Originally published at woitzik.dev
Every internal service in my homelab goes through the same authentication gate: Authelia. Proxmox, PBS, Grafana, ArgoCD, Headscale, ArgoCD, Uptime Kuma, Paperless, Nextcloud — 25+ web services, one login, one session, one set of access rules. The OIDC provider, the Postgres backend, the session store, and the secrets are all running inside k3s, backed by CNPG, Redis, and Vault.
This article is the full implementation: how the pieces fit together, why certain design decisions were made, and the specific bugs that bit me along the way.
View the complete homelab infrastructure source on GitHub 🐙
The Architecture






