Skip to content

Conversation

@KuroIvy
Copy link

@KuroIvy KuroIvy commented Sep 28, 2025

Updated authentik docker example with working example stacks and updated README to better explain how to get setup. I did my best to make it a basic level of secure and simple. If it can be improved please mention how! 😁 The key was specifying the xff-src, and using the correct authentik default headers.

To show that your contribution is compatible with the MIT License, please include the following text somewhere in this PR description:
This PR complies with the DCO; https://developercertificate.org/

@xfallme
Copy link

xfallme commented Nov 4, 2025

Just adding to this, as someone how has struggled quite a lot with Authentik in a homelab environment:

  • It is always a good idea to run the latest release version of Authentik, at the moment of writing its 2025.10.0.
    The current up-to-date docker compose by Authentik can always be found here: https://docs.goauthentik.io/docker-compose.yml
  • Pinning traefik to the latest label might be a recipe for disaster and definitely shouldn't be the value set in an example, nobody wants their reverse proxy to break because of an update (in my experience that's not a fun time)

@KuroIvy @9001 Is this still active?

@9001
Copy link
Owner

9001 commented Nov 4, 2025

this is currently blocked by #943 ; I'm not comfortable making/merging authentication-related changes without careful scrutiny

@xfallme
Copy link

xfallme commented Nov 4, 2025

I am sorry, didn't want disturb your vacation with some random comment. The "still active" question was aimed at the PR in general. But that conversation can wait!

@KuroIvy
Copy link
Author

KuroIvy commented Nov 6, 2025

Just adding to this, as someone how has struggled quite a lot with Authentik in a homelab environment:

  • It is always a good idea to run the latest release version of Authentik, at the moment of writing its 2025.10.0.
    The current up-to-date docker compose by Authentik can always be found here: https://docs.goauthentik.io/docker-compose.yml
  • Pinning traefik to the latest label might be a recipe for disaster and definitely shouldn't be the value set in an example, nobody wants their reverse proxy to break because of an update (in my experience that's not a fun time)

@KuroIvy @9001 Is this still active?

Hey thanks for the feedback. I mostly just wanted to provide a fully working example as the one in the current contrib isn’t complete. I can update the PR with your notes no problem. I love SSO and copy party is really cool so I did what I could to make it work so thought I would share. :)

@nekitbr
Copy link

nekitbr commented Nov 21, 2025

  • [...]
  • Pinning traefik to the latest label might (is) be a recipe for disaster and definitely shouldn't be the value set in an example, nobody wants their reverse proxy to break because of an update (in my experience that's not a fun time)
  • [...]

Btw: enjoy your vacations!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants