Skip to content

feat: add Nginx Proxy Manager importer #66

Description

@RentnerKev

Summary

Provide a guided migration path from Nginx Proxy Manager (NPM) to RentnerProxy on the
v1.0.0-alpha.6 baseline.

Import scope

Import state only when it has a safe, explicit RentnerProxy equivalent:

  • Proxy Hosts and Redirect Hosts
  • domains, upstream targets, and enabled state
  • certificate associations when certificate/private-key material can be validated safely
  • Access Lists that map faithfully to existing Access Policies
  • relevant host settings with a clear typed equivalent

Do not translate arbitrary nginx Advanced Config into Caddy configuration. Unsupported semantics
must be reported as manual migration required, never silently ignored or guessed.

Alpha 6 baseline

The importer must preserve current host/certificate binding jobs, certificate candidate and
operation state, Access Policy invariants, trusted CA behavior, desired-state reconciliation,
RBAC, audit, and live administration behavior. It must not bypass normal service-layer validation
or write directly to runtime state.

Import workflow

  • parse and validate a real NPM export/fixture
  • present a preview before mutation
  • summarize supported items, conflicts, warnings, and unsupported settings
  • detect duplicate domains and collisions with existing RentnerProxy state
  • stage and apply changes transactionally where possible
  • return a durable import result with imported, skipped, and failed items plus reasons
  • reconcile through the normal typed controller path after commit

Safety

  • never overwrite existing state without explicit confirmation
  • validate certificates and private keys without exposing them to the browser or logs
  • enforce server-side RBAC and audit the import without secret material
  • avoid partial silent data loss; define rollback/retry semantics
  • keep arbitrary nginx directives out of the Caddy renderer

Acceptance criteria

  • Common NPM Proxy Hosts and Redirect Hosts import from real fixtures.
  • Preview and conflict detection work before mutation.
  • Unsupported settings are reported with actionable reasons.
  • Certificate/private-key and duplicate-domain failures are safe and redacted.
  • Import results accurately describe imported, skipped, and failed records.
  • Resulting state reconciles through the normal controller and works with Caddy.
  • Tests cover transactional failure, retry/idempotency, RBAC, audit, and no silent data loss.
  • Final UX/accessibility fix: complete beta accessibility and UX review #74 and security security: complete v1 beta security review #72 reviews include the importer journey.

Priority and sequencing

P1 / adoption feature. It can proceed independently after #64/#65 sequencing permits, but it
must reuse the established Access Policy and Alpha 6 certificate/runtime contracts. Required for
#75 unless explicitly deferred with rationale.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: databaseDatabase schema, migrations, and persistence.area: proxyProxy host configuration and request forwarding.enhancementNew feature or request

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions