Skip to main content

Create a Remote Access Control (RAC) provider

For an overview of Remote Access Control (RAC), see the RAC provider documentation.

You can also watch our video on YouTube for setting up RAC:

Workflow to create an RAC provider​

Follow this workflow to create and configure an RAC provider:

  1. Create a RAC provider and application pair.
  2. Create RAC property mappings (that define the access credentials to each remote machine).
  3. Add the devices you want to connect to, either by enrolling them or by adding them manually.
  4. Create an RAC outpost to service the provider.

Depending on whether you are connecting using RDP, SSH, or VNC, the exact configuration choices will differ, but the overall workflow applies to all RAC connections.

Create a RAC provider and application pair​

To create a provider along with the corresponding application that uses it for authentication, navigate to Applications > Applications and click New Application. We recommend this combined approach for most common use cases. Alternatively, you can use the legacy method to create only the provider by navigating to Applications > Providers and clicking New Provider.

  1. Log in to authentik as an administrator, and open the authentik Admin interface.

  2. Navigate to Applications > Applications and click New Application to open the application wizard.

  3. On the New application page, define the application details, and then click Next.

  4. Select the RAC provider type, and then click Next.

  5. On the Configure Remote Access Provider page, provide the configuration settings:

    • Connection expiry: set how long a connection authorization remains valid. The default is hours=8. Reconnecting does not reset this limit, and the connection also ends if the user's authentik session expires or the user logs out.
    • Delete authorization on disconnect: leave disabled, the default, to allow the browser to reuse a valid authorization when reconnecting after a disconnect. Enable it to require a new authorization after every disconnect, including temporary network failures. authentik deletes the stored authorization during connection setup, so it is already unavailable for reconnecting when the connection ends. This setting does not control the remote operating system's login session. See Connection management for details about authorization reuse and expiry.
    • Device access group (optional): limit this provider to the devices in a single device access group. When left empty, every device that a user has access to can be reached through this provider.
    • Maximum concurrent connections: select a value or use -1 to disable the limitation.
  6. Click Submit to create both the application and the provider.

Create RAC property mappings​

Next, you need to add property mappings for each remote machine you want to access. RAC property mappings can be used to pass the access credentials and connection settings of the remote machine.

Refer to the RAC Credentials Prompt and RAC SSH Public Key Authentication documentation for alternative methods of handling RAC authentication.

  1. Log in to authentik as an administrator and open the authentik Admin interface.

  2. Navigate to Customization > Property Mappings, and click New Property Mapping.

  3. Select RAC Provider Property Mapping as the property mapping type, and then click Next.

  4. On the New RAC Provider Property Mapping page, provide the following configuration settings:

    • Name: provide a name for the property mapping
    • Under General settings:
      • Username: the username for the remote machine
      • Password: the password for the remote machine
    • Under Advanced settings:
      • Expression (optional): define other connection settings to be used, such as an SSH key. For more information, refer to the Connection settings documentation.
  5. Click Finish.

Add the devices to connect to​

RAC connects to the devices in your authentik instance. A device that is already enrolled through a connector, such as the authentik agent, can be used as-is: authentik connects to it on the address it reports.

For a remote machine that is not enrolled, such as a server, add it with a connection override:

  1. Log in to authentik as an administrator and open the authentik Admin interface.

  2. Navigate to Applications > Providers.

  3. Click the name of the RAC provider that you previously created.

  4. On the Provider page, under Devices, click New Device, and provide the following settings:

    • Device Name: define a name for the device.
    • Host: enter the host name or IP address of the remote machine, optionally including the port.
    • Protocol: select the protocol to connect to this device with.

    Devices that are enrolled through the authentik agent need no override: the protocols they accept are taken from the facts they report.

  5. Click Create.

The same form is used to give a device that is enrolled a connection override, for example when it must be reached on a jump host address rather than the one it reports.

info

Connection credentials belong in a RAC property mapping or the credentials prompt, not in a connection override.

Create an RAC outpost​

The RAC provider requires the deployment of an RAC Outpost.

  1. Log in to authentik as an administrator and open the authentik Admin interface.

  2. Navigate to Applications > Outposts.

  3. Click Create and set the following values:

    • Name: define a name for the outpost.
    • Type: RAC
    • Integration: select either Docker or Kubernetes, or optionally manually deploy the outpost.
    • Applications: select the RAC application that you previously created.
    • Advanced settings (optional): for further optional configuration settings, refer to RAC Configuration.
  4. Click Create to save your new outpost.

Access the remote machine​

To verify your configuration and access the remote machine, go to the User interface of your authentik instance. On the Application Dashboard page, click the Remote Access application to start a secure session on the remote machine in your web browser.

If multiple devices are available, click the device that you want to access.