Nomploy Nomad Packs

← All packs

tinyauth v0.1.0

Identity

Tinyauth — a tiny authentication middleware that adds a login screen (and optional OAuth/LDAP) in front of any app behind your reverse proxy via forward-auth. Deployed as a single host-networked Nomad service.

nomad-pack run tinyauth --registry nomploy
…or one line (add registry + run)
curl -fsSL https://packs.nomploy.com/install.sh | sh -s -- tinyauth

Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.

1 task http 3000 image ghcr.io/tinyauthapp/tinyauth:v5 pinned :v5 image bumped today
Variables 10
values.hcl

Save as values.hcl, edit, then run:

nomad-pack run tinyauth -f values.hcl --registry nomploy
# The name of the Nomad job.
job_name = "tinyauth"

# The Nomad namespace to deploy into.
namespace = "default"

# The datacenters to deploy to.
datacenters = ["*"]

# The Tinyauth container image. Pin a tag in production.
image = "ghcr.io/tinyauthapp/tinyauth:v5"

# Host port for the Tinyauth server.
port = 3000

# Public URL where Tinyauth is served (required), e.g. https://tinyauth.example.com.
app_url = "http://localhost:3000"

# Exactly 32-character secret used to sign session cookies. CHANGE THIS.
secret = "changeme_changeme_changeme_12345"

# Login users as username:bcrypthash (comma-separate multiple). Default is user:password — CHANGE THIS. Generate with `tinyauth user create`.
users = "user:$2a$10$UdLYoJ5lgPsC0RKqYH/jMua7zIn0g9kPqWmhYayJYLaZQ/FTmH2/u"

# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []

# The task resources.
resources = {
    cpu    = 200
    memory = 128
  }
NameTypeDefaultDescription
job_name string
"tinyauth"
The name of the Nomad job.
namespace string
"default"
The Nomad namespace to deploy into.
datacenters list
["*"]
The datacenters to deploy to.
image string
"ghcr.io/tinyauthapp/tinyauth:v5"
The Tinyauth container image. Pin a tag in production.
port number
3000
Host port for the Tinyauth server.
app_url string
"http://localhost:3000"
Public URL where Tinyauth is served (required), e.g. https://tinyauth.example.com.
secret set me string
"changeme_changeme_changeme_12345"
Exactly 32-character secret used to sign session cookies. CHANGE THIS.
users string
"user:$2a$10$UdLYoJ5lgPsC0RKqYH/jMua7zIn0g9kPqWmhYayJYLaZQ/FTmH2/u"
Login users as username:bcrypthash (comma-separate multiple). Default is user:password — CHANGE THIS. Generate with `tinyauth user create`.
constraints list
[]
Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
resources object
{
    cpu    = 200
    memory = 128
  }
The task resources.
Readme

tinyauth

Tinyauth is the simplest way to add authentication to any application. It runs as a lightweight forward-auth middleware behind your reverse proxy (Traefik, Caddy, Nginx, Traefik Kubernetes…): unauthenticated requests get a clean login screen, and once signed in the request is passed through. It supports simple username/password, OAuth (Google, GitHub, generic OIDC), LDAP and TOTP.

This pack runs Tinyauth as a single host-networked Nomad service.

Deploy

nomad-pack run tinyauth --registry=nomploy \
  --var app_url=https://auth.example.com \
  --var secret=$(openssl rand -hex 16) \
  --var users="admin:$(htpasswd -bnBC 10 '' 'yourpassword' | tr -d ':\n' | sed 's/^/admin:/')"

Then point your proxy's forward-auth at http://<node-ip>:3000/api/auth/traefik (or the Nginx/Caddy equivalent) for the apps you want to protect.

Configuration

Variable Default Description
image ghcr.io/tinyauthapp/tinyauth:v5 Container image (pin a tag in production).
port 3000 Host port for the Tinyauth server.
app_url http://localhost:3000 Public URL Tinyauth is served from.
secret placeholder (32 chars) Session-signing secret (exactly 32 chars).
users user:<bcrypt> (password password) Login users as username:bcrypthash — change this.
resources 200 MHz / 128 MB CPU and memory for the task.

Security: secret must be exactly 32 characters and the default user must be replaced. Generate a user with docker run ghcr.io/tinyauthapp/tinyauth:v5 user create (bcrypt), and set OAuth/LDAP via the additional TINYAUTH_* env vars from the docs.