Skip to content

Add HaVeWa 0.3.0 - #6040

Open
fgilde wants to merge 2 commits into
getumbrel:masterfrom
fgilde:havewa
Open

fgilde wants to merge 2 commits into
getumbrel:masterfrom
fgilde:havewa

Conversation

@fgilde

@fgilde fgilde commented Sep 1, 2026

Copy link
Copy Markdown

HaVeWa 0.3.0

Property-management software for rental and HOA (WEG, the German form of condominium ownership)
administration, with its own PostgreSQL. Properties, units, people and meters; leases with stepped
and index rent and deposits; charges, payments, open items, SEPA mandates and dunning;
service-charge statements with a BetrKV allocation engine; co-ownership shares, economic plan, HOA
fees, annual statement and reserves; owners' meetings with agenda, voting and the resolution
collection; documents; maintenance tickets with workflow and time tracking; tenant and owner
portals; camt.053 import and DATEV/SEPA export. Multi-tenant, role-based, bilingual (German and
English), with a REST API and an MCP server so an agent works under the same permissions a person
has.

Package

havewa/
  umbrel-app.yml
  docker-compose.yml
  exports.sh
  data/storage/.gitkeep
  data/db/.gitkeep

Two services behind app_proxy (port: 3210 → container 3000): the app and its PostgreSQL. Both
bind-mount under ${APP_DATA_DIR}/data — storage for documents and generated statements, db for
the database. No host paths, no Docker socket, no privileged mode, no capabilities, no raw published
ports, no dependencies.

exports.sh derives two independent secrets with derive_entropy: the session secret that signs the
logins and the database password. Keeping them apart is the point — one value for both would tie a
session forgery to a database compromise.

Credentials

None. The first visit opens a setup wizard that creates the administrator and the management
company, so defaultUsername and defaultPassword are empty. The app can also seed a demo data set
with a known login, and this package deliberately does not.

Testing

  • npm run lint:apps -- havewa --check-images: clean.
  • docker buildx imagetools inspect on both pinned digests lists linux/amd64 and linux/arm64.
    The arm64 image is new: the project's CI builds each architecture on a runner of that architecture
    and merges the digests, because next build under emulation does not finish in a CI run.
  • The app and postgres:16.10-alpine were started together with exactly this environment, network
    and volume layout: the schema migrates on first start (43 tables), the app answers on the mapped
    port, the setup page appears rather than a login with default credentials, and a restart against
    the same volumes keeps the data.

Screenshots and logo

Logo: https://raw.githubusercontent.com/fgilde/hausverwaltung/main/icon.png

Dashboard
Service-charge statement
HOA

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant