Comment on Authelia + Bitwarden + other selfhosted stuff
JustEnoughDucks@feddit.nl 6 months agoIf you are looking for user management and registration, then Authelia is the wrong software for you.
Authelia is a very light weight security layer (and more recently SSO) that is only meant for few users precisely because it doesn’t have an onboarding process, dynamic access control, and more advanced features. Everything is done through config files and secrets. The admin has to manually create a file or plaintext lines with the user and password for each new user and restart the container.
Authentik is what you want if you want a bunch of users and new user sign up.
As for bitwarden/SSO, they should be fully separate. Otherwise you will likely break Bitwarden app and browser integration functionality.
You also do not want to run into the case where you don’t know your SSO password so you can’t get into bitwarden to find the password and you are screwed.
Bitwarden, TOTP method, and SSO should ideally be separate and you should be able to access your passwords and TOTP without requiring any password that is exclusively in the Bitwarden database.
Gooey0210@sh.itjust.works 6 months ago
There’s actually a point of doing that, it’s called lock down, but how to explain users how to do this 😆
For bitwarden functionality there are bypass rules on just a nginx location, or network somebody is reaching through
In general the situation reminds me using selfhosted email as a contact email for that hosting 😁 but I think in this case it’s less risk because I control the data
darcmage@lemmy.dbzer0.com 6 months ago
2 Factor Auth and Single Sign On with Authelia - Techno Tim
Authelia - Free, Open Source, Self Hosted authorization and authentication for your web applications - Awesome Open Source
Authenticate & Authorise Everything with Authelia - Jim’s Garage
That should give you a good start.