Skip to content

Rauthy #2405

Description

@MickLesk

Name of the Script

Rauthy

Script Type

CT (LXC Container)

Script path

No response

Where does it run?

Proxmox VE host

Does this script support arm64?

arm64 supported

📋 Script Details

Rauthy is a single sign-on identity and access management server. It is an OpenID Connect and OAuth 2 provider with an admin UI, passkey (FIDO2/WebAuthn) and OTP multi-factor login, upstream login providers, SCIM, forward auth and PAM/SSH login. This script builds Rauthy from the release source and runs it with its embedded Hiqlite (Raft-replicated SQLite) database, served over HTTPS with a self-signed certificate.

Activity

  1. github-actions commented on Oct 9, 2026

    @github-actions
    Contributor

    The Rauthy script is ready for testing. Run it in the Proxmox VE shell (or on an Incus host) to create a container:

    bash -c "$(curl -fsSL https://raw.githubusercontent.com/community-scripts/DevScripts/main/ct/rauthy.sh)"
    

    Default credentials:
    Username: admin@localhost

    Open https://:8443/auth/v1/ and accept the self-signed certificate. Sign in as admin@localhost with the password_plain value under [bootstrap] in /opt/rauthy_data/config.toml (only read on the very first start) and change it on the account page right away.
    Passkeys (WebAuthn) only work under a DNS name with a certificate the browser trusts; an IP address is never a valid relying party. So the script sets admin_force_mfa = false, otherwise the admin UI would be unreachable by IP. For production, serve Rauthy under a domain, set server.pub_url, webauthn.rp_id and webauthn.rp_origin to it before anyone registers a passkey (changing rp_id later breaks existing passkeys), register a passkey for the admin and then set admin_force_mfa = true.
    The OIDC issuer is https://<pub_url>/auth/v1/ (discovery at /auth/v1/.well-known/openid-configuration). server.pub_url in /opt/rauthy_data/config.toml points at the container IP; change it when the IP changes or Rauthy sits behind a domain, then run systemctl restart rauthy. Behind a reverse proxy, proxy to https://:8443 and also set proxy_mode = true and trusted_proxies = ['/32'] under [server].
    Back up /opt/rauthy_data/config.toml together with the Hiqlite database in /opt/rauthy_data/hiqlite. The [encryption] keys encrypt client secrets and other stored values, a database restored without them is unusable.
    No mail server is configured, so password reset, user registration and event e-mails are not sent. Set smtp_url, smtp_username, smtp_password and smtp_from under [email] in /opt/rauthy_data/config.toml and restart Rauthy.
    The self-signed certificate in /etc/ssl/rauthy is valid for one year. Replace rauthy.crt and rauthy.key there with your own certificate (or renew it) and restart Rauthy.
    Rauthy publishes no release binaries, so the install and every update compile it from the release source (Rust). This takes about 50 minutes on 4 cores, up to 2.5 GB of RAM and 9 GB of disk; an update builds while the old version keeps running. The server itself uses about 200 MB, so RAM can be lowered after the install and raised again before an update.

    Note: This is not in the official repo yet—it's just a dev version! After merging into ProxmoxVE, it will need to be recreated.

    Discord testing thread: https://discord.com/channels/1302816934508630047/1558017253310464110

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions