Examples

The examples in this repository are complete stacks that run Zen IdP side by side with real software, end to end, with a single command. Each folder carries its own compose.yaml and config.yaml, so there is nothing to configure and nothing to generate:

git clone https://github.com/varavelio/zen-idp.git
cd zen-idp/examples/<example>/
docker compose up

You only need Docker and an authenticator app for the TOTP codes. If you do not have one at hand, the TOTP generator produces the same codes in your browser from the secret pasted into it.

One demo user for every example

All the examples share the same hardcoded credentials, so you register alice's TOTP secret in your authenticator once and every stack accepts her. Each config.yaml spells out the demo values in comments right next to where they are used, including alice's TOTP secret. The stacks also share the same demo ports, so run one example at a time on the same machine.

Grafana: Sign in with Zen IdP

https://github.com/varavelio/zen-idp/tree/main/examples/grafana

Grafana is a dashboarding and metrics visualization tool that speaks OIDC natively. This example points its login at Zen IdP through Grafana's generic OAuth provider, so the Grafana sign-in page becomes the Zen IdP sign-in page, with the same identifier and TOTP flow as everywhere else.

The Grafana example end to end: from docker compose up to a signed-in dashboard.

OAuth2 Proxy: Protect any web app

https://github.com/varavelio/zen-idp/tree/main/examples/oauth2-proxy

OAuth2 Proxy sits in front of a web application and signs everyone in through Zen IdP before requests reach it. The application itself does not change, which is what makes this the right pattern for internal dashboards, home lab services, or any older tool that was never built with OIDC in mind. The example protects a small nginx demo page and prints the identity headers that OAuth2 Proxy forwards to it.

Gatus: Monitor any service uptime

https://github.com/varavelio/zen-idp/tree/main/examples/gatus

Gatus is a lightweight health dashboard that checks services on an interval and shows their status at a glance. In this example it watches three public websites (GitHub, Google and Wikipedia) enough to see the checks going green. The dashboard itself is locked behind a Zen IdP sign-in.

OliveTin: One-click actions

https://github.com/varavelio/zen-idp/tree/main/examples/olivetin

OliveTin is a web dashboard of one-click actions that run shell commands. In this example it shows three ping buttons (against GitHub, Google and Wikipedia) and the whole dashboard is locked behind a Zen IdP sign-in, so guests are bounced to the login before they see anything.

Zot: Run a private container registry

https://github.com/varavelio/zen-idp/tree/main/examples/zot

Zot is a self-hosted OCI container registry. In this example its web UI is locked behind a Zen IdP sign-in through zot's generic OpenID provider, and only the demo user can browse and push to it. After signing in, create an API key in the UI and use it as the password for docker login.