Add Authelia TrueNAS compose stack
This commit is contained in:
@@ -0,0 +1,140 @@
|
||||
# ============================================
|
||||
# Authelia — TrueNAS Compose
|
||||
# ============================================
|
||||
# Target: TrueNAS regular Docker / Portainer Git-backed Compose deployment.
|
||||
# Source pattern:
|
||||
# - TrueNAS Docker data root: /mnt/HomeStorage02/Docker/Authelia/...
|
||||
# - Runtime secrets are supplied through Portainer stack environment variables.
|
||||
# - The one-shot init service writes initial config/users files only when missing.
|
||||
#
|
||||
# Deploy:
|
||||
# docker compose --env-file authelia-truenas.env -f authelia-truenas-compose.yml up -d
|
||||
#
|
||||
# Validate:
|
||||
# docker compose --env-file authelia-truenas.env.example -f authelia-truenas-compose.yml config
|
||||
#
|
||||
# Notes:
|
||||
# - Do not commit real JWT/session/storage secrets or password hashes.
|
||||
# - Redis is used for sessions; SQLite is used for Authelia storage.
|
||||
# - Initial policy protects guide.wheelz.lab for admins only.
|
||||
# ============================================
|
||||
|
||||
services:
|
||||
authelia-init:
|
||||
image: alpine:3.20
|
||||
container_name: authelia-init
|
||||
restart: "no"
|
||||
environment:
|
||||
AUTHELIA_BOOTSTRAP_USER: ${AUTHELIA_BOOTSTRAP_USER:-wheelz}
|
||||
AUTHELIA_BOOTSTRAP_DISPLAY_NAME: ${AUTHELIA_BOOTSTRAP_DISPLAY_NAME:-Wheelz}
|
||||
AUTHELIA_BOOTSTRAP_EMAIL: ${AUTHELIA_BOOTSTRAP_EMAIL:-wheelz@example.invalid}
|
||||
AUTHELIA_BOOTSTRAP_PASSWORD_HASH: ${AUTHELIA_BOOTSTRAP_PASSWORD_HASH:?set AUTHELIA_BOOTSTRAP_PASSWORD_HASH in runtime env}
|
||||
volumes:
|
||||
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config
|
||||
command:
|
||||
- /bin/sh
|
||||
- -ec
|
||||
- |
|
||||
mkdir -p /config
|
||||
chmod 700 /config
|
||||
|
||||
if [ ! -f /config/configuration.yml ]; then
|
||||
cat > /config/configuration.yml <<'EOF'
|
||||
server:
|
||||
address: tcp://0.0.0.0:9091/
|
||||
|
||||
log:
|
||||
level: info
|
||||
|
||||
theme: dark
|
||||
|
||||
totp:
|
||||
issuer: wheelytho.com
|
||||
|
||||
authentication_backend:
|
||||
file:
|
||||
path: /config/users_database.yml
|
||||
watch: true
|
||||
password:
|
||||
algorithm: bcrypt
|
||||
|
||||
access_control:
|
||||
default_policy: deny
|
||||
rules:
|
||||
- domain: guide.wheelz.lab
|
||||
policy: two_factor
|
||||
subject:
|
||||
- group:admins
|
||||
|
||||
session:
|
||||
name: authelia_session
|
||||
same_site: lax
|
||||
redis:
|
||||
host: authelia-redis
|
||||
port: 6379
|
||||
cookies:
|
||||
- domain: wheelz.lab
|
||||
authelia_url: https://auth.wheelz.lab
|
||||
default_redirection_url: https://guide.wheelz.lab
|
||||
|
||||
storage:
|
||||
local:
|
||||
path: /config/db.sqlite3
|
||||
|
||||
notifier:
|
||||
filesystem:
|
||||
filename: /config/notification.txt
|
||||
|
||||
identity_validation:
|
||||
reset_password:
|
||||
jwt_lifespan: 5 minutes
|
||||
jwt_algorithm: HS256
|
||||
EOF
|
||||
fi
|
||||
|
||||
if [ ! -f /config/users_database.yml ]; then
|
||||
: "${AUTHELIA_BOOTSTRAP_PASSWORD_HASH:?AUTHELIA_BOOTSTRAP_PASSWORD_HASH is required}"
|
||||
cat > /config/users_database.yml <<EOF
|
||||
users:
|
||||
${AUTHELIA_BOOTSTRAP_USER:-wheelz}:
|
||||
disabled: false
|
||||
displayname: "${AUTHELIA_BOOTSTRAP_DISPLAY_NAME:-Wheelz}"
|
||||
password: "${AUTHELIA_BOOTSTRAP_PASSWORD_HASH}"
|
||||
email: "${AUTHELIA_BOOTSTRAP_EMAIL:-wheelz@example.invalid}"
|
||||
groups:
|
||||
- admins
|
||||
- family
|
||||
EOF
|
||||
chmod 600 /config/users_database.yml
|
||||
fi
|
||||
|
||||
authelia-redis:
|
||||
image: redis:7-alpine
|
||||
container_name: authelia-redis
|
||||
restart: unless-stopped
|
||||
command: ["redis-server", "--appendonly", "yes"]
|
||||
volumes:
|
||||
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/redis:/data
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
|
||||
authelia:
|
||||
image: ${AUTHELIA_IMAGE:-authelia/authelia}:${AUTHELIA_TAG:-4.39.10}
|
||||
container_name: authelia
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
authelia-init:
|
||||
condition: service_completed_successfully
|
||||
authelia-redis:
|
||||
condition: service_started
|
||||
ports:
|
||||
- "${AUTHELIA_HTTP_PORT:-9091}:9091"
|
||||
environment:
|
||||
TZ: ${TZ:-America/Chicago}
|
||||
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET: ${AUTHELIA_JWT_SECRET:?set AUTHELIA_JWT_SECRET in runtime env}
|
||||
AUTHELIA_SESSION_SECRET: ${AUTHELIA_SESSION_SECRET:?set AUTHELIA_SESSION_SECRET in runtime env}
|
||||
AUTHELIA_STORAGE_ENCRYPTION_KEY: ${AUTHELIA_STORAGE_ENCRYPTION_KEY:?set AUTHELIA_STORAGE_ENCRYPTION_KEY in runtime env}
|
||||
volumes:
|
||||
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
@@ -0,0 +1,22 @@
|
||||
# Authelia TrueNAS environment example for Wheelz's HomeLab.
|
||||
# Copy to authelia-truenas.env on TrueNAS/Portainer and adjust runtime values there.
|
||||
# Do not commit real secrets, password hashes, recovery codes, or user passwords.
|
||||
|
||||
AUTHELIA_IMAGE=authelia/authelia
|
||||
AUTHELIA_TAG=4.39.10
|
||||
AUTHELIA_HTTP_PORT=9091
|
||||
TZ=America/Chicago
|
||||
|
||||
# Wheelz TrueNAS Docker directory pattern.
|
||||
TRUENAS_DOCKER_ROOT=/mnt/HomeStorage02/Docker
|
||||
|
||||
# Bootstrap user written to /config/users_database.yml only when that file does not exist.
|
||||
AUTHELIA_BOOTSTRAP_USER=wheelz
|
||||
AUTHELIA_BOOTSTRAP_DISPLAY_NAME=Wheelz
|
||||
AUTHELIA_BOOTSTRAP_EMAIL=wheelz@example.invalid
|
||||
AUTHELIA_BOOTSTRAP_PASSWORD_HASH=replace_with_real_bcrypt_hash_generated_from_a_private_bootstrap_password
|
||||
|
||||
# Runtime secrets. Generate long random values and keep them stable after first deployment.
|
||||
AUTHELIA_JWT_SECRET=replace_with_long_random_secret
|
||||
AUTHELIA_SESSION_SECRET=replace_with_long_random_secret
|
||||
AUTHELIA_STORAGE_ENCRYPTION_KEY=replace_with_long_random_secret
|
||||
Reference in New Issue
Block a user