[{"data":1,"prerenderedAt":119},["ShallowReactive",2],{"seo-verification":3,"marketplace-app-en-authelia":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"slug":7,"slugs":8,"categorySlugs":9,"name":13,"description":14,"phase":15,"unavailableReason":16,"docsUrl":17,"logo":18,"github":19,"tagline":20,"longDescription":21,"features":22,"useCases":29,"steps":39,"faq":55,"specs":74,"compatibleOs":83,"relatedApps":85,"relatedPosts":112,"category":116},"authelia",{"fr":7,"en":7,"ar":7},{"fr":10,"en":11,"ar":12},"cybersecurity","cybersecurity-bastion","الأمن-السيبراني-والحصن","Authelia","Open-source authentication and authorization gateway — add MFA, SSO and fine-grained access control in front of any app without touching its code.",1,null,"https:\u002F\u002Fservorbit.com\u002Fblog\u002Fself-host-authelia-on-a-vps-mfa-and-sso-for-your-whole-stack","https:\u002F\u002Fcdn.simpleicons.org\u002Fauthelia","https:\u002F\u002Fgithub.com\u002Fauthelia\u002Fauthelia","Add MFA, SSO and fine-grained access control in front of any app — no code changes required.","Authelia is an open-source authentication and authorization server that acts as a reverse-proxy companion. It intercepts every request to your apps and enforces your policy: one-factor login, two-factor (TOTP, WebAuthn\u002FPasskeys), or bypass — based on domain, path, user group or network. Authelia itself handles the login portal; your app never needs to know it exists.\n\nDeployed on a ServOrbit VPS, Authelia runs as a lightweight Go binary (~25 MB RAM) alongside a Redis session store. It integrates with Nginx, Caddy, Traefik and HAProxy as a forward-auth endpoint, and doubles as a full OpenID Connect (OIDC) provider, letting you add Single Sign-On across your entire self-hosted stack from a single configuration file. Apache 2.0 licensed, ~28 k GitHub stars.",[23,24,25,26,27,28],"MFA out of the box: TOTP, WebAuthn\u002FPasskeys and Duo push — one config line per user or group","OpenID Connect (OIDC) certified provider: add SSO to any OIDC-compatible app in your stack","Fine-grained access control: allow, deny or require 2FA by domain, subdomain, path, IP network or user group","Reverse-proxy agnostic: native forward-auth support for Nginx, Caddy, Traefik, HAProxy and Envoy","Under 30 MB RAM at idle — runs comfortably alongside other services on a 1 GB VPS","File-based or LDAP user backend — start with a local users file, migrate to LDAP later without downtime",[30,33,36],{"title":31,"body":32},"Protect internal tools","Put Authelia in front of Grafana, Dockge, Gitea or any admin UI. Users authenticate once at your auth portal and are forwarded to any protected app without re-entering credentials.",{"title":34,"body":35},"Add MFA to apps that don't support it","Many self-hosted apps have basic password auth or none at all. Authelia adds TOTP or passkey authentication at the proxy layer — zero changes to the app, zero code to write.",{"title":37,"body":38},"Self-hosted SSO across your stack","Configure Authelia as an OIDC provider and connect Nextcloud, Gitea, Mattermost and more. One login session, all your apps — on infrastructure you own.",[40,43,46,49,52],{"title":41,"body":42},"Create the VPS","Order a ServOrbit VPS with at least 1 vCPU and 512 MB RAM (1 GB recommended). Ubuntu 22.04 LTS is the recommended OS. A domain name pointing to this VPS is required — Authelia's session cookies and OIDC callbacks require HTTPS with a valid FQDN.",{"title":44,"body":45},"Point your subdomain","Create an A record for your auth subdomain, for example `auth.yourdomain.com`, pointing to the VPS IP. SSL is handled automatically by the ServOrbit reverse proxy using Let's Encrypt.",{"title":47,"body":48},"Deploy Authelia","Select the Authelia template in the ServOrbit Marketplace. The provisioning job deploys the Compose stack (Authelia + Redis), generates all secrets, writes the initial configuration and creates the admin user. The portal is accessible at `https:\u002F\u002Fauth.yourdomain.com` within minutes.",{"title":50,"body":51},"Configure your reverse proxy","Add a `forward_auth` directive to the Nginx, Caddy or Traefik configuration of each app you want to protect. Authelia's documentation has copy-paste snippets for every major proxy. ServOrbit VPS instances ship with Caddy by default.",{"title":53,"body":54},"Add users and enable MFA","Log in to the Authelia portal with the default admin credentials, register your TOTP app (Google Authenticator, Ente Auth, Aegis…) or a passkey, then create additional users. Update access control rules in `configuration.yml` to enforce 2FA for sensitive apps and one-factor for others.",[56,59,62,65,68,71],{"q":57,"a":58},"What is Authelia?","Authelia is an open-source (Apache 2.0) authentication and authorization gateway. It sits in front of your apps as a forward-auth endpoint, enforcing MFA and fine-grained access control without any changes to the apps themselves.",{"q":60,"a":61},"Does Authelia replace each app's own login?","It depends on the app. For apps without authentication (internal dashboards, admin UIs), Authelia adds a login wall at the proxy layer. For OIDC-compatible apps like Gitea or Nextcloud, Authelia can become the identity provider and replace the app's own login entirely, giving you true SSO.",{"q":63,"a":64},"How much RAM does Authelia need?","Very little. Authelia itself idles under 30 MB RAM. Add ~20 MB for the Redis session store. A 512 MB VPS is sufficient for personal use; 1 GB is comfortable for a team of 10-20 users.",{"q":66,"a":67},"Does Authelia require a domain name?","Yes. Session cookies require a proper domain (`Domain=.yourdomain.com`), and OIDC callbacks and Let's Encrypt certificates require a publicly resolvable FQDN with HTTPS. Authelia cannot work correctly behind a plain IP address.",{"q":69,"a":70},"Which reverse proxies does Authelia support?","Authelia has first-class support for Nginx, Caddy, Traefik, HAProxy, Envoy and Skipper via its `forward_auth` \u002F `ext_authz` endpoint. The documentation provides copy-paste configuration snippets for each proxy.",{"q":72,"a":73},"Is Authelia compatible with passkeys and hardware security keys?","Yes. Authelia v4.38+ supports WebAuthn (FIDO2), which covers passkeys, Touch ID, Face ID, YubiKeys and any FIDO2-compliant hardware key. Users can register multiple second-factor methods and choose at login time.",{"ram":75,"cpu":76,"stack":77,"port":82},"512 MB (1 GB recommended)","1 vCPU",[78,79,80,81],"Docker","Go","SQLite","Redis 7","9091",[84],"ubuntu-24.04",[86,94,103],{"name":87,"slug":88,"categorySlug":11,"categoryName":89,"categoryColor":90,"logo":91,"tagline":92,"description":93},"Vaultwarden","vaultwarden","Cybersecurity & Bastion","text-red-400 bg-red-500\u002F10","https:\u002F\u002Fcdn.jsdelivr.net\u002Fgh\u002Fselfhst\u002Ficons\u002Fsvg\u002Fvaultwarden.svg","Self-hosted Bitwarden in one Rust container — unlimited passwords, zero subscription, your data stays on your VPS.","Self-hosted Bitwarden-compatible password manager written in Rust. All Bitwarden clients work out of the box — browser extensions, mobile apps, desktop — under 50 MB RAM.",{"name":95,"slug":96,"categorySlug":97,"categoryName":98,"categoryColor":99,"logo":100,"tagline":101,"description":102},"WireGuard Server","wireguard-server","networking-vpn","Networking & VPN","text-sky-400 bg-sky-500\u002F10","https:\u002F\u002Fcdn.simpleicons.org\u002Fwireguard","Modern VPN built into the Linux kernel — secure connections for your teams and infrastructure.","Modern, minimal VPN built into the Linux kernel. Secure connections for your teams and infrastructure.",{"name":104,"slug":105,"categorySlug":106,"categoryName":107,"categoryColor":108,"logo":109,"tagline":110,"description":111},"Caddy","caddy","application-deployment-devops","Application Deployment & DevOps","text-success bg-success\u002F10","https:\u002F\u002Fcdn.simpleicons.org\u002Fcaddy","Automatic SSL for your applications — effortless HTTPS, auto-renewed certificates.","A modern web server and reverse proxy with automatic HTTPS. Let's Encrypt SSL certificates are obtained and renewed on their own, with minimal configuration via a Caddyfile.",[113,114,115],"self-host-authelia-vps","deploy-vaultwarden-vps","securiser-vps-crowdsec",{"key":117,"slug":11,"name":89,"objective":118,"icon":117,"color":90},"security","Harden infrastructure security.",1787581038080]