Skip to content
hot-updaterPublic

About

No description, website, or topics provided.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Repository files navigation

Hot Updater Console

Host the full Hot Updater management console on your own infrastructure using Nitro. Choose a Node server, container, Vercel, Netlify, Cloudflare Workers, or another compatible Nitro deployment target. Your backend's database, storage, and plugins are configured separately from the console's hosting preset.

This repository hosts the published @hot-updater/console package. It does not fork the UI or require a running local CLI. Bundles, Insights, Distribution, and events use your existing Hot Updater backend.

The console reads and writes the backend's database directly. Upgrade the backend's @hot-updater/* packages first, then move the console to the version published with them.

Deploy

Follow the Console deployment guide to connect your backend, configure OAuth, choose a Nitro preset, deploy, and verify. Use Node.js 22+ and npm 11+ for the commands below. Choose a host independently of your managed backend: see the hosting guide and the Docker deployment guide.

git clone https://github.com/hot-updater/console.git my-app-console
cd my-app-console
npm install
# Install your backend's package, then copy its example to
# console.config.ts. For AWS:
npm install --save-exact @hot-updater/aws@rc
cp examples/aws/console.config.ts.example console.config.ts
# Set the server runtime variables, then build and start.
npm run build:node
npm start

For another host, set NITRO_PRESET=<preset> on npm run build and follow its Nitro deployment instructions. The console requires a server; a static-only deployment cannot handle authentication or management operations. Your database and storage adapters must support the runtime you choose.

Repository layout

File Responsibility
vite.config.ts Loads the packaged console and Nitro through its Vite plugin
console.config.ts The database, storage, and plugins your server runs
console.auth.ts Google/GitHub OAuth, encrypted sessions, verified-email allowlist
.env.example Shared server authentication variables for local development
examples/ AWS, Firebase, Supabase, and Cloudflare backend configurations
Dockerfile / .dockerignore Standalone Node image and explicit build-context allowlist

Choose a backend example: AWS, Firebase, Supabase, or Cloudflare.

Authentication

GitHub and Google sign-in are included: fill in the authentication environment variables to enable either provider. For another authentication system, customize the adapter and sign-in flow in your clone.

Verified emails can manage the backend when their full address matches HOT_UPDATER_CONSOLE_ALLOWED_EMAILS or their domain matches HOT_UPDATER_CONSOLE_ALLOWED_EMAIL_DOMAINS. Both comma-separated allowlists apply to Google and GitHub and ignore case and surrounding whitespace. Configure at least one allowed email or domain; leave the email list empty for domain-only access.

For example, allow everyone at company.com and one external operator:

HOT_UPDATER_CONSOLE_ALLOWED_EMAILS=operator@example.com
HOT_UPDATER_CONSOLE_ALLOWED_EMAIL_DOMAINS=company.com

Domain entries must omit @ and wildcards. Subdomains are separate: allowing company.com does not allow team.company.com unless it is also listed. Removing an email or domain blocks existing sessions on the next console request unless another allowlist entry still permits the address.

Google addresses must be verified Gmail accounts or have a matching Google Workspace hd claim, following Google's verification guidance. Google accounts registered with third-party email addresses without a matching hd claim are denied, including individually allowlisted addresses. GitHub uses the verification status of the email returned by its provider. Email-domain access does not check GitHub organization membership. Existing sessions require one new sign-in when upgrading to this verification policy.

OAuth state and 24-hour sessions use encrypted cookies, without a separate auth database. Every protected read, write, and download checks access before connecting to the backend. Keep server credentials and mobile signing private keys out of browser code and version control.

Verification

npm test
npm run test:type
npm run build:node
npm run test:node

CI also builds Vercel, Netlify, and Cloudflare outputs and the Docker image. Runtime smoke checks start the actual built Node server or Worker with test-only credentials and verify sign-in rendering plus denied anonymous reads, writes, and downloads.

About

No description, website, or topics provided.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages