repo/services/authelia/configuration.yml
Ezequiel C. 187379de4e multistreaming: scenes/composition, installer build support, service updates
- multistreaming (new): RTMP ingest + multi-platform fan-out with pluggable providers (Twitch/YouTube/Kick/custom), zero-knowledge key vaults, Authelia OIDC auth, shared rooms with editor/streamer roles, single-use invites, per-account streaming grants, and scenes & composition (grid/PiP layouts, text/image overlays, per-output audio routing).
- installer: support Dockerfile build in metadata (not just image) and RSA key generation for the Authelia OIDC JWKS.
- authelia: add OIDC provider with portainer + multistreaming clients (public + PKCE).
- services: remove allprox; add nginx-proxy-manager and portainer; update lldap; regenerate catalog.
2026-09-02 21:18:25 +02:00

131 lines
3.6 KiB
YAML

# Authelia configuration — https://www.authelia.com/configuration/prologue/introduction/
#
# Secrets (JWT_SECRET, RESET_JWT_SECRET, SESSION_SECRET, LDAP_ADMIN_PASSWORD,
# OIDC_HMAC_SECRET, OIDC_PORTAINER_SECRET) are resolved from the service's .env
# by the installer and substituted into this file on install/update, so they are
# not committed here.
#
# The OIDC signing key (jwks) cannot be injected via env/file secrets (Authelia
# does not support that for this field), so it is read from /config/oidc-jwks.pem
# using the `template` file filter (enabled via X_AUTHELIA_CONFIG_FILTERS).
# The installer generates that file on first install and never rotates it.
theme: dark
jwt_secret: '${JWT_SECRET}'
server:
address: 'tcp://0.0.0.0:9091/'
endpoints:
authz:
forward-auth:
implementation: 'ForwardAuth'
log:
level: info
totp:
issuer: 'homelab'
identity_validation:
reset_password:
jwt_secret: '${RESET_JWT_SECRET}'
authentication_backend:
password_reset:
disable: true
refresh_interval: '5m'
ldap:
implementation: 'lldap'
address: 'ldap://lldap:3890'
base_dn: 'dc=homelab,dc=local'
user: 'uid=admin,ou=people,dc=homelab,dc=local'
password: '${LDAP_ADMIN_PASSWORD}'
access_control:
default_policy: deny
rules:
- domain: 'auth.example.com'
policy: bypass
# Everything else on your domain is SSO-protected (one factor by default).
# Apps that talk to Authelia via OIDC (Portainer) are NOT governed by these
# rules — their 2FA requirement lives in the client's authorization_policy.
# Apps behind forward-auth (multistreaming, lldap, …) use these rules; bump a
# specific host to two_factor if you want 2FA on it too.
- domain: '*.example.com'
policy: one_factor
session:
name: 'authelia_session'
secret: '${SESSION_SECRET}'
expiration: '1h'
inactivity: '5m'
remember_me: '1M'
cookies:
- domain: 'example.com'
authelia_url: 'https://auth.example.com'
default_redirection_url: 'https://auth.example.com'
regulation:
max_retries: 3
find_time: '2m'
ban_time: '5m'
storage:
local:
path: '/config/db.sqlite3'
notifier:
filesystem:
filename: '/config/notification.txt'
identity_providers:
oidc:
hmac_secret: '${OIDC_HMAC_SECRET}'
jwks:
- key_id: 'homelab'
algorithm: 'RS256'
use: 'sig'
key: |
{{- fileContent "/config/oidc-jwks.pem" | nindent 10 }}
clients:
- client_id: 'portainer'
client_name: 'Portainer'
client_secret: '${OIDC_PORTAINER_SECRET}'
public: false
redirect_uris:
- 'https://portainer.example.com'
scopes:
- 'openid'
- 'profile'
- 'groups'
- 'email'
grant_types:
- 'refresh_token'
- 'authorization_code'
response_types:
- 'code'
response_modes:
- 'form_post'
- 'query'
authorization_policy: 'two_factor'
- client_id: 'multistreaming'
client_name: 'Multistreaming'
# Public client: the panel is a browser SPA. No client_secret — it is
# protected by PKCE (S256) instead, which is required for public clients.
public: true
redirect_uris:
- 'https://streaming.example.com/api/auth/oidc/callback'
scopes:
- 'openid'
- 'profile'
- 'email'
grant_types:
- 'authorization_code'
response_types:
- 'code'
response_modes:
- 'query'
require_pkce: true
pkce_challenge_method: 'S256'
authorization_policy: 'two_factor'