<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Oidc on Sysadmin Tales</title>
    <link>https://blog.ssb-tech.net/tags/oidc/</link>
    <description>Recent content in Oidc on Sysadmin Tales</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:39:10 -0400</lastBuildDate>
    <atom:link href="https://blog.ssb-tech.net/tags/oidc/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Connecting an Existing FreshRSS instance to OIDC</title>
      <link>https://blog.ssb-tech.net/posts/freshrss-oidc/</link>
      <pubDate>Fri, 15 Aug 2025 21:05:44 -0400</pubDate>
      <guid>https://blog.ssb-tech.net/posts/freshrss-oidc/</guid>
      <description>&lt;h1 id=&#34;connecting-an-existing-freshrss-instance-to-oidc&#34;&gt;Connecting an existing FreshRSS instance to OIDC&lt;/h1&gt;&#xA;&lt;p&gt;Specifically, how to do so without starting over.&lt;/p&gt;&#xA;&lt;p&gt;&lt;span style=color:red&gt;&lt;strong&gt;WARNING:&lt;/strong&gt; I am not responsible for you losing data by doing this. Make sure you have a recent backup before you go digging around and changing things in the filesystem.&lt;/span&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;overview&#34;&gt;Overview&lt;/h2&gt;&#xA;&lt;p&gt;It came to my attention yesterday that the &lt;a href=&#34;https://freshrss.org/index.html&#34;&gt;FreshRSS&lt;/a&gt; project directly supports OIDC now.&lt;/p&gt;&#xA;&lt;p&gt;I&amp;rsquo;ve been using the Traefik &lt;a href=&#34;https://doc.traefik.io/traefik/middlewares/http/forwardauth/&#34;&gt;ForwardAuth middleware&lt;/a&gt; to get the same functionality for some time, but this allows me to get rid of a layer.&lt;/p&gt;&#xA;&lt;p&gt;It was also slightly clunky, since after I&amp;rsquo;d logged in through Authentik, I&amp;rsquo;d have to also authenticate via FreshRSS. I&amp;rsquo;m aware I could have simply disabled authentication, but I chose not to at the time.&lt;/p&gt;&#xA;&lt;p&gt;I had been using the &lt;a href=&#34;https://linuxserver.io&#34;&gt;LinuxServer.io&lt;/a&gt; Docker container, but this functionality depended on Apache&amp;rsquo;s OIDC module, so it was unsupported. (The LinuxServer.io container uses nginx instead of Apache.)&lt;/p&gt;&#xA;&lt;h2 id=&#34;oidc-setup&#34;&gt;OIDC Setup&lt;/h2&gt;&#xA;&lt;p&gt;The first thing I needed to do was switch to the &lt;a href=&#34;https://hub.docker.com/r/freshrss/freshrss&#34;&gt;official container on DockerHub&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The volume layout was a bit different from the LinuxServer container, so I had to stop the container and move some files around.&lt;/p&gt;&#xA;&lt;p&gt;All you should need to do is move the &lt;code&gt;data&lt;/code&gt; and &lt;code&gt;extensions&lt;/code&gt; folders out from under the &lt;code&gt;config&lt;/code&gt; directory that the LSIO container uses, and make them their own separate bind mounts.&lt;/p&gt;&#xA;&lt;p&gt;Next, I set about configuring OIDC.&lt;/p&gt;&#xA;&lt;p&gt;I followed their &lt;a href=&#34;https://freshrss.github.io/FreshRSS/en/admins/16_OpenID-Connect-Authentik.html&#34;&gt;official instructions&lt;/a&gt; to set up OIDC with &lt;a href=&#34;https://goauthentik.io/&#34;&gt;Authentik&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This was &lt;em&gt;mostly&lt;/em&gt; fine, though I had to make a few tweaks to their environment variables. The &lt;code&gt;OIDC_SCOPES&lt;/code&gt; variable in particular was my issue - it would not work if I had it in quotes. I can only assume that this was being interpreted as a single string by the application.&lt;/p&gt;&#xA;&lt;p&gt;Here&amp;rsquo;s what my Docker Compose file wound up looking like at the end. The OIDC values have been replaced with gibberish, make sure to substitute your own if you copy and paste.&lt;/p&gt;&#xA;&lt;div class=&#34;callout callout-note&#34; role=&#34;note&#34;&gt;&lt;div class=&#34;callout-title&#34;&gt;Note&lt;/div&gt;&lt;div class=&#34;callout-content&#34;&gt;2025/08/21 - After posting this I began noticing that my feeds were no longer auto-updating. As it turns out, the FreshRSS official Docker image &lt;a href=&#34;https://freshrss.github.io/FreshRSS/en/admins/08_FeedUpdates.html&#34;&gt;disabled this feature by default unless you pass it the CRON_MIN environment variable&lt;/a&gt;. I have updated the Docker Compose file below with a setting that works.&lt;/div&gt;&lt;/div&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-yaml&#34; data-lang=&#34;yaml&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;services&lt;/span&gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#f92672&#34;&gt;freshrss&lt;/span&gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;container_name&lt;/span&gt;: &lt;span style=&#34;color:#ae81ff&#34;&gt;freshrss&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;environment&lt;/span&gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;PUID=1000&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;PGID=1000&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;TZ=America/New_York&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;CRON_MIN=2,32&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;TRUSTED_PROXY=172.23.0.0/16&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;OIDC_ENABLED=1&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;OIDC_PROVIDER_METADATA_URL=&amp;#34;https://auth.example.com/application/o/fresh-rss-oidc/.well-known/openid-configuration&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;OIDC_REMOTE_USER_CLAIM=preferred_username&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;OIDC_CLIENT_ID=1234455262233&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;OIDC_CLIENT_SECRET=7dfadkfjakldgjad7897324&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;OIDC_CLIENT_CRYPTO_KEY=dfajfakjglkdg70708723434&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;OIDC_SCOPES=openid email profile&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;OIDC_X_FORWARDED_HEADERS=X-Forwarded-Host X-Forwarded-Port X-Forwarded-Proto&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;volumes&lt;/span&gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;./data:/var/www/FreshRSS/data&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;./extensions:/var/www/FreshRSS/extensions&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;restart&lt;/span&gt;: &lt;span style=&#34;color:#ae81ff&#34;&gt;unless-stopped&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;image&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;freshrss/freshrss:latest&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;labels&lt;/span&gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;traefik.enable=true&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;traefik.http.routers.freshrss-external.rule=Host(`rss.example.com`)&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;traefik.http.routers.freshrss-external.entrypoints=https&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;traefik.http.routers.freshrss-external.middlewares=default-headers@file&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;traefik.http.routers.freshrss-external.tls=true&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;traefik.http.routers.freshrss-external.service=freshrss-external&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;traefik.http.services.freshrss-external.loadbalancer.server.port=80&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;networks&lt;/span&gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;      - &lt;span style=&#34;color:#ae81ff&#34;&gt;proxy&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;networks&lt;/span&gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#f92672&#34;&gt;proxy&lt;/span&gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;external&lt;/span&gt;: &lt;span style=&#34;color:#66d9ef&#34;&gt;true&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;I&amp;rsquo;m not 100% certain that the &lt;code&gt;TRUSTED_PROXY&lt;/code&gt; setting is necessary. The subnet there is the subnet used by my &lt;code&gt;proxy&lt;/code&gt; docker network. It works and I&amp;rsquo;m too lazy to try removing it.&lt;/p&gt;&#xA;&lt;p&gt;You can get this subnet by running &lt;code&gt;docker network inspect &amp;lt;network-name&amp;gt;&lt;/code&gt;&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-shell&#34; data-lang=&#34;shell&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&amp;gt; docker-ubuntu in ~/docker/freshrss/data&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;docker network inspect proxy&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;docker network inspect proxy&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;[&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Name&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;proxy&amp;#34;&lt;/span&gt;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Id&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;4b6ea83029c955c6f7609af4552ed053760aadbb6de5c72f8390d3cfa96023b1&amp;#34;&lt;/span&gt;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Created&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;2022-09-24T02:01:57.289063399Z&amp;#34;&lt;/span&gt;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Scope&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;local&amp;#34;&lt;/span&gt;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Driver&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;bridge&amp;#34;&lt;/span&gt;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;EnableIPv6&amp;#34;&lt;/span&gt;: false,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;IPAM&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#f92672&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Driver&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;default&amp;#34;&lt;/span&gt;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Options&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#f92672&#34;&gt;{}&lt;/span&gt;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Config&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#f92672&#34;&gt;[&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#f92672&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                    &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Subnet&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;172.23.0.0/16&amp;#34;&lt;/span&gt;, &amp;lt;-------- This&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                    &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Gateway&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;172.23.0.1&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#f92672&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;]&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;}&lt;/span&gt;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&amp;lt;snip&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;not-losing-data&#34;&gt;Not losing data&lt;/h2&gt;&#xA;&lt;p&gt;Onto the meat and potatoes.&lt;/p&gt;&#xA;&lt;p&gt;In order to not log into a completely fresh profile with no articles and none of your settings - your user ID in FreshRSS &lt;em&gt;needs&lt;/em&gt; to match that of your identity provider.&lt;/p&gt;&#xA;&lt;p&gt;Mine did not, so I had to do a little detective work.&lt;/p&gt;&#xA;&lt;p&gt;I stopped the container with a &lt;code&gt;docker compose down&lt;/code&gt; and started poking about in the filesystem, trying to figure out how I could change my username.&lt;/p&gt;&#xA;&lt;p&gt;As it turns out, it&amp;rsquo;s quite simple - each user has their own directory under &lt;code&gt;data/users/&lt;/code&gt;, and each user has their own individual sqlite database. I poked around in the database a little, but there didn&amp;rsquo;t seem to be any indication of who owned each entry it stored in its tables.&lt;/p&gt;&#xA;&lt;p&gt;This led me to believe that maybe FreshRSS was just reading the directory structure to find its list of users.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-shell&#34; data-lang=&#34;shell&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;docker-ubuntu in ~/docker/freshrss/data&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&amp;gt; tree users&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;users&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;├── MyUsername&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;│   ├── config.php&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;│   ├── db.sqlite&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;│   └── log.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;├── _&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;│   ├── db.sqlite&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;│   ├── index.html&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;│   ├── log.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;│   ├── log_api.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;│   └── log_pshb.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;└── index.html&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt; directories, &lt;span style=&#34;color:#ae81ff&#34;&gt;10&lt;/span&gt; files&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;So as an experiment, I simply renamed the user folder under &lt;code&gt;data/users&lt;/code&gt; to match the one from my identity provider and started FreshRSS back up. Imagine my surprise when that simply worked.&lt;/p&gt;&#xA;&lt;p&gt;I was logged in automatically with Authentik SSO, and I had all of my feeds, saved articles and settings.&lt;/p&gt;&#xA;</description>
    </item>
    <item>
      <title>Configuring Apache for OIDC with an Authentik backend</title>
      <link>https://blog.ssb-tech.net/posts/apache-oidc-authentik/</link>
      <pubDate>Wed, 26 Feb 2025 20:06:16 -0500</pubDate>
      <guid>https://blog.ssb-tech.net/posts/apache-oidc-authentik/</guid>
      <description>&lt;h2 id=&#34;summary&#34;&gt;Summary&lt;/h2&gt;&#xA;&lt;p&gt;For the past year and half I&amp;rsquo;ve been running my own mailserver using &lt;a href=&#34;https://www.postfix.org/&#34;&gt;Postfix&lt;/a&gt; and &lt;a href=&#34;https://www.dovecot.org/&#34;&gt;Dovecot&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This setup works quite well, and I&amp;rsquo;ve also installed &lt;a href=&#34;https://roundcube.net/&#34;&gt;Roundcube&lt;/a&gt; to have a convenient web frontend. It&amp;rsquo;s nice to have, though most of the time I interact with the mailserver via apps like Thunderbird or FairEmail.&lt;/p&gt;&#xA;&lt;p&gt;While Roundcube is quite nice, I don&amp;rsquo;t necessarily trust the authentication mechanism to be exposed directly to the internet.&lt;/p&gt;&#xA;&lt;p&gt;Since I set this up, I put Apache basic authentication in front of it as a deterrent. However, the issue with basic auth is that it requires you to log in again &lt;em&gt;every single time&lt;/em&gt; you restart your browser.&lt;/p&gt;&#xA;&lt;p&gt;So, I decided on a more robust solution. I&amp;rsquo;ve already been running Authentik for some of the other services in my lab that support OIDC, so I decided to tie back into that system, which will give me nice single sign on features.&lt;/p&gt;&#xA;&lt;h2 id=&#34;configuring-apache&#34;&gt;Configuring Apache&lt;/h2&gt;&#xA;&lt;p&gt;Here&amp;rsquo;s how you can set this up for yourself.&lt;/p&gt;&#xA;&lt;p&gt;First, install the Apache module that adds OIDC support:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo apt install mod_auth_openidc&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Enable the module:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo a2enmod auth_openidc&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here&amp;rsquo;s an example Apache virtual host with working OIDC support:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;&amp;lt;VirtualHost *:443&amp;gt;&#xA;ServerAdmin webmaster@localhost&#xA;ServerName mail.example.net&#xA;&#xA;OIDCProviderMetadataURL &amp;#34;https://auth.example.net/application/o/roundcube-webmail/.well-known/openid-configuration&amp;#34;&#xA;OIDCClientID redacted&#xA;OIDCClientSecret redacted&#xA;OIDCRedirectURI &amp;#34;https://mail.example.net/roundcube&amp;#34;&#xA;OIDCCacheType file&#xA;OIDCCacheDir /var/cache/mod_auth_openidc&#xA;OIDCCryptoPassphrase redacted&#xA;&#xA;&amp;lt;Location /roundcube&amp;gt;&#xA;AuthType openid-connect&#xA;Require valid-user&#xA;&amp;lt;/Location&amp;gt;&#xA;&#xA;&amp;lt;Location /&amp;gt;&#xA;AuthType openid-connect&#xA;Require valid-user&#xA;&amp;lt;/Location&amp;gt;&#xA;&#xA;# Handle the case if someone hits the root location and redirect them to /roundcube &#xA;RewriteEngine On&#xA;RewriteCond %{REQUEST_URI} ^/$&#xA;RewriteCond %{HTTP_REFERER} !auth.example.net [NC]&#xA;RewriteRule ^/$ /roundcube/ [R=302,L]&#xA;&#xA;ErrorLog ${APACHE_LOG_DIR}/error.log&#xA;CustomLog ${APACHE_LOG_DIR}/access.log combined&#xA;&#xA;SSLEngine on&#xA;SSLCertificateFile      /etc/letsencrypt/live/mail.example.net/cert.pem&#xA;SSLCertificateKeyFile /etc/letsencrypt/live/mail.example.net/privkey.pem&#xA;SSLCertificateChainFile /etc/letsencrypt/live/mail.example.net/fullchain.pem&#xA;&amp;lt;/VirtualHost&amp;gt;&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Once you have this set up, restart apache:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo systemctl restart apache2&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;On systems other than Ubuntu the service may be called httpd rather than apache2.&lt;/p&gt;&#xA;&lt;h2 id=&#34;oidc-configuration-options&#34;&gt;OIDC configuration options&lt;/h2&gt;&#xA;&lt;p&gt;&lt;code&gt;OIDCClientId&lt;/code&gt;, &lt;code&gt;OIDCProviderMetadataURL&lt;/code&gt; and &lt;code&gt;OIDCClientSecret&lt;/code&gt; can both be found in your Authentik provider configuration.&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;OIDCCryptoPassphrase&lt;/code&gt; is only used internally. You can generate any random string for this, I&amp;rsquo;d recommend at least 64 characters.&lt;/p&gt;&#xA;&lt;p&gt;Don&amp;rsquo;t forget that you also need to set the redirect URI in the provider settings!&lt;/p&gt;&#xA;</description>
    </item>
  </channel>
</rss>
