SSO is handled by Authentik outpost on racknerd Caddy at auth.researchstack.info. Homarr sits behind this outpost and only sees already-authenticated traffic from the public URL. Direct access via tailnet port 7575 uses credentials.
- OIDC provider config inserted into Homarr SQLite database (serverSetting key=authentication, provider=Authentik) - Authentik redirect URIs expanded to include researchstack.info - Homarr login page now shows OIDC option alongside credentials - setup/check scripts committed for future maintenance Access Homarr at https://researchstack.info/ with OIDC login