Skip to main content
Upstream source: Current installation guide. authentik needs PostgreSQL, a web server, and a background worker. Server and worker share the same application data volume. This minimal stack omits the upstream Docker socket mount, so Docker-managed outposts must be arranged separately.

Towbar manifest

.towbar/services/authentik.compose.yml

Compose project

deploy/authentik/compose.yml

Configure

  1. Prepare the example server, connect the repository, and map production to the branch containing these files. Replace the example server IP and domain.
  2. Commit every file shown below under deploy/authentik/. The Towbar manifest points to the Compose file; it does not create it for you.
  3. Sync the repository and inspect the resolved Compose project. Save the runtime values below if this example declares any.
  4. Use a server with at least two CPU cores and 2 GB of RAM, as required by the upstream Compose guide. Save PG_PASS and AUTHENTIK_SECRET_KEY before deploying.
  5. Back up PostgreSQL and the shared data/certificate volumes together. Without the Docker socket, deploy any future outposts manually.
  6. Deploy it manually and run the verification below before enabling auto-deploy.

Runtime values

Save these values on the Compose project after the repository sync. The manifest declares required keys, not their values.

Verify

Open /if/flow/initial-setup/ to set the first akadmin password, create a test application and provider, and confirm the worker is healthy after a redeploy. For field constraints, see Compose guide.
Last modified on September 27, 2026