this post was submitted on 18 Mar 2025
85 points (96.7% liked)

Selfhosted

61475 readers
851 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

What are you folks using for self-hosted single sign-on?

I have my little LDAP server (lldap is fan-fucking-tastic -- far easier to work with than OpenLDAP, which gave me nothing but heartburn). Some applications can be configured to work with it directly; several don't have LDAP account support. And, ultimately, it'd be nice to have SSO - having the same password everywhere if great, but having to sign in only once (per day or week, or whatever) would be even nicer.

There are several self-hosted Auth* projects; which is the simplest and easiest? I'd really just like a basic start-it-up, point it at my LDAP server, and go. Fine grained ACLs and RBAC support is nice and all, but simplicity is trump in my case. Configuring these systems is, IME, a complex process, with no small numbers of dials to turn.

A half dozen users, and probably only two groups: admin, and everyone else. I don't need fancy. OSS, of course. Is there any of these projects that fit that bill? It would seem to be a common use case for self-hosters, who don't need all the bells and whistles of enterprise-grade solutions.

you are viewing a single comment's thread
view the rest of the comments
[–] steventhedev@lemmy.world 8 points 1 year ago* (last edited 1 year ago) (5 children)

Keycloak might seem a little daunting to start with, but is basically glue between your idp (ldap) and whatever apps need to authenticate.

[–] Grunt4019@lemm.ee 5 points 1 year ago (1 children)

My issue with keycloak is that the documentation is very poor as a beginner. It and almost any other guides online assume you already know things that you may not so I wasn’t able to get past that hurdle.

[–] steventhedev@lemmy.world 2 points 1 year ago

Strongly agree. A guide for dead simple setups would be incredibly useful (e.g. gsuite as idp, oauth for a single app).

It took me a few days to get that basic setup working, and a few days more to improve it. But once it was up, it was rock solid.

[–] jaark@infosec.pub 4 points 1 year ago

Another for Keycloak. Though it is probably overkill for many people's needs in here - it certainly is for mine! But it is what I have up and running and see no need to change to a simpler option.

[–] AddiXz@feddit.nl 1 points 1 year ago

Plus one for Keycloak here. Initially it may be a bit daunting but once it's set it's a rock and works flawlessly!

[–] mhzawadi@lemmy.horwood.cloud 1 points 1 year ago

Keycloak here, I plugged my keycloak into my Google workspace. Yes I know Google!!

But the login flow is amazing and I get all the MFA without the faff

[–] towerful@programming.dev 1 points 1 year ago

And keycloak has a decent k8s operator, making deployment on a k8s cluster a breeze