Switch Authelia runtime password env to AD bind
This commit is contained in:
@@ -0,0 +1,72 @@
|
|||||||
|
# Authelia Active Directory / ADUC migration worksheet
|
||||||
|
# Fill this out locally, then we can use it to update Authelia from LLDAP to AD LDAP.
|
||||||
|
# Do NOT commit this file after adding real passwords or secrets.
|
||||||
|
|
||||||
|
# Current deployment context
|
||||||
|
AUTHELIA_URL=https://auth.wheelz.lab
|
||||||
|
AUTHELIA_BACKEND_URL=http://192.168.20.5:9091
|
||||||
|
AUTHELIA_CONFIG_DIR=/mnt/HomeStorage02/Docker/Authelia/config
|
||||||
|
|
||||||
|
# Active Directory domain
|
||||||
|
AD_DOMAIN_FQDN=local.wheelz.com
|
||||||
|
AD_NETBIOS_DOMAIN=WHEELZ
|
||||||
|
AD_BASE_DN=DC=local,DC=wheelz,DC=com
|
||||||
|
AD_DC_HOSTNAME=WheelzDC01.local.wheelz.com
|
||||||
|
AD_DC_IP=192.168.30.15
|
||||||
|
|
||||||
|
# LDAP connection
|
||||||
|
# Start with ldap:// for testing, then move to ldaps:// once CA trust is handled.
|
||||||
|
AD_LDAP_URL=ldap://192.168.30.15:389
|
||||||
|
# AD_LDAPS_URL=ldaps://WheelzDC01.local.wheelz.com:636
|
||||||
|
AD_START_TLS=false
|
||||||
|
AD_TLS_SKIP_VERIFY=false
|
||||||
|
# If using LDAPS, provide/export the AD CA root cert path later.
|
||||||
|
AD_CA_CERT_PATH=/config/certs/ad-ca-root.crt
|
||||||
|
|
||||||
|
# Bind/service account for Authelia LDAP searches
|
||||||
|
# Recommended: create a normal AD user with read/search access only.
|
||||||
|
AD_BIND_USERNAME=svc-authelia@local.wheelz.com
|
||||||
|
AD_BIND_PASSWORD=
|
||||||
|
# Optional DN form if UPN bind does not work:
|
||||||
|
# AD_BIND_DN=CN=svc_authelia_ldap,OU=Service Accounts,DC=local,DC=wheelz,DC=com
|
||||||
|
|
||||||
|
# User search scope
|
||||||
|
# Broad is easiest. Narrow to an OU later if desired.
|
||||||
|
AD_USERS_BASE_DN=DC=local,DC=wheelz,DC=com
|
||||||
|
# Example narrower value:
|
||||||
|
# AD_USERS_BASE_DN=OU=Users,DC=local,DC=wheelz,DC=com
|
||||||
|
AD_USERS_FILTER=(&({username_attribute}={input})(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
|
||||||
|
AD_USERNAME_ATTRIBUTE=sAMAccountName
|
||||||
|
AD_DISPLAY_NAME_ATTRIBUTE=displayName
|
||||||
|
AD_MAIL_ATTRIBUTE=mail
|
||||||
|
|
||||||
|
# Group search scope
|
||||||
|
AD_GROUPS_BASE_DN=DC=local,DC=wheelz,DC=com
|
||||||
|
# Example narrower value:
|
||||||
|
# AD_GROUPS_BASE_DN=OU=Groups,DC=local,DC=wheelz,DC=com
|
||||||
|
AD_GROUPS_FILTER=(member={dn})
|
||||||
|
AD_GROUP_NAME_ATTRIBUTE=cn
|
||||||
|
|
||||||
|
# Authelia AD security groups
|
||||||
|
AD_GROUP_AUTHELIA_ADMINS=Authelia-Admin
|
||||||
|
AD_GROUP_AUTHELIA_FAMILY=Authelia-Family
|
||||||
|
AD_GROUP_AUTHELIA_FRIENDS=Authelia-Friends
|
||||||
|
AD_GROUP_AUTHELIA_GUESTS=Authelia-Guest
|
||||||
|
|
||||||
|
# First admin user to verify after switching
|
||||||
|
AD_FIRST_ADMIN_USERNAME=wheelz
|
||||||
|
AD_FIRST_ADMIN_UPN=wheelz@local.wheelz.com
|
||||||
|
AD_FIRST_ADMIN_MUST_BE_MEMBER_OF=Authelia-Admin
|
||||||
|
|
||||||
|
# Network checks needed before changing Authelia
|
||||||
|
# TrueNAS/Authelia container must reach the DC on one of these:
|
||||||
|
# - TCP 389 for LDAP
|
||||||
|
# - TCP 636 for LDAPS
|
||||||
|
LDAP_PORT_TO_TEST=389
|
||||||
|
|
||||||
|
# Notes for Wheelz:
|
||||||
|
# 1. Create svc_authelia_ldap in ADUC.
|
||||||
|
# 2. Create security groups: Authelia-Admin, Authelia-Family, Authelia-Guest.
|
||||||
|
# 3. Add your real AD user to Authelia-Admin.
|
||||||
|
# 4. Fill in exact DC hostname, any real OU paths, and the service account password.
|
||||||
|
# 5. Do not paste the real password into Obsidian or commit it to Gitea.
|
||||||
@@ -170,7 +170,9 @@ services:
|
|||||||
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET: ${AUTHELIA_JWT_SECRET:?set AUTHELIA_JWT_SECRET in runtime env}
|
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET: ${AUTHELIA_JWT_SECRET:?set AUTHELIA_JWT_SECRET in runtime env}
|
||||||
AUTHELIA_SESSION_SECRET: ${AUTHELIA_SESSION_SECRET:?set AUTHELIA_SESSION_SECRET in runtime env}
|
AUTHELIA_SESSION_SECRET: ${AUTHELIA_SESSION_SECRET:?set AUTHELIA_SESSION_SECRET in runtime env}
|
||||||
AUTHELIA_STORAGE_ENCRYPTION_KEY: ${AUTHELIA_STORAGE_ENCRYPTION_KEY:?set AUTHELIA_STORAGE_ENCRYPTION_KEY in runtime env}
|
AUTHELIA_STORAGE_ENCRYPTION_KEY: ${AUTHELIA_STORAGE_ENCRYPTION_KEY:?set AUTHELIA_STORAGE_ENCRYPTION_KEY in runtime env}
|
||||||
AUTHELIA_AUTHENTICATION_BACKEND_LDAP_PASSWORD: ${LLDAP_LDAP_USER_PASS:?set LLDAP_LDAP_USER_PASS in runtime env}
|
# Active Directory LDAP bind password. The live configuration.yml references this
|
||||||
|
# through Authelia's env override; do not commit the real value.
|
||||||
|
AUTHELIA_AUTHENTICATION_BACKEND_LDAP_PASSWORD: ${AD_BIND_PASSWORD:?set AD_BIND_PASSWORD in runtime env}
|
||||||
volumes:
|
volumes:
|
||||||
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config
|
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config
|
||||||
security_opt:
|
security_opt:
|
||||||
|
|||||||
@@ -30,5 +30,9 @@ LLDAP_GID=1000
|
|||||||
LLDAP_LDAP_BASE_DN=dc=wheelz,dc=lab
|
LLDAP_LDAP_BASE_DN=dc=wheelz,dc=lab
|
||||||
LLDAP_LDAP_USER_EMAIL=wheelz@example.invalid
|
LLDAP_LDAP_USER_EMAIL=wheelz@example.invalid
|
||||||
LLDAP_LDAP_USER_PASS=replace_with_private_lldap_admin_password
|
LLDAP_LDAP_USER_PASS=replace_with_private_lldap_admin_password
|
||||||
LLDAP_JWT_SECRET=replace_with_long_random_secret
|
LLDAP_JWT_SECRET=replace-with-random-secret
|
||||||
LLDAP_KEY_SEED=replace_with_long_random_secret
|
LLDAP_KEY_SEED=replace-with-random-secret
|
||||||
|
|
||||||
|
# Active Directory LDAP backend used by Authelia after AD cutover.
|
||||||
|
# Keep the real bind password only in Portainer/runtime secrets, never in Gitea.
|
||||||
|
AD_BIND_PASSWORD=replace-with-ad-bind-password
|
||||||
|
|||||||
Reference in New Issue
Block a user