Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For anyone, considering authentik, I want to warn you by saying "here be dragons."

To start, I have protected 10+ services at any given time. Both in docker and k8s. Unless you enjoy configuring protection for each service independently, you'll have a bad time in authentik.

Authentik suffers from a debilitating bug[0] where when using a single config to protect all services on subdomains (i.e. app1.example.com, app2.example.com, etc.) your users will be randomly redirected to a different service when reauthenticating after the session expires.

[0]: https://github.com/goauthentik/authentik/issues/6886



Hey, authentik CTO here!

We’ll be addressing the bug in the release after the next one (march-April)


Good to hear, I think it'll make many users happy. For me, I've migrated back to Authelia. I moved to authentik because at the time Authelia had no user management. After all of authentik's sharp edges, I've found lldap[0], and was able to implement a pilot in a few hours. I haven't looked back, since everything was converted.

[0]: https://github.com/lldap/lldap




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: