b3c3fe5c56306d96dcef4a0236f6aeb68e75d1a4
Merge completed authentik Quadlet implementation that resolves all deployment issues and enables external HTTPS access. This brings the working solution developed and tested on authentik-quadlet-fix branch into main. All systemd services now generate correctly and authentik is fully operational at https://auth.jnss.me with proper SSL termination via Caddy.
Rick's Infra
Arch Linux VPS
Ansible
Infrastructure as code for setting up new instance.
- Security
- SSH
- Firewall
- Fail2ban
- Kernel hardening
- Base packages
- Monitoring/Logging
- Backup
Services
Services are managed by serviced
Caddy
Reverse proxy.
Containers
Containers are managed by rootless Podman.
Documentation
Service Integration
- Service Integration Guide - How to add containerized services with PostgreSQL/Valkey access
Role Documentation
- Authentik Role - Authentication service with Unix socket implementation
- PostgreSQL Role - Database service with Unix socket support
- Valkey Role - Cache service with Unix socket support
- Caddy Role - Reverse proxy and SSL termination
Infrastructure Guides
- Deployment Guide - Complete deployment walkthrough
- Security Hardening - Security configuration and best practices
Description
Languages
Jinja
100%