Arama Yap Mesaj Submit
Request a Callback
+90
X
X

Select Your Currency

Turkish Lira $ US Dollar Euro
X
X

Select Your Currency

Turkish Lira $ US Dollar Euro

Contact Us

Location Halkali merkez neighborhood fatih st ozgur apt no 46 , Kucukcekmece , Istanbul , 34303 , TR

Authentik SSO Setup: Secure Access to Multiple Applications

Deploy Authentik with Docker Compose, including PostgreSQL, initial admin, Nginx reverse proxy, OIDC provider, application integration, MFA, recovery account, SMTP and backup.

Authentik SSO Setup: Secure Access to Multiple Applications
What will be running at the end?

Deploy Authentik with Docker Compose, including PostgreSQL, initial admin, Nginx reverse proxy, OIDC provider, application integration, MFA, recovery account, SMTP and backup. Every command is presented as an operational step; replace example hostnames, passwords and secrets before execution.

Architecture and requirements before installation

  • Ubuntu 24.04 LTS with sudo access and a dedicated IPv4 address
  • Docker Engine and Compose v2 where the deployment uses containers
  • A DNS A record pointing the application hostname to the server
  • NVMe capacity sized for application data, logs, temporary files and backups
  • Memory and CPU headroom based on measured concurrency rather than vendor minimums

DNS and port plan

  • 80/443 TCP: reverse proxy
  • 9000/9443 TCP: Authentik iç/yerel erişim
  • 5432 TCP: PostgreSQL yalnız iç ağ

Hands-on installation steps

1. Compose dosyası
mkdir -p /opt/authentik && cd /opt/authentik
wget -O compose.yml https://docs.goauthentik.io/compose.yml
2. Sır üretimi
echo "PG_PASS=$(openssl rand -base64 36 | tr -d '\n')" >> .env
echo "AUTHENTIK_SECRET_KEY=$(openssl rand -base64 60 | tr -d '\n')" >> .env
echo "AUTHENTIK_ERROR_REPORTING__ENABLED=false" >> .env
3. SMTP ayarı
AUTHENTIK_EMAIL__HOST=smtp.example.com
AUTHENTIK_EMAIL__PORT=587
[email protected]
AUTHENTIK_EMAIL__PASSWORD=SMTP_PAROLASI
AUTHENTIK_EMAIL__USE_TLS=true
[email protected]
4. Başlatma
sudo docker compose -f compose.yml config
sudo docker compose -f compose.yml up -d
sudo docker compose -f compose.yml ps
curl -I http://127.0.0.1:9000/if/flow/initial-setup/
5. Ayar doğrulama
sudo docker compose -f compose.yml run --rm worker ak dump_config
sudo docker compose -f compose.yml logs --since 10m server worker
6. PostgreSQL yedeği
sudo docker compose -f compose.yml exec -T postgresql pg_dump -U authentik -d authentik -Fc > authentik-$(date +%F).dump
sha256sum authentik-$(date +%F).dump
7. Yönetici kurtarma
sudo docker compose -f compose.yml exec server ak changepassword akadmin
8. Güncelleme
cd /opt/authentik
sudo docker compose -f compose.yml pull
sudo docker compose -f compose.yml up -d
sudo docker compose -f compose.yml ps
9. Nginx reverse proxy
sudo apt update
sudo apt install -y nginx certbot python3-certbot-nginx
sudo tee /etc/nginx/sites-available/sso.example.com > /dev/null <<'NGINX'
server {
    listen 80;
    listen [::]:80;
    server_name sso.example.com;
    client_max_body_size 10G;
    proxy_read_timeout 3600;
    proxy_send_timeout 3600;
    location / {
        proxy_pass http://127.0.0.1:9000;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}
NGINX
sudo ln -s /etc/nginx/sites-available/sso.example.com /etc/nginx/sites-enabled/sso.example.com
sudo nginx -t
sudo systemctl reload nginx
10. Let’s Encrypt SSL ve yenileme testi
sudo certbot --nginx -d sso.example.com --redirect --agree-tos --no-eff-email -m [email protected]
sudo certbot renew --dry-run
curl -I https://sso.example.com
openssl s_client -connect sso.example.com:443 -servername sso.example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates

What to know before production

Production note
Authentik SSO Setup must be isolated behind HTTPS; databases, queues and internal APIs must not be published directly to the internet.
Production note
Pin tested image versions before production. Read release notes and take an application-consistent backup before database migrations.
Production note
A database dump alone may be incomplete. Preserve persistent files, configuration, encryption keys and the exact deployed version together.
Production note
Validate the installation with a real transaction or workload, then reboot the host and confirm automatic recovery before accepting production traffic.

Common failures and root causes

Belirti / SymptomKök neden ve çözüm / Root cause and fix
Service or container does not startInspect compose configuration, dependency health, file permissions and the first fatal log line instead of repeatedly restarting.
Domain opens but HTTPS failsCheck A/AAAA records, ports 80/443, proxy mode, certificate challenge and conflicting reverse proxies.
Application cannot reach its database or queueUse the internal service hostname, verify credentials and health checks, and keep database ports off the public interface.
Works initially but fails under loadMeasure memory peaks, disk latency, connection pools and worker concurrency; increase capacity only after identifying the bottleneck.

Post-installation validation checklist

  • All services are running and their health checks pass
  • The public hostname serves a valid HTTPS certificate
  • Only explicitly required ports are reachable
  • Administrator MFA and recovery access are configured
  • Backup checksums have been recorded
  • A restore was completed in an isolated environment
  • Logs contain no repeating critical failure
  • Services recover automatically after a host reboot

Official technical sources

Related EKA Sunucu guides

Frequently asked questions

Is this suitable for production?

Yes after secrets are replaced, public access is restricted and a complete restore test has succeeded.

Are minimum resources enough?

Minimums only prove the software can start. Size CPU, memory, IOPS and storage from representative workload measurements.

Can I use Cloudflare?

Yes. Use Full (strict) TLS and configure origin certificates, WebSockets and client IP forwarding where required.

Should upgrades be automatic?

Do not automatically apply major releases. Review migrations, back up data and retain the previous tested image.

What must be backed up?

Back up databases, uploaded files, persistent volumes, configuration, encryption keys and the deployed version together.

VPS or GPU server?

An NVMe VPS fits normal web workloads. Inference, accelerated OCR and video transcoding may require a compatible GPU.

Contact us for deployment

Deploy Authentik with Docker Compose, including PostgreSQL, initial admin, Nginx reverse proxy, OIDC provider, application integration, MFA, recovery account, SMTP and backup.

Explore VPS plansContact us for deployment
Top