-
Notifications
You must be signed in to change notification settings - Fork 0
Authentik and OIDC SSO
This guide walks you through setting up Single Sign-On (SSO) in Brum using Authentik (or any standard OpenID Connect provider such as Keycloak, Authelia, Okta, or Google Workspace).
Brum uses standard OAuth 2.0 / OpenID Connect (OIDC) Authorization Code Flow with PKCE (Proof Key for Code Exchange).
sequenceDiagram
autonumber
actor User as User Browser
participant Brum as Brum Backend (/api/auth)
participant Authentik as Authentik IDP
participant DB as Brum SQLite
User->>Brum: Click "Sign in with Authentik"
Brum-->>User: 302 Redirect to Authentik /authorize (PKCE + State)
User->>Authentik: Authenticate (Password, 2FA, Passkey)
Authentik-->>User: Redirect to /api/auth/oidc/callback?code=...
User->>Brum: Forward authorization code
Brum->>Authentik: POST /token (Exchange code for tokens)
Authentik-->>Brum: Returns ID Token + Access Token
Brum->>DB: Match or auto-provision local user profile
Brum-->>User: Set cd_token session cookie & open Brum
- Log in to your Authentik web dashboard as an administrator.
- In the left navigation sidebar, expand Applications and click Providers.
- Click Create in the top right.
- Select OAuth2/OpenID Provider and click Next.
- Fill in the Provider settings:
-
Name:
Brum Provider(orBrum SSO) -
Authentication flow: Choose your default authentication flow (e.g.,
default-authentication-flow). -
Authorization flow: Choose your default authorization flow (e.g.,
default-provider-authorization-implicit-consent). -
Client type:
Confidential -
Client ID: Leave the auto-generated string or enter a custom one (e.g.
brum-sso). -
Client Secret: Copy this secret — you will need it for
config.toml. -
Redirect URIs / Allowed Callback URLs:
(If testing locally on LAN/HTTP:
https://files.example.com/api/auth/oidc/callbackhttp://192.168.1.100:3140/api/auth/oidc/callbackorhttp://localhost:3140/api/auth/oidc/callback) - Signing Key: Select your Authentik self-signed or Let's Encrypt certificate.
-
Subject mode:
Based on the User's username(orBased on the User's Email). -
Selected property mappings: Ensure the following scopes are highlighted/selected:
authentik default OAuth2 Mapping: OpenID 'openid'authentik default OAuth2 Mapping: OpenID 'email'authentik default OAuth2 Mapping: OpenID 'profile'authentik default OAuth2 Mapping: OpenID 'groups'
-
Name:
- Click Finish.
- In Authentik sidebar, go to Applications > Applications.
- Click Create.
- Fill in the Application settings:
-
Name:
Brum -
Slug:
brum(Note: this defines your Issuer URL) -
Provider: Select the
Brum Provideryou created in Step 1. -
UI Settings (Optional):
-
Launch URL:
https://files.example.com/ - Icon URL: Upload Brum's icon.
-
Launch URL:
-
Name:
- Click Create.
Authentik structures application issuer URLs as:
https://<authentik-domain>/application/o/<application-slug>/
For example, if your Authentik instance is https://auth.company.com and your application slug is brum, your Issuer URL is:
https://auth.company.com/application/o/brum/
(You can verify this by opening https://auth.company.com/application/o/brum/.well-known/openid-configuration in your browser).
To give certain users Superadmin access in Brum automatically:
- In Authentik, go to Directory > Groups.
- Click Create and name the group
brum-admins(or use existingauthentik Admins). - Add your administrator users to this group.
- When a user in
brum-adminslogs in through SSO, Brum automatically elevates their role toadmin.
You can configure Brum using config.toml (or via Docker Environment Variables).
Add or update the [auth.oidc] section in your config.toml:
[auth]
backend = "mixed" # Allows both local admin login and SSO
[auth.oidc]
enabled = true
provider_name = "Authentik" # Text shown on the login button
issuer_url = "https://auth.company.com/application/o/brum/"
client_id = "your-authentik-client-id"
client_secret = "your-authentik-client-secret"
redirect_url = "https://files.company.com/api/auth/oidc/callback"
scopes = ["openid", "profile", "email", "groups"]
# Automatic User Provisioning & Permissions
auto_provision = true # Automatically create local user profile on first SSO login
admin_group = "brum-admins" # Authentik group mapped to Brum Superadmin
default_user_role = "user" # Default role for regular SSO users ("user" or "readonly")
default_home_template = "/home/{username}" # User home directory mapping
force_sso_only = false # Set to true to bypass login screen and redirect directly to Authentik
button_icon = "shield-check" # Icon on login button ("shield-check", "key-round", "lock")If deploying Brum via Docker Compose or Kubernetes, you can configure SSO entirely via environment variables:
services:
brum:
image: ghcr.io/woofson/brum:latest
container_name: brum
ports:
- "3140:3140"
environment:
- BRUM_OIDC_ENABLED=true
- BRUM_OIDC_PROVIDER_NAME=Authentik
- BRUM_OIDC_ISSUER_URL=https://auth.company.com/application/o/brum/
- BRUM_OIDC_CLIENT_ID=your-authentik-client-id
- BRUM_OIDC_CLIENT_SECRET=your-authentik-client-secret
- BRUM_OIDC_REDIRECT_URL=https://files.company.com/api/auth/oidc/callback
- BRUM_OIDC_ADMIN_GROUP=brum-admins
- BRUM_OIDC_FORCE_SSO=false
volumes:
- ./data:/data- Restart or start Brum:
cargo run
- Open Brum in your browser (
http://localhost:3140or your domain). - On the login screen, you will now see:
[ Log In ] -------- or -------- [ Sign in with Authentik ] - Click Sign in with Authentik.
- You will be redirected to Authentik's login portal. Log in with your credentials, passkey, or 2FA.
- Upon successful authentication, Authentik redirects you back to Brum, which automatically:
- Provisions your user profile in Brum's database.
- Assigns your role (
adminif inbrum-admins, oruser). - Creates your session token and opens your file management workspace.
- Cause: The redirect URL configured in Authentik does not match the URL Brum is sending.
-
Fix: Verify that the URL in Authentik > Provider > Redirect URIs matches
redirect_urlinconfig.tomlexactly (includinghttp://vshttps://, domain, port, and trailing path/api/auth/oidc/callback).
If Brum is running behind a reverse proxy, ensure your proxy passes standard forwarding headers:
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;If redirect_url is left blank in config.toml, Brum automatically reconstructs the callback URL from these headers.
If Brum and Authentik are in the same Docker network, ensure Brum can resolve Authentik's public or internal hostname. You can test connectivity from inside the container:
curl -I https://auth.company.com/application/o/brum/.well-known/openid-configurationWhen force_sso_only = true is enabled in config.toml, visiting Brum automatically redirects unauthenticated users to Authentik without displaying the local username/password form. If you ever need to access the local admin account when SSO is forced, open:
https://files.example.com/?local=1
Brum — Multi-Pane Web Environment (File Commander/Manager)
Creator & Lab: Bolt J Woofson @ Woofsons Lab (www.arf.ac) • MIT License