Comment on Self Hosting- Security recommendations
Noggog@programming.dev 1 week ago
I’ve had good success spinning up an authentik instance, and having my reverse proxy hit it first before it routes to the actual app. Puts another security layer in front in case sonarr itself has an issue, for ex.
Caddy snippet ` handle {$host} { route { # always forward outpost path to actual outpost reverse_proxy /outpost.goauthentik.io/* authentik-server-1:9000
# forward authentication to outpost forward_auth authentik-server-1:9000 { uri /outpost.goauthentik.io/auth/caddy # capitalization of the headers is important, otherwise they will be empty copy_headers X-Authentik-Username X-Authentik-Groups X-Authentik-Entitlements X-Authentik-Email X-Authentik-Name X-Authentik-Uid X-Authentik-Jwt X-Authentik-Meta-Jwks X-Authentik-Meta-Outpost X-Authentik-Meta-Provider X-Authentik-Meta-App X-Authentik-Meta-Version } reverse_proxy {this_host_or_ip}:{this_port} }
} `
Works for 70% of apps. Nice to slap on when you can
jacksilver@lemmy.world 1 week ago
I’ve been tempted by things like authentik, but how does that work for things like apps and tv sticks (roku / Chromecast)? Or does it really only work for browser based applications?
Noggog@programming.dev 1 week ago
Yeah, will not work for everything. Things with actual phone/TV apps generally dont like it. That being said, it still helps for a large swath of my setup
fonix232@fedia.io 1 week ago
It depends on the app. You can use Authentik as an OIDC provider and allow apps that offer OIDC to log in through that - and that usually works for TV sticks and such.