<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Use Cloudrons ldap in Authelia]]></title><description><![CDATA[<p dir="auto">Hi everybody,</p>
<p dir="auto">Question...<br />
I have Authelia installed at another location and i use it for applications that are running without 2fauth. I use Authelia here for the 2fauth in front.</p>
<p dir="auto">Now i want to offer my already existing users in Cloudron, to login with Authelia and use the other services at the other location.<br />
I am following this guide:<br />
<a href="https://docs.ibracorp.io/authelia/authelia/configuration" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.ibracorp.io/authelia/authelia/configuration</a><br />
(Option 2 - Using an LDAP database) but not sure wich ldap section i have to follow for the Cloudrons Ldap integration..(?)</p>
<ol>
<li>FreeIpa</li>
<li>OpenLdap</li>
<li>Active Directory</li>
<li>LLDAP/Light Ldap</li>
</ol>
<p dir="auto">Another question is, that Cloudrons LDAP port:636 is exposed to the outside world, but restricted to only the IP adress of the other location in my firewall. And of course in the Cloudrons Ldap section, the IP address of the other location is in place there also.</p>
<p dir="auto">Am i doing this the right way?</p>
]]></description><link>https://forum.cloudron.io/topic/7517/use-cloudrons-ldap-in-authelia</link><generator>RSS for Node</generator><lastBuildDate>Sun, 14 Jun 2026 16:35:40 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/7517.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 16 Aug 2022 14:07:23 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Tue, 17 Jun 2025 21:03:00 GMT]]></title><description><![CDATA[<h1>Closed due to inactivity</h1>
]]></description><link>https://forum.cloudron.io/post/108875</link><guid isPermaLink="true">https://forum.cloudron.io/post/108875</guid><dc:creator><![CDATA[james]]></dc:creator><pubDate>Tue, 17 Jun 2025 21:03:00 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Fri, 24 Feb 2023 11:22:38 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a><br />
I'm totally sure that I have enabled the directory server in Cloudron, not sure where it's stuck...</p>
<p dir="auto">Maybe I will try and give it a go to package Authelia as an app in Cloudron. Only thing is i have zero experience with that, so it's going to be a learning curve....</p>
<p dir="auto">Maybe <a class="plugin-mentions-user plugin-mentions-a" href="/user/jan-macenka" aria-label="Profile: Jan-Macenka">@<bdi>Jan-Macenka</bdi></a> can help/assist me with that?</p>
]]></description><link>https://forum.cloudron.io/post/62394</link><guid isPermaLink="true">https://forum.cloudron.io/post/62394</guid><dc:creator><![CDATA[DanTheMan]]></dc:creator><pubDate>Fri, 24 Feb 2023 11:22:38 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Mon, 20 Feb 2023 13:19:44 GMT]]></title><description><![CDATA[<p dir="auto">I don't quite know Authelia, so hard to say why it wouldn't startup in such a case. Just to be sure, have you enable the directory server in your Cloudron? This can be found at the bottom of the users view in your Cloudron dashboard.</p>
<p dir="auto">But also as you correctly mention the required nginx changes to be persistent across Cloudron updates, it really makes so much more sense to bundle it as a Cloudron app.</p>
]]></description><link>https://forum.cloudron.io/post/62197</link><guid isPermaLink="true">https://forum.cloudron.io/post/62197</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Mon, 20 Feb 2023 13:19:44 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Sun, 19 Feb 2023 17:58:38 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a><br />
If i try to connect through it's Cloudrons external ldap domain, Authelia is not starting anymore, but if i reverse the action and connect through Cloudrons internal ip, Authelia is starting up and working again.</p>
<p dir="auto">Now for the test, if i remove Authelia's ip from the Restrict Access list in Cloudron, as suggested Authelia fails to start and Cloudron is doing it's job by refusing the not listed ip from Authelia.  if i add Authelia's ip in the Restrict Access list in Cloudron again, Authelia starts up.<br />
So i think it's possible to connect internally...... i guess</p>
<p dir="auto">A second question would be, if i have the Ldap part working, how could i Adapt the Nginx-Config for the Cloudron Apps, to protect the required SSO flow Authelia offers?</p>
<p dir="auto">I think and feel that's going to be a lot harder to accomplish....</p>
]]></description><link>https://forum.cloudron.io/post/62168</link><guid isPermaLink="true">https://forum.cloudron.io/post/62168</guid><dc:creator><![CDATA[DanTheMan]]></dc:creator><pubDate>Sun, 19 Feb 2023 17:58:38 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Sun, 19 Feb 2023 16:37:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dantheman" aria-label="Profile: DanTheMan">@<bdi>DanTheMan</bdi></a> you have to use the external ldap domain, as the server will check the source IP.</p>
]]></description><link>https://forum.cloudron.io/post/62166</link><guid isPermaLink="true">https://forum.cloudron.io/post/62166</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Sun, 19 Feb 2023 16:37:40 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Sun, 19 Feb 2023 16:33:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a><br />
Thanks for the quick response.<br />
I do have the alternately way exposed in this setup for now, but it's still the local way i want to connect...<br />
do i have to connect it through domain? or is it still possible to do this via it's ip? locally?</p>
]]></description><link>https://forum.cloudron.io/post/62164</link><guid isPermaLink="true">https://forum.cloudron.io/post/62164</guid><dc:creator><![CDATA[DanTheMan]]></dc:creator><pubDate>Sun, 19 Feb 2023 16:33:18 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Sun, 19 Feb 2023 16:28:00 GMT]]></title><description><![CDATA[<p dir="auto">I think what you really want here is a custom Cloudron app package, running authelia and have the <code>ldap</code> addon enabled.</p>
<p dir="auto">If you connect to the internal ldap server, then it will auth only against per-app generated credentials (the app gets those via env variables) for the initial admin bind to allow searching.</p>
<p dir="auto">Alternately you can enable exposed ldap and connect via the external route to then.</p>
]]></description><link>https://forum.cloudron.io/post/62162</link><guid isPermaLink="true">https://forum.cloudron.io/post/62162</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Sun, 19 Feb 2023 16:28:00 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Sun, 19 Feb 2023 16:29:15 GMT]]></title><description><![CDATA[<p dir="auto">Ok, so i found the following almost working, but i can't login Authelia with Cloudron's credentials (ldap)</p>
<p dir="auto">This is the error i got from Authelia in the logs:<br />
<img src="/assets/uploads/files/1676823905995-schermafbeelding-2023-02-19-172403.jpg" alt="Schermafbeelding 2023-02-19 172403.jpg" class=" img-fluid img-markdown" /></p>
<p dir="auto">This is the config i have in Authelia,</p>
<p dir="auto">authentication_backend:<br />
password_reset:<br />
disable: true<br />
ldap:<br />
implementation: custom<br />
url: ldaps://cloudrons_ip:636<br />
start_tls: false<br />
tls:<br />
server_name: my.cloudrons_domain<br />
skip_verify: true<br />
minimum_version: TLS1.2<br />
base_dn: ou=users,dc=cloudron<br />
username_attribute: uid<br />
additional_users_dn: ou=users,dc=cloudron<br />
users_filter: (&amp;({username_attribute}={input})(objectClass=person))<br />
additional_groups_dn: ou=groups,dc=cloudron<br />
groups_filter: (&amp;(member=uid={input},cn=users,cn=accounts,dc=cloudron)(objectclass=groupofnames))<br />
group_name_attribute: cn<br />
mail_attribute: mail<br />
display_name_attribute: givenName<br />
user: cn=admin,ou=system,dc=cloudron<br />
password: "password for ldap in cloudron"</p>
<p dir="auto">Am i missing a step somewhere or maybe i have the "users_filter" or "groups_filter" setup in the wrong way?<br />
Maybe someone can give me a pointer into the right direction.......<br />
.</p>
<p dir="auto">I feel i'm so close to an almost working situation here.....<img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f635.png?v=13d69e59554" class="not-responsive emoji emoji-android emoji--dizzy_face" style="height:23px;width:auto;vertical-align:middle" title=":dizzy_face:" alt="😵" /></p>
]]></description><link>https://forum.cloudron.io/post/62161</link><guid isPermaLink="true">https://forum.cloudron.io/post/62161</guid><dc:creator><![CDATA[DanTheMan]]></dc:creator><pubDate>Sun, 19 Feb 2023 16:29:15 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Sat, 18 Feb 2023 10:04:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jan-macenka" aria-label="Profile: Jan-Macenka">@<bdi>Jan-Macenka</bdi></a></p>
<p dir="auto">So this is the update so far from my side;</p>
<ol>
<li>
<p dir="auto"><s>Set up a Container with Authelia (cloud also be a VM) in my private network alongside the Cloudron VM as in the same sub-net or vLAN</s><br />
Authelia is running in the same subnet as Cloudron now.  <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44c.png?v=13d69e59554" class="not-responsive emoji emoji-android emoji--ok_hand" style="height:23px;width:auto;vertical-align:middle" title=":ok_hand:" alt="👌" /></p>
</li>
<li>
<p dir="auto"><s>Let Cloudron do the Cert-handling and expose Authelia via Cloudron-App-Proxy</s><br />
Authelia is  running through the Cloudron-App-Proxy and handling certs for Authelia. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44c.png?v=13d69e59554" class="not-responsive emoji emoji-android emoji--ok_hand" style="height:23px;width:auto;vertical-align:middle" title=":ok_hand:" alt="👌" /></p>
</li>
</ol>
<p dir="auto">These are the one's that  i'm struggling with at the moment;</p>
<ol start="3">
<li>
<p dir="auto">Adapt Authelias Config accordingly, utilize LDAP Backend and integrating the one that Cloudron offers. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f448.png?v=13d69e59554" class="not-responsive emoji emoji-android emoji--point_left" style="height:23px;width:auto;vertical-align:middle" title=":point_left:" alt="👈" /></p>
</li>
<li>
<p dir="auto">Adapt the Nginx-Config for the Cloudron Apps, protect to require the SSO flow Authelia offers. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f448.png?v=13d69e59554" class="not-responsive emoji emoji-android emoji--point_left" style="height:23px;width:auto;vertical-align:middle" title=":point_left:" alt="👈" /></p>
</li>
</ol>
]]></description><link>https://forum.cloudron.io/post/62124</link><guid isPermaLink="true">https://forum.cloudron.io/post/62124</guid><dc:creator><![CDATA[DanTheMan]]></dc:creator><pubDate>Sat, 18 Feb 2023 10:04:27 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Tue, 14 Feb 2023 17:23:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jan-macenka" aria-label="Profile: Jan-Macenka">@<bdi>Jan-Macenka</bdi></a><br />
So great to hear that someone wants to do the same thing as i had in mind <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=13d69e59554" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title="👍" alt="👍" /></p>
<p dir="auto">This is how I have set it up at the moment...<br />
<img src="/assets/uploads/files/1676395426575-screenshot_20220820-202949_youtube-resized.png" alt="Screenshot_20220820-202949_YouTube.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I am on holiday this week and coming home this weekend, so I will be here around that time to pick this up.</p>
]]></description><link>https://forum.cloudron.io/post/61934</link><guid isPermaLink="true">https://forum.cloudron.io/post/61934</guid><dc:creator><![CDATA[DanTheMan]]></dc:creator><pubDate>Tue, 14 Feb 2023 17:23:48 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Sun, 12 Feb 2023 12:58:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dantheman" aria-label="Profile: DanTheMan">@<bdi>DanTheMan</bdi></a> did you have success? Trying to do the same thing now. My approach will be:</p>
<ol>
<li><a href="https://www.authelia.com/integration/deployment/docker/#using-secrets" target="_blank" rel="noopener noreferrer nofollow ugc">Set up a Container with Authelia</a> (cloud also be a VM) in my private network alongside the Cloudron VM as in the same sub-net or vLAN</li>
<li><a href="https://www.authelia.com/integration/prologue/get-started/#configuration" target="_blank" rel="noopener noreferrer nofollow ugc">Adapt Authelias Config accordingly</a>, I want it to <a href="https://www.authelia.com/configuration/first-factor/ldap/" target="_blank" rel="noopener noreferrer nofollow ugc">utilize a LDAP Backend</a> and for starters <a href="https://forum.cloudron.io/topic/6118/ldap-integration">integrating the one that Cloudron offers</a>.</li>
<li>Let Cloudron do the Cert-handling and expose Authelia via <a href="https://docs.cloudron.io/apps/#app-proxy" target="_blank" rel="noopener noreferrer nofollow ugc">Cloudron-App-Proxy</a></li>
<li><a href="https://www.authelia.com/integration/proxies/nginx/#standard-example" target="_blank" rel="noopener noreferrer nofollow ugc">Adapt the Nginx-Config</a> for the Cloudron Apps, I want to protect to require the SSO flow Authelia offers.</li>
</ol>
<p dir="auto">How did you approach the issue? Did you do things differently?</p>
]]></description><link>https://forum.cloudron.io/post/61894</link><guid isPermaLink="true">https://forum.cloudron.io/post/61894</guid><dc:creator><![CDATA[Jan Macenka]]></dc:creator><pubDate>Sun, 12 Feb 2023 12:58:49 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Tue, 16 Aug 2022 14:55:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Thanks a lot for the info. I'm going to try it out when I have some spare hours left this week.</p>
<p dir="auto">I'll report back.....</p>
]]></description><link>https://forum.cloudron.io/post/52174</link><guid isPermaLink="true">https://forum.cloudron.io/post/52174</guid><dc:creator><![CDATA[DanTheMan]]></dc:creator><pubDate>Tue, 16 Aug 2022 14:55:13 GMT</pubDate></item><item><title><![CDATA[Reply to Use Cloudrons ldap in Authelia on Tue, 16 Aug 2022 14:47:06 GMT]]></title><description><![CDATA[<p dir="auto">I have no clue about Authelia and what kind of LDAP flavor it supports, but probably OpenLDAP profile is compatible.</p>
<p dir="auto">On your Cloudron side, you have to enable the user directory server. The settings and default values are mentioned in the docs at <a href="https://docs.cloudron.io/user-management/#directory-server" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/user-management/#directory-server</a></p>
]]></description><link>https://forum.cloudron.io/post/52172</link><guid isPermaLink="true">https://forum.cloudron.io/post/52172</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Tue, 16 Aug 2022 14:47:06 GMT</pubDate></item></channel></rss>