mirror of
https://github.com/allaunthefox/Research-Stack.git
synced 2026-07-31 03:05:21 +00:00
263 lines
7.9 KiB
Markdown
263 lines
7.9 KiB
Markdown
# Authentik Setup Guide — Research Stack
|
|
|
|
## Status: 2026-05-21
|
|
|
|
Authentik is deployed in LXC 100 with local PostgreSQL 16 and Redis.
|
|
|
|
### Current State
|
|
|
|
- **URL**: `https://auth.researchstack.info` (Caddy reverse proxy -> `192.168.100.100:9000`)
|
|
- **Default admin**: `akadmin` / `authentik` (CHANGE THIS IMMEDIATELY)
|
|
- **Backend**: PostgreSQL 16 in Docker (`authentik-postgresql`)
|
|
|
|
### Step 1: First Login & Bootstrap
|
|
|
|
1. Open `https://auth.researchstack.info` (use SSH tunnel if netcup ports blocked)
|
|
2. Login with `akadmin` / `authentik`
|
|
3. Go to **Admin Interface** (top right)
|
|
4. Navigate to **Directory -> Users -> akadmin**
|
|
5. Change password to a strong unique password
|
|
6. (Optional) Add your email for recovery
|
|
|
|
### Step 2: Create Forward Auth Provider (for Caddy)
|
|
|
|
This protects `vault.researchstack.info` and future ARR services.
|
|
|
|
1. In Admin Interface, go to **Applications -> Providers**
|
|
2. Click **Create**
|
|
3. Select **Proxy Provider**
|
|
4. Fill in:
|
|
- **Name**: `caddy-forward-auth`
|
|
- **Authorization flow**: `default-provider-authorization-implicit-consent`
|
|
- **Internal host**: `http://192.168.100.100:9100` (vault service)
|
|
- **External host**: `https://vault.researchstack.info`
|
|
- **Mode**: `Forward domain`
|
|
5. Save
|
|
|
|
### Step 3: Create Application
|
|
|
|
1. Go to **Applications -> Applications**
|
|
2. Click **Create**
|
|
3. Fill in:
|
|
- **Name**: `Credential Vault`
|
|
- **Slug**: `vault`
|
|
- **Provider**: `caddy-forward-auth`
|
|
4. Save
|
|
|
|
### Step 4: Configure Outpost
|
|
|
|
1. Go to **Applications -> Outposts**
|
|
2. The **authentik Embedded Outpost** is already running
|
|
3. Edit it, add `Credential Vault` to the list of applications
|
|
4. Save
|
|
|
|
The outpost listens on `192.168.100.100:9000` (same as Authentik).
|
|
|
|
### Step 5: Update Caddy Forward Auth
|
|
|
|
On the VPS, edit `/opt/caddy/Caddyfile`:
|
|
|
|
```caddy
|
|
vault.researchstack.info {
|
|
tls {
|
|
dns porkbun { ... }
|
|
}
|
|
forward_auth 192.168.100.100:9000 {
|
|
uri /outpost.goauthentik.io/auth/caddy
|
|
copy_headers X-Authentik-Username X-Authentik-Groups X-Authentik-Email X-Authentik-Name
|
|
}
|
|
reverse_proxy 192.168.100.100:9100
|
|
}
|
|
```
|
|
|
|
Then reload:
|
|
```bash
|
|
/opt/caddy/caddy reload --config /opt/caddy/Caddyfile
|
|
```
|
|
|
|
### Step 6: Test
|
|
|
|
1. Open `https://vault.researchstack.info` in an incognito window
|
|
2. You should be redirected to Authentik login
|
|
3. After logging in, you should see the credential vault JSON response
|
|
|
|
### Step 7: Add Users
|
|
|
|
1. Go to **Directory -> Users**
|
|
2. Create users for anyone who needs access
|
|
3. (Optional) Add users to **Directory -> Groups** for role-based access
|
|
|
|
### Next: ARR Stack Apps
|
|
|
|
For each ARR service, repeat Steps 2-5:
|
|
|
|
| Service | Internal Host | External Host | Provider Name |
|
|
|---------|--------------|---------------|---------------|
|
|
| Sonarr | `http://192.168.100.100:8989` | `https://sonarr.researchstack.info` | `sonarr-forward-auth` |
|
|
| Radarr | `http://192.168.100.100:7878` | `https://radarr.researchstack.info` | `radarr-forward-auth` |
|
|
| Lidarr | `http://192.168.100.100:8686` | `https://lidarr.researchstack.info` | `lidarr-forward-auth` |
|
|
| Readarr | `http://192.168.100.100:8787` | `https://readarr.researchstack.info` | `readarr-forward-auth` |
|
|
| Prowlarr| `http://192.168.100.100:9696` | `https://prowlarr.researchstack.info` | `prowlarr-forward-auth` |
|
|
| Bazarr | `http://192.168.100.100:6767` | `https://bazarr.researchstack.info` | `bazarr-forward-auth` |
|
|
|
|
All can use the same embedded outpost.
|
|
|
|
### Chat Subdomain (chat.researchstack.info)
|
|
|
|
**Status**: Caddy configured, placeholder deployed. Authentik provider+app pending.
|
|
|
|
**Provider setup** (repeat Steps 2-4 above):
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| **Provider name** | `research-stack-chat` |
|
|
| **Authorization flow** | `default-provider-authorization-implicit-consent` |
|
|
| **Internal host** | `http://100.101.247.127` (placeholder; will become Steam Deck Open WebUI) |
|
|
| **External host** | `https://chat.researchstack.info` |
|
|
| **Mode** | `Forward domain` |
|
|
|
|
**Application setup**:
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| **Name** | `Research Stack Chat` |
|
|
| **Slug** | `research-stack-chat` |
|
|
| **Provider** | `research-stack-chat` |
|
|
|
|
**Outpost**: Add `Research Stack Chat` to the **authentik Embedded Outpost**.
|
|
|
|
**Caddy** (already deployed on microvm-racknerd):
|
|
|
|
```caddy
|
|
chat.researchstack.info {
|
|
forward_auth * http://100.119.165.120:9000 {
|
|
uri /outpost.goauthentik.io/auth/caddy
|
|
copy_headers X-Authentik-Username X-Authentik-Email X-Authentik-Name X-Authentik-Uid X-Authentik-Jwt X-Authentik-Meta-Jwt X-Authentik-Meta-App X-Authentik-Meta-Version
|
|
}
|
|
root * /var/www/researchstack/chat
|
|
file_server
|
|
try_files {path} /index.html
|
|
}
|
|
```
|
|
|
|
**When Steam Deck is onboarded**: Change the Caddy site block from `file_server` to `reverse_proxy <steam-deck-tailscale-ip>:8080`.
|
|
|
|
### Dashboard Subdomain (dash.researchstack.info)
|
|
|
|
**Status**: Deployed. Homer static files on microvm-racknerd. DNS pending.
|
|
|
|
**Provider setup**:
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| **Provider name** | `research-stack-dash` |
|
|
| **Authorization flow** | `default-provider-authorization-implicit-consent` |
|
|
| **Internal host** | `http://100.101.247.127` |
|
|
| **External host** | `https://dash.researchstack.info` |
|
|
| **Mode** | `Forward domain` |
|
|
|
|
**Application setup**:
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| **Name** | `Research Stack Dashboard` |
|
|
| **Slug** | `research-stack-dash` |
|
|
| **Provider** | `research-stack-dash` |
|
|
|
|
**Caddy**:
|
|
|
|
```caddy
|
|
dash.researchstack.info {
|
|
forward_auth * http://100.119.165.120:9000 {
|
|
uri /outpost.goauthentik.io/auth/caddy
|
|
copy_headers ...
|
|
}
|
|
root * /var/www/researchstack/dash
|
|
file_server
|
|
try_files {path} /index.html
|
|
}
|
|
```
|
|
|
|
### Status Monitoring Subdomain (status.researchstack.info)
|
|
|
|
**Status**: Deployed. Uptime Kuma on nixos-laptop via podman. DNS pending.
|
|
|
|
**Provider setup**:
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| **Provider name** | `research-stack-status` |
|
|
| **Authorization flow** | `default-provider-authorization-implicit-consent` |
|
|
| **Internal host** | `http://100.119.165.120:3001` |
|
|
| **External host** | `https://status.researchstack.info` |
|
|
| **Mode** | `Forward domain` |
|
|
|
|
**Application setup**:
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| **Name** | `Research Stack Status` |
|
|
| **Slug** | `research-stack-status` |
|
|
| **Provider** | `research-stack-status` |
|
|
|
|
**Caddy**:
|
|
|
|
```caddy
|
|
status.researchstack.info {
|
|
forward_auth * http://100.119.165.120:9000 {
|
|
uri /outpost.goauthentik.io/auth/caddy
|
|
copy_headers ...
|
|
}
|
|
reverse_proxy http://100.119.165.120:3001
|
|
}
|
|
```
|
|
|
|
### Auth Alias (auth.researchstack.info)
|
|
|
|
**Status**: Deployed. Clean alias redirect to main Authentik interface.
|
|
|
|
**Provider setup**:
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| **Provider name** | `research-stack-auth` |
|
|
| **Authorization flow** | `default-provider-authorization-implicit-consent` |
|
|
| **Internal host** | `http://100.119.165.120:9000` |
|
|
| **External host** | `https://auth.researchstack.info` |
|
|
| **Mode** | `Forward domain` |
|
|
|
|
**Application setup**:
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| **Name** | `Research Stack Auth` |
|
|
| **Slug** | `research-stack-auth` |
|
|
| **Provider** | `research-stack-auth` |
|
|
|
|
**Caddy**:
|
|
|
|
```caddy
|
|
auth.researchstack.info {
|
|
forward_auth * http://100.119.165.120:9000 {
|
|
uri /outpost.goauthentik.io/auth/caddy
|
|
copy_headers ...
|
|
}
|
|
redir / https://researchstack.info/ permanent
|
|
}
|
|
```
|
|
|
|
**Behavior**: Visiting `https://auth.researchstack.info` triggers Authentik login (if not authenticated), then redirects to `https://researchstack.info/`.
|
|
|
|
### Troubleshooting
|
|
|
|
**Certificate errors?**
|
|
- Check `journalctl -u caddy` on the VPS
|
|
|
|
**Authentik not reachable?**
|
|
- Verify Docker containers in LXC 100: `pct exec 100 -- docker ps`
|
|
- Check Authentik logs: `pct exec 100 -- docker logs authentik-server`
|
|
|
|
**Forward auth not working?**
|
|
- Verify outpost application assignment
|
|
- Check Caddy logs for `forward_auth` errors
|
|
- Ensure `auth.researchstack.info` is accessible (the outpost needs to redirect there)
|