# Drop-in: real sessions (and TOTP, and OAuth) in front of the private apps, # instead of a browser basic-auth box. # # docker compose -f docker-compose.yml -f docker-compose.tinyauth.yml up -d # # Tinyauth is the small end of this: configured entirely by environment # variables, under 10 MB, and OpenID Certified as of v5.1.0. Two caveats, both # real: # # * AGPL-3.0. Fine for running it; read it before you build on it. # * Its configuration keys churn between major releases. The tag below is # PINNED for that reason — check the release notes before moving it, and # expect to touch the environment block when you do. # # Set in .env first: # # ARCHILYZER_AUTH_MODE=forward # TINYAUTH_SECRET=<32+ random chars> # TINYAUTH_USERS=you:$$2a$$14$$... # htpasswd-style bcrypt, see below # TINYAUTH_APP_URL=http://localhost:8084 # where YOU reach the login page # # Generate the user entry: # docker run --rm ghcr.io/steveiliop56/tinyauth:v5.1.0 user create --interactive # # The login page needs to be reachable from the browser, so it is the one extra # published port here. It binds loopback like everything else. services: tinyauth: image: ghcr.io/steveiliop56/tinyauth:v5.1.0 restart: unless-stopped networks: [archilyzer] env_file: - path: .env required: false environment: APP_URL: ${TINYAUTH_APP_URL:-http://localhost:8084} USERS: ${TINYAUTH_USERS:-} SECRET: ${TINYAUTH_SECRET:-} ports: - "${TINYAUTH_BIND:-127.0.0.1}:${TINYAUTH_HTTP_PORT:-8084}:3000" caddy: environment: ARCHILYZER_AUTH_MODE: forward ARCHILYZER_FORWARD_AUTH_UPSTREAM: tinyauth:3000 ARCHILYZER_FORWARD_AUTH_URI: /api/auth/caddy