Authentik

Authentik

2026.2.2

Category: Security, IAM, VPN & Privacy

#security#self-hosted#docker#authentik

Overview

Authentik is an open-source Identity Provider for authentication and authorization. It provides a comprehensive solution for managing user authentication, authorization, and identity federation with support for SAML, OAuth2, OIDC, and more.

Primary Use Cases

1

Centralize Single Sign-On (SSO), OAuth 2.0 / OIDC, and LDAP authentication across all your self-hosted apps.

2

Protect servers and applications against brute-force attacks, malicious IPs, and unauthorized access.

3

Host a secure private VPN or DNS ad-blocker for encrypted remote access to internal networks.

Key Features

  • Multi-factor authentication (TOTP, WebAuthn/Passkeys, Duo)
  • Self-service password resets and user profile management
  • Distributed threat intelligence and automated firewall rules
  • Zero-trust network architecture with end-to-end encryption

Container Specification

Docker Image

authentik:latest

Default Version

2026.2.2

SSL & Domain Routing

Automated Let's Encrypt (Caddy / Traefik)

Persistent Volumes

Managed host volume mounts

How to Deploy Authentik with tug.sh

1

Connect your Linux server

Run the 1-line tug.sh agent install command on any Ubuntu, Debian, or Rocky Linux VPS.

2

Select Authentik from the Marketplace

Pick your domain name, configure custom environment variables if needed, and choose your persistent storage folder.

3

Click Deploy & Go Live

tug.sh pulls the container, sets up HTTPS certificates, configures the reverse proxy, and boots the service in under 60 seconds.