Tinyauth — a tiny authentication middleware that adds a login screen (and optional OAuth/LDAP) in front of any app behind your reverse proxy via forward-auth. Deployed as a single host-networked Nomad service.
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 8.3k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "tinyauth"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The Tinyauth container image. Pin a tag in production.
image = "ghcr.io/tinyauthapp/tinyauth:v5"
# Host port for the Tinyauth server.
port = 3000
# Public URL where Tinyauth is served (required), e.g. https://tinyauth.example.com.
app_url = "http://localhost:3000"
# Exactly 32-character secret used to sign session cookies. CHANGE THIS.
secret = "changeme_changeme_changeme_12345"
# Login users as username:bcrypthash (comma-separate multiple). Default is user:password — CHANGE THIS. Generate with `tinyauth user create`.
users = "user:$2a$10$UdLYoJ5lgPsC0RKqYH/jMua7zIn0g9kPqWmhYayJYLaZQ/FTmH2/u"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# The task resources.
resources = {
cpu = 200
memory = 128
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "tinyauth" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "ghcr.io/tinyauthapp/tinyauth:v5" | The Tinyauth container image. Pin a tag in production. |
| port | number | 3000 | Host port for the Tinyauth server. |
| app_url | string | "http://localhost:3000" | Public URL where Tinyauth is served (required), e.g. https://tinyauth.example.com. |
| secret set me | string | "changeme_changeme_changeme_12345" | Exactly 32-character secret used to sign session cookies. CHANGE THIS. |
| users | string | "user:$2a$10$UdLYoJ5lgPsC0RKqYH/jMua7zIn0g9kPqWmhYayJYLaZQ/FTmH2/u" | Login users as username:bcrypthash (comma-separate multiple). Default is user:password — CHANGE THIS. Generate with `tinyauth user create`. |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 200
memory = 128
} | The task resources. |
No variables match.
Tinyauth is the simplest way to add authentication to any application. It runs as a lightweight forward-auth middleware behind your reverse proxy (Traefik, Caddy, Nginx, Traefik Kubernetes…): unauthenticated requests get a clean login screen, and once signed in the request is passed through. It supports simple username/password, OAuth (Google, GitHub, generic OIDC), LDAP and TOTP.
This pack runs Tinyauth as a single host-networked Nomad service.
nomad-pack run tinyauth --registry=nomploy \
--var app_url=https://auth.example.com \
--var secret=$(openssl rand -hex 16) \
--var users="admin:$(htpasswd -bnBC 10 '' 'yourpassword' | tr -d ':\n' | sed 's/^/admin:/')"
Then point your proxy's forward-auth at http://<node-ip>:3000/api/auth/traefik
(or the Nginx/Caddy equivalent) for the apps you want to protect.
| Variable | Default | Description |
|---|---|---|
image |
ghcr.io/tinyauthapp/tinyauth:v5 |
Container image (pin a tag in production). |
port |
3000 |
Host port for the Tinyauth server. |
app_url |
http://localhost:3000 |
Public URL Tinyauth is served from. |
secret |
placeholder (32 chars) | Session-signing secret (exactly 32 chars). |
users |
user:<bcrypt> (password password) |
Login users as username:bcrypthash — change this. |
resources |
200 MHz / 128 MB | CPU and memory for the task. |
Security:
secretmust be exactly 32 characters and the default user must be replaced. Generate a user withdocker run ghcr.io/tinyauthapp/tinyauth:v5 user create(bcrypt), and set OAuth/LDAP via the additionalTINYAUTH_*env vars from the docs.