Harden infrastructure security.

Logo Authelia

Authelia

Add MFA, SSO and fine-grained access control in front of any app — no code changes required.

512 MB (1 GB recommended) RAM 1 vCPU Port 9091 Available

Tech stack

DockerGoSQLiteRedis 7
Minimum RAM512 MB (1 GB recommended)
Minimum CPU1 vCPU
Default port9091
Compatible OSubuntu-24.04

Authelia is an open-source authentication and authorization server that acts as a reverse-proxy companion. It intercepts every request to your apps and enforces your policy: one-factor login, two-factor (TOTP, WebAuthn/Passkeys), or bypass — based on domain, path, user group or network. Authelia itself handles the login portal; your app never needs to know it exists.

Deployed on a ServOrbit VPS, Authelia runs as a lightweight Go binary (~25 MB RAM) alongside a Redis session store. It integrates with Nginx, Caddy, Traefik and HAProxy as a forward-auth endpoint, and doubles as a full OpenID Connect (OIDC) provider, letting you add Single Sign-On across your entire self-hosted stack from a single configuration file. Apache 2.0 licensed, ~28 k GitHub stars.

Key features

MFA out of the box: TOTP, WebAuthn/Passkeys and Duo push — one config line per user or group
OpenID Connect (OIDC) certified provider: add SSO to any OIDC-compatible app in your stack
Fine-grained access control: allow, deny or require 2FA by domain, subdomain, path, IP network or user group
Reverse-proxy agnostic: native forward-auth support for Nginx, Caddy, Traefik, HAProxy and Envoy
Under 30 MB RAM at idle — runs comfortably alongside other services on a 1 GB VPS
File-based or LDAP user backend — start with a local users file, migrate to LDAP later without downtime

When to use this solution?

1

Protect internal tools

Put Authelia in front of Grafana, Dockge, Gitea or any admin UI. Users authenticate once at your auth portal and are forwarded to any protected app without re-entering credentials.

2

Add MFA to apps that don't support it

Many self-hosted apps have basic password auth or none at all. Authelia adds TOTP or passkey authentication at the proxy layer — zero changes to the app, zero code to write.

3

Self-hosted SSO across your stack

Configure Authelia as an OIDC provider and connect Nextcloud, Gitea, Mattermost and more. One login session, all your apps — on infrastructure you own.

Deploy Authelia on your VPS

Guide optimized for ServOrbit Cloud VPS.

01

Create the VPS

Order a ServOrbit VPS with at least 1 vCPU and 512 MB RAM (1 GB recommended). Ubuntu 22.04 LTS is the recommended OS. A domain name pointing to this VPS is required — Authelia's session cookies and OIDC callbacks require HTTPS with a valid FQDN.

02

Point your subdomain

Create an A record for your auth subdomain, for example auth.yourdomain.com, pointing to the VPS IP. SSL is handled automatically by the ServOrbit reverse proxy using Let's Encrypt.

03

Deploy Authelia

Select the Authelia template in the ServOrbit Marketplace. The provisioning job deploys the Compose stack (Authelia + Redis), generates all secrets, writes the initial configuration and creates the admin user. The portal is accessible at https://auth.yourdomain.com within minutes.

04

Configure your reverse proxy

Add a forward_auth directive to the Nginx, Caddy or Traefik configuration of each app you want to protect. Authelia's documentation has copy-paste snippets for every major proxy. ServOrbit VPS instances ship with Caddy by default.

05

Add users and enable MFA

Log in to the Authelia portal with the default admin credentials, register your TOTP app (Google Authenticator, Ente Auth, Aegis…) or a passkey, then create additional users. Update access control rules in configuration.yml to enforce 2FA for sensitive apps and one-factor for others.

Frequently asked questions

Authelia is an open-source (Apache 2.0) authentication and authorization gateway. It sits in front of your apps as a forward-auth endpoint, enforcing MFA and fine-grained access control without any changes to the apps themselves.

Harden infrastructure security.

Activate Authelia on your infrastructure.

Dedicated Cloud VPS — IPv4 included, European datacenter, support included. Your data never leaves your server.

Recommended configuration: 512 MB (1 GB recommended) RAM · 1 vCPU

Need help?

Browse our help center and FAQ, or write to our team — support in French, English and Arabic.