Anyone can read this page. Nothing behind it is private. janserv home
Tier 1 · Public
You are not logged in, and you were never asked to be.
That is the whole point of this page. It sits outside
in.thesuit.be, so the single-sign-on cookie is never sent here,
and Caddy serves it without the import authelia line that gates
everything in tier 2.
| Served by | janserv |
|---|---|
| Host requested | home.app.thesuit.be |
| Your address | 10.10.20.1 |
| Scheme at the edge | http |
| Identity headers | none — correct for tier 1 |
If Identity headers ever shows a Remote-User,
this page has been put behind forward-auth by mistake and is no longer tier 1.
Tier 1 is not a property of a machine. This exact service runs on both, with the same quadlet shape and the same Caddy block - only the host differs.
https://demo.app.thesuit.be suitvps
home.thesuit.be - by adding one DNS record and appending the
name to this site's address line in the Caddyfile. Nothing else changes: it is
already outside the Authelia cookie scope either way.
| Tier | Auth | Example |
|---|---|---|
| Tier 1 · Public | none, or crude in-app | this page, the DJ site, quiz apps |
| Tier 2 · IdP-gated | Authelia forward-auth | the dashboard, netstat |
| Tier 3 · Own login | the app's own accounts | AFFiNE, Home Assistant |
| Tier 4 · Never published | not published at all | Samba, Cockpit, the *arrs |
| Tier 5 · LAN-only name | LAN-only name, real cert | Jellyfin |