Identity Architecture: Authelia SSO · advanced

Anonymous Monitoring Probes Do Not Prove a Human Session Is Broken

Synthetic health checks normally have no browser cookie, so anonymous AuthRequest logs can be completely healthy behavior.

Current. Current production engineering note based on the hserver authentication and secret-control-plane architecture.

One of the easiest SSO debugging mistakes is reading an anonymous authorization log and assuming the operator browser lost authentication.

Monitoring probes are not the browser. Blackbox checks, connectivity tests and unauthenticated endpoint probes usually send no Authelia session cookie. The authorization layer should therefore identify them as anonymous and either redirect or reject them according to the route policy.

The real verification path is different: authenticate in a browser, reach the protected application and confirm the AuthRequest flow identifies the expected user. The Authelia runbook explicitly separates that test from periodic anonymous monitoring traffic.

This is an observability lesson as much as an authentication lesson. Logs only make sense when the actor and request context are known. A correct anonymous probe and a broken authenticated browser can produce superficially similar lines, so correlation matters before diagnosis.

Engineering evidence

The hserver repository evidence for this note is commit ce8b908. The architecture is documented as current state or future phase explicitly; planned OIDC integration is not presented as already deployed.

Quick navigationEsc