main
Pocket ID
Self-hosted OIDC identity provider using passkeys for authentication.
Deployment layout
- Compose:
/srv/docker/pocketid/docker-compose.yml - Static configuration/source: none
- Non-secret environment: application URL, trusted-proxy policy, UID, GID, and the encryption-key file location
are declared inline in Compose; there is no project-local
.env - Secrets:
/srv/docker/secrets/pocketid/encryption_key - NVMe application state:
/srv/appdata/pocketid/data - Bulk HDD data: none
- Other mounts: none
Secrets are never committed to this repository. The central encryption key is
supplied to the Pocket ID service as the pocketid_encryption_key Docker secret
and referenced through ENCRYPTION_KEY_FILE.
Dependencies and recovery
- Networks/dependencies: Pocket ID uses the external
npm_proxynetwork at192.168.100.10; no dependent services are declared - Back up:
/srv/appdata/pocketid/dataand the separately protected/srv/docker/secrets/pocketid/ encryption_key - Re-creatable: the Pocket ID container itself; no persistent cache is declared
Description
Self-hosted OIDC identity provider using passkeys for authentication.
https://pocket-id.org
27 KiB