traefik-forward-auth
awesome-zero-trust
Our great sponsors
traefik-forward-auth | awesome-zero-trust | |
---|---|---|
32 | 3 | |
2,005 | 706 | |
- | 3.0% | |
0.0 | 0.0 | |
24 days ago | over 1 year ago | |
Go | ||
MIT License | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
traefik-forward-auth
- Show HN: Obligator – An OpenID Connect server for self-hosters
-
Authentik reverse proxy vs swag
BTW also keycloak and other similar products offer the oauth-proxy capability, I even used the original oauth2-proxy https://github.com/oauth2-proxy/oauth2-proxy for a while, but it was getting too difficult to maintain for me. I used for a while https://github.com/thomseddon/traefik-forward-auth that was a smart hack configuring a single upstream provider, but it look abandoned. So I was considering authentik but apparently it's just oauth2-proxy embedded in it, at that point why not use oauth2-proxy directly.
-
Traefik with traefik-forward-auth towards Azure AD loop-redirect and fail
It seems there are some more recently updated forks.
-
Dell T320 vs T620 Idle Power
Traefik Forward Auth
-
Assuming I have each individual service working (cloudflare-tunnel, keycloak, nginx, arrs, dashy), how would I go about having a system like this? (more in comments)
One way I got this to work (for another app that doesn’t go through cloudflare) was to use Traefik with forward-auth and this: https://github.com/thomseddon/traefik-forward-auth
-
Just finished migrating my old tower servers to a Kubernetes cluster on my new rack!
In front of all of my private dashboards, I use Traefik Forward Auth to limit who can access them.
-
Is there something like Keycloak or Authelia that supports both forward auth and identity providers?
Hm, interesting. I have worked with traefik-forward-auth before, but I didn't know there is a fork. Are you using the fork? Would you happen to know if this issue from the original project still exists or if it's fixed in the fork?
-
How do you expose some of your services to the internet?
https://github.com/thomseddon/traefik-forward-auth (just another option if everyone accessing already has a google account)
-
Cant wrap my head around auth process
Traefik ingress + forward auth middleware + traefik-forward-auth does the trick.
-
SSO with keycloak and traefik
Hey have u setup a forward auth? https://github.com/thomseddon/traefik-forward-auth
awesome-zero-trust
- Curated collection of resources for the zero trust security model
-
Single sign-on and identity for government services: What we've learned so far
Two great places to start are "Beyond Corp"/zero trust and "WebAuthN". BeyondCorp is the name brand of a zero trust model, where the perimeter security model is broken down for authorization ("authz") and authentication ("authn") everywhere. WebAuthN is using PKI infrastructure with a purposeful UX to migrate off usernames and passwords for authentication.
https://www.beyondcorp.com/
https://github.com/pomerium/awesome-zero-trust/
https://webauthn.guide/
-
NSA Issues Guidance on Zero Trust Security Model
I found the the NIST / UK docs similarly high-level albeit more exhaustive. Gitlab and google's write-ups are a good read if you are looking for more of an operationalized perspective on zero-trust principles.
What are some alternatives?
oauth2-proxy - A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers.
trasa - Zero Trust Service Access
authelia - The Single Sign-On Multi-Factor portal for web apps
home - Head to https://github.com/JanssenProject/jans
pam-keycloak-oidc - PAM module connecting to Keycloak for user authentication using OpenID Connect/OAuth2, with MFA/2FA/TOTP support
Pomerium - Pomerium is an identity and context-aware reverse proxy for zero-trust access to web applications and services.
vouch-proxy - an SSO and OAuth / OIDC login solution for Nginx using the auth_request module
Ockam - Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications – at massive scale.
Synology-Docker-Mediaserver - Working Docker media server containers running on Synology, served by Swag with auth via Organizr (and auth bypass for API, so NZB360 etc. work).
Traefik-with-Pomerium-Forward-Auth-and-Proxy-on-Kubernetes-with-Helm - Traefik with Pomerium in Forward Auth and Proxy mode on Kubernetes with Helm/Helmfile
mistborn
traefik-forward-auth0 - A backend for performing forward authentication with Auth0 using the Traefik reverse proxy.