Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Authelia

In Oracle review

DCA Hardened Single Sign-On Portal for Authelia — Support & Quick Start

A hardened, CVE-patched virtual machine image running Authelia — the open-source single sign-on (SSO) and two-factor authentication (2FA) portal for reverse proxies — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version4.39.28
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 9091/tcp
CategorySecurity
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. On first boot the image generates an instance-unique TLS certificate, Authelia's session, password-reset and storage-encryption secrets (separate files in /etc/authelia/secrets, never written into the configuration) and the admin user, then starts Authelia. Check both units and the health endpoint:
    sudo systemctl status authelia-firstboot authelia
    curl -s --cacert /etc/authelia/tls/cert.pem https://127.0.0.1:9091/api/health
  3. Read the admin password generated uniquely for this instance (root only):
    sudo cat /root/.authelia_default_credentials

    Users live in /var/lib/authelia/users_database.yml as argon2id digests. To add one, run authelia crypto hash generate argon2 (it prompts for the password and prints a Digest), copy the admin entry under a new name with that Digest, then run:

    sudo systemctl restart authelia

  4. Authelia needs a real domain: it issues its session cookie for one parent domain and the portal must be served under it. The image ships the placeholder example.com. Set yours once (replace YOUR_DOMAIN, for example corp.example.org; the portal becomes https://auth.YOUR_DOMAIN):
    sudo sed -i 's/example[.]com/YOUR_DOMAIN/g' /etc/authelia/configuration.yml && sudo systemctl restart authelia

    Access control: every site under YOUR_DOMAIN requires the password plus a second factor (policy two_factor) and anything else is denied. For password-only sites, change two_factor to one_factor in /etc/authelia/configuration.yml and restart.

  5. Authelia listens on 127.0.0.1:9091 (HTTPS) as shipped, which is all a reverse proxy on this instance needs. For a proxy or OCI load balancer on another host, bind all interfaces; it then reaches https://PRIVATE_IP:9091 (the certificate covers the private IP):
    sudo sed -i 's#tcp://127.0.0.1:9091/#tcp://0.0.0.0:9091/#' /etc/authelia/configuration.yml && sudo systemctl restart authelia

    Port 9091 is already permitted in the host firewall. Restrict it in your VCN security list to the proxy's CIDR; never expose it to the internet.

  6. Put an app behind Authelia with your reverse proxy: it serves auth.YOUR_DOMAIN and app.YOUR_DOMAIN with your public certificate and trusts /etc/authelia/tls/cert.pem for the hop to Authelia (https://127.0.0.1:9091 here, https://PRIVATE_IP:9091 from another host).

    Caddy: in the auth.YOUR_DOMAIN site, reverse_proxy https://127.0.0.1:9091; in the app.YOUR_DOMAIN site, forward_auth https://127.0.0.1:9091 with the subdirectives uri /api/authz/forward-auth and copy_headers Remote-User Remote-Groups Remote-Email Remote-Name, before the app's own reverse_proxy. In both, add a transport http block containing tls_trust_pool file /etc/authelia/tls/cert.pem.

    nginx: in the app's location, auth_request to an internal location that proxy_passes to https://127.0.0.1:9091/api/authz/auth-request with proxy_set_header X-Original-Method $request_method and X-Original-URL $scheme://$http_host$request_uri, then auth_request_set $redirection_url $upstream_http_location and error_page 401 =302 $redirection_url. Full examples: https://www.authelia.com/integration/proxies/
  7. Second factors and password resets work without SMTP: when a user registers a TOTP app or security key, or resets a password, Authelia writes the one-time code or link to a file instead of e-mailing it (latest message only):
    sudo cat /var/lib/authelia/notification.txt

    For production, configure the smtp notifier in /etc/authelia/configuration.yml.

  8. Data (SQLite, encrypted with the storage key) lives in /var/lib/authelia; sessions are held in memory, so a restart signs users out. Back up /var/lib/authelia and /etc/authelia together: the database is unreadable without the storage key. Metrics telemetry is off and the startup probe of a public NTP server is disabled; chronyd keeps the clock accurate for TOTP.

The image is CVE-patched at build time. Apply ongoing operating system updates with:

sudo dnf -y update

Authelia itself is installed from the signed upstream release and is refreshed by launching a newer image version of this listing.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Authelia is a trademark of its respective owner. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Authelia project.