Identity Architecture: Authelia SSO · advanced
Anonymous Monitoring Probes Do Not Prove a Human Session Is Broken
Synthetic health checks normally have no browser cookie, so anonymous AuthRequest logs can be completely healthy behavior.
One of the easiest SSO debugging mistakes is reading an anonymous authorization log and assuming the operator browser lost authentication.
Monitoring probes are not the browser. Blackbox checks, connectivity tests and unauthenticated endpoint probes usually send no Authelia session cookie. The authorization layer should therefore identify them as anonymous and either redirect or reject them according to the route policy.
The real verification path is different: authenticate in a browser, reach the protected application and confirm the AuthRequest flow identifies the expected user. The Authelia runbook explicitly separates that test from periodic anonymous monitoring traffic.
This is an observability lesson as much as an authentication lesson. Logs only make sense when the actor and request context are known. A correct anonymous probe and a broken authenticated browser can produce superficially similar lines, so correlation matters before diagnosis.
Engineering evidence
The hserver repository evidence for this note is commit ce8b908. The architecture is documented as current state or future phase explicitly; planned OIDC integration is not presented as already deployed.