# TB-006 — Authentik SSO at the edge **Status:** batches 1–3 deployed (2026-06-11) — batch 4 deferred **Your call:** **Done for now** (2026-06-11) — batch 4 (romm, router UI) later --- ## Talk first > **Stop.** Don't read Reference until we've talked. > In chat, say **"let's do TB-006"** or **"authentik on admin uis"**. **In one sentence:** Every site that already shows its own login screen should authenticate through Authentik instead — without breaking webhooks, API keys, or Overseerr/Plex for friends. **Why it came up:** LAN-only IP checks aren't the same as identity — Authentik is already running for famapp. ### Scope (decided 2026-06-10) **In:** All Caddy-proxied sites with an app login UI → Authentik (native OIDC/OAuth where supported; else `forward_auth` + disable local auth). **Out / untouched:** - **Overseerr** (`requests.ginnoir.com`) — friends use Plex accounts; leave as-is. - **Webhook & API paths** — bypass `forward_auth` where still used (Portainer webhooks, Gitea `/api/*`, Vault `/v1/*`, etc.). - **Static / no login** — 5etools, pf2e, ffttsystems, romhacks wiki files, etc. **Explicitly out (confirmed):** - **Obsidian/CouchDB** — tailnet-only (TB-005); LiveSync stays on CouchDB basic auth. - **Foundry / Foundry2** — players use Foundry accounts; no Authentik. - **Overseerr** — Plex login for friends. ### What we decided | | | |---|---| | **Decision** | Batches 1–3 done; batch 4 (romm, router UI) deferred — not now | | **Notes** | Batch 3 uses **native OIDC/OAuth** for ownCloud, FreshRSS, resume — not edge-only `forward_auth` (double-login). ntfy + `storage.j-costa.com` have **no Authentik**. Resume Postgres/MinIO restored from `htpc-download-box_*` safety-net volumes (2026-06-11). | | **Date** | 2026-06-11 (batch 3 complete) | ---
Reference (only open if we're doing it) ### Stack / files Caddyfile + Authentik UI + `stacks/authentik/scripts/` ### Rollout batches | Batch | Sites | Status | |-------|-------|--------| | 1 — Admin | portainer, code, registry-ui, vault, minio, homarr, uptime, backup/kopia, gitea, dbx, bookstack, plane | Deployed | | 2 — Media | sonarr, radarr, bazarr, prowlarr, tautulli, qbit, deluge, nzbget, whisparr, stash | Deployed | | 3 — Public + login | files, freshrss, ntfy, resume, storage.j-costa.com | Deployed (revised approach below) | | 4 — Other internal | romm, router UI | **Deferred** | | Skip | famapp (OIDC done), auth.ginnoir.com, overseerr, obsidian, foundry×2, static sites | — | ### Batch 3 — final approach (2026-06-11) | Site | Authentik method | Notes | |------|------------------|-------| | **files** (ownCloud) | Native OIDC | `setup-batch1-oidc.py` → `owncloud-web`; `oidc.config.php` via `scripts/apply-batch3-app-auth.sh`; Caddy `/.well-known/openid-configuration` rewrite | | **freshrss** | Native OIDC | Apache `mod_auth_openidc` (`OIDC_*` in notify stack); provider `freshrss` in Authentik — **Application must bind to OAuth2 provider**, not proxy | | **resume** | Native OAuth | `reactive-resume` provider; `OAUTH_*` in resume stack; `FLAG_DISABLE_EMAIL_AUTH=true` | | **ntfy** | **None** | Native ntfy login only; forward_auth breaks web UI | | **storage.j-costa.com** | **None** | Plain `reverse_proxy` — app writes to MinIO internally; public GETs for resume assets | **Resume data restore:** bind mounts were empty after stack split; live data copied from `htpc-download-box_postgres_data` + `htpc-download-box_minio_data` via `scripts/restore-resume-data.sh`. After restore, run `scripts/fix-resume-oauth-link.sh` (email_verified) and `scripts/fix-resume-jwks.sh` if sessions loop (JWKS encrypted with old `AUTH_SECRET`). **Ops scripts (batch 3):** - `scripts/run-batch1-oidc.py` wrapper → `run-batch1-oidc.sh` - `scripts/run-forward-auth-admin.sh` - `scripts/apply-batch3-app-auth.sh` — ownCloud oidc.config.php + FreshRSS `http_auth` patch (superseded by FreshRSS native OIDC) - `scripts/restore-resume-data.sh`, `scripts/fix-resume-oauth-link.sh`, `scripts/fix-resume-jwks.sh` ### Done when - [x] Batch 1 admin sites require Authentik before app UI loads (or native OAuth equivalent) - [x] Batch 2 media sites — forward_auth + external/disabled local auth (Tautulli excepted) - [x] Batch 3 — ownCloud, FreshRSS, resume single Authentik login (native OIDC/OAuth) - [x] ntfy — native auth only; Vigilant/famapp push unchanged - [x] storage.j-costa.com — no Authentik; public resume assets work - [x] Public resume pages viewable without Authentik - [x] ownCloud share links work without Authentik session - [ ] Batch 4 — romm, router UI (deferred) - [ ] Portainer OAuth configured in Settings → Authentication (provider created; UI step optional) - [ ] Plane OIDC configured in god-mode (optional; forward_auth accepted) - [ ] Reap orphan `htpc-download-box_*` volumes after trusting bind mounts (TB-011)