71 lines
1.5 KiB
YAML
71 lines
1.5 KiB
YAML
# Authelia configuration — https://www.authelia.com/configuration/prologue/introduction/
|
|
#
|
|
# Secrets (JWT_SECRET, RESET_JWT_SECRET, SESSION_SECRET, LDAP_ADMIN_PASSWORD) are
|
|
# resolved from the service's .env by the installer and substituted into this file
|
|
# on install/update, so they are not committed here.
|
|
|
|
theme: dark
|
|
|
|
jwt_secret: '${JWT_SECRET}'
|
|
|
|
server:
|
|
address: 'tcp://0.0.0.0:9091/'
|
|
endpoints:
|
|
authz:
|
|
forward-auth:
|
|
implementation: 'ForwardAuth'
|
|
|
|
log:
|
|
level: info
|
|
|
|
totp:
|
|
issuer: 'homelab'
|
|
|
|
identity_validation:
|
|
reset_password:
|
|
jwt_secret: '${RESET_JWT_SECRET}'
|
|
|
|
authentication_backend:
|
|
password_reset:
|
|
disable: true
|
|
refresh_interval: '5m'
|
|
ldap:
|
|
implementation: 'lldap'
|
|
address: 'ldap://lldap:3890'
|
|
base_dn: 'dc=homelab,dc=local'
|
|
user: 'uid=admin,ou=people,dc=homelab,dc=local'
|
|
password: '${LDAP_ADMIN_PASSWORD}'
|
|
|
|
access_control:
|
|
default_policy: deny
|
|
rules:
|
|
- domain: 'auth.example.com'
|
|
policy: bypass
|
|
- domain: 'portal.example.com'
|
|
policy: one_factor
|
|
- domain: '*.example.com'
|
|
policy: one_factor
|
|
|
|
session:
|
|
name: 'authelia_session'
|
|
secret: '${SESSION_SECRET}'
|
|
expiration: '1h'
|
|
inactivity: '5m'
|
|
remember_me: '1M'
|
|
cookies:
|
|
- domain: 'example.com'
|
|
authelia_url: 'https://auth.example.com'
|
|
default_redirection_url: 'https://portal.example.com'
|
|
|
|
regulation:
|
|
max_retries: 3
|
|
find_time: '2m'
|
|
ban_time: '5m'
|
|
|
|
storage:
|
|
local:
|
|
path: '/config/db.sqlite3'
|
|
|
|
notifier:
|
|
filesystem:
|
|
filename: '/config/notification.txt'
|