MirrorNest
← All guides

Authentik

Authentik is a flexible identity provider supporting OAuth2/OIDC, SAML, LDAP, and proxy-based SSO, officially deployed via a single downloadable Docker Compose file.

Target: Any Docker hostSecurityAuthenticationOfficial homepage ↗Official docs ↗
This guide is synthesized from Authentik's own official documentation, linked above — always cross-check exact package/version names there before running these commands on a production server, since distro and project versions move over time.
  1. 1Download the official compose file

    wget https://docs.goauthentik.io/compose.yml
  2. 2Generate required secrets

    echo "PG_PASS=$(openssl rand -base64 36 | tr -d '\n')" >> .env
    echo "AUTHENTIK_SECRET_KEY=$(openssl rand -base64 60 | tr -d '\n')" >> .env
  3. 3Start authentik

    docker compose pull
    docker compose up -d

    Do not bind-mount /etc/timezone or /etc/localtime into the authentik containers.

  4. 4Complete initial setup

    Open http://<server-ip-or-hostname>:9000 and set a password for the default akadmin user.