Architecture Decision Record

ADR 004: Authentik as the Identity Provider

One login for everything — including the infrastructure itself — with every provider and application declared in Terraform.

Status: Accepted  ·  Date: Aug 2025  ·  ← All ADRs


Context

A platform running a dozen web UIs accumulates a dozen credential stores unless identity is centralized early. I wanted single sign-on with MFA in one place, group-based authorization, and — critically — the identity configuration itself under version control.

Options:

Decision

Authentik is the identity provider for everything. OAuth2/OIDC provider-application pairs are generated in Terraform from a single for_each map — adding SSO to a new app is one map entry. (Ten at the time of writing, nine today: grocy moved to a proxy provider in ADR 017, for reasons worth reading.) Authorization is two groups: application admins and application users, bound per-application.

The deliberate part is scope: not just user apps (Paperless, Outline, Home Assistant, and the rest) but the infrastructure itself — Vault, ArgoCD, Gitea, and even Proxmox authenticate against Authentik via OIDC.

Reasoning

Tradeoffs

Outcome

Onboarding the second user was a group membership, not ten account creations. The for_each pattern has held: new applications get SSO in roughly ten lines of diff.

Correction, Sep 2026. This section originally opened with “Every web surface on the platform sits behind the same login.” That was not true when it was written and had not been for some time. Seven surfaces — kiali, hubble-ui, netdata, dozzle, homepage, Stirling PDF, and grocy — had no working login, and grocy’s OIDC application pointed at a callback route it has never had. All seven are now behind the outpost; see ADR 017 for the decision and Everything Was Green for how a claim like that survives a year unchallenged.