Six Workspace Apps, One Login

A lot of the software I use every day is a handful of Google apps. Project Anvil is my attempt to see what a self-hosted version of that set looks like when the pieces actually share a foundation. It has six apps: Drive, Docs, Video, Maps, Search and Mail.

One sign-in, shared packages

All six sit behind a single Keycloak login. They share packages in one monorepo: an auth package that handles OIDC with PKCE, a UI component package, an API client built around OpenAPI, and a notifications package over WebSocket. Writing the login once, as a package, is what keeps six apps from turning into six separate projects.

Each app uses the tool that fits

Drive pairs a Fastify API with PostgreSQL and MinIO, which speaks the S3 protocol. Docs uses Tiptap for the editor and Yjs for collaboration, served through a Hocuspocus WebSocket server, so edits merge as CRDTs. Maps renders vector maps with MapLibre GL, with OSRM for routing and Nominatim for place search. Search runs on Meilisearch with BM25 and vector embeddings. Mail speaks JMAP, the open email protocol defined in RFC 8620, against the Stalwart mail server. Every front end is Next.js 15, and the infrastructure starts with docker compose.

The demo links in the README are marked coming soon, so I will not claim more than the code. What exists today is the repository: six apps, shared auth, shared UI, and the services behind them. The point of the exercise is the shape. Privacy-first software is easier to run when the login, the design system and the notifications are shared, and each app is free to use the protocol that suits it. The repo is github.com/yethikrishna/project-anvil.

← back to the journal