Ory Hydra v26.2.0[1] 오픈소스 바이너리를 Linux 서버 한 대에 설치하고, PostgreSQL 을 붙여 systemd 서비스로 올리는 절차다. 공식 배포 예제[2]의 구성을 따르며, TLS 종단은 앞단 Nginx 가 맡는다. 예시 값 — issuer https://oauth2.example.com, 로그인 · 동의 앱 http://127.0.0.1:3000.
ory/hydra-login-consent-node 를 3000 포트에 띄워 시험한다.useradd --system --home-dir /opt/hydra --shell /sbin/nologin hydra
mkdir -p /opt/hydra/bin /opt/hydra/config
sudo -u postgres psql <<'SQL'
CREATE USER hydra WITH PASSWORD '${HYDRA_DB_PASSWORD}';
CREATE DATABASE hydra OWNER hydra ENCODING 'UTF8';
SQL
GitHub 릴리스의 Linux 64bit 아카이브를 받는다[1:1].
cd /opt/hydra/bin
curl -LO https://github.com/ory/hydra/releases/download/v26.2.0/hydra_26.2.0-linux_64bit.tar.gz
tar xzf hydra_26.2.0-linux_64bit.tar.gz
rm -f hydra_26.2.0-linux_64bit.tar.gz *.md LICENSE
./hydra version
# Version: v26.2.0
secrets.system 은 토큰 · 세션 암호화 키다. 32자 이상의 난수로 만들고 바꾸지 않는다 — 바꾸면 기존 토큰이 모두 무효가 된다. 임의 키 생성.
openssl rand -hex 32
공식 5분 예제 설정[3]에 DSN · issuer 를 채운 것이다.
serve:
public:
host: 127.0.0.1
port: 4444
admin:
host: 127.0.0.1
port: 4445
cookies:
same_site_mode: Lax
# DSN 은 환경변수 DSN 으로 넘긴다 (아래 systemd)
# dsn: postgres://hydra:${HYDRA_DB_PASSWORD}@127.0.0.1:5432/hydra?sslmode=disable&max_conns=20&max_idle_conns=4
urls:
self:
issuer: https://oauth2.example.com
consent: http://127.0.0.1:3000/consent
login: http://127.0.0.1:3000/login
logout: http://127.0.0.1:3000/logout
device:
verification: http://127.0.0.1:3000/device/verify
success: http://127.0.0.1:3000/device/success
secrets:
system:
- ${SYSTEM_SECRET_32_CHARS_OR_MORE}
oidc:
subject_identifiers:
supported_types:
- pairwise
- public
pairwise:
salt: ${PAIRWISE_SALT_32_CHARS_OR_MORE}
log:
level: info
format: json
serve.public.host · serve.admin.host 를 127.0.0.1 로 묶어 Nginx 만 접근하게 한다.urls.self.issuer 는 토큰의 iss 값이 된다. Nginx 가 받는 외부 URL 과 정확히 같아야 한다.urls.login · urls.consent 는 사용자의 브라우저가 가는 주소다. 운영에서는 공개 URL 로 바꾼다.cat > /etc/hydra.env <<'EOF'
DSN=postgres://hydra:${HYDRA_DB_PASSWORD}@127.0.0.1:5432/hydra?sslmode=disable&max_conns=20&max_idle_conns=4
EOF
chmod 600 /etc/hydra.env
chown -R hydra:hydra /opt/hydra
sudo -u hydra env $(cat /etc/hydra.env) /opt/hydra/bin/hydra migrate sql -e -y -c /opt/hydra/config/hydra.yml
-e 는 DSN 을 환경변수에서 읽는다는 뜻이다. 버전을 올릴 때도 같은 명령을 먼저 돌린다.
sudo -u hydra env $(cat /etc/hydra.env) /opt/hydra/bin/hydra serve all -c /opt/hydra/config/hydra.yml
# 다른 터미널에서
curl -s http://127.0.0.1:4444/health/ready
# {"status":"ok"}
cat > /etc/systemd/system/hydra.service <<'EOF'
[Unit]
Description=Ory Hydra OAuth2/OIDC Server
After=network-online.target postgresql.service
Wants=network-online.target
[Service]
Type=simple
User=hydra
Group=hydra
EnvironmentFile=/etc/hydra.env
ExecStart=/opt/hydra/bin/hydra serve all -c /opt/hydra/config/hydra.yml
Restart=always
RestartSec=3
[Install]
WantedBy=multi-user.target
EOF
systemctl daemon-reload
systemctl enable --now hydra
systemctl status hydra
4444 · 4445 는 localhost 에만 열려 있으므로 방화벽 규칙이 필요 없다. 외부에는 Nginx 의 443 만 연다.
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
curl -s https://oauth2.example.com/.well-known/openid-configuration | jq -r .issuer,.token_endpoint
# https://oauth2.example.com
# https://oauth2.example.com/oauth2/token
클라이언트를 하나 만들어 client credentials 흐름으로 토큰을 받아 본다. Admin API 는 서버 안에서만 부른다.
/opt/hydra/bin/hydra create client \
--endpoint http://127.0.0.1:4445 \
--name test-m2m \
--grant-type client_credentials \
--format json
# {"client_id":"...","client_secret":"...", ...}
/opt/hydra/bin/hydra perform client-credentials \
--endpoint https://oauth2.example.com \
--client-id ${CLIENT_ID} --client-secret ${CLIENT_SECRET}
# ACCESS TOKEN ...
브라우저 로그인 흐름(authorization code)은 로그인 · 동의 앱이 있어야 끝까지 간다. 예제 앱은 다음과 같이 띄운다.
docker run -d --name hydra-login-consent --network host \
-e HYDRA_ADMIN_URL=http://127.0.0.1:4445 \
-e PORT=3000 oryd/hydra-login-consent-node:v26.2.0
최신 버전 v26.2.0 (2026-03-20), 아카이브 hydra_26.2.0-linux_64bit.tar.gz — 2026-09-20 확인. https://github.com/ory/hydra/releases/latest ↩︎ ↩︎
Ory Hydra — Deploy example (binary + PostgreSQL + Nginx). 2026-09-20 확인. https://www.ory.com/docs/hydra/self-hosted/deploy-hydra-example · CLI hydra migrate sql https://www.ory.com/docs/hydra/cli/hydra-migrate-sql · hydra serve all https://www.ory.com/docs/hydra/cli/hydra-serve-all ↩︎
5분 빠른 시작 설정 파일 (v26.2.0). 2026-09-20 확인. https://raw.githubusercontent.com/ory/hydra/v26.2.0/contrib/quickstart/5-min/hydra.yml · 설정 참조 https://www.ory.com/docs/hydra/reference/configuration ↩︎