Make getting-started.sh the single entry point for all self-hosted
deployments. The wizard now asks two independent questions - identity
provider (built-in vs standalone OIDC) and architecture (combined
netbird-server vs separate management/signal/relay containers) - and
renders the matching Docker Compose deployment with full reverse-proxy
parity (built-in Traefik, external Traefik, Nginx, NPM, Caddy, manual).
Highlights:
- setup.env contract: every wizard answer is persisted; --non-interactive
re-renders idempotently from the file (IaC), --render-only generates
without starting services. Secrets are generated once and appended so
re-renders never rotate them.
- Split architecture renders a modern management.json (embedded Dex or
external OIDC via PKCE), drops coturn entirely (the relay container
serves STUN via NB_ENABLE_STUN), and optionally adds a PostgreSQL
container when the postgres engine is selected without a DSN.
- The standalone-IdP path is framed around its real differentiator:
multi-account support. The built-in IdP supports external SSO
connectors but enforces single account mode.
- configure.sh, getting-started-with-dex.sh and
getting-started-with-zitadel.sh print deprecation banners; their
templates are frozen pending removal.
- New tests/test-render.sh validates all 8 combos (JSON validity,
compose config, idempotent re-render, combined+external rejection)
and runs in CI as the test-render-matrix job.