Remove Keycloak; standardize on Authelia for SSO

Keycloak never reliably ran (fiddly reverse-proxy/hostname config) and the
repo has standardized on Authelia for SSO + 2FA. This rips Keycloak out
entirely:

- Delete the install block, whiptail menu entry, uninstall plumbing, and
  EXISTING_SERVICES detection from both 24.04 and 26.04 scripts
- Delete docker-compose-keycloak.yml, fix-keycloak-proxy.sh, and
  KEYCLOAK-SETUP-GUIDE.md
- Remove the Keycloak block from caddy-setup-helper.sh
- Update docs (CADDY-FAIL2BAN-SETUP.md, SECURITY-IMPROVEMENTS.md,
  NEW-SCRIPT-STRUCTURE.md, SCRIPT-FLOW-INTRO.txt) to reference Authelia

Also documents the fail2ban/Authelia overlap: Authelia handles failed-login
regulation (per-account lockout); the Caddy fail2ban jail is complementary
firewall-level IP banning. Neither does geo-blocking — noted CrowdSec / Caddy
GeoIP as the path for that.

https://claude.ai/code/session_017eA2qqq9jfF2tNtpUYL8vK
This commit is contained in:
Claude
2026-06-03 03:44:26 +00:00
parent c54cd9ecc6
commit f564b4b6d8
10 changed files with 45 additions and 2473 deletions
+1 -1
View File
@@ -31,7 +31,7 @@ This script is divided into TWO main phases:
│ • Skip services you don't want │
│ │
│ Services include: │
│ • Self-hosted apps (ActualBudget, Keycloak, Jellyfin, etc.) │
│ • Self-hosted apps (ActualBudget, Authelia, Jellyfin, etc.) │
│ • Network services (Samba, VPNs, fail2ban) │
│ • Monitoring tools (Uptime Kuma, Portainer, Watchtower) │
│ • And many more... │