Single sign-on & dashboard
With several admin tools, each with its own password, two services help:
- Authelia, at
auth.<DOMAIN>: one login, with two-factor authentication, for Grafana, GlitchTip and Portainer, which hand sign-in over to it. - Homepage, at
home.<DOMAIN>: one page with a tile per tool and live figures. It has no login of its own, so it requires Authelia in front of it.
These are for you, the administrator: Loomkeep’s own accounts don’t go through Authelia. Unleash and Umami keep their own login, since parts of them must stay public: see Feature flags and Analytics.
Setting up Authelia
Section titled “Setting up Authelia”Authelia’s commands below run through its Docker image, so there is nothing to install. Never paste the plain values they print anywhere but the files named.
-
Copy the two templates, then fill in every
REPLACE_MEas you go:Terminal window cp docker/authelia/configuration.yml.example docker/authelia/configuration.ymlcp docker/authelia/users_database.yml.example docker/authelia/users_database.yml -
Generate the four secrets: the password reset JWT secret, the session secret, the storage encryption key and the OIDC HMAC secret. Run this once for each:
Terminal window docker run --rm authelia/authelia:4.39.28 authelia crypto rand --length 64Each command prints
Random Value: …: copy only what follows the label. Pasting the label too is the most common reason sign-in later fails. -
Generate the OIDC signing key, from
docker/authelia/:Terminal window docker run --rm -v "$(pwd):/out" authelia/authelia:4.39.28 \authelia crypto pair rsa generate -d /outPaste the whole of
private.pem,BEGINandENDlines included and indented, into theoidc.jwkskey, then deleteprivate.pemandpublic.pem. -
Create your login in
users_database.yml, with your password’s hash:Terminal window docker run --rm authelia/authelia:4.39.28 \authelia crypto hash generate argon2 --password 'your-password'Copy what follows
Digest:. You sign in with the username, the YAML key in that file, not the email address. -
Give each tool a client secret. For
grafana,glitchtipandportainerinconfiguration.yml, generate a secret and its hash. Keep the plain secret for the next steps; the hash goes inclient_secret:Terminal window docker run --rm authelia/authelia:4.39.28 \authelia crypto rand --length 64 --charset alphanumericdocker run --rm authelia/authelia:4.39.28 \authelia crypto hash generate pbkdf2 --variant sha512 --password 'the-plain-secret' -
Fill in SMTP under
notifier.smtp, with the same login asSMTP_USERandSMTP_PASS. Authelia checks it at startup and refuses to start without working SMTP. -
Start it: set
GRAFANA_OIDC_CLIENT_SECRETin.envto Grafana’s plain secret, adddocker/docker-compose.authelia.ymltoCOMPOSE_FILE, then:Terminal window docker compose pulldocker compose up -d
Grafana is then connected already. GlitchTip and Portainer take one more step each, in their own interface.
GlitchTip
Section titled “GlitchTip”-
Set
ENABLE_ADMIN: trueindocker/docker-compose.glitchtip.yml, thendocker compose up -d glitchtip. -
At
https://errors.<DOMAIN>/admin/socialaccount/socialapp/, add an application: provider OpenID Connect, provider idauthelia, client idglitchtip, secret key GlitchTip’s plain secret, and settings:{ "server_url": "https://auth.<DOMAIN>/.well-known/openid-configuration" } -
Set
ENABLE_ADMINback tofalse, and rundocker compose up -d glitchtipagain.
Portainer
Section titled “Portainer”In Settings › Authentication › OAuth, choose the Custom provider:
| Field | Value |
|---|---|
| Client ID | portainer |
| Client secret | Portainer’s plain secret |
| Authorization URL | https://auth.<DOMAIN>/api/oidc/authorization |
| Access token URL | https://auth.<DOMAIN>/api/oidc/token |
| Resource URL | https://auth.<DOMAIN>/api/oidc/userinfo |
| Redirect URL | https://portainer.<DOMAIN> |
| User identifier | preferred_username |
| Scopes | openid profile email |
Signing out
Section titled “Signing out”Authelia can’t yet pass a sign-out on to the tools, nor take one from them:
signing out of Grafana ends Grafana’s session only. To end the single
sign-on itself, sign out at auth.<DOMAIN>; otherwise it expires after an
hour (session.expiration in configuration.yml).
Setting up Homepage
Section titled “Setting up Homepage”With Authelia running, add docker/docker-compose.homepage.yml to
COMPOSE_FILE and restart. Homepage gets no access to the Docker socket:
its tiles read each tool’s own API, through keys set in .env. A missing
key only leaves its tile without figures.
| Tile | Variables |
|---|---|
| Portainer | PORTAINER_API_KEY (My account › Access tokens), PORTAINER_ENV_ID |
| GlitchTip | GLITCHTIP_API_TOKEN (an auth token with project:read), GLITCHTIP_ORG_SLUG |
| Healthchecks.io | HEALTHCHECKS_API_KEY (read-only) |
| UptimeRobot | UPTIMEROBOT_API_KEY (read-only) |
| Loomkeep’s own figures | HOMEPAGE_STATS_API_KEY: any long random string, shared with the API |
Grafana’s tile reuses GRAFANA_ADMIN_USER and GRAFANA_ADMIN_PASSWORD. The
tiles themselves are in docker/homepage/services.yaml: edit them to your
liking.
To add Loomkeep’s figures to a Homepage you already run, see the Homepage recipe.