From 42fa7234d881c03d3469aa64c6248f595d14235f Mon Sep 17 00:00:00 2001 From: wheelz Date: Mon, 24 Aug 2026 18:27:45 +0000 Subject: [PATCH] Switch Authelia runtime password env to AD bind --- authelia-ad.env.template | 72 ++++++++++++++++++++++++++++++++++++ authelia-truenas-compose.yml | 4 +- authelia-truenas.env.example | 8 +++- 3 files changed, 81 insertions(+), 3 deletions(-) create mode 100644 authelia-ad.env.template diff --git a/authelia-ad.env.template b/authelia-ad.env.template new file mode 100644 index 0000000..96f32ad --- /dev/null +++ b/authelia-ad.env.template @@ -0,0 +1,72 @@ +# Authelia Active Directory / ADUC migration worksheet +# Fill this out locally, then we can use it to update Authelia from LLDAP to AD LDAP. +# Do NOT commit this file after adding real passwords or secrets. + +# Current deployment context +AUTHELIA_URL=https://auth.wheelz.lab +AUTHELIA_BACKEND_URL=http://192.168.20.5:9091 +AUTHELIA_CONFIG_DIR=/mnt/HomeStorage02/Docker/Authelia/config + +# Active Directory domain +AD_DOMAIN_FQDN=local.wheelz.com +AD_NETBIOS_DOMAIN=WHEELZ +AD_BASE_DN=DC=local,DC=wheelz,DC=com +AD_DC_HOSTNAME=WheelzDC01.local.wheelz.com +AD_DC_IP=192.168.30.15 + +# LDAP connection +# Start with ldap:// for testing, then move to ldaps:// once CA trust is handled. +AD_LDAP_URL=ldap://192.168.30.15:389 +# AD_LDAPS_URL=ldaps://WheelzDC01.local.wheelz.com:636 +AD_START_TLS=false +AD_TLS_SKIP_VERIFY=false +# If using LDAPS, provide/export the AD CA root cert path later. +AD_CA_CERT_PATH=/config/certs/ad-ca-root.crt + +# Bind/service account for Authelia LDAP searches +# Recommended: create a normal AD user with read/search access only. +AD_BIND_USERNAME=svc-authelia@local.wheelz.com +AD_BIND_PASSWORD= +# Optional DN form if UPN bind does not work: +# AD_BIND_DN=CN=svc_authelia_ldap,OU=Service Accounts,DC=local,DC=wheelz,DC=com + +# User search scope +# Broad is easiest. Narrow to an OU later if desired. +AD_USERS_BASE_DN=DC=local,DC=wheelz,DC=com +# Example narrower value: +# AD_USERS_BASE_DN=OU=Users,DC=local,DC=wheelz,DC=com +AD_USERS_FILTER=(&({username_attribute}={input})(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) +AD_USERNAME_ATTRIBUTE=sAMAccountName +AD_DISPLAY_NAME_ATTRIBUTE=displayName +AD_MAIL_ATTRIBUTE=mail + +# Group search scope +AD_GROUPS_BASE_DN=DC=local,DC=wheelz,DC=com +# Example narrower value: +# AD_GROUPS_BASE_DN=OU=Groups,DC=local,DC=wheelz,DC=com +AD_GROUPS_FILTER=(member={dn}) +AD_GROUP_NAME_ATTRIBUTE=cn + +# Authelia AD security groups +AD_GROUP_AUTHELIA_ADMINS=Authelia-Admin +AD_GROUP_AUTHELIA_FAMILY=Authelia-Family +AD_GROUP_AUTHELIA_FRIENDS=Authelia-Friends +AD_GROUP_AUTHELIA_GUESTS=Authelia-Guest + +# First admin user to verify after switching +AD_FIRST_ADMIN_USERNAME=wheelz +AD_FIRST_ADMIN_UPN=wheelz@local.wheelz.com +AD_FIRST_ADMIN_MUST_BE_MEMBER_OF=Authelia-Admin + +# Network checks needed before changing Authelia +# TrueNAS/Authelia container must reach the DC on one of these: +# - TCP 389 for LDAP +# - TCP 636 for LDAPS +LDAP_PORT_TO_TEST=389 + +# Notes for Wheelz: +# 1. Create svc_authelia_ldap in ADUC. +# 2. Create security groups: Authelia-Admin, Authelia-Family, Authelia-Guest. +# 3. Add your real AD user to Authelia-Admin. +# 4. Fill in exact DC hostname, any real OU paths, and the service account password. +# 5. Do not paste the real password into Obsidian or commit it to Gitea. diff --git a/authelia-truenas-compose.yml b/authelia-truenas-compose.yml index 9c30e78..420fddb 100644 --- a/authelia-truenas-compose.yml +++ b/authelia-truenas-compose.yml @@ -170,7 +170,9 @@ services: AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET: ${AUTHELIA_JWT_SECRET:?set AUTHELIA_JWT_SECRET in runtime env} AUTHELIA_SESSION_SECRET: ${AUTHELIA_SESSION_SECRET:?set AUTHELIA_SESSION_SECRET in runtime env} AUTHELIA_STORAGE_ENCRYPTION_KEY: ${AUTHELIA_STORAGE_ENCRYPTION_KEY:?set AUTHELIA_STORAGE_ENCRYPTION_KEY in runtime env} - AUTHELIA_AUTHENTICATION_BACKEND_LDAP_PASSWORD: ${LLDAP_LDAP_USER_PASS:?set LLDAP_LDAP_USER_PASS in runtime env} + # Active Directory LDAP bind password. The live configuration.yml references this + # through Authelia's env override; do not commit the real value. + AUTHELIA_AUTHENTICATION_BACKEND_LDAP_PASSWORD: ${AD_BIND_PASSWORD:?set AD_BIND_PASSWORD in runtime env} volumes: - ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config security_opt: diff --git a/authelia-truenas.env.example b/authelia-truenas.env.example index 9d22fcf..8704cf3 100644 --- a/authelia-truenas.env.example +++ b/authelia-truenas.env.example @@ -30,5 +30,9 @@ LLDAP_GID=1000 LLDAP_LDAP_BASE_DN=dc=wheelz,dc=lab LLDAP_LDAP_USER_EMAIL=wheelz@example.invalid LLDAP_LDAP_USER_PASS=replace_with_private_lldap_admin_password -LLDAP_JWT_SECRET=replace_with_long_random_secret -LLDAP_KEY_SEED=replace_with_long_random_secret +LLDAP_JWT_SECRET=replace-with-random-secret +LLDAP_KEY_SEED=replace-with-random-secret + +# Active Directory LDAP backend used by Authelia after AD cutover. +# Keep the real bind password only in Portainer/runtime secrets, never in Gitea. +AD_BIND_PASSWORD=replace-with-ad-bind-password