Replies: 14 comments 39 replies
|
Thank you very much @StafLoker for writing that down! This looks exactly like the solution I'd love.... but I haven't got it working as of now. My COMPOSE_FILE variable looks like this: So as you can see, without So, if you could please let us know the base-installation/your starting point for this config manual to, that would be great and maybe I'll get it working then. :-) Thanks in advance! |
|
@irrwitzer42 |
|
thanks a lot, it is working perfectly. |
|
🤔 i built opencloud from source according to the Install Bare-Metal | OpenCloud Docs , but where should i put
|
|
Big Thanks of all here. It runs on Authentik 2025.10.2 |
|
Thanks for the guide 👍 I’m running OpenCloud 4.0.1 with Authentik 2025.10.3, and authentication generally behaves as expected. iOS and desktop apps work without issues. The only remaining problem is that I occasionally get logged out in the browser for no obvious reason. I suspect something around refresh tokens not being picked up or refreshed correctly by the browser/WebDAV flow. I see this in the OpenCloud proxy logs from time to time: error="token is expired" It’s not constant, but happens sporadically. Has anyone else seen similar behavior or found specific Authentik token/refresh settings that work best with OpenCloud? |
|
@chiragkrishna the error
is unrelated, see opencloud-eu/opencloud-compose#173. |
|
Thanks so much for the guide. I wanted to share some issues I ran into while I was setting up my authentik SSO that may help anyone else following along. This environment variable is important when using Authentik, as you have to setup different providers for each of the different apps and then the token issuer does not match the main "web" server when using the applications on mobile/desktop. I'm not 100% sure the security implications of setting it to none, however I am running everything on my LAN behind VPN. I also ended up using a property mapping in Authentik to place the claims of the scopes "roles" into "profile". [Customization->Property Mappings] In the opencloud documentation this notated as the following on page: https://docs.opencloud.eu/docs/admin/configuration/authentication-and-user-management/external-idp "As the OpenCloud clients currently only request a hardcoded list of scopes, the automatic role-assignment currently requires the IDP to be able to provide additional claims in the Access Token and the UserInfo endpoint independent of the requested scopes. If your IDP does not support this, automatic role assignment will not work."
In addition, you remove the "openid profile" scope mapping from the opencloud providers, as this includes the standard profile claims. You can then make the following groups in Authentik and assign your users to them. OpenCloud Admins |
|
#2072 is going to be merged soon to simplify that config process drastically. Last chance for feedback & reviews. |
|
Has anyone tried this again after that pull request getting merched in the latest version? Unfortunately, there's no way to use multiple issuer URLs (per client in Authentik), or am I mistaken? I’ve been tinkering with this for two days now, diligently reading GitHub PRs, discussions, etc., and testing things out, and I’m slowly reaching my limits. If anyone has gotten it working, I’d appreciate a quick chat. I’d also be happy to help update the documentation. |
|
I wish someone would cleanly rewrite this how-to now that #2072 got merged. It's so hard to keep track of all the details across all these different discussions, issues and PRs :( Like: One or multiple providers? What do the client id(s) have to be? What issuer url should I set when I have multiple providers? I am so confused 🥲️ |
|
@StrangeGirlMurph proxy_role_assignment_oidc_claim: opencloud-roles Custom Role Mapping in Authentik: Finally, I’d like to add that it’s extremely frustrating that the desktop client can’t be used right now. and that there isn't a ETA for implementation. I’d like to migrate my data from my Samba share, but I haven’t been able to do so for over two months now. |











Uh oh!
There was an error while loading. Please reload this page.
Replace with your domain:
domain.comOpencloud
Env file (opencloud.env)
CSP file (csp.yaml)
Proxy file (proxy.yaml)
Authentik
Providers
Web
Desktop app
iOS app
Groups
Create two groups, one for admin other for users.
Apps
Other
If you hace active desktop or mobile apps session, is not repair with login.
All reactions