Skip to main content
Version: 0.5.6

Authentik on Aruba Cloud

Deploy Authentik — a modern, open-source identity provider supporting SSO, OIDC, OAuth2, SAML, LDAP, and SCIM — on Aruba Cloud using Terraform and cloud-init. Deployed via Docker Compose with PostgreSQL and Redis.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

Authentik is a lighter-weight alternative to Keycloak, providing a polished admin UI and flexible authentication flows. This example deploys:

  • Authentik server and worker via the official Docker image
  • PostgreSQL 16 for persistent storage
  • Redis for caching and task queuing
  • Web UI on HTTP port 9000 and HTTPS port 9443 (self-signed cert)
  • Setup wizard on first access

Keycloak comparison: See the Keycloak example for an alternative identity provider. Authentik excels at lightweight deployments and has a more modern UI; Keycloak is better for enterprise-grade federation and standards compliance.


Architecture Overview​


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectauth-prodProject container
arubacloud_vpcauth-prod-vpcVirtual Private Cloud
arubacloud_subnetauth-prod-subnetBasic subnet
arubacloud_securitygroupauth-prod-vm-sgSecurity group
arubacloud_securityruleauth-prod-vm-sshSSH ingress
arubacloud_securityruleauth-prod-vm-httpAuthentik HTTP port 9000
arubacloud_securityruleauth-prod-vm-httpsAuthentik HTTPS port 9443
arubacloud_elasticipauth-prod-vm-eipVM public IP
arubacloud_blockstorageauth-prod-boot20 GB boot disk (Performance)
arubacloud_keypairauth-prod-keypairSSH public key
arubacloud_cloudserverauth-prod-vmCloudServer VM

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO2A4 — 2 vCPU / 4 GB~€20
Boot disk20 GB Performance~€3
Elastic IP—~€3
Total~€26/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 1.0
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content
pg_passwordPostgreSQL password (min 12 characters)
authentik_secret_keyAuthentik signing secret (min 32 chars — use openssl rand -hex 32)

Optional​

VariableDefaultDescription
app_name"auth"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO2A4"CloudServer flavor
vm_disk_size_gb20Boot disk size in GB
ssh_cidr"0.0.0.0/0"CIDR for SSH
authentik_version"latest"Authentik Docker image tag

Outputs​

OutputDescription
authentik_urlAuthentik web UI URL (HTTP)
authentik_url_httpsAuthentik web UI URL (HTTPS)
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/authentik

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

Generate a strong secret key:

openssl rand -hex 32

3. Deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 3–5 minutes.

4. Initial setup​

Navigate to http://<IP>:9000/if/flow/initial-setup/ and create the admin account.


References​