Files
sso-manager-node/docs/index.md
T
wmantly 3d3b15b283 README: rewrite with feature overview, comparison, and tiered quick start (#40)
* README: rewrite with feature overview, comparison, and tiered quick start

Expands the README with a fuller feature description, a "why this over
the alternatives" comparison against Keycloak/Authentik/Authelia/Zitadel,
an architecture diagram, and a three-tier quick start (unified theta-env
stack, standalone Docker, bare metal) instead of the old OpenLDAP-setup-
first structure.

* docs/index.md: fix stale setup.env quickstart snippet (.env -> setup.env, CFG_DOMAIN)
2026-07-14 00:24:40 -04:00

3.6 KiB

layout, title
layout title
default Home

SSO Manager

A self-hosted OpenID Connect provider with a bundled OpenLDAP directory and a web management UI — for home labs and small businesses that want their own identity provider instead of a hosted one.

Features

  • OpenID Connect / OAuth 2.0 provider — issue your own access/refresh/id tokens; protect your apps with OIDC login.
  • OpenLDAP directory — users, groups, POSIX accounts (posixAccount/ inetOrgPerson), SSH public keys, and sudo roles, with memberOf + referential-integrity overlays.
  • Web management UI — manage users, groups, and OAuth clients from a browser; invite/password-reset flows over email.
  • LDAPS for legacy apps — apps that bind LDAP directly (Gitea, Emby, …) can use LDAPS (636) / StartTLS.
  • All-in-one Docker image — app + OpenLDAP + Redis in one container, or run each piece separately via app_* env config.

Quick Start

Docker (all-in-one)

git clone https://github.com/theta42/sso-manager-node.git
cd sso-manager-node
cp secrets.js.example nodejs/conf/secrets.js   # edit it, or use app_* env
docker compose up -d --build

The web UI comes up at http://localhost:3001. See the Deployment Guide for the full set of app_* env vars.

Bare metal (Debian/Ubuntu)

sudo ./install.sh

Idempotent installer — installs Node.js, OpenLDAP, Redis, configures the app, and starts a systemd unit. Re-run to update.

Run it together with the proxy

The proxy (theta42/proxy) fronts this SSO under TLS and protects it with OIDC, while also binding LDAP directly. Run both with one command via theta-env:

git clone --recursive https://github.com/theta42/theta-env.git
cd theta-env && cp setup.env.example setup.env   # set CFG_DOMAIN to your domain, then:
./setup.sh

Documentation

  • Deployment Guide — Docker + bare metal, the config layers, the app_* env reference, backups.
  • Configuration — every app_* env var and the conf merge order.
  • OAuth / OIDC — the provider: discovery, client management, token lifetimes, scopes.
  • LDAP — directory layout, TLS, overlays, schema, direct-bind service accounts.

Architecture

┌─────────────┐
│  Browser /  │
│  OIDC apps  │
└──────┬──────┘
       │ HTTP/HTTPS
       ▼
┌────────────────────────┐      ┌─────────────┐
│  Express SSO Manager   │◄────►│   Redis     │
│  - OIDC provider       │      │ - sessions  │
│  - web UI (:3001)      │      │ - models    │
│  - management API      │      └─────────────┘
└────────┬───────────────┘
         │ ldapi/ldap (localhost)
         ▼
┌────────────────────────┐
│  OpenLDAP (slapd)      │
│  - users / groups      │
│  - LDAPS :636          │─── legacy apps bind directly
│  - StartTLS :389       │
└────────────────────────┘

Community

License

MIT License — see the repository for details.