Protects /config, selective labdata, and nightly DB dumps; documents homelab improvement plan briefs.
1.4 KiB
1.4 KiB
TB-006 — Authentik on admin UIs
Status: not started
Your call: (unset — talk first)
Talk first
Stop. Don't read Reference until we've talked. In chat, say "let's do TB-006" or "authentik on admin uis".
In one sentence: Require Authentik login before Portainer, code-server, registry, etc.
Why it came up: LAN-only IP checks aren't the same as identity — Authentik is already running for famapp.
Questions
- Which admin sites do you actually use? (No point gating ones you never open)
- Portainer git webhooks must keep working — okay to test carefully?
- Do this for everything internal, or just the scary ones (Portainer, code, vault)?
Your options
| Option | Meaning |
|---|---|
| Do it | We're doing this — I'll implement or walk you through it |
| Later | Keep on the list, not now |
| Drop | Remove from plan — totally fine |
| Tweak | Change scope; tell me how |
What we decided
| Decision | |
| Notes | |
| Date |
Reference (only open if we're doing it)
Stack / files
Caddyfile + Authentik UI
If we do it — rough steps
- Authentik proxy provider + outpost
- Caddy forward_auth snippet
- Tier 1: portainer, code, registry-ui, vault, minio console
Done when
- Tier 1 sites require login
- Portainer webhooks still work