Skip to content

Configuration

Cratis AuthProxy is configured entirely through the Cratis:AuthProxy section of appsettings.json (or equivalent environment variables using the Cratis__AuthProxy__ prefix).

{
"Cratis": {
"AuthProxy": {
"Authentication": { ... },
"Authorization": { ... },
"Admission": { ... },
"TenantResolutions": [ ... ],
"TenantVerification": { ... },
"Tenants": { ... },
"Services": { ... },
"Ingress": { ... },
"Invite": { ... },
"Management": { ... },
"PagesPath": "",
"DataProtectionKeysPath": ""
}
}
}
TopicDescription
AuthenticationOIDC providers, OAuth 2.0 providers such as GitHub, and JWT Bearer configuration.
AuthorizationRequiring a claim — a role, a group, a GitHub organization or team — before any request is forwarded.
AdmissionAnswering nothing at all until a caller presents a capability your own verifier admits, for a deployment whose existence is not meant to be discoverable.
TenancyHow the auth proxy resolves the current tenant from each request, and how to verify tenant existence.
Tenant Selection PageHow selection-based tenant resolution works and how to build/override select-tenant.html.
Trusted ProxiesWhich callers may speak for the client through X-Forwarded-For and X-Forwarded-Proto, and how many hops to follow.
ServicesRouting requests to backend and frontend services.
Management ListenerAn opt-in private listener carrying liveness and readiness endpoints, so a probe tests more than “a process accepted a socket”.
LobbyInvite and registration flows that hand users off to the lobby experience.
Well-Known PagesBuilt-in HTML pages (provider selection, errors, tenant not found) and how to override them via a mounted volume.