||
@@ -135,7 +131,7 @@ Auth capability is a hard gate before packaging (see
|
||||
LDAP acceptable (risk flag), 🔄 = auth-proxy (no users), ❌ = local-only
|
||||
(unacceptable / blocked-on-auth).
|
||||
|
||||
### Completed packages (19)
|
||||
### Completed packages (18)
|
||||
|
||||
| App | OIDC | LDAP | Verdict | Note |
|
||||
|-----|------|------|---------|------|
|
||||
@@ -149,7 +145,6 @@ LDAP acceptable (risk flag), 🔄 = auth-proxy (no users), ❌ = local-only
|
||||
| draw.io | n/a | n/a | 🔄 proxy | **Packaged** with `httpAuth.type=proxy` (no users, stateless) |
|
||||
| Windmill | yes | no | ✅ preferred | **Packaged**; OIDC configured via Admin Settings UI (no env vars) |
|
||||
| Easy-Gate | n/a | n/a | 🔄 proxy | **Packaged** with `httpAuth.type=proxy` (no user concept; IP-subnet groups only) |
|
||||
| Rathole | n/a | n/a | 🔄 proxy | **Packaged** with `httpAuth.type=proxy` on the status page; tunnels secured by mandatory per-service tokens (Noise/TLS optional) |
|
||||
| Database Gateway | yes | no | ✅ preferred | **Packaged**; native OIDC-only app — platform provider env (`CLOUDRON_OIDC_*`) seeded into config.json; roles from the `groups` claim |
|
||||
| FX | n/a | n/a | 🔄 proxy | **Packaged**; CLI-only FaaS tool with no user concept — pinned binary + workspace driven from the Cloudron terminal; landing page gated by `httpAuth.type=proxy` |
|
||||
| ChirpStack | yes | no | ✅ preferred | **Packaged**; native `[user_authentication.openid_connect]` wired to `CLOUDRON_OIDC_*`; OIDC-registered users are non-admin — one-time `CHIRPSTACK_AUTH_MODE=internal` bootstrap links the seeded `admin` to your SSO email (README) |
|
||||
@@ -173,11 +168,11 @@ HOLD while the founder reviews the queue.**
|
||||
|
||||
| Bucket | Tickets |
|
||||
|--------|---------|
|
||||
| Landed — Feedback (awaiting UAT) | #633 #639 #640 #648 #650 #651 #653 #658 #668 #669 |
|
||||
| Landed — Feedback (awaiting UAT) | #633 #639 #640 #648 #651 #653 #658 #668 #669 |
|
||||
| APPROVED — queued (hold) | #673 NCA Toolkit (proxy-eligible Flask API; RustFS makes S3 a non-issue) |
|
||||
| GO — no explicit ruling yet | #634 Tirreno (verify-only; already deployed) · #642 Rundeck (OSS LDAP, no OIDC) · #662 KillBill · #647 Fleet (SAML risk; digest banked) · #833 jamovi (new; proxy; 3-origin risk) |
|
||||
| GO-with-risk — no ruling yet | #637 Docassemble · #643 HyperSwitch (no-node dashboard workaround needed) · #671 Resgrid (bundle RabbitMQ) |
|
||||
| KILLED by rulings (this wave) | #635 Runme · #645 OpenBoxes · #656 Gophish · #661 WireViz · #638 Pimcore (open-core) · #659 Mender (SSO tax) |
|
||||
| KILLED by rulings | #635 Runme · #645 OpenBoxes · #656 Gophish · #661 WireViz · #638 Pimcore (open-core) · #659 Mender (SSO tax) · **#650 Rathole (superseded by netbird — package dir deleted)** |
|
||||
| → k8s queue | #636 DataHub (joins #663 #678) |
|
||||
| OUT OF SCOPE (ruling pending) | #646 Nautilus · #649 SeaTunnel · #654 BOINC · #655 Slurm · #672 SDRangel · #675 SAT |
|
||||
| Upstream gone | #657 SniperPhish (404) |
|
||||
|
||||
Reference in New Issue
Block a user