Tier 1 — public demo

Anyone can read this page. Nothing behind it is private. janserv home

Tier 1 · Public

You are not logged in, and you were never asked to be. That is the whole point of this page. It sits outside in.thesuit.be, so the single-sign-on cookie is never sent here, and Caddy serves it without the import authelia line that gates everything in tier 2.

What the far end sees

Served byjanserv
Host requestedhome.app.thesuit.be
Your address10.10.20.1
Scheme at the edgehttp
Identity headersnone — correct for tier 1

If Identity headers ever shows a Remote-User, this page has been put behind forward-auth by mistake and is no longer tier 1.

The same page, on the other machine

Tier 1 is not a property of a machine. This exact service runs on both, with the same quadlet shape and the same Caddy block - only the host differs.

https://demo.app.thesuit.be  suitvps

Promotable to an apex name. A tier-1 app that outgrows the wildcard can take a short public name of its own - home.thesuit.be - by adding one DNS record and appending the name to this site's address line in the Caddyfile. Nothing else changes: it is already outside the Authelia cookie scope either way.

The five tiers

TierAuthExample
Tier 1 · Publicnone, or crude in-appthis page, the DJ site, quiz apps
Tier 2 · IdP-gatedAuthelia forward-auththe dashboard, netstat
Tier 3 · Own loginthe app's own accountsAFFiNE, Home Assistant
Tier 4 · Never publishednot published at allSamba, Cockpit, the *arrs
Tier 5 · LAN-only nameLAN-only name, real certJellyfin
The decision rule. If leaking an app's entire database to the internet would be merely embarrassing, it is tier 1. If it would be bad, it is tier 2, behind Authelia, no exceptions.