Extend authentik + FreshRSS session lifetimes

Authentik's default-authentication-login stage ships with
session_duration: seconds=0, so the SSO session died with the browser.
New blueprint raises it to 30 days for every app on that flow.

FreshRSS runs OIDC through Apache mod_auth_openidc, whose defaults are a
5 minute inactivity timeout and a ~7.5 hour max duration in a non-persistent
cookie. Bumped to a 30 day sliding inactivity window (refreshed on every
request) with a 90 day hard cap, and made the cookie persistent so it
survives a browser restart.
This commit is contained in:
Ruben Hensen
2026-09-03 15:21:07 +02:00
parent ec5405fc29
commit 20cf119dbd
4 changed files with 69 additions and 0 deletions
+16
View File
@@ -11,6 +11,22 @@ Authentik is deployed as the central identity provider, providing OIDC and LDAP
- `blueprint-ldap.yaml` — LDAP provider (base DN: `DC=ldap,DC=goauthentik,DC=io`)
- `blueprint-mail-oidc.yaml` — OAuth2/OIDC provider for Stalwart mail
- `blueprint-vault-oidc.yaml` — OIDC provider for Vault
- `blueprint-argocd-oidc.yaml` — OIDC provider for ArgoCD
- `blueprint-freshrss-oidc.yaml` — OIDC provider for FreshRSS
- `blueprint-actualbudget-proxy.yaml` — Proxy provider for Actual Budget
- `blueprint-session-duration.yaml` — Session lifetime of the default authentication flow
## Session lifetime
Authentik ships the login stage of `default-authentication-flow` with
`session_duration: seconds=0`, i.e. the SSO session dies when the browser closes.
`blueprint-session-duration.yaml` raises this to 30 days for every app that uses
that flow (FreshRSS, ArgoCD, Vault, Actual Budget, mail).
The expiry is **absolute** — Authentik does not extend a session on activity. A
sliding window has to come from the application itself; FreshRSS does this via
`OIDC_SESSION_INACTIVITY_TIMEOUT` (see `freshrss/freshrss-deployment.yaml`), which
Apache mod_auth_openidc refreshes on every request.
## LDAP Outpost