# TB-006 — Authentik on admin UIs **Status:** not started **Your call:** _(unset — talk first)_ --- ## Talk first > **Stop.** Don't read Reference until we've talked. > In chat, say **"let's do TB-006"** or **"authentik on admin uis"**. **In one sentence:** Require Authentik login before Portainer, code-server, registry, etc. **Why it came up:** LAN-only IP checks aren't the same as identity — Authentik is already running for famapp. ### Questions 1. Which admin sites do you actually use? (No point gating ones you never open) 2. Portainer git webhooks must keep working — okay to test carefully? 3. Do this for everything internal, or just the scary ones (Portainer, code, vault)? ### Your options | Option | Meaning | |--------|---------| | **Do it** | We're doing this — I'll implement or walk you through it | | **Later** | Keep on the list, not now | | **Drop** | Remove from plan — totally fine | | **Tweak** | Change scope; tell me how | ### What we decided | | | |---|---| | **Decision** | | | **Notes** | | | **Date** | | ---
Reference (only open if we're doing it) ### Stack / files Caddyfile + Authentik UI ### If we do it — rough steps 1. Authentik proxy provider + outpost 2. Caddy forward_auth snippet 3. Tier 1: portainer, code, registry-ui, vault, minio console ### Done when - [ ] Tier 1 sites require login - [ ] Portainer webhooks still work