<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.nixos.org/w/index.php?action=history&amp;feed=atom&amp;title=Authentik</id>
	<title>Authentik - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.nixos.org/w/index.php?action=history&amp;feed=atom&amp;title=Authentik"/>
	<link rel="alternate" type="text/html" href="https://wiki.nixos.org/w/index.php?title=Authentik&amp;action=history"/>
	<updated>2026-07-21T11:19:45Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33770&amp;oldid=prev</id>
		<title>Writer: Consolidate example domains</title>
		<link rel="alternate" type="text/html" href="https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33770&amp;oldid=prev"/>
		<updated>2026-07-19T11:48:16Z</updated>

		<summary type="html">&lt;p&gt;Consolidate example domains&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:48, 19 July 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l24&quot;&gt;Line 24:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 24:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Preresiquites ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Preresiquites ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# This example suggest to use https://auth.example&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;.com &lt;/del&gt;as the URL of authentik. Add the DNS records (A and AAAA) for &amp;lt;code&amp;gt;auth&amp;lt;/code&amp;gt; to the DNS configuration of your domain. If you change the &amp;lt;code&amp;gt;domain&amp;lt;/code&amp;gt; option, you can use any other subdomain.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# This example suggest to use https://auth&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;.yourdomain&lt;/ins&gt;.example as the URL of authentik. Add the DNS records (A and AAAA) for &amp;lt;code&amp;gt;auth&amp;lt;/code&amp;gt; to the DNS configuration of your domain. If you change the &amp;lt;code&amp;gt;domain&amp;lt;/code&amp;gt; option, you can use any other subdomain.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Create an agenix secret file named &amp;lt;code&amp;gt;authentik-secret-key.age&amp;lt;/code&amp;gt; and add a secret key using &amp;lt;code&amp;gt;openssl rand -base64 60 | tr -d &amp;#039;\n&amp;#039;&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[https://docs.goauthentik.io/install-config/install/docker-compose/#generate-postgresql-password-and-secret-key authentik&amp;#039;s Docker Compose installation documentation]&amp;lt;/ref&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Create an agenix secret file named &amp;lt;code&amp;gt;authentik-secret-key.age&amp;lt;/code&amp;gt; and add a secret key using &amp;lt;code&amp;gt;openssl rand -base64 60 | tr -d &amp;#039;\n&amp;#039;&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[https://docs.goauthentik.io/install-config/install/docker-compose/#generate-postgresql-password-and-secret-key authentik&amp;#039;s Docker Compose installation documentation]&amp;lt;/ref&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key mediawiki:diff:1.41:old-33769:rev-33770:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Writer</name></author>
	</entry>
	<entry>
		<id>https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33769&amp;oldid=prev</id>
		<title>Writer: Fix capitalization of env vars</title>
		<link rel="alternate" type="text/html" href="https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33769&amp;oldid=prev"/>
		<updated>2026-07-19T11:43:18Z</updated>

		<summary type="html">&lt;p&gt;Fix capitalization of env vars&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:43, 19 July 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l61&quot;&gt;Line 61:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 61:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   # Configuration that is common to authentik&amp;#039;s server and worker processes&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   # Configuration that is common to authentik&amp;#039;s server and worker processes&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   commonEnvironment = {&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   commonEnvironment = {&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_POSTGRESQL__HOST &lt;/del&gt;= &quot;/run/postgresql&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_POSTGRESQL__HOST &lt;/ins&gt;= &quot;/run/postgresql&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_POSTGRESQL__NAME &lt;/del&gt;= &quot;authentik&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_POSTGRESQL__NAME &lt;/ins&gt;= &quot;authentik&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_POSTGRESQL__USER &lt;/del&gt;= &quot;authentik&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_POSTGRESQL__USER &lt;/ins&gt;= &quot;authentik&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_LISTEN__TRUSTED_PROXY_CIDRS &lt;/del&gt;= &quot;127.0.0.0/8,::1/128&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_LISTEN__TRUSTED_PROXY_CIDRS &lt;/ins&gt;= &quot;127.0.0.0/8,::1/128&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_STORAGE__FILE__PATH &lt;/del&gt;= authentikStateDir;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_STORAGE__FILE__PATH &lt;/ins&gt;= authentikStateDir;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_SECRET_KEY &lt;/del&gt;= &quot;file://${config.age.secrets.authentik-secret-key.path}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_SECRET_KEY &lt;/ins&gt;= &quot;file://${config.age.secrets.authentik-secret-key.path}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_LOG_LEVEL &lt;/del&gt;= &quot;info&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_LOG_LEVEL &lt;/ins&gt;= &quot;info&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   };&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   };&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   serverEnvironment = commonEnvironment // {&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   serverEnvironment = commonEnvironment // {&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_LISTEN__HTTP &lt;/del&gt;= &quot;127.0.0.1:${toString serverHttpPort}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_LISTEN__HTTP &lt;/ins&gt;= &quot;127.0.0.1:${toString serverHttpPort}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_LISTEN__METRICS &lt;/del&gt;= &quot;127.0.0.1:${toString serverMetricsPort}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_LISTEN__METRICS &lt;/ins&gt;= &quot;127.0.0.1:${toString serverMetricsPort}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   };&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   };&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   workerEnvironment = commonEnvironment // {&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   workerEnvironment = commonEnvironment // {&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_LISTEN__HTTP &lt;/del&gt;= &quot;127.0.0.1:${toString workerHttpPort}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_LISTEN__HTTP &lt;/ins&gt;= &quot;127.0.0.1:${toString workerHttpPort}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik_LISTEN__METRICS &lt;/del&gt;= &quot;127.0.0.1:${toString workerMetricsPort}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;AUTHENTIK_LISTEN__METRICS &lt;/ins&gt;= &quot;127.0.0.1:${toString workerMetricsPort}&quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   };&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   };&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key mediawiki:diff:1.41:old-33768:rev-33769:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Writer</name></author>
	</entry>
	<entry>
		<id>https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33768&amp;oldid=prev</id>
		<title>Writer: Fix file name</title>
		<link rel="alternate" type="text/html" href="https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33768&amp;oldid=prev"/>
		<updated>2026-07-19T11:41:26Z</updated>

		<summary type="html">&lt;p&gt;Fix file name&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:41, 19 July 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l39&quot;&gt;Line 39:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 39:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/nowiki&amp;gt;}}&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/nowiki&amp;gt;}}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{File&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{File&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|name=/etc/nixos/&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;configuration&lt;/del&gt;.nix&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|name=/etc/nixos/&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;authentik&lt;/ins&gt;.nix&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|lang=nix&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|lang=nix&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|3={ config, pkgs, lib, ... }:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|3={ config, pkgs, lib, ... }:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key mediawiki:diff:1.41:old-33767:rev-33768:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Writer</name></author>
	</entry>
	<entry>
		<id>https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33767&amp;oldid=prev</id>
		<title>Writer: Remove superfluous &gt;</title>
		<link rel="alternate" type="text/html" href="https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33767&amp;oldid=prev"/>
		<updated>2026-07-19T11:37:40Z</updated>

		<summary type="html">&lt;p&gt;Remove superfluous &amp;gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:37, 19 July 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l24&quot;&gt;Line 24:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 24:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Preresiquites ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Preresiquites ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# This example suggest to use https://auth.example.com as the URL of authentik. Add the DNS records (A and AAAA) for &amp;lt;code&amp;gt;auth&amp;lt;/code&amp;gt; to the DNS configuration of your domain. If you change the &amp;lt;code&amp;gt;domain&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;gt;&lt;/del&gt;&amp;lt;/code&amp;gt; option, you can use any other subdomain.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# This example suggest to use https://auth.example.com as the URL of authentik. Add the DNS records (A and AAAA) for &amp;lt;code&amp;gt;auth&amp;lt;/code&amp;gt; to the DNS configuration of your domain. If you change the &amp;lt;code&amp;gt;domain&amp;lt;/code&amp;gt; option, you can use any other subdomain.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Create an agenix secret file named &amp;lt;code&amp;gt;authentik-secret-key.age&amp;lt;/code&amp;gt; and add a secret key using &amp;lt;code&amp;gt;openssl rand -base64 60 | tr -d &amp;#039;\n&amp;#039;&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[https://docs.goauthentik.io/install-config/install/docker-compose/#generate-postgresql-password-and-secret-key authentik&amp;#039;s Docker Compose installation documentation]&amp;lt;/ref&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Create an agenix secret file named &amp;lt;code&amp;gt;authentik-secret-key.age&amp;lt;/code&amp;gt; and add a secret key using &amp;lt;code&amp;gt;openssl rand -base64 60 | tr -d &amp;#039;\n&amp;#039;&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[https://docs.goauthentik.io/install-config/install/docker-compose/#generate-postgresql-password-and-secret-key authentik&amp;#039;s Docker Compose installation documentation]&amp;lt;/ref&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key mediawiki:diff:1.41:old-33766:rev-33767:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Writer</name></author>
	</entry>
	<entry>
		<id>https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33766&amp;oldid=prev</id>
		<title>Writer: Add security category</title>
		<link rel="alternate" type="text/html" href="https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33766&amp;oldid=prev"/>
		<updated>2026-07-19T11:31:00Z</updated>

		<summary type="html">&lt;p&gt;Add security category&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:31, 19 July 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l168&quot;&gt;Line 168:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 168:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Applications]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Applications]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Web Applications]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Web Applications]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;references /&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Security]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key mediawiki:diff:1.41:old-33765:rev-33766:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Writer</name></author>
	</entry>
	<entry>
		<id>https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33765&amp;oldid=prev</id>
		<title>Writer: Created page with &quot;[https://goauthentik.io/ authentik] is an identity provider supporting protocols such as OAuth 2.0, OpenID Connect, SAML, and LDAP. It provides a free open-source edition and a paid Enterprise edition with additional features and support. It is an alternative to Keycloak.  There are currently three ways to use authentik on NixOS:  # the official [https://docs.goauthentik.io/install-config/install/docker-compose/ docker-compose] # unofficial [https://github.com/nix-co...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.nixos.org/w/index.php?title=Authentik&amp;diff=33765&amp;oldid=prev"/>
		<updated>2026-07-19T11:29:35Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;[https://goauthentik.io/ authentik] is an identity provider supporting protocols such as OAuth 2.0, OpenID Connect, SAML, and LDAP. It provides a free open-source edition and a paid Enterprise edition with additional features and support. It is an alternative to &lt;a href=&quot;/wiki/Keycloak&quot; title=&quot;Keycloak&quot;&gt;Keycloak&lt;/a&gt;.  There are currently three ways to use authentik on NixOS:  # the official [https://docs.goauthentik.io/install-config/install/docker-compose/ docker-compose] # unofficial [https://github.com/nix-co...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[https://goauthentik.io/ authentik] is an identity provider supporting protocols such as OAuth 2.0, OpenID Connect, SAML, and LDAP. It provides a free open-source edition and a paid Enterprise edition with additional features and support. It is an alternative to [[Keycloak]].&lt;br /&gt;
&lt;br /&gt;
There are currently three ways to use authentik on NixOS:&lt;br /&gt;
&lt;br /&gt;
# the official [https://docs.goauthentik.io/install-config/install/docker-compose/ docker-compose]&lt;br /&gt;
# unofficial [https://github.com/nix-community/authentik-nix flake]&lt;br /&gt;
# your own NixOS module&lt;br /&gt;
&lt;br /&gt;
As of NixOS 26.05 there is no module in nixpkgs which would start the service with something like &amp;lt;code&amp;gt;services.authentik.enable = true;&amp;lt;/code&amp;gt;. Therefore, if you don&amp;#039;t want to use docker containers or flakes, writing your own modules is the only way to run authentik, currently.&lt;br /&gt;
&lt;br /&gt;
== Your own NixOS module ==&lt;br /&gt;
&lt;br /&gt;
Advantages of this option are not having to use flakes and having more integration and less indirection than with containers.&lt;br /&gt;
&lt;br /&gt;
The example configuration below&lt;br /&gt;
&lt;br /&gt;
# creates two systemd services: authentik server and authentik worker (this is analog to the to containers in the official docker-compose solution)&lt;br /&gt;
# reuses an existing PostgreSQL instance (the official docker-compose solution creates its own instance)&lt;br /&gt;
# uses [[Agenix]] for storing the authentik sercret key&lt;br /&gt;
# uses nginx as a reverse proxy&lt;br /&gt;
# does not store authentik&amp;#039;s configuration such as users, groups, policies declaratively&lt;br /&gt;
# uses the unstable version of authentik. authentik version 2026 introduced several configuration option changes and therefore, for a new installation, it is advisable to use the unstable nixpkgs package which is already on 2026.x.y. This reduces future required configuration changes.&lt;br /&gt;
&lt;br /&gt;
=== Preresiquites ===&lt;br /&gt;
&lt;br /&gt;
# This example suggest to use https://auth.example.com as the URL of authentik. Add the DNS records (A and AAAA) for &amp;lt;code&amp;gt;auth&amp;lt;/code&amp;gt; to the DNS configuration of your domain. If you change the &amp;lt;code&amp;gt;domain&amp;gt;&amp;lt;/code&amp;gt; option, you can use any other subdomain.&lt;br /&gt;
# Create an agenix secret file named &amp;lt;code&amp;gt;authentik-secret-key.age&amp;lt;/code&amp;gt; and add a secret key using &amp;lt;code&amp;gt;openssl rand -base64 60 | tr -d &amp;#039;\n&amp;#039;&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[https://docs.goauthentik.io/install-config/install/docker-compose/#generate-postgresql-password-and-secret-key authentik&amp;#039;s Docker Compose installation documentation]&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
&lt;br /&gt;
You can import the authentik module below to your main configuration using &amp;lt;code&amp;gt;imports&amp;lt;/code&amp;gt;. For example:&lt;br /&gt;
{{file|/etc/nixos/configuration.nix|nix|&amp;lt;nowiki&amp;gt;&lt;br /&gt;
  ...&lt;br /&gt;
  imports = [&lt;br /&gt;
    ./hardware-configuration.nix&lt;br /&gt;
    ./authentik.nix&lt;br /&gt;
  ];&lt;br /&gt;
  ...&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;}}&lt;br /&gt;
{{File&lt;br /&gt;
|name=/etc/nixos/configuration.nix&lt;br /&gt;
|lang=nix&lt;br /&gt;
|3={ config, pkgs, lib, ... }:&lt;br /&gt;
let&lt;br /&gt;
  unstable-pkgs = import &amp;lt;nixpkgs-unstable&amp;gt; { };&lt;br /&gt;
&lt;br /&gt;
  # TODO: Change this to your domain&lt;br /&gt;
  domain = &amp;quot;auth.yourdomain.example&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
  authentikStateDirName = &amp;quot;authentik&amp;quot;;&lt;br /&gt;
  authentikStateDir = &amp;quot;/var/lib/${authentikStateDirName}&amp;quot;;&lt;br /&gt;
  authentikUser = &amp;quot;authentik&amp;quot;;&lt;br /&gt;
  authentikGroup = &amp;quot;authentik&amp;quot;;&lt;br /&gt;
  authentikPackage = unstable-pkgs.authentik;&lt;br /&gt;
&lt;br /&gt;
  serverHttpPort = 9000;&lt;br /&gt;
  serverMetricsPort = 9300;&lt;br /&gt;
  workerHttpPort = 9001;&lt;br /&gt;
  workerMetricsPort = 9301;&lt;br /&gt;
&lt;br /&gt;
  # Configuration that is common to authentik&amp;#039;s server and worker processes&lt;br /&gt;
  commonEnvironment = {&lt;br /&gt;
    authentik_POSTGRESQL__HOST = &amp;quot;/run/postgresql&amp;quot;;&lt;br /&gt;
    authentik_POSTGRESQL__NAME = &amp;quot;authentik&amp;quot;;&lt;br /&gt;
    authentik_POSTGRESQL__USER = &amp;quot;authentik&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
    authentik_LISTEN__TRUSTED_PROXY_CIDRS = &amp;quot;127.0.0.0/8,::1/128&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
    authentik_STORAGE__FILE__PATH = authentikStateDir;&lt;br /&gt;
&lt;br /&gt;
    authentik_SECRET_KEY = &amp;quot;file://${config.age.secrets.authentik-secret-key.path}&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
    authentik_LOG_LEVEL = &amp;quot;info&amp;quot;;&lt;br /&gt;
  };&lt;br /&gt;
&lt;br /&gt;
  serverEnvironment = commonEnvironment // {&lt;br /&gt;
    authentik_LISTEN__HTTP = &amp;quot;127.0.0.1:${toString serverHttpPort}&amp;quot;;&lt;br /&gt;
    authentik_LISTEN__METRICS = &amp;quot;127.0.0.1:${toString serverMetricsPort}&amp;quot;;&lt;br /&gt;
  };&lt;br /&gt;
&lt;br /&gt;
  workerEnvironment = commonEnvironment // {&lt;br /&gt;
    authentik_LISTEN__HTTP = &amp;quot;127.0.0.1:${toString workerHttpPort}&amp;quot;;&lt;br /&gt;
    authentik_LISTEN__METRICS = &amp;quot;127.0.0.1:${toString workerMetricsPort}&amp;quot;;&lt;br /&gt;
  };&lt;br /&gt;
&lt;br /&gt;
  # Function to generate the systemd configuration for each role (server or worker).&lt;br /&gt;
  authentikSystemdService = role: environment: {&lt;br /&gt;
    description = &amp;quot;authentik ${role}&amp;quot;;&lt;br /&gt;
    wantedBy = [ &amp;quot;multi-user.target&amp;quot; ];&lt;br /&gt;
    after = [ &amp;quot;postgresql.service&amp;quot; ];&lt;br /&gt;
    requires = [ &amp;quot;postgresql.service&amp;quot; ];&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    # `environment` is both the argument name of this function and the NixOS option name to set a&lt;br /&gt;
    # systemd services environemnt. Thus, here we simply set the option&amp;#039;s value to the argument&amp;#039;s value.&lt;br /&gt;
    inherit environment;&lt;br /&gt;
&lt;br /&gt;
    # postgresql.service may be started before the database is ready to accept connections. Therefore,&lt;br /&gt;
    # check the latter explicitly.&lt;br /&gt;
    preStart = &amp;#039;&amp;#039;&lt;br /&gt;
      ${config.services.postgresql.package}/bin/pg_isready -h /run/postgresql -d authentik -U authentik&lt;br /&gt;
    &amp;#039;&amp;#039;;&lt;br /&gt;
&lt;br /&gt;
    serviceConfig = {&lt;br /&gt;
      Type = &amp;quot;simple&amp;quot;;&lt;br /&gt;
      User = authentikUser;&lt;br /&gt;
      Group = authentikGroup;&lt;br /&gt;
      WorkingDirectory = authentikStateDir;&lt;br /&gt;
      StateDirectory = authentikStateDirName;&lt;br /&gt;
      StateDirectoryMode = &amp;quot;0750&amp;quot;;&lt;br /&gt;
      ExecStart = &amp;quot;${authentikPackage}/bin/ak ${role}&amp;quot;;&lt;br /&gt;
      Restart = &amp;quot;on-failure&amp;quot;;&lt;br /&gt;
      RestartSec = &amp;quot;10s&amp;quot;;&lt;br /&gt;
    };&lt;br /&gt;
  };&lt;br /&gt;
in&lt;br /&gt;
{&lt;br /&gt;
  age.secrets.authentik-secret-key = {&lt;br /&gt;
    # TODO: adjust this to your path&lt;br /&gt;
    file = ../../secrets/authentik-secret-key.age;&lt;br /&gt;
    owner = authentikUser;&lt;br /&gt;
    group = authentikGroup;&lt;br /&gt;
    mode = &amp;quot;0400&amp;quot;;&lt;br /&gt;
  };&lt;br /&gt;
&lt;br /&gt;
  users.groups.${authentikGroup} = { };&lt;br /&gt;
&lt;br /&gt;
  users.users.${authentikUser} = {&lt;br /&gt;
    isSystemUser = true;&lt;br /&gt;
    group = authentikGroup;&lt;br /&gt;
    home = authentikStateDir;&lt;br /&gt;
  };&lt;br /&gt;
&lt;br /&gt;
  services.postgresql = {&lt;br /&gt;
    ensureDatabases = [ &amp;quot;authentik&amp;quot; ];&lt;br /&gt;
    ensureUsers = [&lt;br /&gt;
      {&lt;br /&gt;
        name = &amp;quot;authentik&amp;quot;;&lt;br /&gt;
        ensureDBOwnership = true;&lt;br /&gt;
      }&lt;br /&gt;
    ];&lt;br /&gt;
    authentication = lib.mkAfter &amp;#039;&amp;#039;&lt;br /&gt;
      local authentik authentik peer&lt;br /&gt;
    &amp;#039;&amp;#039;;&lt;br /&gt;
  };&lt;br /&gt;
&lt;br /&gt;
  systemd.services = {&lt;br /&gt;
    authentik-server = authentikSystemdService &amp;quot;server&amp;quot; serverEnvironment;&lt;br /&gt;
    authentik-worker = authentikSystemdService &amp;quot;worker&amp;quot; workerEnvironment;&lt;br /&gt;
  };&lt;br /&gt;
&lt;br /&gt;
  services.nginx.virtualHosts.${domain} = {&lt;br /&gt;
    forceSSL = true;&lt;br /&gt;
    enableACME = true;&lt;br /&gt;
&lt;br /&gt;
    locations.&amp;quot;/&amp;quot; = {&lt;br /&gt;
      proxyPass = &amp;quot;http://127.0.0.1:${toString serverHttpPort}&amp;quot;;&lt;br /&gt;
      recommendedProxySettings = true;&lt;br /&gt;
      proxyWebsockets = true;&lt;br /&gt;
    };&lt;br /&gt;
  };&lt;br /&gt;
}&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
Search for all &amp;lt;code&amp;gt;TODO&amp;lt;/code&amp;gt;s and set your system&amp;#039;s values accordingly.&lt;br /&gt;
&lt;br /&gt;
[[Category:Server]]&lt;br /&gt;
[[Category:Applications]]&lt;br /&gt;
[[Category:Web Applications]]&lt;/div&gt;</summary>
		<author><name>Writer</name></author>
	</entry>
</feed>