Files
oikos/knowledge/wiki/containers/106-auth-outpost.md
dtoro b5c1247093 docs: streamline & consolidate the tree (phase 6)
Problem: after the wiki-hq reorg, agent-instruction and human-doc domains
were still scattered across the repo root, with three now-redundant stub
files cluttering it. The organizing principle wasn't visible in the layout.

Change — enforce three clear buckets:
- .agents/  = how agents operate: OIKOS.md, HERMES.md (moved from root),
  shared/ conventions, domains/ schemas, skills/, and operations/ (operator
  cheatsheet + enrollment + hermes-agent, moved from root).
- knowledge/ = what exists + evidence: wiki/, GLOSSARY.md, and sources/ now
  including investigations/ (incident records are evidence/sources).
- root = substrate + two entry points (AGENTS.md, README.md), plus plans/
  as its own design-intent domain.

Moves:
- investigations/ -> knowledge/sources/investigations/ (incl. archive/, index).
- operations/ -> .agents/operations/.
- HERMES.md -> .agents/HERMES.md.
- Deleted unreferenced root stubs CAVEMAN.md, CONTRIBUTING.md, and OIKOS.md
  (its 7 remaining linkers repointed to .agents/OIKOS.md).

Consumers updated:
- inventory.yaml doc_page (agent-enrollment) + regenerated hosts/*.yaml + cards.
- tools/setup-hermes-soul.sh and bootstrap.sh (x2) -> .agents/HERMES.md.
- bin/homelab help string -> .agents/operations/hermes-agent.md.
- knowledge/operations schemas, llm-wiki, page-templates, incident-investigation
  skill, AGENTS.md/README nav -> new investigations/operations paths.
- All markdown links rewritten via the path-resolving mapper.

Left in place (substrate/executable/separate-domain): hosts/, ledger/, tools/,
plans/, oikos/, mcp/, secrets/, bin/, inventory.yaml.

Verification: docs-lint at baseline (2 intentional cross-repo refs, no new
breakage); gen-topology.py --check exit 0; build_host_files.py idempotent; all
doc_page targets resolve; Hermes provisioning scripts point at the new path.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 18:12:14 +02:00

5.0 KiB

106 — auth-outpost

Authentik forward-auth outpost for LAN-gated apps. A stateless proxy that connects outbound to the VPS Authentik core and serves forward-auth locally, so Caddy (121) never hairpins auth through VPS Traefik.

At a glance

  • Hostname: auth-outpost
  • IP: 192.168.8.6 (static)
  • Privilege: privileged (Docker-in-LXC, features: nesting=1)
  • Resources: 1 core / 512 MiB / 4 GiB rootfs
  • Mounts: none
  • Created: 2026-06-01, Debian 13, replacing the embedded outpost on 124

Role

Runs one container — ghcr.io/goauthentik/proxy — that opens an outbound websocket to https://auth.hubris.network (the VPS core), pulls its proxy-provider config, and answers Caddy's forward_auth subrequests on 192.168.8.6:9000 (LAN-only bind). Because the call path is Caddy → outpost (LAN), with no Traefik in between, X-Forwarded-Host is preserved — the failure that 404s when Caddy is pointed at https://auth.hubris.network directly (Traefik rewrites the header). See the migration investigation.

Service / port map

Service Listen Notes
authentik proxy outpost 192.168.8.6:9000 /outpost.goauthentik.io/* (ping, auth/caddy)

Config paths

  • /opt/authentik-outpost/docker-compose.ymlghcr.io/goauthentik/proxy:2026.5.2, AUTHENTIK_HOST=https://auth.hubris.network, AUTHENTIK_INSECURE=false, port bound 192.168.8.6:9000.
  • /opt/authentik-outpost/.env (mode 600, untracked) — AUTHENTIK_TOKEN for outpost hubris-lan-outpost (sops-encrypt into secrets/ — TODO Phase 5).

The outpost object (VPS Authentik)

  • Outpost hubris-lan-outpost (type proxy), providers: hubris-forward-auth (domain, Paperless + domain-level apps), Provider for Torrent (qBittorrent), Provider for Artifacto (single).
  • Health: VPS admin → Applications → Outposts → last-seen current; curl http://192.168.8.6:9000/outpost.goauthentik.io/ping204; container log Successfully connected websocket.

Caddy wiring

Caddy (121) (authentik) snippet reverse_proxy/forward_authhttp://192.168.8.6:9000 (was 192.168.8.180:9000 on LXC 124). Tracked in dtoro/caddy-conf.

sso.hubris.network — the callback domain (critical)

Domain-level (forward_domain) providers redirect the browser to {external_host}/outpost.goauthentik.io/callback after login. On LXC 124 that external_host was auth.hubris.network, which resolved (LAN) to Caddy → the 124 outpost — same box, so it worked. Post-migration auth.hubris.network points to the VPS core, so the callback hit the wrong outpost → 400 / redirect-uri mismatch.

Fix: the LAN outpost gets its own domain.

  • DNS: sso.hubris.network → 192.168.8.175 (Caddy). (in dnsmasq today — must be carried into Technitium in DNS Phase 2.)
  • Caddy: site sso.hubris.network { tls dns ionos; reverse_proxy 192.168.8.6:9000 } (in caddy-conf).
  • Authentik: hubris-forward-auth and Provider for Torrent have external_host=https://sso.hubris.network; their redirect_uris must match (set_oauth_defaults() regenerates them from external_host — changing external_host alone does NOT update them).
  • Provider for Artifacto is forward_single on its own domain, so it was unaffected.

Lesson: when the IdP core and the forward-auth outpost live on different hosts, the outpost needs a dedicated domain distinct from the core's — and proxy-provider redirect_uris must be regenerated, not just external_host.

Changelog

2026-06-06 — Authentik session lifetime extended to 30 days

VPS Authentik core user_login stage updated: session_duration changed from seconds=0 (session cookie, cleared on browser close) to days=30 (persistent 30-day cookie). Also set AUTHENTIK_SESSIONS__UNAUTHENTICATED_AGE=days=30 in /opt/authentik.env on the VPS. See investigation.

2026-06-01 — created; forward-auth cut over from LXC 124

New dedicated LXC for the LAN forward-auth outpost (Phase 1 of the architecture migration). Deployed goauthentik/proxy:2026.5.2 pointed at the VPS core; repointed Caddy (authentik) from 192.168.8.180:9000192.168.8.6:9000. Verified Paperless/qBittorrent/Artifacto return the SSO redirect with 124-Authentik stopped, confirming the frozen instance is out of the path. dnsmasq stays on 124 until DNS is relocated.