view the rest of the comments
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
-
No spam posting.
-
Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.
-
Don't duplicate the full text of your blog or github here. Just post the link for folks to click.
-
Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).
-
No trolling.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
I’ve been looking into some kind of simple SSO to handle this. I’m tired of entering passwords (even if it’s all done by the password manager) a single authentication point with a single user would be great.
Keycloak and friend are way too complex. Ideally I would like to have something in my nginx reverse proxies that would handle authentication at that level and tell the final app what user is logged on in some safe way.
any oauth (I use kanidm) and oauth2-proxy solves that and now you can easily use passkeys to log into your intranet resources.
Never tried Authelia or Authentik but I've heard good things about them. I'm sure one of them will integrate with a reverse proxy.
Those solutions are still way too complex and corporate to my likes. :(
I'd like to encourage you to take another look at Authentik, it sounds like their Proxy Provider is exactly what you're looking for: https://docs.goauthentik.io/docs/providers/proxy/
Authentik can certainly get complex, but only if you want/need it to. It is by far the most user-friendly IDP solution I've found, especially for what it offers. Their docs also have step-by-step guides for how to integrate a lot of popular self-hosted apps.
Only takes a couple mins to spin up a test environment using their Docker compose file: https://docs.goauthentik.io/docs/installation/docker-compose
Thanks, I’ll have another look.
For sure! If you do end up taking it for a spin, feel free to ping me with any questions.
Too much pieces that can potentially break. I've been looking at http://nginx.org/en/docs/http/ngx_http_auth_request_module.html and there's this https://github.com/kendokan/phpAuthRequest that is way more self contained and simple to maintain long term. The only issue I'm facing with that solution is that I'm yet capable of passing a token / username in a header to the final application.
Is there a passkey setup that's easy to self host? I think passkeys with a backup would be best.
I’ve been looking at https://github.com/stonith404/pocket-id?ref=selfh.st
Hmm this is actually interesting, passkeys would indeed make things simpler.