What is this about
Tracking issue for six independent app additions to the Cozystack catalog. Per the "single component" guidance, each is arguably its own scoped feature (new helm chart/app definition), and one of them (SLES read-only RDP) touches on access-control design that likely needs a proposal. Filing as a tracking issue with items broken out — happy to split into individual issues myself if maintainers prefer.
Context
Cozystack ships a curated app catalog for tenant workloads, but several commonly requested categories of self-hosted tools are missing today, forcing users to add them manually outside Cozystack's managed lifecycle or skip them entirely:
-
OpenCloud — lighter/more modern alternative to Nextcloud for file sync/collaboration. Reference community Helm chart: https://github.com/Tim-herbie/opencloud-helm. Would follow the same integration pattern as the existing Nextcloud app (values via app CRD/UI, storage class integration, ingress/TLS wiring).
-
NetBox — no built-in way to track hardware/network infrastructure (IPAM/DCIM). Would need persistent Postgres/Redis backing (reusing Cozystack's managed DB primitives where possible) plus standard ingress.
-
GitLab (CE) — no self-hosted Git platform with CI/CD available out of the box. Needs persistent storage for repos/CI artifacts and integration with Cozystack's ingress/cert management.
-
Browser-based VS Code — no "VS Code in the browser" style workspace (à la coder.com/code-server) for quick in-cluster dev environments. Per-tenant/per-user deployable, accessible via browser through Cozystack ingress. Adding OpenCode (for LLM-assisted coding) alongside would also be valuable.
-
SLES image with read-only RDP — no image/app for remote desktop with fine-grained access control, where view-only access (no copy/clipboard, no permission changes) can be granted to some users/groups while others get full edit/manage access. This has real access-control design implications — how "view-only, no-copy" is enforced at the RDP/session level, and how it maps onto Cozystack's user/group model — so this specific item likely needs a short design note/proposal before implementation.
-
NetBird — no built-in mesh VPN/overlay networking option between tenant resources.
All six are proposed as first-class Cozystack catalog apps (Helm charts/app definitions), rather than manual out-of-band deployments, to get Cozystack-managed lifecycle, storage provisioning, ingress/TLS, and UI integration — consistent with how Nextcloud is currently handled.
Alternatives considered and rejected:
- Manual/out-of-band deployment for these tools: loses Cozystack lifecycle, storage, ingress, and UI integration benefits.
- Nextcloud-only, skip OpenCloud: rejected, since OpenCloud is wanted as a separate lighter-weight catalog option, not a replacement.
- Using the generic "custom app" path for GitLab/NetBox/etc.: works as a stopgap but doesn't give first-class catalog visibility, versioned upgrades, or a native config surface.
What would help
- Feedback on whether to split this into six separate issues now (one per app), or keep it as a single umbrella/tracking issue with sub-items — I'm happy to do the split myself if that's preferred.
- A decision on whether the SLES read-only RDP access-control mechanism needs a full design proposal or just a short design discussion before an issue is opened for it.
- Any prioritization signal on which of the six are most wanted, to help sequence individual issues/PRs.
What is this about
Tracking issue for six independent app additions to the Cozystack catalog. Per the "single component" guidance, each is arguably its own scoped feature (new helm chart/app definition), and one of them (SLES read-only RDP) touches on access-control design that likely needs a proposal. Filing as a tracking issue with items broken out — happy to split into individual issues myself if maintainers prefer.
Context
Cozystack ships a curated app catalog for tenant workloads, but several commonly requested categories of self-hosted tools are missing today, forcing users to add them manually outside Cozystack's managed lifecycle or skip them entirely:
OpenCloud — lighter/more modern alternative to Nextcloud for file sync/collaboration. Reference community Helm chart: https://github.com/Tim-herbie/opencloud-helm. Would follow the same integration pattern as the existing Nextcloud app (values via app CRD/UI, storage class integration, ingress/TLS wiring).
NetBox — no built-in way to track hardware/network infrastructure (IPAM/DCIM). Would need persistent Postgres/Redis backing (reusing Cozystack's managed DB primitives where possible) plus standard ingress.
GitLab (CE) — no self-hosted Git platform with CI/CD available out of the box. Needs persistent storage for repos/CI artifacts and integration with Cozystack's ingress/cert management.
Browser-based VS Code — no "VS Code in the browser" style workspace (à la coder.com/code-server) for quick in-cluster dev environments. Per-tenant/per-user deployable, accessible via browser through Cozystack ingress. Adding OpenCode (for LLM-assisted coding) alongside would also be valuable.
SLES image with read-only RDP — no image/app for remote desktop with fine-grained access control, where view-only access (no copy/clipboard, no permission changes) can be granted to some users/groups while others get full edit/manage access. This has real access-control design implications — how "view-only, no-copy" is enforced at the RDP/session level, and how it maps onto Cozystack's user/group model — so this specific item likely needs a short design note/proposal before implementation.
NetBird — no built-in mesh VPN/overlay networking option between tenant resources.
All six are proposed as first-class Cozystack catalog apps (Helm charts/app definitions), rather than manual out-of-band deployments, to get Cozystack-managed lifecycle, storage provisioning, ingress/TLS, and UI integration — consistent with how Nextcloud is currently handled.
Alternatives considered and rejected:
What would help