How to Setup Authelia in Docker with SWAG Reverse Proxy (2026)

submitted by Nerd Veteran

https://corelab.tech/authelia-mfa-swag-setup/

SbTEwwlrjN5y7jq.webp

How Authelia Performs Multi-Factor Authentication

Authelia sits between your reverse proxy and the apps behind it, intercepting requests and performing auth checks before forwarding traffic, giving you true MFA that can be integrated with something like Google Authenticator, or Yubikey/Titan key, etc…

Stop exposing unsecured apps. Learn how to deploy Authelia in Docker with a KeyDB backend and SWAG to enforce centralized Multi-Factor Authentication.

Setting up Authelia can be a bit intensive at first, but very worth the payoff / time and effort!

Disclaimers: I’m the author & run this exact setup, in production for myself. It’s a “battle tested” setup, which has been in use for a few years now. Written & verified by a human! The header image is a composite of my Authelia MFA token page & AI generated infographic. NO ADS or affiliate marketing on page!

Happy to chat in the comments!

13
53

Log in to comment

13 Comments

Very nice site set up man. Looks like a lot of good info and a lot of work involved. I too use Authelia as an added security step. I have your site bookmarked and will peruse it’s contents in a bit. Thanks for sharing.

by Nerd Veteran OP depth: 2

Thank you for taking a peek!

Let me know if there’s something you’re looking for. The search function isn’t to bad but sometimes the posts can get buried a bit ;)

You bet. So far, it’s an enjoyable read.




Oh, you’re actually that corelab. I use your Vaulwarden guide as reference when I rebuild a while ago. Thanks for the write up !

Though, I wish you have something for Traefik and I know you wrote about why you chose SWAG but mine’s all docker anyway that’s why I go with Traefik.

There’s not many articles talking about TF with multiple host without going full Kubernetes. Looking up forward auth (for something without native OIDC) is confusing af.

Well hello there!

Yes, the one and only Core Lab Joe, in the digital flesh (packets, tcp-stream!). Thanks for reading and I’m glad it helped you!

I’m picky when writing tech guides and generally will only write (and recommend!) what I run, and what I have experience with, so that would not be traefik.

My entire system/setup is all dockerized as well. I run 50+ dockers, and anything publicly exposed goes through my SWAG instance. It doesn’t matter what reverse proxy you use, or even if the apps are containers or not really, it’s all networking.

That said I’ve got a good Traefik resource for you, FoxxMD Blog and his migrating from SWAG to Traefik post!

One of the things I need to tackle fully myself, understand, break, troubleshoot and then fix is OIDC for myself, so I can write a good guide on it. A lot of apps do natively do it now, but from what I understand for those that do not, you can use Authelia and the like to slap that authentication into (over top) of it.



Honestly, the one major thing I want from Authelia is the ability to add to it without deauthenticating the entire userbase.

Well, that and an easier way to organize than everything in one single file…


Is rayfish compatible with Authelia or Yggdrasil?

by Nerd Veteran OP depth: 2

Never heard of Rayfish but just googled, it’s a mesh VPN so probably wouldn’t want to push that through a reverse proxy to authelia, it would just slow it down….

I personally use wireguard as my VPN, not tailscale or headscale or any of that but I do understand some people need something that can get around CGNAT or other issues.



SWAG. SWAG. SWAG.

Apparently it is just a customized nginx set up.

by Nerd Veteran OP depth: 2

If you knew what was under the hood you would not say it’s “just” customized nginx… It’s more like customised, optimized and simplified.

It has many enhancements builtin like automatic certificate generation and renewal, fail2ban, prebuilt optimized configs, and easily enhanced security with crowdsec and even geofencing.

But made way easier than doing that separately with raw NGINX.

It’s much more friendly to pickup and run with then raw NGINX.



Deleted by moderator

 reply
0

Your link is broken and currently displays a Claude Code announcement. Are you even real?


by Nerd Veteran OP depth: 2

No I had no issues flipping it over to keydb. I was on redis originally so I stopped the containers, took a backup and simply changed the image I was using for my backend to keydb end it was like a drop in replacement! Didn’t even need to do a dB upgrade or anything complex.


Just run authentik and postgres. No additional miffleware needed.



ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86

Insert image