
Authentik is an open-source identity provider (IdP) that implements OAuth 2.0, OpenID Connect (OIDC), and SAML. Deploying Authentik on a Vultr Cloud Compute instance gives you full control over authentication, enables single sign-on (SSO) across internal tools, and keeps user data on your own infrastructure.
In this guide, you deploy Authentik with Docker Compose, secure it behind a reverse proxy (Caddy or NGINX) with HTTPS, harden the server, and register an OAuth 2.0 client to protect a sample web application. When you finish, you’ll have a production-ready, self-hosted authentication service running on Vultr.
Before you begin,
sudo privileges.auth.example.com. Replace all occurrences of auth.example.com in this guide with your actual domain.Create a dedicated project directory for Authentik in your home directory.
Generate a 64-character hexadecimal secret key for Authentik.
Copy the generated key for use in the next step.
Create a .env file to store the secrets.
Add the following content in the .env file:
Replace <POSTGRES_USER_PASSWORD> and <64_CHAR_SECRET_KEY> with the alphanumeric password and the secret key you generated earlier, respectively.
Save and exit the file.
Download the official docker-compose.yml manifest for Authentik.
Start the stack in detached mode.
List the running services and verify that all services are healthy.
Output:
Ensure your domain resolves to the public IP of your Vultr instance that runs Authentik. TLS issuance will fail if DNS is wrong or ports are closed.
View the ufw status.
If the status of ufw displays inactive then run the below command.
Allow the required HTTP and HTTPS ports.
View the ufw status.
Install the Caddy web server using apt.
Create and configure the Caddyfile to reverse proxy to Authentik.
Remove the existing content and add the following:
Save and exit the file.
Format the Caddyfile configuration file.
Validate the configuration and reload the Caddy service.
Caddy automatically issues and renews TLS certificates when DNS is correctly configured and ports 80/443 are accessible.
Open the Initial Setup flow to create the first administrator account.
On the setup page, enter your email and a strong password to complete the admin account setup.
If the application is not reachable, check the Caddy web server logs.
In this section, you’ll register an OAuth 2.0 client in Authentik, then run a minimal Node.js app that uses it to validate authentication.
Sign in to the Authentik Admin UI.
Create an OAuth2/OpenID Provider for the sample application.
Sample App Providerdefault-provider-authorization-explicit-consentConfidentialhttps://app.example.com/auth/callbackdefault-authentication-flowBased on the User's hashed IDCreate the application and link it to the provider you just created.
Sample Web Appsample-web-appSample App ProviderANYhttps://auth.example.comFollow the steps below to provision a minimal web application and validate the Authorization Code flow against Authentik.
Clone the sample repository and enter the project directory.
Install npm.
Install runtime dependencies.
Generate a session secret.
Configure environment variables.
Paste the following and set the values precisely:
In the above file:
https://auth.example.com with the URL of your Authentik instance.https://app.example.com with the URL where your sample app will run.<CLIENT_ID_FROM_AUTHENTIK_PROVIDER> and <CLIENT_SECRET_FROM_AUTHENTIK_PROVIDER> with the values generated when you created the OAuth2/OpenID Provider in Authentik.<RANDOM_SESSION_SECRET_GENERATED_ABOVE> with the session secret you generated in the previous step.Make sure all values are set correctly before starting the application.
Start the application.
Ensure that you configure a reverse proxy and SSL for the app, similar to how you configured auth.example.com but for port 3000.
Navigate to https://app.example.com and click Login with Authentik.
Enter your OAuth2 user credentials.
After authentication, the app exchanges the authorization code for tokens and redirects to /protected.
If you encounter issues while connecting your sample app to Authentik, follow these steps:
Check the OAuth2 Provider and Application settings,eEnsure that your Authentik Provider and Application are configured correctly, particularly the Redirect URI.
Authentik server logs can provide insight into errors during login or token exchange. Use the following command to view the logs in real-time.
Look for any warnings or errors related to OAuth2 flows, redirect URIs, or authentication failures.
Confirm that your reverse proxy (Caddy or NGINX) forwards requests correctly to 127.0.0.1:9000 and that HTTPS is properly configured. Misconfigured proxy settings can prevent callback URLs from reaching Authentik.
OAuth2 state mismatches may occur due to stale sessions. Try logging in using a private or incognito browser window to ensure a clean session.
You successfully deployed a self-hosted Authentik instance on Vultr with Docker Compose, secured it behind HTTPS, and verified OAuth2 SSO with a sample Node.js app. With this foundation, you can now onboard additional applications, enable email flows, and scale your authentication infrastructure while keeping full control over user data.
0 Comments
Be the first to comment and share your perspective with the community.