src/lib/dev-login-config.ts — startup assertion: throws if NODE_ENV=production + ENABLE_DEV_LOGIN=true, scoped to runtime (skipped during next build).
Container
scripts/migrate.mjs — runs Drizzle migrations against DATABASE_URL.
deploy/docker-entrypoint.sh — runs migrations then exec node server.js. Skip with RUN_MIGRATIONS=false.
Dockerfile — copies drizzle/, scripts/migrate.mjs, entrypoint into runner stage; ENTRYPOINT now points at the script.
Compose
deploy/compose.yaml — famapp now image: ${FAMAPP_IMAGE:-ghcr.io/ginnoir/famapp:latest} (build still works locally as fallback). Authentik pinned via AUTHENTIK_IMAGE_TAG (default 2024.12.3). New RUN_MIGRATIONS env passed through.
.env.production.example — documents FAMAPP_IMAGE, AUTHENTIK_IMAGE_TAG, RUN_MIGRATIONS.
CI/CD
.github/workflows/ci.yml — push/PR: typecheck + lint + format:check + build.
.github/workflows/release.yml — v* tag: build + push ghcr.io/ginnoir/famapp:vX.Y.Z, :X.Y, :latest to GHCR.
Docs
deploy/README.md — full deploy/rollback/release runbook.
CHANGELOG.md — release log seeded with an Unreleased entry.
docs/tasks/09-pre-deploy-checklist.md — task 09 reframed from one-shot removal to a recurring pre-deploy checklist.
STATUS.md — updated.
Verified: pnpm typecheck, pnpm format, pnpm build, and docker compose config all clean.
Task briefs
Each file here is a self-contained brief for a sub-session (typically Sonnet) to execute one chunk of work. Briefs assume the executor has read /CLAUDE.md — do not restate the stack or architecture there.
How to use a brief
- Read
/CLAUDE.mdfirst. - Read the task file end-to-end.
- Stop when all acceptance criteria pass. Do not bolt on extra scope.
- If a brief turns out to be wrong, update the brief in the same commit as the code.
Brief format
Every task file has these sections:
- Goal — one sentence.
- Why — what this unlocks; how it fits the larger plan.
- Depends on — task numbers that must be done first.
- Scope — bullet list of what to build.
- Out of scope — explicit non-goals to prevent drift.
- Acceptance criteria — checkable list. Done = all checked.
- Notes — gotchas, recommended libs, sketches.
Phase index
Phase 1 — Scaffold
- 01 — Repo init & tooling
- 02 — Next.js app skeleton
- 03 — Drizzle + Postgres setup
- 04 — Module loader & registry
- 05 — Compose stack & Caddy
- 06 — Authentik install + OIDC integration
- 07 — Household seeding & session
- 08 — Theming infrastructure (multi-theme + dark mode)
Phase 2 — Core modules
Phase 3 — Dashboard & UX
- 20 — Dashboard composition (single-dashboard MVP)
- 21 — Quick-add registry
- 22 — Activity log
- 25 — Multiple dashboards per user
- 26 — Customizable layout + widget configuration