turkushan-auth

turkushan-auth

Docker app from turkushan-auth's Repository

Overview

Self-hosted login portal (forward auth) for your subdomains behind Nginx Proxy Manager. People register their own account, you approve who may open which site in the admin panel, and one login works on all subdomains (SSO cookie). Per site you choose: approval required or open to any logged-in user, and whether a verified email is required. Single container, SQLite database in /data, no extra services. Work in progress: login, forward auth and the admin panel are being built.

turkushan-auth

Self-hosted login portal (forward auth) for your subdomains behind Nginx Proxy Manager. People register their own account, you approve per site who may enter, and one login works on all subdomains. One container: a Go backend and a Svelte frontend in a single binary, with SQLite in /data.

Beta / work in progress. The skeleton runs: database, admin account bootstrap and /healthz. Login, forward auth and the admin panel are being built.

Install on Unraid

Via Community Apps: search for turkushan-auth in the Apps tab (once it's listed).

Manually: open the Unraid terminal and run:

wget -O /boot/config/plugins/dockerMan/templates-user/my-turkushan-auth.xml \
  https://raw.githubusercontent.com/turkushan490/turkushan-auth/main/templates/turkushan-auth.xml

Then go to Docker → Add Container → Template and pick turkushan-auth.

Fill in APP_URL (e.g. https://auth.example.com), ADMIN_USER and ADMIN_PASSWORD (at least 6 characters, 1 capital letter, 1 symbol), then click Apply. Check http://<server-ip>:3010/healthz: it should return ok.

The container starts as root only to fix ownership of the appdata folder, then runs as PUID:PGID (default 99:100).

Settings

Variable Default
APP_URL required public portal URL, e.g. https://auth.example.com
ADMIN_USER / ADMIN_PASSWORD admin created on first start; the password is not overwritten on restart
COOKIE_DOMAIN derived from APP_URL auth.example.com gives .example.com, shared by all subdomains
PORTAL_INTERNAL_URL how NPM reaches the portal, e.g. http://192.168.1.10:3010 (used in the generated nginx snippets)
TRUSTED_PROXIES 172.16.0.0/12 proxy addresses allowed to pass client IP headers
SESSION_SECRET auto-generated in /data/secret
PUID / PGID 99 / 100
PORT 3010 port inside the container

Build

GitHub Actions (.github/workflows/build.yml) builds the frontend, runs go vet and go test, then pushes ghcr.io/turkushan490/turkushan-auth:latest on every push to main. A v1.2.3 tag also pushes :1.2.3.

Local development:

cd web && npm install && npm run build && cd ..
APP_URL=http://localhost:3010 DATA_DIR=./data ADMIN_USER=admin ADMIN_PASSWORD='Change!me' go run ./cmd/turkushan-auth

License

MIT

Install turkushan-auth on Unraid in a few clicks.

Find turkushan-auth in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.

Open the Apps tab on your Unraid server Search Community Apps for turkushan-auth Review the template variables and paths Click Install

Requirements

Nginx Proxy Manager (or nginx with auth_request) and a domain with HTTPS.

Related apps

Explore more like this

Explore all

Details

Repository
ghcr.io/turkushan490/turkushan-auth:latest
Last Updated2026-09-30
First Seen2026-09-30

Runtime arguments

Web UI
http://[IP]:[PORT:3010]/
Network
bridge
Privileged
false

Template configuration

Web portPorttcp

Port Nginx Proxy Manager uses to reach the portal.

Target
3010
Default
3010
Value
3010
DataPathrw

SQLite database and generated secret.

Target
/data
Default
/mnt/user/appdata/turkushan-auth
Value
/mnt/user/appdata/turkushan-auth
APP_URLVariable

Public URL of the portal, e.g. https://auth.example.com

ADMIN_USERVariable

Admin account created on first start.

ADMIN_PASSWORDVariable

Admin password (min 10 characters). Only used when the admin account is created; change it in the panel afterwards.

COOKIE_DOMAINVariable

Optional. Cookie domain shared by all protected subdomains. Empty = derived from APP_URL (auth.example.com gives .example.com).

PORTAL_INTERNAL_URLVariable

Optional. How Nginx Proxy Manager reaches this container, e.g. http://192.168.1.10:3010. Filled into the nginx snippets the admin panel generates.

TRUSTED_PROXIESVariable

IPs/CIDRs of your proxy. Client IP headers are only trusted from these. Default covers Docker networks.

Default
172.16.0.0/12
Value
172.16.0.0/12
PUIDVariable

User the app runs as (99 = nobody).

Default
99
Value
99
PGIDVariable

Group the app runs as (100 = users).

Default
100
Value
100
SESSION_SECRETVariable

Optional (min 32 characters). Empty = generated once and stored in /data/secret.