posted in Selfhosted
Auth apps
What auth apps do you use ive seen authelia, authentik, keycloack but whats overall the best
posted in Selfhosted
Auth apps
What auth apps do you use ive seen authelia, authentik, keycloack but whats overall the best
There is no “overall best”, just one that works best for you. I like to keep mine on a managed encrypted server so I use Ente Auth. I think Proton has one as well.
Replying to @artyom@piefed.social
I think they are talking about sso, not 2fa.
Replying to @DrunkAnRoot@sh.itjust.works
I ended up at PocketID. Authentik (and I think authelia too) is good but way more complicated than what I needed for a homelab. A lot of people like VoidAuth, but i didn’t care for the visual style. Don’t think I ever tried keycloak.
Replying to @AbidanYre@lemmy.world
Voidauth looks intresting. Thanks!
Replying to @AbidanYre@lemmy.world
I second PocketID if all you’re looking for is Passkeys + forward-auth. The others are overkill.
Replying to @AbidanYre@lemmy.world
my mates and i are also hosting pocketID. it’s solid stuff
I use Authentik - works well - but I’m prepping to switch to Authelia for the config-based setup.
I updated Authentik across 2 versions (they did 2 month-long supported tags, missed one; now they do 3 month-long supported tags) and it destroyed itself. Had to recover the DB from a backup (and then step through the version I tried to skip), and while I was doing that I was like “wait why does this have only a DB? Should just be a config file cause that’s all the depth I do with it” and lo that’s what Authelia is.
Authentik is audited and Authelia has not been. Initially while I chose Authentik. But config-file robustness in the face of Authentik’s GUI-setup DB imploding swayed me not to care, it’d take so long and be so tedious to redo all my proxies and auths through the GUI. Plus I always forget what to click in the GUI when I come back to add some new program in 4 months.
Replying to @DrunkAnRoot@sh.itjust.works
I personally run authelia. I prefer the config file over a gui where i have to click everything together. For the actual user storage i got lldap.
But my requirements a possibly different to yours, my main focus was no docker and no javascript backend.
Keycloak is definetly overkill for a homelab. Both in effort to get it to run, and maintaining it.
Replying to @DrunkAnRoot@sh.itjust.works
It has a modest UI for end-users to handle self-service scenarios, and an app portal for OpenID Connect configured applications.
The backend is fully CLI based.
It is very robust and performant, built on Rust.
Yet very much in active development, so do not expect full parity with commercial alternatives at a feature level.
I run it to provision users for my home Linux devices and it supports offline login, my Homelab servers, and my self-hosted web applications through OIDC.
A nice ‘one stop shop’ for my purposes.
EDIT: Actually their comparison page might be a worthwhile read considering your question OP.
I like kanidm too ! And I think that something that could be really powerful would be to have the local client daemon provide a token for user applications (browsers with an extension, dedicated app…).
Replying to @haroldfinch@feddit.nl
Also switched to Kanidm, and using the Kubernetes operator someone made have made it easy to configure also.
I have custom resources that create HTTPRoutes and then protect public traffic with Kanidm by creating a a OAuthClient per site.
Chefs kiss.
Replying to @DrunkAnRoot@sh.itjust.works
The best is pretty subjective and partially relies on what you need.
Keycloak is one of the most feature complete ones I think.
I’ve used authelia before and liked it, but it had a very bare UI and everything was done through config files which forced redeploys on changes. It wasn’t ideal for me.
I’m currently trying out voidauth. It’s got some more Ui features compared to authelia and can apparently also simulate some Active Directory queries to forward your users to third party tools for provisioning ( unless I saw that wrong, I haven’t tested any yet ).
Authentik looked nice, but I haven’t gotten around to checking that one out yet.
Replying to @DrunkAnRoot@sh.itjust.works
Authentik is great, super versatile, if not a bit of effort to get it set up initially
Replying to @DrunkAnRoot@sh.itjust.works
I use my Nextcloud instance as a OIDC provider for all my other apps.
Same. Would be cool if Nextcloud could also act as a LDAP server for apps that don’t support OIDC.
Replying to @DrunkAnRoot@sh.itjust.works
"The best" depends on what you really need.
Authentik and Authelia are two of the top most quoted solutions, but they aim to be an "everything in one" package, with tons of features a simple homelab will rarely need. They're aimed more at enterprise-like setups.
On the other end of the spectrum you have e.g. Pocket-ID, which only does OIDC by itself (you can hook up an LDAP server as user database though); but that tradeoff means it uses little to no CPU time, and, in my experience, around 130MB RAM. Given RAM is getting more expensive than gold, one needs to consider memory footprint, especially for older homelab setups. We can't all be running 256GB nodes after all.
So instead of hunting the mythical "best" solution, decide what features you really need, grab a list of providers that cover those features, and compare them to see what fits your needs best.
Replying to @DrunkAnRoot@sh.itjust.works
I used authentik first as it was suggested by a friend with whom we are sharing the vps, and so I kept using that also for another personal vps.
It is a good combination of robustness and flexibility for me, plus we needed a user dashboard or at least a list of apps. Custom workflows, blueprints and stuff were a bit of a pain to understand, so I just copy them between the two install I have because I keep forgetting how everything works. It’s also quite resource-heavy, so I might try something different in the future.
I like Ente, and according to their docs you can spin up your own host.
Replying to @DrunkAnRoot@sh.itjust.works
Authentik
Openbao -> keycloak with a TOTP on new devices
Replying to @DrunkAnRoot@sh.itjust.works
I’ll second Pocket-ID.
I originally had Authentik setup. It worked well enough. However, their packaging constantly broke and no-one seemed to care.
Switched to Pocket-ID and won’t be looking back. Passkey-based OAuth was all I wanted anyways. (Also, the logins themselves are noticeably faster!)
Replying to @smiletolerantly@awful.systems
I would third this. I only came across pocket id a few days ago and hooked it up to a few containers for testing and it’s really impressed me.
Replying to @DrunkAnRoot@sh.itjust.works
f-droid.orgAegis Authenticator | F-Droid - Free and Open Source Android App RepositoryFree, secure and open source 2FA app to manage tokens for your online servicesReplying to @SeaDawg@lemmy.world
Same. I tried a few other options from F-Droid/Droidify and Aegis was the easiest for me.
Replying to @technocrit@lemmy.dbzer0.com
I think OP means server side auth apps
Replying to @SeaDawg@lemmy.world
Yep switched to aegis a year ago. Works great.
Replying to @DrunkAnRoot@sh.itjust.works
The one built in to Caddy for anything that doesn’t really have authentication. Everything else uses its own and i only have a couple services accessible outside the home.
Most everything is only accessible within my home and my guest wifi is on its own vLAN. Even then I’m the only person who actually uses most things that I setup.
Replying to @DrunkAnRoot@sh.itjust.works
I use Stratum on android and GNOME Authenticator on Linux desktop
GitHubGitHub - stratumauth/app: 📱 Two-Factor Authentication (2FA) client for Android + Wear OS📱 Two-Factor Authentication (2FA) client for Android + Wear OS - stratumauth/appReplying to @DrunkAnRoot@sh.itjust.works
Developer of VoidAuth here; if you decide to give it a try let me know if you run into any issues during setup, or have any feedback!
Replying to @notquitenothing@sh.itjust.works
I have been loving it so far and got immich and going to add others and under it soon.
Replying to @notquitenothing@sh.itjust.works
I did try it out and its great! One issue i had is after logging in it says not found however
Replying to @notquitenothing@sh.itjust.works
Any plans to support FreeBSD in the future? Or mainly focusing on a docker solution?
Replying to @notquitenothing@sh.itjust.works
Using VoidAuth here, really good software and documentation. Thanks for that piece of freedom !
Replying to @DrunkAnRoot@sh.itjust.works
Its really stange seeing kanidm basically never mentioned in these types of threads dispite how perfect it is for selfhosting: great documentation, incredibly easy to get setup, easy to make a custom themed/setup auth page, lets users name themselves how they prefer instead of requiring “firstname lastname” (why does every service need a lastname when it never gets used?)
Authelia and authentik are cool but are way more complex then you need for authenticating a couple services and for me at least feel “bloated” for my usecase
Replying to @lilith267@lemmy.blahaj.zone
Its really stange seeing kanidm basically never mentioned in these types of threads
I think the no-nonsense, minimal hype and visual contribute to that. Also, the name didn’t automatically conjure “authentication” like authentik/authelia/pocket-id does, so maybe people just gloss over it.
I’ll probably tried this over now that I’m aware. Thanks for sharing.
Replying to @DrunkAnRoot@sh.itjust.works
I love authentik
Now it needs no middleware. Just authentik and postgres
The ui is great, features are great, great api. Super easy to self host and manage
Open source, small dedicated team. Can’t ask for more
Replying to @DrunkAnRoot@sh.itjust.works
I use authentik. It’s probably fairly easy to set up if you use their docker-compose, but I run it as rootless podman, which took a little work to get it converted to a quadlet pod. But now that it’s set up, it works great and handles a variety of self-hosted apps that use saml, oidc, ldap, and forward-auth. It’s one of the few options that handles all the different authentication types natively. I also set up passkeys and standard two-factor time codes.
There are some very helpful authentik youtube tutorials by Cooptonian.
Replying to @The_Zen_Cow_Says_Mu@infosec.pub
Would you be willing to share that Quadlet? I also run rootless Podman on my main VPS and I’m approaching that point where I have enough services to justify a dedicated IDM solution.
Replying to @jabberwock@lemmy.dbzer0.com
authentik.pod [Pod] PodName=authentik PublishPort=9000:9000 PublishPort=9443:9443 PublishPort=3389:3389 PublishPort=6636:6636 authenik_db.container [Unit] Description=authentik_db Wants=network-online.target After=network-online.target [Service] Restart=always [Container] EnvironmentFile=.env Pod=authentik.pod ContainerName=authentik_db Image=docker.io/library/postgres:17-alpine AutoUpdate=registry Volume=authentik_db.volume:/var/lib/postgresql/data:Z Environment=POSTGRES_USER=authentik Environment=POSTGRES_DB=authentik [Install] WantedBy=default.target authentik_server.container [Unit] Description=authentik_server Wants=network-online.target After=network-online.target [Service] Restart=always [Container] EnvironmentFile=.env Pod=authentik.pod ContainerName=authentik_server Image=ghcr.io/goauthentik/server:2026.5 Exec=server AutoUpdate=registry Environment=AUTHENTIK_POSTGRESQL__HOST=authentik_db Environment=AUTHENTIK_POSTGRESQL__USER=authentik Environment=AUTHENTIK_POSTGRESQL__NAME=authentik Volume=authentik_media.volume:/data/media:U,Z Volume=authentik_data.volume:/data:U,Z Volume=authentik_templates.volume:/templates:U,Z [Install] WantedBy=default.target authentik_worker.container [Unit] Description=authentik_worker Wants=network-online.target After=network-online.target [Service] Restart=always [Container] EnvironmentFile=.env Pod=authentik.pod ContainerName=authentik_worker Image=ghcr.io/goauthentik/server:2026.5 Exec=worker AutoUpdate=registry Environment=AUTHENTIK_POSTGRESQL__HOST=authentik_db Environment=AUTHENTIK_POSTGRESQL__USER=authentik Environment=AUTHENTIK_POSTGRESQL__NAME=authentik Environment=AUTHENTIK_LISTEN__HTTP=[::]:9001 Environment=AUTHENTIK_LISTEN__METRICS=[::]:9301 Volume=authentik_media.volume:/data/media:U,Z Volume=authentik_data.volume:/data:U,Z Volume=authentik_templates.volume:/templates:U,Z Volume=authentik_certs.volume:/certs:U,Z Volume=/run/user/1000/podman/podman.sock:/var/run/docker.sock:z [Install] WantedBy=default.target authentik_ldap.container [Unit] Description=authentik_ldap Wants=network-online.target After=network-online.target [Service] Restart=always [Container] Pod=authentik.pod ContainerName=authentik_ldap Image=ghcr.io/goauthentik/ldap:2026.5 AutoUpdate=registry Environment=AUTHENTIK_HOST=https://authentik.mydomain.com/ Environment=AUTHENTIK_INSECURE="false" Environment=AUTHENTIK_TOKEN=wowthisisquitethelongandsafetokenthatnoonewilleverhack [Install] WantedBy=default.target ````___`
Replying to @The_Zen_Cow_Says_Mu@infosec.pub
You a real one, much appreciated
Replying to @DrunkAnRoot@sh.itjust.works
I use kanidm because the footprint is lower than the alternatives you mention, and it’s written in Rust.