All apps · 0 apps
turkushan-auth
Docker app from turkushan-auth's Repository
Overview
Readme
View on GitHubturkushan-auth
Self-hosted login portal (forward auth) for your subdomains behind Nginx Proxy Manager.
People register their own account, you approve per site who may enter, and one login works on all subdomains.
One container: a Go backend and a Svelte frontend in a single binary, with SQLite in /data.
Beta / work in progress. The skeleton runs: database, admin account bootstrap and
/healthz. Login, forward auth and the admin panel are being built.
Install on Unraid
Via Community Apps: search for turkushan-auth in the Apps tab (once it's listed).
Manually: open the Unraid terminal and run:
wget -O /boot/config/plugins/dockerMan/templates-user/my-turkushan-auth.xml \
https://raw.githubusercontent.com/turkushan490/turkushan-auth/main/templates/turkushan-auth.xml
Then go to Docker → Add Container → Template and pick turkushan-auth.
Fill in APP_URL (e.g. https://auth.example.com), ADMIN_USER and ADMIN_PASSWORD (at least 6 characters, 1 capital letter, 1 symbol), then click Apply.
Check http://<server-ip>:3010/healthz: it should return ok.
The container starts as root only to fix ownership of the appdata folder, then runs as PUID:PGID (default 99:100).
Settings
| Variable | Default | |
|---|---|---|
APP_URL |
required | public portal URL, e.g. https://auth.example.com |
ADMIN_USER / ADMIN_PASSWORD |
admin created on first start; the password is not overwritten on restart | |
COOKIE_DOMAIN |
derived from APP_URL |
auth.example.com gives .example.com, shared by all subdomains |
PORTAL_INTERNAL_URL |
how NPM reaches the portal, e.g. http://192.168.1.10:3010 (used in the generated nginx snippets) |
|
TRUSTED_PROXIES |
172.16.0.0/12 |
proxy addresses allowed to pass client IP headers |
SESSION_SECRET |
auto-generated in /data/secret |
|
PUID / PGID |
99 / 100 |
|
PORT |
3010 |
port inside the container |
Build
GitHub Actions (.github/workflows/build.yml) builds the frontend, runs go vet and go test, then pushes ghcr.io/turkushan490/turkushan-auth:latest on every push to main. A v1.2.3 tag also pushes :1.2.3.
Local development:
cd web && npm install && npm run build && cd ..
APP_URL=http://localhost:3010 DATA_DIR=./data ADMIN_USER=admin ADMIN_PASSWORD='Change!me' go run ./cmd/turkushan-auth
License
MIT
Install turkushan-auth on Unraid in a few clicks.
Find turkushan-auth in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.
Requirements
Categories
Related apps
Explore more like this
Explore allDetails
ghcr.io/turkushan490/turkushan-auth:latestRuntime arguments
- Web UI
http://[IP]:[PORT:3010]/- Network
bridge- Privileged
- false
Template configuration
Port Nginx Proxy Manager uses to reach the portal.
- Target
- 3010
- Default
- 3010
- Value
- 3010
SQLite database and generated secret.
- Target
- /data
- Default
- /mnt/user/appdata/turkushan-auth
- Value
- /mnt/user/appdata/turkushan-auth
Public URL of the portal, e.g. https://auth.example.com
Admin account created on first start.
Admin password (min 10 characters). Only used when the admin account is created; change it in the panel afterwards.
Optional. Cookie domain shared by all protected subdomains. Empty = derived from APP_URL (auth.example.com gives .example.com).
Optional. How Nginx Proxy Manager reaches this container, e.g. http://192.168.1.10:3010. Filled into the nginx snippets the admin panel generates.
IPs/CIDRs of your proxy. Client IP headers are only trusted from these. Default covers Docker networks.
- Default
- 172.16.0.0/12
- Value
- 172.16.0.0/12
User the app runs as (99 = nobody).
- Default
- 99
- Value
- 99
Group the app runs as (100 = users).
- Default
- 100
- Value
- 100
Optional (min 32 characters). Empty = generated once and stored in /data/secret.