Elektrine lite

← Feed

@bplein@bvp.me

Post #642516

2026-03-06 14:19 UTC

Anyone using a 3rd party SSO Identity Provider for their #homelab or family? I started down this rabbit hole with looking at providers for #tailscale which include Okta and OneLogin (as well as Github, Google, Apple, and Microsoft) and I was considering a OneLogin... thoughts? -- Added later: This is for a family, so I need flexible options suitable for non-techies.

Replies (6)

  • @bplein@bvp.me 2026-03-06 14:20

    I also have Mailcow email (SoGo) to protect.... thanks in advance!

    Open ##2284790

  • @mttaggart@infosec.exchange 2026-03-06 14:21

    @bplein@bvp.me I haven't done it yet, but I've been eyeing setting up a Keycloak instance for exactly this reason. And it very much fits in a homelab scenario. https://www.keycloak.org

    Open ##2284792

  • @benny@mastodontech.de 2026-03-06 14:28

    @bplein@bvp.me I use a selfhosted PocketID

    Open ##2284796

  • @apenwarr.ca@bsky.brid.gy 2026-03-06 15:09

    Try out my atlogin.net and use bluesky as your "custom" OIDC provider in Tailscale! Looks like you have your own domain handle already so you should be able to get it working within a few minutes. ATLogin - OIDC for ATProto/Blu...

    Open ##2284798

  • @arichtman@eigenmagic.net 2026-03-06 15:44

    @bplein@bvp.me we just run up keycloak at work and it's... Really not something I'd want at home unless I *needed* the huge amount of customization. I'm running Kanidm myself and it's... Fine. Zero frills, pretty great docs, bit heavily opinionated on security but probably for the best. Otherwise it's usually pocketId, zitadel, authentik, guacamole I think

    Open ##2284803

  • @zrail@hachyderm.io 2026-03-06 15:44

    @bplein@bvp.me the thing about Tailscale is that it really doesn't matter because you can invite anyone to your account using whatever SSO they happen to have. Ex: my tailnet is a legacy GitHub open source account. My spouse and kids access it with their free Microsoft SSO logins.

    Open ##2284805