With SSO though, it's much simpler. I can just run an OIDC server and log into all my self-hosted services once, and I can use all of them. Vaultwarden is an exception to the rule though, as you can't really bootstrap that in the individual case.
Another use case I'm currently exploring is for sharing netflix/prime/disney+ passwords with roommates, partners and friends. They just sign in with their Google/Apple/whatever account and get access to the shared streaming provider passwords.
Authelia? Authentik? Keycloak? (These are the three I see a lot about.) Something else?
(Whose server I really don't enjoy, it's very enterprise-y and heavy on resources for no real reason I could find.)
But like all community-made open source stuff, If you want to use it for "production" stuff you should invest in audits and contribute/fund development
But also what about the whole lifecycle?
I can easily deploy a HA Postgres cluster that is backed up for me. I'd have to do the same thing to back up BW.
For real? That would mean a requirement for a software license that costs about $1,000 for the cheapest option.
"All Bitwarden self-hosted server deployments, except for unified, ship with an MSSQL Express image by default."
Had then some fun adding roles/groups support (not yet merged).
Team of <10 though so hosting is trivial with NixOS. We also have almost no money available for purchasing software so official self-hosted bitwarden was not an option unfortunately (if we had money, that would've been the way to go).
LastPass is out of question due to the security issues in the past. I always advocate for Bitwarden but I'm not sure they can handle any kind of SSO yet. And Vaultwarden, being a fork of a not-so-famous-yet password vault (at least in the managers's world), is not a contender anywhere.
My fairly large (>20k) company uses Okta. That's just to say, be wary of issuing ultimatums.
Anyone can spin up an Authentik/Authelia/Keycloak/whatever instance or even use Microsoft/Google if they already pay for it in a matter of minutes. The only reason people don't is because tons of apps make it annoyingly difficult to integrate SSO or don't offer it at all in the lower price tiers.
If app installers started with "create a root user or paste the OIDC secret here", everyone and their dog would be running SSO. But that's not as profitable.
And also, in what world is SSO meant for enterprise?
It's Single Sign On, not having to login separately for each service is perfect for any context of any size - wherever these services only have 1 user or 100 thousand.
Yes, it does.