Next steps
You now have a portal that authenticates users and a policy that admits one user while rejecting another. Choose the next task based on your application.
Connect your identity source
- Use an external provider: start with OAuth and OIDC, then select the provider guide in Identity providers.
- Use a directory: review LDAP and its user search settings.
- Keep local users: learn about the local identity store and password management.
Keep the provider's callback URL, the portal mount path, and the policy's login URL consistent. When changing the identity source, verify the claims and roles it produces before relying on the existing app policy.
Shape login and access
- Add multi-factor authentication and understand authentication challenges.
- Map identities into application roles with user transforms.
- Refine access with role-based rules and path rules.
- Pass selected identity information to an upstream application using headers.
Repeat both the allowed-user and denied-user checks after changing the rules. An upstream application that trusts identity headers must only accept them from the trusted proxy; users must not be able to bypass that proxy or supply trusted headers themselves.
Prepare a deployment
The learning Caddyfile is deliberately local. Before turning it into a service, make these deployment choices:
| Area | What must change |
|---|---|
| HTTPS and addresses | Use your real HTTPS hostnames and matching login/callback URLs. Remove cookie insecure enabled. Revisit the loopback binding and cookie scope for your topology. |
| Users | Remove the public demo accounts and passwords. Review every account and role in the store, including any bootstrap administrator. |
| Signing keys | Supply protected, durable key material. The shell-generated demo secret is temporary; changing it prevents existing tokens from verifying against the new key. |
| Storage | Give the service durable, access-controlled storage and a backup plan. Relative paths resolve from its working directory. Keeping a user database is distinct from preserving sessions across restarts. |
| Application | Replace the demo response with your application handler, such as reverse_proxy, after the authorization handler in the matched route. |
| Operations | Choose a service manager, logging, updates, and an explicit administration/reload strategy. The tutorial disables Caddy's admin endpoint. |
Use Caddy's reverse proxy reference for upstream configuration and its running guide for service operation. Keep the authorization check ahead of the app handler and test the full set of application paths you intend to protect.
For a specific task, continue with the topic directory. For configuration details, use the reference.