461bd6380415694c27a0f19c1831a3370c722db3
The Authentik blueprint that provisions the OAuth2 Provider/Application only lived on CT121's filesystem via ad-hoc scp/pct push -- deploy/authentik/ is now the source of truth, with redeploy steps in docs/oidc-setup.md. Also documents two bugs found and fixed while implementing issue #19: the first RP-Initiated Logout attempt only ended the app-scoped session, and the provider had no property_mappings so the ID token's username claim was missing (fell back to a raw sub hash that looked like a leaked session token). Both are covered by new Playwright regression tests. The deep-check Fingerbank test now skips instead of failing when its target device (192.168.1.106) has since been manually labeled known via the dashboard, rather than assuming it stays unlabeled forever.
Homelab Monitor
A single dashboard for the health of everything in the homelab (documented in
jhodgkin/homelab): Proxmox host + LXC + bare-metal
CPU/mem/disk/pressure, historical sparklines, and a LAN device inventory. Local auth always available,
plus an optional "Sign in with Authentik" OIDC button. Live at https://monitor.jerodrigged.com.
Project status, architecture, and how to resume work: see CLAUDE.md.
Playwright e2e tests against the live deployment: see e2e/README.md.
Local development
# terminal 1
cd apps/api && npm install && cp ../../.env.example ../../.env # fill in .env first
npm run dev
# terminal 2
cd apps/web && npm install && npm run dev
Web dev server proxies /api to localhost:3000 (see apps/web/vite.config.ts).
Production deploy
Runs as Docker Compose on CT122 (homelab-monitor, 192.168.1.103):
ssh homelab-monitor
cd /opt/homelab-monitor
git pull
docker compose up -d --build
Description
Unified dashboard for monitoring the homelab: server health, resource usage, and LAN device inventory.
Languages
TypeScript
87.1%
Shell
6.9%
CSS
4.9%
Dockerfile
0.8%
HTML
0.3%