Two related additions for gating a cross-host service (garage WebUI on a storage host) behind authentik without breaking on TLS or X-Forwarded-Host: garage role: - Add garage_webui_domains (list), mirroring garage_s3_domains. The console router now accepts every entry, so a DMZ reverseproxy can use a backend_host whose cert SAN matches an internal *.int.* name instead of connecting by IP (which fails acme cert verification). Defaults to the single garage_webui_domain so existing inventories are unaffected. authentik_outpost_proxy role (new): - Standalone proxy (ForwardAuth) outpost, modelled on authentik_outpost_ldap. Co-locate it with the protected service so the ForwardAuth subrequest reaches authentik over the local docker network. The embedded outpost only works for services on the authentik host: a cross-host subrequest routed through an extra reverse-proxy hop arrives with a polluted X-Forwarded-Host (port/comma-appended), which the outpost no longer matches against the provider's external_host (404). |
||
|---|---|---|
| .. | ||
| defaults | ||
| handlers | ||
| meta | ||
| tasks | ||
| templates | ||
| tests | ||
| vars | ||
| README.md | ||
authentik_outpost_proxy
Deploys an authentik proxy (ForwardAuth)
outpost via Docker Compose. The outpost serves the
/outpost.goauthentik.io/auth/* endpoints locally, so a Traefik
ForwardAuth middleware on the same host can gate services behind
authentik without routing the auth subrequest through additional reverse
proxies.
Use this when the protected service runs on a different host than the
authentik server: the embedded outpost only works for services co-located
with authentik (the subrequest must reach it without an intermediate proxy
mangling X-Forwarded-Host). Co-locating a proxy outpost with the service
keeps the ForwardAuth subrequest on the local docker network.
The outpost connects back to an authentik server using an outpost token issued in the authentik admin interface (register the outpost there and assign the proxy providers it should serve). The image version must match the authentik server version.
Requirements
- Docker and Docker Compose on the target host (e.g. via
digitalboard.core.base) - Ansible collection:
community.docker - An authentik proxy outpost registered on the server, with the proxy providers for the protected services assigned to it.
Role variables
| Variable | Default | Description |
|---|---|---|
authentik_outpost_proxy_image |
ghcr.io/goauthentik/proxy:2026.2.2 |
Outpost image (match the server version). |
authentik_outpost_proxy_host |
https://authentik.local.test |
URL of the authentik server. |
authentik_outpost_proxy_token |
changeme |
Outpost token — override this. |
authentik_outpost_proxy_insecure |
"true" |
Skip TLS verification toward the authentik server. |
authentik_outpost_proxy_network |
proxy |
Docker network the local Traefik routers and this outpost share. |
authentik_outpost_proxy_extra_hosts |
[] |
Extra host:ip entries for in-container DNS. |
The local ForwardAuth middleware then points at the container over the
shared network, e.g.
http://authentik-outpost-proxy-proxy-1:9000/outpost.goauthentik.io/auth/traefik.
Example
- hosts: storage
become: true
roles:
- role: digitalboard.core.authentik_outpost_proxy
vars:
authentik_outpost_proxy_host: "https://auth.example.com"
authentik_outpost_proxy_token: "{{ vault_authentik_proxy_outpost_token }}"
License
MIT-0