-
-
Notifications
You must be signed in to change notification settings - Fork 0
[Needs discussion] SSO / OIDC support #46
Copy link
Copy link
Open
Labels
area:authAuth, roles, RBACAuth, roles, RBACneeds-discussionArchitecture fork requiring a product decision before schedulingArchitecture fork requiring a product decision before scheduling
Milestone
Description
Metadata
Metadata
Assignees
Labels
area:authAuth, roles, RBACAuth, roles, RBACneeds-discussionArchitecture fork requiring a product decision before schedulingArchitecture fork requiring a product decision before scheduling
Projects
StatusShow more project fields
Todo
Why
Homelabbers commonly centralize auth through Authelia, Authentik, Keycloak, or Tailscale Auth rather than managing per-app passwords. But Hestia's current auth model (CLAUDE.md) is deliberately one system: a single household email/password account for remote login, with per-profile PINs gating restricted actions — not two parallel auth systems.
This needs a decision, not an implementation, first
Depends on
None.
Acceptance criteria