identity:accessControl service¶
Single sign-on in front of a published module: Authentik forward-auth on the module's reverse-proxy route, so a request has to log in before it reaches the app (#45).
What a consumer gets¶
- An Authentik application for the module — a Proxy Provider and an Application, attached to Authentik's embedded outpost.
- Forward-auth on its route: the Caddy handler that
network:proxycreated for the module is switched to forward-auth, so an unauthenticated request is redirected through Authentik. The global Authentik endpoint and the headers Caddy passes on are set up once, by the identity module's own install. - Delete removes the Application and the Provider. The Caddy handler is left to
network:proxy, whose delete removes the whole route.
How to use it¶
List it after network:proxy — it layers onto the route that service creates:
Who may log in to the app is decided by Authentik's groups and policies, managed with identity-manager.
Fields¶
identity:accessControl declares no fields.