Skip to content
DnsLister Forum

Where domain hunters compare notes

Homelab’s IDM/SSO plan review

Hi everyone,

Sharing my plan (already half implemented lol) to hear thoughts and suggestions before I complete it.
I doing it for the challenge and as part of preparing for CKS.

Hardware:
– Protecteli built running opnsense & Caddy
– Rpi 5 running stepca TinyCA
– Turinpi2 cluster (3x RK1 nodes) running talos

My end goal is:
– Using TinyCA for TLS and PKI
– Okta-like experience using Kanidm as IDM with Oauth2-proxy for OIDC/forward auth.
– mTLS (istio ambiant in the cluster, client certificates all over)
– Cillium eBPF capabilities (CNI + np)
– internal DNS using Adguard home dns rewrites

Client -> Caddy -> Kanidm App Portal -> Services

My current status that broke the whole thing was adding Istio Gateway, not sure why. Client certs and validation and currently skipped.
Should I do something’s different? Get dedicated hardware for Caddy + Kanidm? Or pick another reverse proxy instead? I hope to use the os-acme-client plugin to have opnsense ui also accessible via Kanidm, and manage Adguard rewrites using externaldns. I stick to gitops and also use kaniopto manage kanidm, is there a similar way to manage opnsense itself?

TIA

Source: r/homelab · by /u/zMynxx

Leave a Reply

Your email address will not be published. Required fields are marked *