Ad Widget

Collapse

Zabbix Authentication with Authelia + Traefik

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • crepearms
    Junior Member
    • May 2025
    • 2

    #1

    Zabbix Authentication with Authelia + Traefik




    Hey, I've been trying to configure Zabbix for two days to authenticate with Authelia.
    I want to use HTTP authentication with Traefik in between.
    I've configured Zabbix to accept HTTP authentication. My Traefik forwards correctly to Authelia, and Authelia accepts credentials, but Zabbix displays this error.

    However, the same username is also created in the Zabbix database. The configurations are consistent, and the "Remote-USer" header is being sent correctly.

    Has anyone already configured Zabbix with Authelia, or knows a way to solve this?

    Thanks
    Click image for larger version

Name:	image.png
Views:	264
Size:	57.5 KB
ID:	502707​
  • jancwe
    Junior Member
    • Sep 2026
    • 1

    #2
    Hey, I guess you found a solution by now, but in case this is helpful for someone:

    My setup is authelia configured as auth backend for traefik and zabbix custom configured via docker compose and ldap configured for user provisioning in authelia and zabbix. For zabbix web I use the zabbix/zabbix-web-nginx-pgsql container.

    The "issue" is that authelia writes the http auth header variable REMOTE_USER correctly and nginx by default rewrites it to something like HTTP_REMOTE_USER, so we need to map that back to the REMOTE_USER variable so zabbix understands it.

    My solution was to use the containers /etc/nginx/fastcgi_params as a reference:

    Code:
      docker compose exec zabbix-web cat /etc/nginx/fastcgi_params > fastcgi_params
    append the following line to the fastcgi_param file

    Code:
      fastcgi_param REMOTE_USER $http_remote_user;
    and then edit the docker-compose.yml to add the bind mount to zabbix-web nginx:

    Code:
      zabbix-web: 
        volumes:
          - ./fastcgi_params:/etc/nginx/fastcgi_params:ro
    This might break something in the future if the fastcgi_params file changes upstream so just be aware to manually incorporate possible changes if that happens.

    Comment

    Working...