Skip to main content

Authentik Role

Deploy the Authentik identity provider (server, worker, PostgreSQL, and Redis) as a Podman quadlet.


Variables​

VariableTypeOptionsDefaultDescription
podman_userstring---{{ ansible_user }}system user for rootless podman operations
authentik_proxy_enabledbooltrue, falsefalseenable HTTP proxy for image pulls
authentik_proxy_httpstring---""HTTP proxy URL
authentik_proxy_httpsstring---""HTTPS proxy URL
authentik_proxy_no_proxystring---""comma-separated list of proxy exclusions
authentik_proxy_envlist of string---[]generated proxy environment entries
authentik_network_enabledbooltrue, falsetruecreate and manage the podman network
authentik_network_driverstring---bridgepodman network driver
authentik_network_namestring---authentik-internalpodman network name
authentik_bind_ipstring---127.0.0.1host IP to bind exposed ports to
authentik_port_map_enabledbooltrue, falsetrueexpose container ports on the host
authentik_port_maplist of string---["9000:9000","9443:9443"]host:container port mappings
valkey_versionstring---9.1.1-alpineValkey (Redis) container image version
postgresql_versionstring---18.6-alpinePostgreSQL container image version
authentik_versionstring---2026.8.0Authentik container image version
authentik_cache_autoupdatebooltrue, falsetrueenable auto-update for the Valkey container
authentik_postgresql_autoupdatebooltrue, falsetrueenable auto-update for the PostgreSQL container
authentik_server_autoupdatebooltrue, falsetrueenable auto-update for the Authentik server container
authentik_worker_autoupdatebooltrue, falsetrueenable auto-update for the Authentik worker container
authentik_secret_keystring---""application secret key (openssl rand -base64 60)
authentik_db_passwordstring---""PostgreSQL password for the Authentik database
authentik_domainstring---""external domain for the Authentik instance
authentik_base_environment_varsdict---{}base environment variables shared by Authentik containers
authentik_server_environment_varsdict---{}extra environment variables for the server container
authentik_worker_environment_varsdict---{}extra environment variables for the worker container
authentik_postgresql_environment_varsdict---{}extra environment variables for the PostgreSQL container
authentik_cache_environment_varsdict---{}extra environment variables for the Valkey container
authentik_extra_fileslist of dict---[]arbitrary file entries with src (controller path) or source (target path), dest, optional mount, mode, and template
authentik_extra_dirslist of dict---[]arbitrary directory entries with src (controller directory) or source (target path), dest, optional mount and mode
authentik_entrypointstring---""optional Authentik server container entrypoint override
authentik_worker_entrypointstring---""optional Authentik worker container entrypoint override
authentik_cache_entrypointstring---""optional Authentik cache container entrypoint override
authentik_postgresql_entrypointstring---""optional Authentik PostgreSQL container entrypoint override