Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 4.39.28 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 9091/tcp |
|---|
| Category | Security |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
- On first boot the image generates an instance-unique TLS certificate, Authelia's session, password-reset and storage-encryption secrets (separate files in /etc/authelia/secrets, never written into the configuration) and the admin user, then starts Authelia. Check both units and the health endpoint:
sudo systemctl status authelia-firstboot authelia
curl -s --cacert /etc/authelia/tls/cert.pem https://127.0.0.1:9091/api/health
- Read the admin password generated uniquely for this instance (root only):
sudo cat /root/.authelia_default_credentials
Users live in /var/lib/authelia/users_database.yml as argon2id digests. To add one, run authelia crypto hash generate argon2 (it prompts for the password and prints a Digest), copy the admin entry under a new name with that Digest, then run:
sudo systemctl restart authelia
- Authelia needs a real domain: it issues its session cookie for one parent domain and the portal must be served under it. The image ships the placeholder example.com. Set yours once (replace YOUR_DOMAIN, for example corp.example.org; the portal becomes https://auth.YOUR_DOMAIN):
sudo sed -i 's/example[.]com/YOUR_DOMAIN/g' /etc/authelia/configuration.yml && sudo systemctl restart authelia
Access control: every site under YOUR_DOMAIN requires the password plus a second factor (policy two_factor) and anything else is denied. For password-only sites, change two_factor to one_factor in /etc/authelia/configuration.yml and restart.
- Authelia listens on 127.0.0.1:9091 (HTTPS) as shipped, which is all a reverse proxy on this instance needs. For a proxy or OCI load balancer on another host, bind all interfaces; it then reaches https://PRIVATE_IP:9091 (the certificate covers the private IP):
sudo sed -i 's#tcp://127.0.0.1:9091/#tcp://0.0.0.0:9091/#' /etc/authelia/configuration.yml && sudo systemctl restart authelia
Port 9091 is already permitted in the host firewall. Restrict it in your VCN security list to the proxy's CIDR; never expose it to the internet.
- Put an app behind Authelia with your reverse proxy: it serves auth.YOUR_DOMAIN and app.YOUR_DOMAIN with your public certificate and trusts /etc/authelia/tls/cert.pem for the hop to Authelia (https://127.0.0.1:9091 here, https://PRIVATE_IP:9091 from another host).
Caddy: in the auth.YOUR_DOMAIN site, reverse_proxy https://127.0.0.1:9091; in the app.YOUR_DOMAIN site, forward_auth https://127.0.0.1:9091 with the subdirectives uri /api/authz/forward-auth and copy_headers Remote-User Remote-Groups Remote-Email Remote-Name, before the app's own reverse_proxy. In both, add a transport http block containing tls_trust_pool file /etc/authelia/tls/cert.pem.
nginx: in the app's location, auth_request to an internal location that proxy_passes to https://127.0.0.1:9091/api/authz/auth-request with proxy_set_header X-Original-Method $request_method and X-Original-URL $scheme://$http_host$request_uri, then auth_request_set $redirection_url $upstream_http_location and error_page 401 =302 $redirection_url. Full examples: https://www.authelia.com/integration/proxies/
- Second factors and password resets work without SMTP: when a user registers a TOTP app or security key, or resets a password, Authelia writes the one-time code or link to a file instead of e-mailing it (latest message only):
sudo cat /var/lib/authelia/notification.txt
For production, configure the smtp notifier in /etc/authelia/configuration.yml.
- Data (SQLite, encrypted with the storage key) lives in /var/lib/authelia; sessions are held in memory, so a restart signs users out. Back up /var/lib/authelia and /etc/authelia together: the database is unreadable without the storage key. Metrics telemetry is off and the startup probe of a public NTP server is disabled; chronyd keeps the clock accurate for TOTP.
The image is CVE-patched at build time. Apply ongoing operating system updates with:
sudo dnf -y update
Authelia itself is installed from the signed upstream release and is refreshed by launching a newer image version of this listing.
What the image provides
- Authelia 4.39.28, installed from the project's official release on GitHub with its release-signing GPG signature and SHA-256 digest verified at build time, running as the dedicated unprivileged authelia service under a hardened systemd unit (read-only operating system, no capabilities, private temporary files and devices, system-call filter).
- Instance-unique secrets generated on first boot and never baked into the image: the session, password-reset and storage-encryption secrets (separate root-owned files passed to Authelia by reference, never written into its configuration), a self-signed TLS certificate that covers the instance's private IP, and the administrator password — generated inside Authelia, stored only as an argon2id digest and surfaced to the operator over SSH.
- Safe-by-default network posture: HTTPS only, listening on loopback until you expose it with one documented command; the host firewall permits only SSH and the portal port. Metrics telemetry is off and the startup probe of a public time server is disabled, so the image makes no outbound calls of its own.
- A strict access policy out of the box: every site under your domain requires the password plus a second factor and everything else is denied, with a one-line change for password-only sites. You set your own domain with one documented command, and password reset and second-factor registration work without an SMTP server through a local notification file.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny, no account with a usable password, no stray keys, and the image fully patched at build time. The operating system keeps receiving Oracle's security errata through dnf update; Authelia itself is refreshed by a new image version on each upstream release.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Authelia is a trademark of its respective owner. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Authelia project.