Unified monorepo for All Things Linux: marketing site, portal (identity stack), chat infrastructure (IRC / XMPP / bridge), self-hosted tools (atl.tools), network services, and observability stack.
apps/
βββ web @atl/web β marketing site (Next.js 16, OpenNext / Cloudflare)
βββ portal @atl/portal β identity & admin portal (Next.js 16, PostgreSQL)
βββ chat-web @atl/chat-web β atl.chat landing page (Next.js 16)
βββ docs @atl/docs β product documentation (Mintlify)
βββ tools-web @atl/tools-web β atl.tools directory (Next.js 16, OpenNext / Cloudflare)
βββ bridge DiscordβIRCβXMPP bridge (Python / uv β NOT in pnpm workspace)
packages/
βββ ui @atl/ui β shared design system (shadcn/ui + @base-ui/react)
βββ auth @atl/auth β Better Auth config, client, hooks, and DAL
βββ db @atl/db β shared Drizzle schema, client, and relations
βββ api @atl/api β TanStack Query keys, server queries, hydration helpers
βββ schemas @atl/schemas β shared Zod schemas (user, integrations)
βββ types @atl/types β shared TypeScript types (auth, API, email, routes)
βββ email @atl/email β email sending utilities (React Email)
βββ env @atl/env β shared environment variable validation (t3-env)
βββ config @atl/config β shared static config (community, events, donate)
βββ seo @atl/seo β metadata, JSON-LD, robots, sitemap helpers
βββ utils @atl/utils β shared utility functions (date, format, error)
βββ discord @atl/discord β Discord REST API client (guild, members, channels, roles)
βββ integrations @atl/integrations β third-party API clients (GitHub, Fibery, webhooks)
βββ fibery @atl/fibery β Fibery SDK (portal admin, career applications)
βββ observability @atl/observability β Sentry / OpenTelemetry helpers
βββ tools-manifest @atl/tools-manifest β tool definitions consumed by apps/tools-web
βββ tsconfig @atl/tsconfig β shared TypeScript configurations
services/
βββ chat/ IRC (UnrealIRCd + Atheme), XMPP (Prosody), web clients
βββ network/ DNS (Blocky), TURN (coturn), uptime (Gatus), SFTP
βββ tools/ Self-hosted tools (PrivateBin, SearXNG, Stirling-PDF, β¦)
βββ observability/ Grafana, Loki, Mimir, Alloy, Alloy Agent, Blackbox
infra/
βββ chat/ Docker Compose fragments (chat-*.yaml)
βββ network/ Docker Compose fragments (network.yaml)
βββ observability/ Docker Compose fragments (observability.yaml)
βββ tools/ Docker Compose fragments (tools-*.yaml)
βββ nginx/ Nginx reverse proxy config (Prosody HTTPS)
βββ sh/ atl.sh pubnix provisioning (Ansible, Terraform, skel, Vagrant)
βββ cert-manager.yaml TLS certificate management (included by root compose.yaml)
βββ networks.yaml Shared Docker network definitions (included by root compose.yaml)
scripts/ Shell scripts (init.sh β data dirs + dev certs)
tests/
βββ unit/ Bridge unit tests
βββ integration/ Bridge integration tests
βββ e2e/ End-to-end tests
βββ protocol/ Protocol-level tests
βββ ... fixtures/, controllers/, irc_utils/, utils/, legacy/
apps/ = software we build and own (polyglot: Next.js + Python).
services/ = external software we extend, configure, and operate.
packages/ = shared JS/TS libraries.
Package names: @atl/* for org-level apps and shared libraries. @portal/* for portal-internal packages under apps/portal/packages/*.
| Tool | Version | Notes |
|---|---|---|
| Node.js | >=24 |
Pinned in .nvmrc and mise.toml |
| pnpm | >=10 |
Managed via Corepack (packageManager field) |
| uv | latest | Python package manager for apps/bridge |
| Docker + Compose | β | Required for services/* |
| just | latest | Task runner (cargo install just or OS pkg) |
git clone https://github.com/allthingslinux/monorepo.git
cd monorepo
just setup # pnpm install + uv sync + init.sh + env filesjust setup copies .env.example β .env and .env.dev.example β .env.dev if they don't already exist. Edit them before starting services.
Run just to see all available recipes grouped by domain.
| Command | Purpose |
|---|---|
just setup |
Full bootstrap (JS + Python + env + certs) |
just install |
pnpm install |
just install-frozen |
pnpm install --frozen-lockfile |
just dev |
Start all JS apps via Turborepo |
just build |
Production build (Turbo graph) |
just check |
Lint + format check (Ultracite) |
just fix |
Lint + format fix (Ultracite) |
just typecheck |
TypeScript validation across all packages |
just test |
Run all tests via Turborepo |
just test-coverage |
Run tests with coverage |
just clean |
Remove build artifacts |
just renovate-validate |
Validate Renovate config |
just docker-clean |
Prune unused Docker images and volumes |
just docker-push-all |
Push all Docker images to registry |
| Command | Purpose |
|---|---|
just web-dev |
Marketing site dev server |
just web-build |
Build marketing site |
just web-deploy |
Deploy to Cloudflare Workers |
just web-destroy |
Destroy Cloudflare Workers deployment |
just web-shadcn-add [args] |
Add shadcn/ui component to web |
just chat-web-dev |
atl.chat dev server |
just chat-web-build |
Build atl.chat site |
just chat-web-deploy |
Deploy atl.chat to Cloudflare Workers |
just portal-dev |
Portal dev server |
just portal-build |
Build portal |
just portal-start |
Start portal (production mode) |
just portal-db-up |
Start PostgreSQL (Docker) |
just portal-db-down |
Stop PostgreSQL |
just portal-db-generate |
Generate Drizzle migration files |
just portal-db-migrate |
Run pending migrations |
just portal-db-push |
Push schema to dev DB |
just portal-db-seed |
Seed the database |
just portal-db-studio |
Open Drizzle Studio |
just portal-shadcn-add [args] |
Add shadcn/ui component to portal |
just docs-dev |
Mintlify docs preview |
just docs-build |
Build docs |
just docs-check-links |
Check for broken links |
| Command | Purpose |
|---|---|
just tools-dev |
Start all tools Docker services (dev) |
just tools-up |
Start all tools Docker services (prod) |
just tools-down |
Stop all tools Docker services |
just tools-logs |
Tail tools container logs |
just tools-status |
Show running tools containers |
just tools-build |
Build custom service images |
just tools-web-dev |
atl.tools Next.js dev server |
just tools-web-build |
Build atl.tools site |
just tools-web-deploy |
Deploy atl.tools to Cloudflare Workers |
| Command | Purpose |
|---|---|
just chat-init |
Initialize chat data directories and config |
just chat-dev |
Start all chat services (dev profile) |
just chat-prod |
Start all chat services (production profile) |
just chat-down |
Stop chat services (dev) |
just chat-down-prod |
Stop chat services (production) |
just chat-logs |
Tail logs (optionally filter by name) |
just chat-status |
Show running containers |
just chat-build |
Build all service images |
just chat-build-clean [svc] |
Build service images (no cache) |
just prosody-token |
Generate a Prosody API token |
just gencloak |
Generate IRC cloaking key |
| Command | Purpose |
|---|---|
just bridge-install |
uv sync --all-extras |
just bridge-check |
Ruff lint + format check |
just bridge-fix |
Ruff lint fix + format |
just bridge-typecheck |
basedpyright type check |
just bridge-test |
pytest suite |
just bridge-logs |
Tail bridge container logs |
| Command | Purpose |
|---|---|
just pubnix-setup |
Install Ansible deps + galaxy roles |
just pubnix-install |
Install Ansible collections |
just pubnix-deploy <target> |
Ansible deploy (dev/staging/prod) |
just pubnix-deploy-tag <target> <tag> |
Deploy specific roles by tag |
just pubnix-deploy-check <target> |
Dry run (check mode) |
just pubnix-deploy-list-tags |
List available deploy tags |
just pubnix-ping <target> |
Ping Ansible hosts |
just pubnix-syntax-check |
Ansible syntax check |
just pubnix-create-user <user> <key> <target> |
Create user on pubnix server |
just pubnix-remove-user <user> <target> |
Remove user from pubnix server |
just pubnix-molecule-test <role> |
Molecule test for an Ansible role |
just pubnix-molecule-converge <role> |
Molecule converge (apply role) |
just pubnix-molecule-verify <role> |
Molecule verify |
just pubnix-molecule-destroy <role> |
Molecule destroy |
just pubnix-smoke-test [target] |
End-to-end smoke test |
just pubnix-tf-init |
Terraform init |
just pubnix-tf-plan |
Terraform plan |
just pubnix-tf-apply |
Terraform apply |
just pubnix-vault-edit |
Edit Ansible vault secrets |
just pubnix-dev-up |
Start Vagrant dev VM |
just pubnix-dev-down |
Stop Vagrant dev VM |
just pubnix-lint |
ansible-lint + pre-commit |
Three env file layers at the repo root:
| File | Purpose |
|---|---|
.env |
Shared secrets and base config |
.env.dev |
Dev-only overrides (ports, debug flags) |
.env.prod |
Production overrides |
Docker Compose always requires --env-file .env --env-file .env.dev (or .env.prod). The just recipes handle this automatically.
Two Compose override files handle environment-specific service config:
| File | Purpose |
|---|---|
compose.dev-override.yaml |
Dev overrides (bind mounts, debug ports, etc.) |
compose.prod-override.yaml |
Production overrides (restart policies, etc.) |
just chat-dev uses compose.yaml + compose.dev-override.yaml. just chat-prod uses compose.yaml + compose.prod-override.yaml.
Portal has its own .env at apps/portal/.env β see apps/portal/README.md for details.
| Concern | Location |
|---|---|
| Git | Root .gitignore |
| Commits | commitlint.config.cjs + .husky/commit-msg |
| Lint / format | .oxlintrc.json + .oxfmtrc.jsonc (Ultracite: Oxlint + Oxfmt) |
| Pre-commit | Husky + lint-staged (see below) |
| Turborepo | Root turbo.json; app overrides in apps/*/turbo.json |
| Dependency versions | pnpm-workspace.yaml catalog: section |
| CI | .github/workflows/ + .github/actions/setup-node-pnpm/ |
| Renovate | .github/renovate.json5 |
| Docker | infra/{chat,network,observability,tools}/*.yaml included by root compose.yaml |
| Glob | Tools |
|---|---|
*.{ts,tsx,js,jsx} |
Oxlint + Oxfmt |
*.py |
Ruff check --fix + format |
*.sh |
ShellCheck + shfmt |
Workflows in .github/workflows/:
portal-ci.ymlβ lint, type-check, build, test, knip, release for @atl/portalportal-deploy.ymlβ Docker build + SSH deploy (staging / production)portal-rollback.ymlβ manual rollback via workflow_dispatchportal-migrate.ymlβ manual database migrationportal-maintenance.ymlβ TODO-to-issue conversion on push to mainweb-deploy.ymlβ Alchemy / OpenNext deploy to Cloudflare Workers (PR previews + prod)chat-ci.ymlβ bridge lint / test / coverage, Docker builds for IRC / XMPP / bridgechat-web-ci.ymlβ lint, typecheck, turbo build for @atl/chat-webchat-web-deploy.ymlβ Alchemy / OpenNext deploy for atl.chat (prod)tools-ci.yml/tools-deploy.ymlβ @atl/tools-web + tools-manifest checks and deploypubnix-ci.ymlβ Ansible lint, Terraform validate, ShellCheck forinfra/sh(Molecule is local:just pubnix-molecule-test)docs-ci.ymlβ Mintlify validate + broken link checkcodeql.ymlβ CodeQL SAST (JS/TS, Python, Actions)dependency-review.ymlβ PR dependency vulnerability checkdependency-submission.ymlβ bridgeuv.lockβ GitHub dependency graphlint-infra.ymlβ actionlint, hadolint, shellcheck, shfmtpr-title.ymlβ conventional commit PR title validationpr-label.ymlβ auto-label PRs by changed paths
Reusable workflows: reusable-py-check.yml, reusable-docker-build.yml
Composite: .github/actions/setup-node-pnpm/ (Node + pnpm + frozen install).
Maintainers: required checks and merge queue β .github/REQUIRED_CHECKS.md; workflow metrics β .github/docs/CI_METRICS.md; harden-runner policy β .github/HARDEN_RUNNER.md.