Hacker Newsnew | past | comments | ask | show | jobs | submit | fheisler's commentslogin

Just for clarity: Cloudflare runs authentik for their workforce identity. (source/disclosure: am CEO)

Glad to see them making use of Hydra for OAuth apps!


Authentik Security | Security Engineer | US | REMOTE (anywhere) | Full-time

Authentik Security (https://goauthentik.io) is the company behind authentik (https://github.com/goauthentik/authentik), an open source identity provider with 1M+ unique installations. Help us replace Okta/Auth0, Ping Identity, and Microsoft Entra with modern, secure identity for all!

We are a small remote team, looking to scale up with experienced software engineers, primarily with a backend security focus. Bonus points if you have significant experience with identity/SSO standards and/or Django/Python.

To apply, please use: https://forms.gle/NYXH4E19LUohbpmJA


> open source, help us replace... (Big Tech)

> Apply via this google form...

;-)


Thanks for the mention! (Authentik Security CEO here.) We've become something of Okta migration experts at this point... Cloudflare moved to us a couple years back after they had to be the ones to let Okta know it'd been breached yet again. [1]

[1] https://blog.cloudflare.com/how-cloudflare-mitigated-yet-ano...


Cloudflare??? Damn. that is HUGE! Congratulations. You guys have a super solid product full of features and a decent founder. Maybe enterprises don't care about my favorite feature but it makes securing EVERYTHING a breeze. Embedded proxy! That is GOAT.


Not sure if this counts fully as 'distributed' here, but we (Authentik Security) help many companies self-host authentik multi-region or in (private cloud + on-prem) to allow for quick IAM failover and more reliability than IAMaaS.

There's also "identity orchestration" tools like Strata that let you use multiple IdPs in multiple clouds, but then your new weakest link is the orchestration platform.


Disclosure: I work for FusionAuth, a competitor of Authentik.

Curious. Is your solution active-active or active-passive? We've implemented multi-region active-passive CIAM/IAM in our hosted solution[0]. We've found that meets needs of many of our clients.

I'm only aware of one CIAM solution that seems to have active-active: Ory. And even then I think they shard the user data[1].

0: https://fusionauth.io/docs/get-started/run-in-the-cloud/disa...

1: https://www.ory.com/blog/global-identity-and-access-manageme... is the only doc I've found and it's a bit vague, tbh.


Hey Dan, appreciate the discussion!

Ory’s setup is indeed true multi-region active-active; not just sharded or active-passive failover. Each region runs a full stack capable of handling both read and write operations, with global data consistency and locality guarantees.

We’ll soon publish a case study with a customer that uses this setup that goes deeper into how Ory handles multi-region deployments in production (latency, data residency, and HA patterns). It’ll include some of the technical details missing from that earlier blog post you linked. Keep an eye out!

There are also some details mentioned here: https://www.ory.com/blog/personal-data-storage


Authentik Security | Senior Engineer | US | REMOTE (anywhere) | Full-time

Authentik Security (https://goauthentik.io) is the company behind authentik (https://github.com/goauthentik/authentik), an open source identity provider with 1M+ unique installations. Help us replace Okta/Auth0, Ping Identity, and Microsoft Entra with modern, secure identity for all!

We are a small remote team, looking to scale up with experienced software engineers, primarily with a backend focus. Bonus points if you have significant experience with identity/SSO standards and/or Django/Python.

There is also the opportunity to be "forward deployed" spending 20%+ of time with enterprise customers (remotely) on configuration best practices and rollout strategies, _if_ that is of interest to the right candidate.

To apply, please use: https://forms.gle/NYXH4E19LUohbpmJA


A PBC is just a for-profit company that has _some_ sort of specific mandate to benefit the "public good" - however it chooses to define that. It's generally meant to provide some balance toward societal good over the more common, strictly shareholder profit-maximizing alternative.

(IANAL but run a PBC that uses this charter[1] and have written about it here[2] as part of our biennial reporting process.)

[1] https://github.com/OpenCoreVentures/ocv-public-benefit-compa...

[2] https://goauthentik.io/blog/2024-09-25-our-biennial-pbc-repo...


This is exactly our thinking with authentik (open source IdP), and it's played out in practice so far. Enterprise sales conversations are so much easier when they start with "we all use you in our homelabs already." We're much more focused on giving those individual users a positive early experience (in hopes that some small percentage will really pay off down the road) than in extracting a few dollars from each of them.


I had this exact conversation with a Cloudflare rep a year or two ago, after I told her how I user their free DNS service. She said, "that free service was the best thing we ever did". And we wound up buying their bot management and DDOS services.


Love it! I think we'd get along - https://github.com/everythingishacked/CheekyKeys


Oh wow, I love this, thank you :)


Authentik Security | Engineer | US | REMOTE (anywhere) | Full-time

Authentik Security (https://goauthentik.io) is the company behind authentik (https://github.com/goauthentik/authentik), an open source identity provider with over 250k+ unique installations and 12M+ downloads. Help us replace Okta/Auth0, Ping Identity, and Microsoft Entra with modern, secure identity for all!

We are a small remote team, looking to scale up with a couple experienced software engineers, primarily with a backend focus. Bonus points if you have significant experience with identity/SSO standards and/or Django/Python.

There is also the opportunity to be "forward deployed" spending 15-20% of time with enterprise customers (remotely) on configuration best practices and rollout strategies, _if_ that is of interest to the right candidate.

To apply, please use: https://forms.gle/TjRuTCec8M6UaN2Q8


Hello, is there an email address to reach out to you?


Sure, you can reach out to 'hello' at our domain to send a message to the team!


I patched together a rough lookalike using quote data from https://gitlab.com/dwrodri/bash_irc_quotes and the archived pages. It's hosted on GitHub pages, using some simple JS since the entire database is 6MB.

All of the code and data, such as it is, is available at https://github.com/everythingishacked/newbash.org

Previous discussion: https://news.ycombinator.com/item?id=38950721


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: