I’ve got 2 hosts. A slightly more powerful sff tower running my media stuff and arr services. VPN gateway that the arr’s route through etc. I have a raspberry pi that’s running my Adblocker, reverse proxy, Wireguard some stuff for a small business I run… So a website platform and invoice/time logging system.

Anyway these various services are mostly secured by password. Only the website is accessible externally. Any other service is only accessible internally or via Wireguard VPN.

Just at that stage asking myself “where do I draw the line?”

Would be nice to centrally manage logins but I suspect the mismash of services I run wont all support SSO.

I think In today it must be near 25-30 services / containers.

Authentik looks good. But wondering whether it’s just going to be something I only use a fraction of and “a bit overkill” for my needs?

  • thecomputerguy7@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    I was actually looking at Keycloak myself due to needing something more “professional looking” and something more “enterprise-y” which translates to our security guy hearing more about keycloak than authentik. They all should work somewhat the same though, and have the same end functionality.

    I’m not sure of the technical stuff, but I believe you could use something like Oauth2 Proxy in front of your services, but that may or may not be more trouble than it’s worth, assuming it works the way I think it does. I could be wrong.