Authelia vs Authentik: two complementary tools
Authelia and Authentik are often confused because both touch authentication. The difference is fundamental: Authelia is a forward-auth proxy — it intercepts HTTP requests and requires MFA before passing them through, without managing users itself. Authentik is a full Identity Provider: it has its own user directory, admin console, OIDC and SAML flows, and can export those identities to Authelia or any other consumer. In practice: Authelia protects a service in 5 minutes; Authentik takes 30 minutes but gives you true SSO and user lifecycle management.
What you get with Authentik
- OIDC/OAuth2 provider — connect Gitea, Nextcloud, Mattermost, Grafana, Docmost for SSO with a 4-field form.
- SAML 2.0 IdP — integrate enterprise SaaS (GSuite, Office 365) that requires SAML without a paid vendor.
- LDAP proxy — expose your Authentik directory via LDAP for legacy apps that don't speak OIDC.
- Passkeys & WebAuthn — Touch ID, Face ID, YubiKey as a second factor, no plugin required.
- Visual flow editor — drag-and-drop canvas to design any auth journey: enrolment, progressive MFA, email verification, captcha.
- Self-serve user portal — each user manages their own password, MFA devices and social connections.
- Lean stack — PostgreSQL 16 + server + worker, Redis removed since v2025.10.
Architecture: 3 containers, no external dependencies
Since v2025.10, the Authentik stack no longer needs Redis. The minimum is: a PostgreSQL 16 container (users, tokens, events) + a server container (Django/Python, admin console on port 9000, /if/admin/) + a worker container (async tasks: emails, token cleanup, LDAP sync). On a 2 GB ServOrbit VPS, all three containers consume around 550 MB at idle — enough for a team of 20 with several OIDC applications connected.
Deployment in 6 steps
Order a ServOrbit VPS
2 GB RAM on Ubuntu 24.04 is the recommended minimum. The admin console can be resource-hungry during complex configurations; 4 GB is comfortable for production use.
Point a subdomain
Create an A record for
auth.yourdomain.compointing to the VPS IP. ServOrbit's reverse proxy automatically provisions a TLS certificate via Let's Encrypt. OIDC callbacks require HTTPS — without a domain, the install cannot work.Install from the marketplace
In the ServOrbit console: Marketplace → Cybersecurity & Bastion → Authentik → Deploy. The AWX job starts PostgreSQL, generates APP_SECRET and ADMIN_PASSWORD, and starts the server and worker. The admin console is reachable at
https://auth.yourdomain.com/if/admin/in 60–90 seconds.Create your first OIDC provider
In the Authentik admin: Applications → Providers → Create → OAuth2/OpenID Provider. Name it
gitea(or the target service), select the default flow, copy the Client ID and Client Secret. In Gitea, go to Administration → Authentication → Add → OAuth2, fill in these values and the discovery URLhttps://auth.yourdomain.com/application/o/gitea/.well-known/openid-configuration. Users can now log in to Gitea via Authentik.Enable passkeys for the admin account
In the Authentik user portal (
/if/user/), click MFA Devices → Add WebAuthn. Your browser will prompt you to register a passkey (Touch ID / Face ID / FIDO2 key). On the next login to/if/admin/, your fingerprint is enough — no password typed, no TOTP code to copy.Logging in for the first time
Open https://<your-domain>/if/admin/ and sign in with the username akadmin and the password provided. If the application takes you to an initial setup screen, set the password yourself there, immediately.
Connect your entire stack via SSO
Every service you deploy from the ServOrbit marketplace can be connected to Authentik in minutes. Nextcloud supports OIDC via the Social Login app. Mattermost is configured under System Console → OAuth 2.0. Grafana reads OIDC from grafana.ini. Docmost, Metabase and Dockge each have an OAuth/OIDC configuration form. Once the plumbing is done, a newly created user in Authentik instantly gains access to all connected services — and revoking an account means a global logout at the next token refresh.
Custom authentication flows
The visual flow editor is what truly sets Authentik apart. You can build an enrollment flow that sends a verification email, requests a TOTP, then shows a profile-completion form — all without writing a single line of code. Pre-built stages (Email, Authenticator, Prompt, User Write, Deny) chain together on a canvas and each transition can carry a condition. It's the equivalent of what Auth0 offers with Actions, but open-source and entirely under your control.