Add LLDAP to Authelia stack
This commit is contained in:
@@ -52,11 +52,11 @@ services:
|
||||
issuer: wheelytho.com
|
||||
|
||||
authentication_backend:
|
||||
file:
|
||||
path: /config/users_database.yml
|
||||
watch: true
|
||||
password:
|
||||
algorithm: bcrypt
|
||||
ldap:
|
||||
implementation: lldap
|
||||
address: ldap://lldap:3890
|
||||
base_dn: dc=wheelz,dc=lab
|
||||
user: uid=admin,ou=people,dc=wheelz,dc=lab
|
||||
|
||||
access_control:
|
||||
default_policy: deny
|
||||
@@ -118,6 +118,28 @@ services:
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
|
||||
|
||||
lldap:
|
||||
image: ${LLDAP_IMAGE:-lldap/lldap}:${LLDAP_TAG:-stable}
|
||||
container_name: lldap
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
# Web UI for family/user management. LDAP stays internal to the Docker network unless explicitly published later.
|
||||
- "${LLDAP_HTTP_PORT:-17170}:17170"
|
||||
environment:
|
||||
TZ: ${TZ:-America/Chicago}
|
||||
UID: ${LLDAP_UID:-1000}
|
||||
GID: ${LLDAP_GID:-1000}
|
||||
LLDAP_JWT_SECRET: ${LLDAP_JWT_SECRET:?set LLDAP_JWT_SECRET in runtime env}
|
||||
LLDAP_KEY_SEED: ${LLDAP_KEY_SEED:?set LLDAP_KEY_SEED in runtime env}
|
||||
LLDAP_LDAP_BASE_DN: ${LLDAP_LDAP_BASE_DN:-dc=wheelz,dc=lab}
|
||||
LLDAP_LDAP_USER_PASS: ${LLDAP_LDAP_USER_PASS:?set LLDAP_LDAP_USER_PASS in runtime env}
|
||||
LLDAP_LDAP_USER_EMAIL: ${LLDAP_LDAP_USER_EMAIL:-wheelz@example.invalid}
|
||||
volumes:
|
||||
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/lldap:/data
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
|
||||
authelia:
|
||||
image: ${AUTHELIA_IMAGE:-authelia/authelia}:${AUTHELIA_TAG:-4.39.10}
|
||||
container_name: authelia
|
||||
@@ -127,6 +149,8 @@ services:
|
||||
condition: service_completed_successfully
|
||||
authelia-redis:
|
||||
condition: service_started
|
||||
lldap:
|
||||
condition: service_started
|
||||
ports:
|
||||
- "${AUTHELIA_HTTP_PORT:-9091}:9091"
|
||||
environment:
|
||||
@@ -134,6 +158,7 @@ services:
|
||||
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET: ${AUTHELIA_JWT_SECRET:?set AUTHELIA_JWT_SECRET in runtime env}
|
||||
AUTHELIA_SESSION_SECRET: ${AUTHELIA_SESSION_SECRET:?set AUTHELIA_SESSION_SECRET in runtime env}
|
||||
AUTHELIA_STORAGE_ENCRYPTION_KEY: ${AUTHELIA_STORAGE_ENCRYPTION_KEY:?set AUTHELIA_STORAGE_ENCRYPTION_KEY in runtime env}
|
||||
AUTHELIA_AUTHENTICATION_BACKEND_LDAP_PASSWORD: ${LLDAP_LDAP_USER_PASS:?set LLDAP_LDAP_USER_PASS in runtime env}
|
||||
volumes:
|
||||
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config
|
||||
security_opt:
|
||||
|
||||
@@ -20,3 +20,15 @@ AUTHELIA_BOOTSTRAP_PASSWORD_HASH=replace_with_real_bcrypt_hash_generated_from_a_
|
||||
AUTHELIA_JWT_SECRET=replace_with_long_random_secret
|
||||
AUTHELIA_SESSION_SECRET=replace_with_long_random_secret
|
||||
AUTHELIA_STORAGE_ENCRYPTION_KEY=replace_with_long_random_secret
|
||||
|
||||
# LLDAP user/group management GUI for Authelia LDAP backend.
|
||||
LLDAP_IMAGE=lldap/lldap
|
||||
LLDAP_TAG=stable
|
||||
LLDAP_HTTP_PORT=17170
|
||||
LLDAP_UID=1000
|
||||
LLDAP_GID=1000
|
||||
LLDAP_LDAP_BASE_DN=dc=wheelz,dc=lab
|
||||
LLDAP_LDAP_USER_EMAIL=wheelz@example.invalid
|
||||
LLDAP_LDAP_USER_PASS=replace_with_private_lldap_admin_password
|
||||
LLDAP_JWT_SECRET=replace_with_long_random_secret
|
||||
LLDAP_KEY_SEED=replace_with_long_random_secret
|
||||
|
||||
Reference in New Issue
Block a user