Traefik + Authentik + Shelfmark Proxy Authentication #555
Jammrock
started this conversation in
Show and tell
Replies: 1 comment 1 reply
|
Asking because I am an idiot; any reason to pick Proxy Authentication over OIDC (OpenID Connect)? For context I am also using Traefik + Authentik stack. |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
How I setup Shelfmark Proxy Authentication with Traefik and Authentik. I suggest performing the steps in this order.
My setup:
Authentik
Groups [Optional]
I reused my CWA admin group for Shelfmark. Groups are technically optional, but I use a group so they are part of the guide.
Application + Provider + Outpost
Proxy authentication needs a Provider tied to an application that is added to the default Outpost for Authentik proxy forward authentication to work.
a. Application Name: Shelfmark
b. [auto-populated value is fine] Slug: shelfmark
c. Policy Engine Mode: ANY
d. Next
a. [Optional] Remove "Provider for " so the provider name matches the Application name. This is my personal preference.
b. Authorization flow:
i. Select "Explicit" to require Authentik to prompt the user about sending auth data to Shelfmark
ii. Select "Implicit" to let Authentik send auth data to Shelfmark without user consent (which is fine for a homelab)
c. Select "Forward auth (single application)"
d. External host: https://shelfmark.company.domain
i. The host is the URL used to access the site from OUTSIDE of Traefik
ii. shelfmark.company.domain is a placeholder for your Shelfmark URL.
e. No other settings need to be changed, but "Authentication Settings > Intercept header authentication" must be toggled on (default)
f. Next
a. Group
b. Click into the Group text box to get a list of groups
c. Select your admin group (i.e. Shelfmark-Admins)
d. Order: 1
e. Save binding
f. Next
There will now be an Application named Shelfmark and a Provider named "[Provider for ]Shelfmark".
Application:

Provider:

The Authentik setup is now complete!
Traefik
I used a YAML file in a rules dir that Traefik watches rather then adding labels in the Docker compose file. The YAML file can be converted to compose labels or a TOML file.
There can be only one [in a Highlander voice] Shelfmark definition in Traefik. Comment, remove, or adjust any existing labels/definitions before using this configuration.
When using the YAML method, make sure traefik.yaml has a watcher:
File [Traefik container path]: /etc/traefik/rules/shelfmark.yaml
Replace:
auth.company.domainwith the external URL to your Authentik site.shelfmark.company.domainwith the external URL to your Shelfmark site.<ip>:<port>with the internal IP address (127.0.0.1 or 192.168.xxx.yyy) and port used by Shelfmark. I recommend testing the URL locally first, and use a known working http-based URL in the loadBalancer config.Testing
Open an Incognito/InPrivate instance of your browser of choice and go to your external Shelfmark site (i.e. https://shelfmark.company.domain).
The backend is configured correctly when you are prompted to authenticate via Authentik before being redirected to Shelfmark.
You will still have access to settings because Shelfmark is not setup yet.
Shelfmark
It's time to setup Proxy Authentication in Shelfmark. These steps include the optional step of enabling an admin group.
Proxy Auth Logout URLblank.Optional Admin Group Configuration
This step is for those who are granting access to users who you don't trust with Settings access.
Testing
When everything is setup correctly, users in the Shelfmark/CWA admins group will have access to Settings once logged on via Authentik. All other users can search and download, but will not have Settings access.
Please test an admin and a normal user before releasing Shelfmark to non-admin users.
All reactions