# LTX DeskWEB A standalone browser port of **LTX Athena / LTX Desktop**, for a separately managed LTX Desktop backend. Independent of the Athena Deck repository. Includes the existing project overview, Gen Space, media gallery and timeline editor; browser login, uploads with progress, native API forwarding, authenticated video playback/download and CPU thumbnails. **No Python inference environment, CUDA, model downloads on startup, GPU access or Docker socket.** This is the first web preview. Real Athena generation still needs an integration check; it is not yet a fully equivalent replacement for every desktop feature. Athena installation and operation: [deployment guide](docs/ATHENA_DEPLOYMENT.md). See [limitations and architecture](docs/ARCHITECTURE.md) and [provenance](docs/PROVENANCE.md). Future upstream updates: [Upgrade-Info (Deutsch)](docs/UPGRADE_INFO.md). Prebuilt-image installation: [Container Registry](docs/CONTAINER_REGISTRY.md) (published image for linux/amd64; no local build required). **Vollständige manuelle Anleitung (Deutsch): [Docker Pull, Labels, Volumes, Ports und Start](docs/DOCKER_INSTALLATION_DE.md).** Athena Decks zusätzliche **LTX Original**-Laufzeit: [Anbindung und Medien-Mounts](docs/LTX_ORIGINAL.md). ## Debian / Docker deployment Prerequisites: Docker Engine + Compose; a separately configured LTX Desktop backend; shared input/output directories; a free web port. The web image includes Node and ffmpeg only. It does not install or restart LTX, Deck, WireGuard or a GPU driver. 1. Clone `ssh://git@192.168.1.2:33/michael/LTX-DeskWEB.git`. 2. Copy `.env.example` to `.env` and set the backend address and shared directories. For Deck, use its common API port and enable **Video mode in Deck** yourself. The address must be reachable from the GUI container. `host.docker.internal` reaches the Docker host, but not a service bound only to host loopback. Do not change production bindings blindly; use an existing reachable Deck address. 3. Create `secrets/web-password` with your chosen password (at least 16 characters) and `secrets/ltx-token` with the Deck API token (or direct LTX token). Do not commit these files. Set file permissions so only the selected WEB_UID can read them. For a backend without authentication, the token file can be empty. 4. Ensure WEB_UID/WEB_GID can write the input directory and read the output directory. Use a shared group with the LTX process for inputs: a dedicated input directory with mode 2750, files 0640. Both containers need this group. Do not recursively change ownership of existing LTX data. 5. Set PUBLIC_ORIGIN to the browser URL, e.g. `http://127.0.0.1:8118` for an SSH tunnel. 6. Start: `docker compose up -d --build`. 7. Stop: `docker compose down`. Shared media is retained; LTX keeps running. Default UI port is 8118, bound only to server loopback. Example SSH tunnel from Mac: ```sh ssh -i /Users/mike_i386/.ssh/athena_key -o BatchMode=yes -N \ -L 8118:127.0.0.1:8118 root@192.168.1.212 ``` Then open http://127.0.0.1:8118. The Mac is only a browser/SSH client; deployment runs on Debian. This command assumes the container has actually been deployed. The Compose service has `io.athena-deck.managed=true` and `io.athena-deck.role=application`, matching Deck's existing filtered inventory for “Weitere Dienste”. Only this frontend is labeled; no other containers are adopted. The GUI has no authority to start/stop other containers. ## Development and verification Node 22+, npm, ffmpeg/ffprobe. `npm ci`, then: ```sh npm run typecheck npm test npm run build ``` For the web service set WEB_PASSWORD_FILE, LTX_TOKEN_FILE, LTX_BACKEND_URL, LOCAL_INPUT_DIR, BACKEND_INPUT_DIR, LOCAL_OUTPUT_DIR, BACKEND_OUTPUT_DIR and PUBLIC_ORIGIN, then `npm start`. It serves the built application on 127.0.0.1:8118. `npm run dev` serves Vite on 5188 and proxies HTTP to 8118; set PUBLIC_ORIGIN to http://127.0.0.1:5188 for that development session. Tests use temporary files and isolated HTTP servers, not production services. They check authentication, logout, token replacement, native API forwarding, validation errors, uploads, range playback, path/symlink restrictions and rate limits.