ai-flow improvement / add langchain
This commit is contained in:
@@ -46,6 +46,13 @@ This document is a **complete revision** of the Authentik SSO implementation pla
|
||||
5. Create backup snapshots at every milestone
|
||||
6. Update this document with progress and issues as we go
|
||||
|
||||
**SSO Inclusion Policy:**
|
||||
- ✅ **Include:** Web-based admin interfaces, dashboards, APIs requiring browser access
|
||||
- ❌ **Exclude:** Services with native mobile/desktop apps that work better with username/password
|
||||
- ❌ **Exclude:** Media streaming services (Jellyfin) - app integration priority
|
||||
- ❌ **Exclude:** Development tools (code-server) - IDE integration priority
|
||||
- ⏸️ **Defer:** Disabled/inactive services (Nextcloud) - implement when re-enabled
|
||||
|
||||
---
|
||||
|
||||
## Table of Contents
|
||||
@@ -870,23 +877,52 @@ curl -I https://auth.schweitz.net # Should return error (Authentik not running)
|
||||
|
||||
**Dependencies:** M3 completed successfully
|
||||
|
||||
**Configuration:** See original plan Section 5.1.3 for detailed implementation.
|
||||
**Status:** ✅ **COMPLETE** - Using forward auth (shares Organizr Proxy provider)
|
||||
|
||||
**Expected Duration:** 90-120 minutes
|
||||
**Implementation Decision (2025-11-23):**
|
||||
- Core API already protected with forward auth via NPM
|
||||
- Shares "Organizr Proxy" provider with home.schweitz.net
|
||||
- Authentication working correctly with Google OAuth
|
||||
- Headers forwarded: X-authentik-username, X-authentik-email, X-authentik-groups, X-authentik-name, X-authentik-uid
|
||||
- **Decision:** Keep current setup, defer separate admin provider to avoid complexity
|
||||
- **Rationale:** Current implementation is secure and functional for homelab use case
|
||||
|
||||
**Status:** ⏳ Not Started
|
||||
**Configuration:**
|
||||
- Provider: Organizr Proxy (shared)
|
||||
- External host: https://api.schweitz.net
|
||||
- Outpost: Standalone proxy (port 9445)
|
||||
- Mode: forward_single
|
||||
|
||||
**Expected Duration:** ~~90-120 minutes~~ SKIPPED (already functional)
|
||||
|
||||
---
|
||||
|
||||
### Milestone 5: Remaining Services (Gradual Rollout)
|
||||
|
||||
**Objective:** Enable forward auth on remaining 9 services, one at a time, testing each before proceeding.
|
||||
**Objective:** Enable forward auth on remaining services, one at a time, testing each before proceeding.
|
||||
|
||||
**Dependencies:** M3 and M4 completed successfully
|
||||
|
||||
**Services:** Nextcloud, Gitea, Jellyfin, Open WebUI, code-server, Netdata, Uptime Kuma, AMP, Tatlock
|
||||
**Services to Protect:**
|
||||
- Gitea (git.schweitz.net)
|
||||
- Open WebUI (no external domain yet)
|
||||
- Netdata (no external domain yet)
|
||||
- Uptime Kuma (no external domain yet)
|
||||
- AMP (amp.schweitz.net)
|
||||
- Tatlock (tatlock.schweitz.net)
|
||||
|
||||
**Expected Duration:** 4-8 hours (30-60 min per service)
|
||||
**Services EXCLUDED from SSO (Keep Native Auth):**
|
||||
- ❌ **Jellyfin (media.schweitz.net)** - Better mobile app integration with native auth
|
||||
- ❌ **code-server (code.schweitz.net)** - Better VS Code integration with native auth
|
||||
- ❌ **Nextcloud (cloud.schweitz.net)** - Service disabled, SSO deferred until re-enabled
|
||||
|
||||
**Rationale for Exclusions:**
|
||||
- Jellyfin and code-server have excellent native authentication
|
||||
- Mobile apps and desktop clients work better with username/password
|
||||
- SSO adds complexity without significant security benefit for these services
|
||||
- Nextcloud is not currently in active use
|
||||
|
||||
**Expected Duration:** 3-6 hours (30-60 min per service)
|
||||
|
||||
**Status:** ⏳ Not Started
|
||||
|
||||
|
||||
Reference in New Issue
Block a user