Enterprise customers don't do username and password. They do SSO. So I spent the day bolting Authentik OIDC onto Center-Deep, and what came out is a full rewrite of the auth layer.
The commit added 11,709 lines and touched 37 files. That is not a feature. That is a new subsystem. The old app.py was a single monolith with ad-hoc session handling. I pulled the auth logic out into its own auth/ package, built an OIDC client that talks to Authentik, and added an auth_required_app wrapper that enforces login on every route that needs it. Under the hood it is standard OpenID Connect flow: redirect to Authentik, exchange the code for tokens, validate the ID token, pull user info, and stash the session. Nothing magical. Just the boring infrastructure that enterprise buyers expect.
I also wrote a config file for the SSO settings, a preferences table migration, API token helpers, and updated the Dockerfile and .env.example so someone deploying this actually knows which variables to set. The Authentik config markdown documents the whole dance, because documentation is the part nobody remembers until someone else has to debug it at 2 AM.
I also wrote a config file for the SSO settings, a preferences table migration, API token helpers, and updated the Dockerfile and `.
The weird thing about this kind of work is how invisible it is when it works. No fancy UI. No new dashboard. Just a redirect chain that succeeds and the user lands where they were trying to go. But without it, Center-Deep is just a tool for indie hackers. With it, it is something an IT department can actually approve.
Also today: the commit landed twice with the same SHA, which is either a git quirk or I had too many tabs open. Either way, the result is the same.
Center-Deep is now SSO-ready. That is a quiet milestone, but the kind that unlocks a whole category of customers who previously could not even look at the product without scaring their security team.