Troubleshooting¶
| Symptom | Cause and fix |
|---|---|
| "Permission denied … Policy binding returned result False" in Authentik | Your Authentik user is not in any group allowed for the app. Add the user to one of the groups (Authentik → Directory → Groups → Users), or change the app's groups. |
| "No permission"/"token is required" right after deploy | The browser still has an old session: sign out of Authentik or open a private window. |
| The browser refuses the site (HSTS error) right after a delete and re-create | The browser reached the domain while it had no certificate yet. Close the tab, restart the browser or "Forget about this site". |
| Deploy rolled back at "HTTPS certificate" | DNS not propagated, port 80 blocked, or Let's Encrypt rate limit (5 certificates per exact name per week). Re-use the name later or another name; Deployer reuses an existing certificate. |
| Deploy rolled back at "Starting containers" | The app did not become healthy: the run log shows the last container logs. Fix the image, port, variables or memory limit. |
| "another operation is running: wait for it to finish" (409) | One server-changing run at a time; wait for it to end. |
| The app shows its own login although "Same account as Authentik" is chosen | The compose file was edited in advanced mode (the settings are listed to add by hand), the app was created before its recipe existed (use Use it), or the app's setting must be done once in its admin page (the steps are on the app page). |
| OIDC: redirect URI error | The provider accepts any path of the app's domain; check that the app builds its callback with https:// (it must trust X-Forwarded-Proto). |
| OIDC callback ends in "missing state" | The callback hit the forward-auth bounce. Happens with apps whose service worker fetches without the session; use a recipe with ownDoor (as for Actual). |
| SAML: the app never receives the assertion | The ACS URL must be on the app's own domain so its path is exempted from forward auth; check the ACS URL in Account in the app. |
| Auto-login: "no login form found" | The login page is not at a usual address (/login, /signin, /auth/login…) or the app logs in with JavaScript only: it needs an adapter (a recipe with login). Keep the app's own login meanwhile. |
| Auto-login: "the app showed its login form again" | Wrong username/password, or the form needs more (captcha, two-factor). |
| Authentik answers 500 "too many clients" | Authentik's PostgreSQL reached max_connections. Restart the Authentik server container; raise max_connections if it repeats. |
| The editor says "edited by hand" | The file on disk differs from what Deployer would write; the advanced editor shows it as it is. Switch back to simple mode only after removing the hand-written settings. |
| A delete left objects behind | When a service was unreachable (DNS API, Authentik), the run says what it could not remove; remove dp-<name>* in Authentik or the record in the DNS zone by hand. |
Logs: the run log on the app page first, then journalctl -u deployer, docker compose logs in the stack folder,
/var/log/nginx/error.log, and Authentik's server logs for sign-in problems.