K.I.S.S MFA for homelab
I'm looking for a relatively simple solution (for my users) for MFA/2FA into my homelab jellyfin and webservers (one apache, one Guacamole). I know the adage that if its easy for the end user it was probably a PITA for the admin so I'm not expecting miracles. I just want something that my non IT professional friends/family don't have to jump through flaming hoops to get to my stuff yet keep it relatively secure. I would like MFA/2FA but that doesn't mean that I'll get it. Many people that work remote already have MS, Duo and/or Google Authenticators but I don't want to assume anyone has them, or necessarily force them to install them. Several vendors I work with in my day job just send a time based OTP to your email for auth. Nice. Easy. Nothing to remember. Again, if its that simple its probably a PITA (or not free) to config. I run pfsense, fail2ban (switching to crowdsec soon), proxmox, and truenas in my lab and I have docker (VM) on my proxmox and also a caddy reverse proxy (LXC) so I'm reasonably open to just about anything. I really don't want to externally host anything (i.e. Cloudflare, etc) where my users have to register, or I might be rate limited, or I might be user count limited (or have to pay). Am I asking for too much? Any suggestions that won't force me to get an MBA in six new apps to pull this all together?