Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Selfhosted
  3. Authentik vs Authelia?

Authentik vs Authelia?

Scheduled Pinned Locked Moved Selfhosted
selfhosted
27 Posts 20 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K This user is from outside of this forum
    K This user is from outside of this forum
    [email protected]
    wrote last edited by
    #1

    I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

    Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

    So, for those using Authentik, how has your experience been so far?

    L A E sk@utsukta.orgS roofuskit@lemmy.worldR 17 Replies Last reply
    25
    • K [email protected]

      I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

      Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

      So, for those using Authentik, how has your experience been so far?

      L This user is from outside of this forum
      L This user is from outside of this forum
      [email protected]
      wrote last edited by
      #2

      Authelia + lldap(lightweight ldap) has been a really nice and powerful setup that negates the need for authentik for me. Authelia and authentik have diffrent goals tho, authelia is by design less powerfull and has a much smaller code base so that independent teams can audit the code themselves and a "set and forget" type configuration. Authentik is targeted at being an enterprise solution with all the bells and whistles. If you need those bells and whistles and dont want to use authentik try looking at keycloak (which also needs an ldap backend)

      A 1 Reply Last reply
      9
      • K [email protected]

        I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

        Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

        So, for those using Authentik, how has your experience been so far?

        A This user is from outside of this forum
        A This user is from outside of this forum
        [email protected]
        wrote last edited by
        #3

        I just switched from Authelia to PocketID
        No good reason.
        Mainly because Authelia was a bit convoluted and I needed something very basic.

        1 Reply Last reply
        2
        • L [email protected]

          Authelia + lldap(lightweight ldap) has been a really nice and powerful setup that negates the need for authentik for me. Authelia and authentik have diffrent goals tho, authelia is by design less powerfull and has a much smaller code base so that independent teams can audit the code themselves and a "set and forget" type configuration. Authentik is targeted at being an enterprise solution with all the bells and whistles. If you need those bells and whistles and dont want to use authentik try looking at keycloak (which also needs an ldap backend)

          A This user is from outside of this forum
          A This user is from outside of this forum
          [email protected]
          wrote last edited by
          #4

          Keycloak user here!
          You don't need** LDAP to use keycloak, but you can use it (I do too). Afaik keycloak is not always the easiest (not always clear instructions) but it works flawlessly for me and those who I authenticate. I use it for almost all my self hosted services except those who don't support it (obviously).I can manage my users in LDAP and use keycloak for SSO etc. I would definitely recommend it!

          1 Reply Last reply
          3
          • K [email protected]

            I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

            Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

            So, for those using Authentik, how has your experience been so far?

            E This user is from outside of this forum
            E This user is from outside of this forum
            [email protected]
            wrote last edited by
            #5

            I'm using PocketID as it is super simple to set up. I've also paired it with TinyAuth for those services that don't support SSO.

            I also use Swag as my reverse proxy, which just added native support for TinyAuth.

            moonraven@feddit.nlM 1 Reply Last reply
            9
            • K [email protected]

              I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

              Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

              So, for those using Authentik, how has your experience been so far?

              sk@utsukta.orgS This user is from outside of this forum
              sk@utsukta.orgS This user is from outside of this forum
              [email protected]
              wrote last edited by
              #6
              I doubt authentik will enshittify, i have been using it since 2 years and have been on their discord interacting with the team. They are very helpful and recently made some useful enterprise features available for self hosted users which is the opposite of enshittification.
              1 Reply Last reply
              2
              • K [email protected]

                I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

                Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

                So, for those using Authentik, how has your experience been so far?

                roofuskit@lemmy.worldR This user is from outside of this forum
                roofuskit@lemmy.worldR This user is from outside of this forum
                [email protected]
                wrote last edited by
                #7

                I very much enjoy authentik. Great tool. Lots of great documentation.

                1 Reply Last reply
                2
                • K [email protected]

                  I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

                  Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

                  So, for those using Authentik, how has your experience been so far?

                  notquitenothing@sh.itjust.worksN This user is from outside of this forum
                  notquitenothing@sh.itjust.worksN This user is from outside of this forum
                  [email protected]
                  wrote last edited by
                  #8

                  You can try VoidAuth, it is kinda similar to Authelia+lldap. I am the developer and I created it because I wasn’t satisfied with Authelia’s user management. If you decide you want to try it and run into any issues or questions I will try to help 🙂

                  sxan@midwest.socialS K 2 Replies Last reply
                  8
                  • K [email protected]

                    I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

                    Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

                    So, for those using Authentik, how has your experience been so far?

                    J This user is from outside of this forum
                    J This user is from outside of this forum
                    [email protected]
                    wrote last edited by
                    #9

                    I use authentik and like it. The learning curve isn’t that steep so not a lot of wasted investment if you decide to ditch it for something else. No password flow with webauthn is pretty cool.

                    1 Reply Last reply
                    0
                    • E [email protected]

                      I'm using PocketID as it is super simple to set up. I've also paired it with TinyAuth for those services that don't support SSO.

                      I also use Swag as my reverse proxy, which just added native support for TinyAuth.

                      moonraven@feddit.nlM This user is from outside of this forum
                      moonraven@feddit.nlM This user is from outside of this forum
                      [email protected]
                      wrote last edited by [email protected]
                      #10

                      Seconding Pocket ID. Very lightweight and fast while also doing everything I need.

                      1 Reply Last reply
                      1
                      • notquitenothing@sh.itjust.worksN [email protected]

                        You can try VoidAuth, it is kinda similar to Authelia+lldap. I am the developer and I created it because I wasn’t satisfied with Authelia’s user management. If you decide you want to try it and run into any issues or questions I will try to help 🙂

                        sxan@midwest.socialS This user is from outside of this forum
                        sxan@midwest.socialS This user is from outside of this forum
                        [email protected]
                        wrote last edited by
                        #11

                        I like the motivation behind this, but have a allergy to running critical infrastructure like authentication on node.

                        To each their own, though, and good luck with the project. Diversity is life.

                        1 Reply Last reply
                        3
                        • K [email protected]

                          I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

                          Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

                          So, for those using Authentik, how has your experience been so far?

                          sxan@midwest.socialS This user is from outside of this forum
                          sxan@midwest.socialS This user is from outside of this forum
                          [email protected]
                          wrote last edited by
                          #12

                          Why don't you like LDAP? OpenLDAP is a PITA (necessarily, I guess, to be considered "enterprise"), but lldap has been pretty nice to me. I mean, it's the identity protocol, it's just that the server software has been complex until relatively recently.

                          What would you use instead? A SQL DB with some custom schema, that just re-invents LDAP?

                          possiblylinux127@lemmy.zipP 1 Reply Last reply
                          2
                          • K [email protected]

                            I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

                            Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

                            So, for those using Authentik, how has your experience been so far?

                            M This user is from outside of this forum
                            M This user is from outside of this forum
                            [email protected]
                            wrote last edited by
                            #13

                            There’s also Zitadel: https://zitadel.com/

                            K 1 Reply Last reply
                            0
                            • K [email protected]

                              I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

                              Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

                              So, for those using Authentik, how has your experience been so far?

                              bear@slrpnk.netB This user is from outside of this forum
                              bear@slrpnk.netB This user is from outside of this forum
                              [email protected]
                              wrote last edited by
                              #14

                              Authentik has done the opposite of enshittification. As they've gotten more successful, they've taken enterprise features and moved them into the community edition. I've been extremely happy with Authentik so far and the dev has been nothing short of fantastic every time I've seen them interacting with the community.

                              1 Reply Last reply
                              2
                              • K [email protected]

                                I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

                                Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

                                So, for those using Authentik, how has your experience been so far?

                                M This user is from outside of this forum
                                M This user is from outside of this forum
                                [email protected]
                                wrote last edited by [email protected]
                                #15

                                I'm on my phone rn and can't write a longer post. This comment is to remind me to write an essay later. I've been using authentik heavily for my cybersecurity club and have a LOT of thoughts about it.

                                The tldr about authentik's risk of enshittification is that authentik follows a pattern I call "supportware". It's when extremely (intentionally/accidentally) complex software (intentionally/accidentally) lacks edge cases in their docs,because you are supposed to pay for support.

                                I think this is a sustainable business model, and I think keycloak has some similar patterns (and other Red Hat software).

                                The tldr about authentik itself is that it has a lot of features, but not all of them are relevant to your usecase, or worth the complexity. I picked up authentik for invites (which afaik are rare, also official docs about setting up invites were wrong, see supportware), but invites may not something you care about.

                                Anyway. Longer essay/rant later. Despite my problems, I still think authentik is the best for my usecase (cybersecurity club), and other options I've looked at like zitadel (seems to be more developer focused),or ldap + sso service (no invites afaik) are less than the best option.

                                Sidenote: Microsoft entra is offers similar features to what I want from authentik, but I wanted to self host everything.

                                K 1 Reply Last reply
                                2
                                • sxan@midwest.socialS [email protected]

                                  Why don't you like LDAP? OpenLDAP is a PITA (necessarily, I guess, to be considered "enterprise"), but lldap has been pretty nice to me. I mean, it's the identity protocol, it's just that the server software has been complex until relatively recently.

                                  What would you use instead? A SQL DB with some custom schema, that just re-invents LDAP?

                                  possiblylinux127@lemmy.zipP This user is from outside of this forum
                                  possiblylinux127@lemmy.zipP This user is from outside of this forum
                                  [email protected]
                                  wrote last edited by
                                  #16

                                  LDAP and ldaps are not great from a security perspective. They pass password though the application which means a single compromised app will create a full breach.

                                  Better to use OpenID which uses a single sign on portal that tells the underlying app when authentication is successful. It has a much smaller attack surface and allows for much more flexibility.

                                  K 1 Reply Last reply
                                  0
                                  • K [email protected]

                                    I'm currently using Authelia to authenticate for some of my self hosted services. It works fine, but the limited user backends (ldap or... yaml??) make me want to look for an alternative.

                                    Authentik seems good, but after looking at their website I get the feeling of imminent enshitification, where they're going to either pull the rug on the open source version, or basically gatekeep essential features behind an enterprise license.

                                    So, for those using Authentik, how has your experience been so far?

                                    possiblylinux127@lemmy.zipP This user is from outside of this forum
                                    possiblylinux127@lemmy.zipP This user is from outside of this forum
                                    [email protected]
                                    wrote last edited by
                                    #17

                                    Keycloak all the way

                                    1 Reply Last reply
                                    2
                                    • M [email protected]

                                      I'm on my phone rn and can't write a longer post. This comment is to remind me to write an essay later. I've been using authentik heavily for my cybersecurity club and have a LOT of thoughts about it.

                                      The tldr about authentik's risk of enshittification is that authentik follows a pattern I call "supportware". It's when extremely (intentionally/accidentally) complex software (intentionally/accidentally) lacks edge cases in their docs,because you are supposed to pay for support.

                                      I think this is a sustainable business model, and I think keycloak has some similar patterns (and other Red Hat software).

                                      The tldr about authentik itself is that it has a lot of features, but not all of them are relevant to your usecase, or worth the complexity. I picked up authentik for invites (which afaik are rare, also official docs about setting up invites were wrong, see supportware), but invites may not something you care about.

                                      Anyway. Longer essay/rant later. Despite my problems, I still think authentik is the best for my usecase (cybersecurity club), and other options I've looked at like zitadel (seems to be more developer focused),or ldap + sso service (no invites afaik) are less than the best option.

                                      Sidenote: Microsoft entra is offers similar features to what I want from authentik, but I wanted to self host everything.

                                      K This user is from outside of this forum
                                      K This user is from outside of this forum
                                      [email protected]
                                      wrote last edited by
                                      #18

                                      I like the "supportware" term, I can apply that to a few other tools (airbyte, teleport).
                                      I ended up setting up authentik today and it went really smoothly. So far I like it a lot, so hopefully the full enshittification process doesn't happen soon.
                                      Even though right now I just want to use it for my own self-hosting purposes, I'm also interested in potentially using it for work. We have a few hundred thousand users and AWS cognito is getting pretty expensive.

                                      1 Reply Last reply
                                      1
                                      • possiblylinux127@lemmy.zipP [email protected]

                                        LDAP and ldaps are not great from a security perspective. They pass password though the application which means a single compromised app will create a full breach.

                                        Better to use OpenID which uses a single sign on portal that tells the underlying app when authentication is successful. It has a much smaller attack surface and allows for much more flexibility.

                                        K This user is from outside of this forum
                                        K This user is from outside of this forum
                                        [email protected]
                                        wrote last edited by
                                        #19

                                        Yep, this is what I'm looking for

                                        1 Reply Last reply
                                        0
                                        • M [email protected]

                                          There’s also Zitadel: https://zitadel.com/

                                          K This user is from outside of this forum
                                          K This user is from outside of this forum
                                          [email protected]
                                          wrote last edited by
                                          #20

                                          I tried it before authelia, and it felt like an unfinished product. Nice looking, but there were weird issues, like you could create projects (or apps? i don't remember) through the UI, but then if you wanted to delete them you had to use the API.
                                          The hierarchy of resources also didn't really feel intuitive to me. But that's just personal preference.
                                          I've been testing out authentik today and I really like it. I like that the UI works great, but there's also a terraform provider to manage things declaratively.

                                          1 Reply Last reply
                                          1
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups