Update Authentik status: Stage 2 + Enrollment/Recovery/2FA fixes (2026-07-27)

Thore Cimbal
2026-07-27 23:58:00 +02:00
parent 280aa36cc3
commit 08d4a50d22
3 changed files with 38 additions and 8 deletions
+10 -1
@@ -174,7 +174,16 @@
## 🔄 In Progress / Blocked
### Authentik Stage 2 MAS Integration (⏳ Depends on Manual Config)
**Update 2026-07-27**: Authentik Stage 2 wurde bereits am 2026-05-15 fertiggestellt (Commit
`cdfbf7d`) — der Abschnitt darunter ist historisch. Zusätzlich heute repariert: der komplett
kaputte `matrix-invitation`-Enrollment-Flow (fehlende Write/Password/Login-Stages, 16
fehlerhafte `validation_policies`), der leere `matrix-recovery`-Flow (Passwort-Reset), sowie
optionales 2FA/Passkey-Self-Service (`axion1337.chat/docs/setup/security.html`). Alles als
Authentik Blueprint (`apps/authentik/authentik-blueprints.yaml`) deklarativ im Repo, siehe
[Authentik-OIDC.md](Authentik-OIDC.md) für Details. Backlog-Punkt ergänzt: MAS
Custom-Template-Link auf `account.axion1337.chat`.
### Authentik Stage 2 MAS Integration (⏳ Depends on Manual Config) — historisch, siehe Update oben
**Beschreibung**: Authentik OIDC Provider muss manuell im Authentik Admin UI konfiguriert werden, bevor Stage 2 Deployment möglich ist.
**Schritte**:
+23 -2
@@ -1,7 +1,6 @@
# Authentik als Identity Provider für Matrix
**Status**: ✅ Stage 1 Deployed (Authentik läuft)
**Pending**: Stage 2 (MAS Integration)
**Status**: ✅ Deployed (Stage 1 + Stage 2 + Enrollment/Recovery/2FA)
**Domain**: `auth.axion1337.chat`
## Überblick
@@ -41,5 +40,27 @@ Authentik = OIDC Provider für MAS → Zentrales Login + Einladungs-basierte Reg
Authentik Admin → Flows & Stages → Invitations → Create
## Enrollment/Recovery/2FA Fix (2026-07-27)
Der `matrix-invitation`-Flow hatte nur 2 von 5 nötigen Stages (kein Write/Password/Login,
beide vorhandenen Stages auf derselben `order`). Nutzer wurden nie in Synapse angelegt.
Behoben und als **Authentik Blueprint** (`apps/authentik/authentik-blueprints.yaml`)
deklarativ ins Repo übernommen, statt Klick-Anleitung:
- `matrix-invitation`: Invite → Prompt → Write → Password → Login → Redirect (axion1337.chat)
- `matrix-invitation-prompt`: 16 fehlerhafte `validation_policies` entfernt (crashten mit `AnonymousUser`/`NoneType`-Fehlern)
- `matrix-recovery`: war komplett leer (0 Stages) — jetzt vollständig, verlinkt als "Passwort vergessen?" auf der echten Login-Seite (`default-authentication-flow`)
- `Brand.default_application` auf die `matrix`-Application gesetzt, damit `/` für eingeloggte User nicht mehr in der `/if/user/`-Sackgasse landet (die für `type=external` Matrix-Accounts gesperrt ist)
**2FA/Passkey (optional, `not_configured_action=skip`)** — Selbst-Einrichtung, da `/if/user/`
für externe User gesperrt ist:
- Passkey: `https://auth.axion1337.chat/if/flow/default-authenticator-webauthn-setup/`
- TOTP: `https://auth.axion1337.chat/if/flow/default-authenticator-totp-setup/`
- Auffindbar für Nutzer über `axion1337.chat/docs/setup/security.html`
**Backlog**: Link direkt auf `account.axion1337.chat/account/` (MAS) anzeigen, statt nur
über die Doku-Seite — erfordert MAS Custom-Template-Override (`templates.path`), höherer
Aufwand/Risiko, siehe `docs/TASKS.md`.
---
**Weitere Details**: Siehe Kapitel 2 in diesem Projekt.
+5 -5
@@ -16,7 +16,7 @@
| Komponente | Link | Status | Beschreibung |
|-----------|------|--------|-------------|
| **TURN Server** | [TURN-Server.md](TURN-Server.md) | ✅ Deployed | WebRTC Video-Call Media Relay |
| **Authentik OIDC** | [Authentik-OIDC.md](Authentik-OIDC.md) | 🔄 Stage 2 Pending | Identity Provider für Matrix |
| **Authentik OIDC** | [Authentik-OIDC.md](Authentik-OIDC.md) | ✅ Deployed | Identity Provider für Matrix (Enrollment/Recovery/2FA seit 2026-07-27 repariert) |
| **Monitoring** | [Monitoring.md](Monitoring.md) | ✅ Deployed | Alloy → Prometheus/Loki |
| **Element Customization** | [Element-Customization.md](Element-Customization.md) | ✅ Deployed | Themes, Desktop Setup, Admin Panel |
| **Room Policies** | [Room-Policies.md](Room-Policies.md) | ✅ Deployed | Retention, Publication, Auto-Join |
@@ -68,12 +68,12 @@ PostgreSQL + TURN (turn.axion1337.chat)
| Category | Count | Status |
|----------|-------|--------|
| **Completed** | 6 | ✅ K3S, Flux, ESS, Themes, Desktop, Monitoring, TURN |
| **In Progress** | 1 | 🔄 Authentik Stage 2 (awaiting manual config) |
| **Backlog** | 15+ | 📋 Element Call Fork, DB Backups, NetworkPolicies, etc. |
| **Completed** | 7 | ✅ K3S, Flux, ESS, Themes, Desktop, Monitoring, TURN, Authentik (Enrollment/Recovery/2FA) |
| **In Progress** | 0 | |
| **Backlog** | 15+ | 📋 Element Call Fork, DB Backups, NetworkPolicies, MAS custom-template account link, etc. |
| **Security** | 10 | 🔒 Firewall, SSH, auditd, Kernel hardening, CrowdSec, Falco |
---
**Last Updated**: 2026-05-15
**Last Updated**: 2026-07-27
**Maintained by**: Claude Code + Team