apalrd's adventures
apalrd's adventures
  • 118
  • 6 427 654
Simple Self-Hosted Security with Authelia
In this video, I'm setting up Authelia. It's a very lightweight authentication service, which can be used to provide authentication to services which don't natively support any form of authentication. I think this is a great choice for small scale homelab environments, as it's simple to run and administer.
Blog post with instructions:
www.apalrd.net/posts/2024/ultimate_authelia/
FlexiSpot C7 Premium Ergonomic Chair:
Use my code C730 for $30 0ff!
US: bit.ly/4c8Tq2z
CA: bit.ly/4aWkpNQ
Support me on Ko-Fi if you enjoy my content and find it useful:
ko-fi.com/apalrd
Feel free to chat about my upcoming projects on Discord!
discord.gg/xJsaEukAr4
Timestamps:
00:00 - Introduction
00:29 - Overview
02:33 - Installation
10:20 - User Database
11:26 - Certbot
13:16 - Caddy Forward Auth
14:40 - Advanced Auth
16:23 - Two Factor Setup
17:36 - Conclusions
Переглядів: 8 228

Відео

Exploring my KEVIN and upgrading to 6GHz WiFi! (Davolink Minions Wifi 6E Router)
Переглядів 3,2 тис.14 днів тому
You've probably seen Kevin hanging out in the background of some of my recent videos, so let's take a look and see what we can get for $129. He's rated at 'AXE5400', which in wifi naming means it support 802.11AX (wifi 6), E means it supports the 6Ghz band, and 5400 is the sum of the wifi bandwidth across all bands in absolutely perfect conditions, 5400 isn't that high for tri-band. Despite his...
SELF-HOSTING behind CGNAT for fun and IPv6 transition
Переглядів 12 тис.Місяць тому
This video started as the answer to a simple question - how can I self-host a service for my friends and family, behind cgnat, without requiring them to install any apps (like tunnels)? This video turned into a bunch of different ways to proxy IPv4 to IPv6, so you can receive IPv6 traffic natively and bring in legacy traffic from a VPS which does have public IPv4. I cover several different meth...
ALL ABOUT VPNs in OPNsense! Wireguard, OpenVPN, and IPSec Setup and Configuration
Переглядів 8 тис.Місяць тому
In this very long video, I cover all the basics of VPN technologies (not the youtube shill type), how tunnels work, and the different topologies that are used in modern networks. Then I setup several examples for each of them using different protocols and methods. Hopefully you find it useful in your own network! Support me on Ko-Fi if you enjoy my content and find it useful: ko-fi.com/apalrd F...
Tracking my CAT with AI! Feat. Object Detection in Frigate and Viseron NVR
Переглядів 6 тис.Місяць тому
Today I try to use AI Object Recognition with a high resolution security camera to track my cat in the yard. Unfortunately he's a very stealthy cat with beautiful camouflaged fur , but I did see some other cool animals. Sponsored by Reolink and the Duo 3 PoE! reolink.com/us/product/reolink-duo-3-poe/?aff=329 Support me on Ko-Fi if you enjoy my content and find it useful: ko-fi.com/apalrd Feel f...
Using a LASER CUTTER with my VEX Robotics Students
Переглядів 2,1 тис.2 місяці тому
Creality wanted to send me their Falcon2 Pro Laser Cutter, and I know just the people to help me test it, my robotics students! Join me as we try to cut different materials, engrave on wood and laser-safe vinyl, and overall improve our CAD abilities one student at a time. Buy a Crealiity Falcon2 Pro (Use my code FL22WH for 15% off): DTC store: bit.ly/3vORflv US Store: bit.ly/3UmXFS5 Facebook Gr...
A Software Disappointment: Kwumsy H3 Stream Dock
Переглядів 3,3 тис.2 місяці тому
The Stream Dock: kwumsy.com/products/kwumsy-h3-8-in-1-visual-macro-keyboard-hub?ref=EeoX5XElS_V68N So today I'm taking a look at the Kwumsy H3 'Stream Dock' No, not THAT Stream Deck, not a dock for the Steam Deck, there's already enough name confusion. Basically, it tries to be a lower cost touchscreen alternative to the real Stream Deck, making use of the same addon format for wide addon suppo...
Saving Power in my Homelab with Auto-Shutdown for Proxmox Backup Server
Переглядів 25 тис.2 місяці тому
Today I'm trying to reduce the power consumption of my [Proxmox Backup Server](/posts/2023/pbs_intro/). The HP Microserver is great for what I need, but it's kinda loud and I'm working on optimizing my power bill. The homelab is the largest single consumer of electricity aside from the air conditioning in the summer, so it's something I'm looking at heavily. I tried doing S3 speep (normal suspe...
A NEW PLAYER enters the NAS Market: Hardware Teardown and More
Переглядів 16 тис.2 місяці тому
Today I'm tearing down the UGreen DXP4800 Plus, as UGreen tries to enter the NAS market. Will the hardware and software be enough to compete with established players? Stay tuned to find out. Links to the UGreen NASync Family: Ugreen NASync DXP4800 Plus: kck.st/3TKOdYB 3/28-5/9: Up to 35% OFF during 3/28-5/9 I do a deep-dive into the hardware, build quality, overview of the included software, an...
Do you need LoRa for LONG RANGE Sensor Networks? Locally-Hosted Setup w/ Chirpstack
Переглядів 10 тис.3 місяці тому
Do you like sensors and data collection as much as me, but need a solution for longer range than you can get with WiFi, Zigbee, Z-Wave, etc? Maybe you should take a look at LoRa, and the LoRaWAN network topology. In this video, I walk through what LoRa and LoRaWAN are, how you can setup a LoRaWAN gateway and self-hosted Chirpstack cloud for your own home network, and eventually get sensor data ...
Proxmox SOFTWARE DEFINED NETWORKING: Zones, VNets, and VLANs
Переглядів 37 тис.3 місяці тому
I made a Proxmox VLANs, Bridges, and Bonds tutorial awhile ago, but since then, the Software Defined Networking module has come out of tech preview! So it's time to take a look at it! With SDN, you can manage your Proxmox VNets and VNet Zones cluster-wide, and enforce permissions on users who can configure VNets for VM and Container resources. While the SDN has additional functionality for mana...
Use your LAPTOP as a KVM! The Pi-Cast USB KVM
Переглядів 25 тис.3 місяці тому
Today, I take a look at the Pi-Cast KVM, a PiKVM compatible system which lets you use your laptop as the keyboard/display/mouse when working with PCs and servers. Based on the Raspberry Pi Compute Module 4, the Pi-Cast features USB3 gigabit Ethernet between the Pi-Cast and your laptop, HDMI input, USB gadget emulation, and a number of accessory hats are available to add ATX power control and a ...
Going IPv6-Mostly with Tayga NAT64 on OPNsense
Переглядів 8 тис.3 місяці тому
Today I'm going to expand on my previous IPv6-only experiments and try to move to an IPv6-mostly network, a few devices at a time. But for this to work well, I need to give my IPv6-only clients access to the IPv4 internet, via NAT64. So join me as I setup Tayga to provide NAT64 functionality on OPNsense! And once I have NAT64 setup, I can start to migrate clients entirely away from legacy netwo...
New Boot SSD for my PROXMOX System
Переглядів 19 тис.4 місяці тому
Today I'm replacing the old SATA boot drive in my Proxmox system with an NVMe drive. I walk through a bit about NVMe, DRAM caches, and Host Memory Buffer, test the new SSD, and finally setup the partition table, boot partitions, and copy my root filesystem onto the new SSD. The SSD: amzn.to/4bLKSj4 fikwot.net/discount/VMHYP s.click.aliexpress.com/e/_olb7UkC Support me on Ko-Fi if you enjoy my c...
Ultimate S-Tier Wifi Security with EAP-TLS Certificates (feat. Smallstep)
Переглядів 8 тис.4 місяці тому
Ultimate S-Tier Wifi Security with EAP-TLS Certificates (feat. Smallstep)
Secure Your OPNsense Network with Zenarmor NGFW!
Переглядів 23 тис.5 місяців тому
Secure Your OPNsense Network with Zenarmor NGFW!
How Secure is YOUR WiFi Network?
Переглядів 15 тис.5 місяців тому
How Secure is YOUR WiFi Network?
UniFi, Get your (IPv6) act together!
Переглядів 12 тис.5 місяців тому
UniFi, Get your (IPv6) act together!
Does your Desk need a TOUCHSCREEN + Keyboard? The Kwumsy K3
Переглядів 7 тис.6 місяців тому
Does your Desk need a TOUCHSCREEN Keyboard? The Kwumsy K3
All About SUBNETTING your Networks! IPv6, IPv4, and VLAN Numbering Guide and OPNsense Demo
Переглядів 16 тис.6 місяців тому
All About SUBNETTING your Networks! IPv6, IPv4, and VLAN Numbering Guide and OPNsense Demo
Unleash your Home Cameras with FRIGATE Self-Hosted AI Video Recorder! Install on Proxmox LXC
Переглядів 36 тис.7 місяців тому
Unleash your Home Cameras with FRIGATE Self-Hosted AI Video Recorder! Install on Proxmox LXC
Building a TELEPROMPTER with a Raspberry Pi
Переглядів 2,9 тис.7 місяців тому
Building a TELEPROMPTER with a Raspberry Pi
A $9 Introduction to the RISC-V Future of Computing
Переглядів 353 тис.8 місяців тому
A $9 Introduction to the RISC-V Future of Computing
Add a DAS to your NAS! USB Direct Attach Storage with ZFS
Переглядів 38 тис.8 місяців тому
Add a DAS to your NAS! USB Direct Attach Storage with ZFS
Migrating my PERSONAL SERVER from TrueNAS to Proxmox + Cockpit
Переглядів 33 тис.9 місяців тому
Migrating my PERSONAL SERVER from TrueNAS to Proxmox Cockpit
Gitea: Easy Self-Hosted Git Repositories!
Переглядів 25 тис.9 місяців тому
Gitea: Easy Self-Hosted Git Repositories!
HOW TO SETUP OPNsense: From First Boot to Fully Functional (with IPv6!)
Переглядів 69 тис.9 місяців тому
HOW TO SETUP OPNsense: From First Boot to Fully Functional (with IPv6!)
Should I use TAPE BACKUP in 2023? LTO-5 Drive with Proxmox Backup Server
Переглядів 50 тис.10 місяців тому
Should I use TAPE BACKUP in 2023? LTO-5 Drive with Proxmox Backup Server
Updating my WORKSTATION! F in the Chat for my Threadripper :(
Переглядів 6 тис.10 місяців тому
Updating my WORKSTATION! F in the Chat for my Threadripper :(
MOVING My Website from Static Hosting to Caddy!
Переглядів 11 тис.10 місяців тому
MOVING My Website from Static Hosting to Caddy!

КОМЕНТАРІ

  • @n8lbv
    @n8lbv 20 годин тому

    While presenting "option one" This Video completely disregards the absolute hard and so incredibly obvious FACT that pretty much EVERY ISP and especially large well known wireless or satellite providers BLOCK any/all inbound on IPV6 with absolutely no options to get around this. Not even mentioned or discussed whatsoever. I mean seriously?

  • @dougbeard7624
    @dougbeard7624 23 години тому

    What's confusing me is having two NICs and each are on a VLAN assigned by the router. But I'm unable to setup a gateway for one of them, despite it need it. Confusing as hell.

    • @apalrdsadventures
      @apalrdsadventures 23 години тому

      You should only have one gateway on a system (unless its a router itself)

  • @kriansa
    @kriansa День тому

    What's the app you use to create these diagrams?

  • @BrashTV
    @BrashTV День тому

    I hit the like and the sub, here's a comment - ALGORITHM GO

  • @Prowlyi
    @Prowlyi День тому

    Incredible overall

  • @chrisfung443
    @chrisfung443 2 дні тому

    Does it support vlan for different ssid?

    • @apalrdsadventures
      @apalrdsadventures День тому

      Doesn't appear to. Hoping for OpenWRT support eventually.

  • @dhruvdnar
    @dhruvdnar 2 дні тому

    You have a gift for simple but deep explanation. Great work

  • @dhruvdnar
    @dhruvdnar 2 дні тому

    Thanks

  • @lucian6172
    @lucian6172 2 дні тому

    Is RISC-V faster or slower than the Raspberry Pi ?

  • @AlessandroTischer
    @AlessandroTischer 2 дні тому

    I'm using cloudflare tunnels to access my homelab services, as long as they provide authentication. With frigate I prefer not to expose it since it doesn't provide any auth. Messing with proxies inside my network is something I would like to avoid, I feel like it complicates things a lot... I would like to have a 2FA like the one I have in Home assistant in all services... Exposing HA with cloudflare is so easy and safe!

  • @jgm3796
    @jgm3796 2 дні тому

    Shoot, did I miss it? What about bonding tlb and alb? Will watch again. Very informative!

  • @sohail579
    @sohail579 2 дні тому

    how can I do this but my new boot drive I would like to install 2 new mirrored drives?

    • @apalrdsadventures
      @apalrdsadventures 2 дні тому

      you can convert single drives to/from mirrors or add more disks to a mirror using zpool attach and zpool detach. In this example I attach the one new drive then detach the one old drive (so it goes single -> 2-way mirror -> single), but you could just as easily prep the 2 new drives (using the same boot / efi partition process on each drive) then attach both (now in a 3-way mirror). Once resilvering is done with both drives, you can detach the first (now in a 2-way mirror).

    • @sohail579
      @sohail579 2 дні тому

      @@apalrdsadventures thanks for the information I have started to do it now and when I write the partition file back to the first new disk (not tried the other yet) it comeplets but i get this error too Partition 1 does not start on physical sector boundary. is this ok?

    • @sohail579
      @sohail579 2 дні тому

      ok also just realized my single boot drive is not in a zpool by its self am i screwed here?

    • @apalrdsadventures
      @apalrdsadventures 2 дні тому

      hrm I wonder if your existing drive is using 512 byte sectors and the new drive is using 4096 byte sectors? Usually we partition everything assuming 4096 byte even if the drive claims 512 byte. As to the zpool, is the zpool combined with more disks or is it not using zfs at all?

    • @sohail579
      @sohail579 2 дні тому

      @@apalrdsadventures Yes its using 512 if i recall now when i installed (just installed with the proxmox installer gui) i remember thinking why would i use zfs with only 1 drive so didnt now that im learning im moving over to 2 drives in a zfs pool, do i have a way around this?

  • @netroy
    @netroy 2 дні тому

    7:00 For SMTP I run local mailpit. It's pretty good.

    • @apalrdsadventures
      @apalrdsadventures 2 дні тому

      That looks super useful, especially in a test environment

  • @thaddeuscleo5920
    @thaddeuscleo5920 3 дні тому

    Hello apalrds would you Zitadel SSO server?

  • @colinstu
    @colinstu 3 дні тому

    Frigate has been on my list to mess around with. TIL that it didn't have auth yet. (but seeing in another comment saying it does now in beta)

  • @projectpanic2291
    @projectpanic2291 3 дні тому

    Are there any implications of self-hosting repos, specifically Infra-as-code, and disaster recovery?

    • @apalrdsadventures
      @apalrdsadventures 3 дні тому

      In general a Git repo is stored as files in a folder, so recovering it doesn't require Gitea to be running. As to recovering infrastructure, sometimes it's good to have a bootstrapping plan on how to setup a minimal set of functions to get the code back to provision everything again.

    • @projectpanic2291
      @projectpanic2291 3 дні тому

      @@apalrdsadventures I assume that Ansible, Terraform, and other related tools are part of a good recovery plan. Is your Ansible video still in the works?

    • @apalrdsadventures
      @apalrdsadventures 3 дні тому

      Ansible is in the long term plans, not being produced yet. I'm slowly working on setting up some things I'd like to have in place before I start with IaaC (specifically, Netbox). I won't make a video until I'm using Ansible, so that's part of the delay. I did work through a Netbox test setup, so at least that is moving along and a video on that will come out eventually. I did just have to do a disaster recovery (ironically, the backup server itself failed) and the PBS dataset was very useful. I'll probably have a video on mounting / using PBS datasets for disaster recovery soon.

  • @TTURKI
    @TTURKI 3 дні тому

    I just want to game in the basement, would this be better than bringing a mini PC and stream using moonlight ?

  • @jasonm2477
    @jasonm2477 3 дні тому

    Im happy to see that im not the only one who always chooses those vlan id's in test networks

  •  3 дні тому

    I have one question about mobile devices (with generated MAC addresses) Solution you used is for every phones (every devices with dynamic MAC adrs) Is there a way to connect differently phones which are from family members so that only visitors has different vlan ? I hope that I describe what I want to do, my English is not so good :-)

    • @apalrdsadventures
      @apalrdsadventures 3 дні тому

      The mobile devices generate a random MAC, but it does not change over time for the same network. So you can initially log them in with the 'default' password, find the MAC they are using, and then change the password for that MAC specifically. Visitors get the default password / vlan.

    •  3 дні тому

      @@apalrdsadventures WoW I did not realized that. Thank you a lot.

    •  3 дні тому

      @@apalrdsadventures I have microtik as main router. So I tried to figureout how to setup this only with UserManager as a Radius server. But I did not find out how to do something as you did with mobile generated MAC adrs. So I thing, that I have to setup Radius server as you did. Thank you a lot for this video.

    • @apalrdsadventures
      @apalrdsadventures 2 дні тому

      I'm guessing their UserManager has an implicit default deny if there is no user. Instead, I have default accept with a default password.

  • @UnNumptyTube
    @UnNumptyTube 3 дні тому

    I struggle with a two cat parade on a daily basis. I got a split keyboard to reduce my attack surface. I've given up on getting them off the desk. Shutting the door is just chaos.

  • @dirtybrokkoli
    @dirtybrokkoli 3 дні тому

    Currently i do not host any service that does not have it's own authentication but authelia looks pretty good, do you know if authelia could in theory authenticate the user on the backend service, like some kind of sso? Without using ldap? That would help me get rid of one reverse proxy and really simplify my setup but i would prefer to keep it simple instead of adding a behemoth like ldap

    • @apalrdsadventures
      @apalrdsadventures 3 дні тому

      File and LDAP are the options with Authelia. LDAP is a bit of a lowest common denominator, it's so old that it's generally the core of most big networks. Some more complex options support other backends, for example Keycloak supports Kerberos.

  • @user-rw6qd7fz4m
    @user-rw6qd7fz4m 3 дні тому

    круто, но слишком замороченная настройка

  • @hanley-development
    @hanley-development 4 дні тому

    Authentik is great and works with duo push.

  • @codeman99-dev
    @codeman99-dev 4 дні тому

    I intend to setup authentik at some point. It's probably way too much for my needs. That said, I know there's documentation for the one application I actually host. Heh.

  • @LaurenceHartje
    @LaurenceHartje 4 дні тому

    I'm running Windows AD on my homelab and Keycloak for handling the SSO to OIDC apps (Portainer, Paperless-NGX, PGAdmin, XO-CE and Proxmox [as I'm experimenting with different hypervisors at the moment]). Nothing exposed publicly, remote access is all over Wireguard.

  • @LucasHartmann
    @LucasHartmann 4 дні тому

    I use pfsense/haproxy as entrypoint. Sensitive services require a client certificate to connect, and are otherwise routed to dummy servers. Haproxy can also be set with multiple CA for differentiating admin/viewer user classes. Cool thing is that client certificates reside in the phone, so any app that uses chrome internally works transparently.

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      Mutual TLS works well, but requires client-side involvement

  • @userou-ig1ze
    @userou-ig1ze 4 дні тому

    I thought I'm a homelab guy, but then I found myself not know what frigate is. Taking my hat, eating it, and taking my leave

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      It's more popular when there's overlap with Home Automation, but it's also an app I use that has no authentication and made a good demo

  • @Ed19601
    @Ed19601 4 дні тому

    interesting, but the shipping costs suddenly make it a lot less interesting

  • @SideQuestStijn
    @SideQuestStijn 4 дні тому

    My Proxmox host has 6 NIC's. On NIC1 a trunk comes in with 3 VLAN's. I set my VM's to their specific VLANs. Works great! Buuuut, I want VLAN 2 from NIC1 to be put on NIC2 untagged. How do I do this?

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      add enx1.2 and enx2 as bridge ports on a non-vlan-aware bridge.

  • @RyanParmeter
    @RyanParmeter 4 дні тому

    I've been able to get Authentik working for a simple setup and plan to expand. It can act as an LDAP (and other) user stores for wide compatibility.

    • @dirtybrokkoli
      @dirtybrokkoli 3 дні тому

      Is the setup as "simple" as the authelia setup seems here? And how easy is it to integrate it with common applications like nextcloud, jellyfin, etc?

  • @KeithHanlan
    @KeithHanlan 4 дні тому

    I like how this proxy setup is able to support differing policies for different URIs. Once you have authenticated without 2FA for a non-config URI, your config is still protected. This sort of behaviour from built in authentication would require much more work for the developers and consequently introduce risk. Very slick. Once again, thank you for sharing your experience!

  • @hoaxbuster78
    @hoaxbuster78 4 дні тому

    i tried to install ceph dashoard, do you have tutorial ? thanks !

  • @74357175
    @74357175 4 дні тому

    What's the advantage of 6 GHz? Aside from less interference with 5 GHz channels?

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      basically just that. There are 29 possible 20mhz channels in the 5ghz band, over half of which are in the DFS region, and not including DFS there is not a single 160Mhz channel possible (just one 80+80). There are 59x 20mhz channels in the 6ghz band, and currently there are barely any users of that band, so it's currently realistic to use higher bandwidth channels (80Mhz and beyond) without having a bad time. 6Ghz will have somewhat less range indoors than 5Ghz for the legal transmit power limit, but it's not a drastic difference like it is between 2.4 -> 5Ghz.

  • @74357175
    @74357175 4 дні тому

    What OS does Kevin use?

  • @projectpanic2291
    @projectpanic2291 4 дні тому

    What do you run OPNsense on?

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      Currently have a Protectli FW4B as 'primary' and a FW4C as my test system, but I eventually plan on swapping the two.

    • @projectpanic2291
      @projectpanic2291 4 дні тому

      @@apalrdsadventures Those look really nice. Thanks for the info!

  • @georgH
    @georgH 4 дні тому

    I use a different approach, none of my services are exposed to the internet except for v2ray. I used v2ray when I lived in a country with censored internet and I keep using it to connect to my services securely. Because it can be set up to work over standard https, it works everywhere, even in places were wireguad and OpenVPN are blocked (which is very common nowadays). Because nothing is exposed, I use the DNS method of renewing the letsencrypt certificate instead of the https.

    • @Darkk6969
      @Darkk6969 4 дні тому

      Yep. I use pfsense's HAProxy and ACME to handle the certificates for Let's Encrypt. Real happy that it supports DNS to verify the domain.

  • @olokelo
    @olokelo 4 дні тому

    Thank you for the video! As for my current setup I don't run any authentication server however I'm using client TLS certificates and Wireguard for remote access. I think that's secure enough.

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      client TLS certs are an extremely secure form of auth if the CA is properly hardened / offline I've been using client tls certs before I had this setup, it's just a pain to re-key clients every few months.

    • @John-kd6gi
      @John-kd6gi 2 дні тому

      @@apalrdsadventures hello, can authella be used to add 2FA to wireguard?

  • @lightechoes
    @lightechoes 4 дні тому

    Great stuff as always. I've been thinking about authentication for a while.

  • @DawidKellerman
    @DawidKellerman 4 дні тому

    Can I beg a keycloak video?

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      I'll consider it... it does Kerberos so maybe

    • @DawidKellerman
      @DawidKellerman 4 дні тому

      @@apalrdsadventures Thank you! I don't have much experience with Kerberos Know there are some cool SSO Stuff

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      Kerberos is actually quite old (Developed in the 80s), so it's unrelated to 'modern' standards like TLS and doesn't even use public key cryptography at all (purely AES). So while it's extremely well designed from a security and usability standpoint, it's hard to integrate into web apps and requires a client program. Microsoft Active Directory uses Kerberos auth for domain joined computers, so that's where it's most commonly used. The client requirement means it's really only usable on domain-joined or similarly managed devices.

  • @Felix-ve9hs
    @Felix-ve9hs 4 дні тому

    Pretty cool, definitely something I'll take a look at the next time I rework my home network :^)

  • @flosen569
    @flosen569 4 дні тому

    Great Video, are there any GUI available for managing Authelia? If so, could you create a video?

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      Authelia itself has a GUI for managing password reset and TOTP/WebAuthn configuration. The only thing 'missing' is the initial user creation.

    • @darkpixel1128
      @darkpixel1128 4 дні тому

      if you connect to an LDAP service you can create users with a GUI. LLDAP is an easy, lightweight way to do this

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      I'm expecting this to be used by people with <20 users, where adding them to the file is weighed against the suffering of running an LDAP server

  • @tomascorreia6923
    @tomascorreia6923 4 дні тому

    Check out Keycloak and OpenLDAP

  • @lifefromscratch2818
    @lifefromscratch2818 4 дні тому

    Someday I would like to get far enough with my learning where I feel comfortable trying to implement a single sign on solution.

  • @AndrewFrink
    @AndrewFrink 4 дні тому

    I'd like to run a single sign on thing, but covering web apps; user accounts on lxcs, smb shares, real hosts, and windows computers; and managing ssh keys is just too much. None of my services (except wireguard) are publicly accessible, so i basically have 0 authentication on services.

  • @apalrdsadventures
    @apalrdsadventures 4 дні тому

    Now is the best time to buy FlexiSpot Ergonomic Chair. 30 days free return, try it with confidence! Use code "C730" for $30 off! US: bit.ly/4c8Tq2z CA: bit.ly/4aWkpNQ

  • @TheUkeloser
    @TheUkeloser 4 дні тому

    I work for a network security company that provides, among other things, a large enterprise grade authentication platform, and I get it for free for "testing" purposes, so I run that in my lab. Way overkill, but it does RADIUS, LDAP, SAML, etc. so I can make it work with just about anything I want to run. Definitely don't recommend it for home labbers though, since even the smallest VM license is 4 figures.

    • @almc8445
      @almc8445 4 дні тому

      RADIUS, LDAP, SAML… Kerberos, NTLM, OIDC, OAuth 2… Fk me no wonder so many apps don’t implement SSO, it shouldn’t be this hard…

    • @apalrdsadventures
      @apalrdsadventures 4 дні тому

      Part of the issue is that different industries have different historical standards which they follow. RADIUS came from dial-up authentication and became the standard in everything networking (like 802.1X), OIDC/OAuth run over HTTP(s) so they can be done by web apps without an installed client, and Kerberos is a great solution and could be universal but is really only possible on domain-joined computers (at least with current implementations), unfortunately.

    • @almc8445
      @almc8445 4 дні тому

      @@apalrdsadventures Yeah it definitely makes sense how we got to this point, just sad we haven't seen a unified push to adopt or build a universal standard. And I don't think we're likely to see it happen in my lifetime...

  • @Tntdruid
    @Tntdruid 4 дні тому

    Blog link -> 404 - Page not found...

  • @BartomiejSacharski
    @BartomiejSacharski 4 дні тому

    About Frigate not having authentication - the current beta (0.14) has authentication exposed on port 8080, with 5000 being now considered an "internal endpoint", that should isolated from "normal" network.

  • @lavishjaat
    @lavishjaat 4 дні тому

    First 😅

  • @ktraglin
    @ktraglin 4 дні тому

    How can I do this without the proxmox-boot-tool, using Ubuntu?