Thanks for the feedback. We're currently working on adding a simple single username/password authentication to all of the OSS Airbyte by default. That way you don't need to worry about accidentally leaking your Airbyte instance in publicly accessible networks anymore. And for the case you wanna run a custom auth solution (via a reverse proxy or such), you'll still be able to disable the build in auth for that.