Uptime Kuma Uptime Kuma

[SSO] Monitoring tool

Uptime Kuma is an easy-to-use self-hosted monitoring tool.

TODO Possible improvement:
AutoKuma is a utility that automates the creation of Uptime Kuma monitors based on Docker container labels - GitHub - BigBoot/AutoKuma: AutoKuma is a utility that automates the creation of Uptime Kuma monitors based on Docker container labels. With AutoKuma, you can eliminate the need for manual monitor creation in the Uptime Kuma UI.

Links:

Authentik ForwardAuth

Uptime Kuma has no native OIDC configuration. Traefik protects its browser UI with Authentik ForwardAuth for the monitoring group. Do not publish its UI port outside the proxy network.

Setup

Create the Authentik application and provider, then deploy the service:

scripts/authentik-apps.py --application uptime-kuma --apply
scripts/labctl.py service recreate monitoring/uptime-kuma

The service label must use localaccess-authentik@file; the shared Traefik configuration routes /outpost.goauthentik.io/ for the application hostname.

Verify

Confirm a monitoring member reaches the UI and live updates work. Confirm a non-member is denied, group removal is applied after the proxy session refresh, logout returns to the intended login flow, and no direct UI path exists.

name: uptime-kuma
services:
  uptime-kuma:
    image: louislam/uptime-kuma:2.5.5
    container_name: uptime-kuma
    restart: unless-stopped
    volumes:
      - ${DOCKER_VOLUMES}/uptime-kuma:/app/data
    networks:
      - proxy
    labels:
      traefik.enable: true
      traefik.http.routers.uptime-kuma.middlewares: localaccess-authentik@file
      traefik.http.services.uptime-kuma.loadbalancer.server.port: 3001
      homepage.group: Monitoring
      homepage.name: Uptime Kuma
      homepage.icon: uptime-kuma.png
      homepage.href: https://uptime-kuma.${MYDOMAIN}/
      homepage.description: "[SSO] Monitoring tool"

networks:
  proxy:
    external: true