#Authentik in local and NPM

1 messages · Page 1 of 1 (latest)

full dagger
#

Can not comment on your first issue, I'm also not very experienced with authentik. But I'd assume you have a wrong redirect somewhere, I'd suggest you post some screenshots of your proxy and outpost config.

Passwordless login only works on the same domain, the Idea behind this authentication method is, that it verifies the domain and the identity of the one you are authenticating to. The only think you could do is register one passkey for the domain and one for the IP, but in generall I'd suggest you either use IP or name from now on. 😉

gentle mountain
#

Thank you very much for the quick response, I am going to attach some screenshots of my configuration (I have probably done something wrong) the subdomain.domain.com is not public on the internet, it is a private subdomain with local access.

It also happens that when entering the service through subdomain.domain.com it redirects me to the Authentik username and password but in http and not https (I have an SSL certificate in NGINX)

#

In the Advanced tab of NGINX I have the following:

Increase buffer size for large headers

This is needed only if you get 'upstream sent too big header while reading response

header from upstream' error when trying to access an application protected by goauthentik

proxy_buffers 8 16k;
proxy_buffer_size 32k;

Make sure not to redirect traffic to a port 4443

port_in_redirect off;

location / {
# Put your proxy_pass to your application here
proxy_pass $forward_scheme://$server:$port;
# Set any other headers your application might need
# proxy_set_header Host $host;
# proxy_set_header ...

##############################
# authentik-specific config
##############################
auth_request     /outpost.goauthentik.io/auth/nginx;
error_page       401 = @goauthentik_proxy_signin;
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header       Set-Cookie $auth_cookie;

# translate headers from the outposts back to the actual upstream
auth_request_set $authentik_username $upstream_http_x_authentik_username;
auth_request_set $authentik_groups $upstream_http_x_authentik_groups;
auth_request_set $authentik_email $upstream_http_x_authentik_email;
auth_request_set $authentik_name $upstream_http_x_authentik_name;
auth_request_set $authentik_uid $upstream_http_x_authentik_uid;
#

proxy_set_header X-authentik-username $authentik_username;
proxy_set_header X-authentik-groups $authentik_groups;
proxy_set_header X-authentik-email $authentik_email;
proxy_set_header X-authentik-name $authentik_name;
proxy_set_header X-authentik-uid $authentik_uid;
}

all requests to /outpost.goauthentik.io must be accessible without authentication

location /outpost.goauthentik.io {
proxy_pass http://192.168.11.150:9090/outpost.goauthentik.io;
# ensure the host of this vserver matches your external URL you've configured
# in authentik
proxy_set_header Host $host;
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
add_header Set-Cookie $auth_cookie;
auth_request_set $auth_cookie $upstream_http_set_cookie;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
}

Special location for when the /auth endpoint returns a 401,

redirect to the /start URL which initiates SSO

location @goauthentik_proxy_signin {
internal;
add_header Set-Cookie $auth_cookie;
return 302 /outpost.goauthentik.io/start?rd=$request_uri;
# For domain level, use the below error_page to redirect to your authentik server with the full redirect path
# return 302 https://authentik.company/outpost.goauthentik.io/start?rd=$scheme://$http_host$request_uri;
}

If I put proxy_pass https, error 500 occurs