Add Recyclarr to the media stack, pin database/object-store/Caddy/Vault images with Watchtower disabled, expose JDownloader at jd.ginnoir.com, and restrict minio/homarr/docs to internal_only. Mark TB-002–004 and TB-033 complete; bundle batch-3 OIDC env for FreshRSS, ownCloud, and Reactive Resume.
4.8 KiB
TB-006 — Authentik SSO at the edge
Status: batches 1–3 deployed (2026-06-11) — batch 4 deferred
Your call: Done for now (2026-06-11) — batch 4 (romm, router UI) later
Talk first
Stop. Don't read Reference until we've talked. In chat, say "let's do TB-006" or "authentik on admin uis".
In one sentence: Every site that already shows its own login screen should authenticate through Authentik instead — without breaking webhooks, API keys, or Overseerr/Plex for friends.
Why it came up: LAN-only IP checks aren't the same as identity — Authentik is already running for famapp.
Scope (decided 2026-06-10)
In: All Caddy-proxied sites with an app login UI → Authentik (native OIDC/OAuth where supported; else forward_auth + disable local auth).
Out / untouched:
- Overseerr (
requests.ginnoir.com) — friends use Plex accounts; leave as-is. - Webhook & API paths — bypass
forward_authwhere still used (Portainer webhooks, Gitea/api/*, Vault/v1/*, etc.). - Static / no login — 5etools, pf2e, ffttsystems, romhacks wiki files, etc.
Explicitly out (confirmed):
- Obsidian/CouchDB — tailnet-only (TB-005); LiveSync stays on CouchDB basic auth.
- Foundry / Foundry2 — players use Foundry accounts; no Authentik.
- Overseerr — Plex login for friends.
What we decided
| Decision | Batches 1–3 done; batch 4 (romm, router UI) deferred — not now |
| Notes | Batch 3 uses native OIDC/OAuth for ownCloud, FreshRSS, resume — not edge-only forward_auth (double-login). ntfy + storage.j-costa.com have no Authentik. Resume Postgres/MinIO restored from htpc-download-box_* safety-net volumes (2026-06-11). |
| Date | 2026-06-11 (batch 3 complete) |
Reference (only open if we're doing it)
Stack / files
Caddyfile + Authentik UI + stacks/authentik/scripts/
Rollout batches
| Batch | Sites | Status |
|---|---|---|
| 1 — Admin | portainer, code, registry-ui, vault, minio, homarr, uptime, backup/kopia, gitea, dbx, bookstack, plane | Deployed |
| 2 — Media | sonarr, radarr, bazarr, prowlarr, tautulli, qbit, deluge, nzbget, whisparr, stash | Deployed |
| 3 — Public + login | files, freshrss, ntfy, resume, storage.j-costa.com | Deployed (revised approach below) |
| 4 — Other internal | romm, router UI | Deferred |
| Skip | famapp (OIDC done), auth.ginnoir.com, overseerr, obsidian, foundry×2, static sites | — |
Batch 3 — final approach (2026-06-11)
| Site | Authentik method | Notes |
|---|---|---|
| files (ownCloud) | Native OIDC | setup-batch1-oidc.py → owncloud-web; oidc.config.php via scripts/apply-batch3-app-auth.sh; Caddy /.well-known/openid-configuration rewrite |
| freshrss | Native OIDC | Apache mod_auth_openidc (OIDC_* in notify stack); provider freshrss in Authentik — Application must bind to OAuth2 provider, not proxy |
| resume | Native OAuth | reactive-resume provider; OAUTH_* in resume stack; FLAG_DISABLE_EMAIL_AUTH=true |
| ntfy | None | Native ntfy login only; forward_auth breaks web UI |
| storage.j-costa.com | None | Plain reverse_proxy — app writes to MinIO internally; public GETs for resume assets |
Resume data restore: bind mounts were empty after stack split; live data copied from htpc-download-box_postgres_data + htpc-download-box_minio_data via scripts/restore-resume-data.sh. After restore, run scripts/fix-resume-oauth-link.sh (email_verified) and scripts/fix-resume-jwks.sh if sessions loop (JWKS encrypted with old AUTH_SECRET).
Ops scripts (batch 3):
scripts/run-batch1-oidc.pywrapper →run-batch1-oidc.shscripts/run-forward-auth-admin.shscripts/apply-batch3-app-auth.sh— ownCloud oidc.config.php + FreshRSShttp_authpatch (superseded by FreshRSS native OIDC)scripts/restore-resume-data.sh,scripts/fix-resume-oauth-link.sh,scripts/fix-resume-jwks.sh
Done when
- Batch 1 admin sites require Authentik before app UI loads (or native OAuth equivalent)
- Batch 2 media sites — forward_auth + external/disabled local auth (Tautulli excepted)
- Batch 3 — ownCloud, FreshRSS, resume single Authentik login (native OIDC/OAuth)
- ntfy — native auth only; Vigilant/famapp push unchanged
- storage.j-costa.com — no Authentik; public resume assets work
- Public resume pages viewable without Authentik
- ownCloud share links work without Authentik session
- Batch 4 — romm, router UI (deferred)
- Portainer OAuth configured in Settings → Authentication (provider created; UI step optional)
- Plane OIDC configured in god-mode (optional; forward_auth accepted)
- Reap orphan
htpc-download-box_*volumes after trusting bind mounts (TB-011)