This week was an exercise in frustration. Not the fault of anyone but I was trying out a combination of new software, which ends up being how fast you find the answers on Google.
The main thing I got from this week: Documentation is still hard.
Either way…
I’ve got a couple of old Mac minis lying around. I wanted to use them to create isolated containers so I could try out things and not make a collosal mess on my desktop. That meant futzing with LXD/LXC and multipass.
Multipass is pretty cool. Basically one command after installation and you have a VM going. As a developer tool, it’s great, but it felt heavy. No real evidence to support that, but it just did.
I had previously tried out LXD/LXC. I liked it enough that I tried figuring out how to create completely isolated containers.
Jesus. H. Christ.
Networking is hard.
And I hate iptables.
I got to a good place and decided to take a break.
On to the next…
I’ve been itching to look at IdPs. Mainly I wanted to look at options that could be self-hosted, so the well known options were out. I decided to look at Keycloak first.
Where was I going to host this? In a LXC, right now?
No…but yes…
Years ago, I had tried out some of the app infrastructure platforms like Railway and Fly.io. I liked them but didn’t have the bandwidth to devote time to them.
To make my life harder, I decided to host Keycloak on a bunch of different platforms: Railway, Koyeb, Fly.io, and Render. And why not try out Keycloak alternatives like Authentik, Authelia, and Zitadel?
I could go into the gnarly details, but ultimately I had the most and quickest success with Railway and Authentik. Once you’ve set up Authentik a couple of times, you realize how easy it is. I am a now a fan.
To complicate things even more, I wanted to find a non-Docker solution. I have Docker exhaustion. Like most technology, it gets you to 85% really quickly, but that final mile will make anyone suicidal.
The only authentication tool I could find that didn’t require Docker was Authelia.
Authelia is small and fast.
The downside? It’s totally driven by YAML files. There is no GUI at all.
Now, I try to be a CLI person, but damn, creating large configuration in YAML is not fun.
After a few hours, I did get it working. Well, kinda. One factor (passowrd) authentication works perfectly. Two factor (TOTP for now) is a work in progress.
Not already being frustrated enough already, I wanted the set up to be Cloudflare —> Caddy —> Authelia. Cloudflare —> Authelia is easy. Have Cloudflare point to the non-HTTP Authelia port and bam, you are done. But if you don’t want Cloudflare accessing Authelia directly for obvious reasons, you gotta stick a reverse proxy beween them. Authelia works really well with Caddy (well, Caddy itself is awesome too):
domain.com {
reverse_proxy authelia:9091
}Done.
The Cloudflare tunnel took a bit of messing around with X-Forwarded-For headers, but nothing too challenging.
(Of course you might ask why use Caddy between Cloudflare and Authelia when the Cloudflare tunnel already has access to the host. My answer: let me have my delusions.)
Once I got this stack working, I had one last thing I wanted to try out: Proxmox. Why? I wanted to run ephemeral VMs for trying things around, containers for Docker instances, and completely isolated VMs that no one should have access to and shouldn’t be able to access the LAN, only the Internet.
Believe it or not, a GUI comes in really handy when trying to visualize everything. There are web interfaces for LXD/incus, but I liked the idea of a tool that envisioned handling all these use cases from the start. Sometimes hiding the details goes a long way to alleviate mental overload.
The few days of Proxmox has been good so far. Getting things up and running is easy enough. One thing I hate: everything is done as root. Ugggggghhhhhhh. When you create a new VM or container, you are dropped into root and are able to log in remotely as root. Come on man. When creating the instance, it accepts ssh keys, so this decision makes no sense to me.
Oh well.
Still, lots of frustrating but productive Fourth of July break.