Building a Self-Hosted Identity Layer with Authentik
How Authentik replaced a dozen separate logins with a single SSO layer across my entire homelab, and why forward auth through Traefik is the missing piece.

Every self-hosted service comes with its own login page. Jellyfin has one, Grafana has one, Gitea has one. Before Authentik, I had a spreadsheet of credentials and a growing sense of dread every time I added a new service. Now I have one login for everything.
What Authentik does
Authentik is a self-hosted identity provider that supports OIDC, SAML, LDAP, and proxy authentication. Think of it as your own mini Okta. Anything that speaks OIDC gets proper SSO integration. Everything else sits behind Traefik's forward auth, with Authentik in front handling the login before the request ever reaches the service. That second group is most of a homelab.
The Traefik integration
Traefik has a forwardAuth middleware that sends every request to Authentik first, and that is the piece that ties it together. If you're authenticated, the request passes through. If not, you get redirected to the login page. This means even services with no auth support at all, static dashboards and internal tools, get SSO for free.
The LDAP bridge
Some services only support LDAP for user management, Jellyfin being the big one. Authentik has a built-in LDAP outpost that exposes your users and groups via LDAP. Configure Jellyfin to authenticate against it, and your media server users are managed in the same place as everything else.
What I learned
The biggest lesson was about trust boundaries. Not every service needs the same level of protection. Public-facing services get OIDC with MFA. Internal dashboards get forward auth. Development tools get basic proxy auth. Authentik lets you define different flows for different risk levels, which is exactly what a homelab needs.