Add Authelia TrueNAS compose stack

This commit is contained in:
2026-08-20 19:49:16 +00:00
parent 9c9dd3f85e
commit 745cd4e9fa
2 changed files with 162 additions and 0 deletions
+140
View File
@@ -0,0 +1,140 @@
# ============================================
# Authelia — TrueNAS Compose
# ============================================
# Target: TrueNAS regular Docker / Portainer Git-backed Compose deployment.
# Source pattern:
# - TrueNAS Docker data root: /mnt/HomeStorage02/Docker/Authelia/...
# - Runtime secrets are supplied through Portainer stack environment variables.
# - The one-shot init service writes initial config/users files only when missing.
#
# Deploy:
# docker compose --env-file authelia-truenas.env -f authelia-truenas-compose.yml up -d
#
# Validate:
# docker compose --env-file authelia-truenas.env.example -f authelia-truenas-compose.yml config
#
# Notes:
# - Do not commit real JWT/session/storage secrets or password hashes.
# - Redis is used for sessions; SQLite is used for Authelia storage.
# - Initial policy protects guide.wheelz.lab for admins only.
# ============================================
services:
authelia-init:
image: alpine:3.20
container_name: authelia-init
restart: "no"
environment:
AUTHELIA_BOOTSTRAP_USER: ${AUTHELIA_BOOTSTRAP_USER:-wheelz}
AUTHELIA_BOOTSTRAP_DISPLAY_NAME: ${AUTHELIA_BOOTSTRAP_DISPLAY_NAME:-Wheelz}
AUTHELIA_BOOTSTRAP_EMAIL: ${AUTHELIA_BOOTSTRAP_EMAIL:-wheelz@example.invalid}
AUTHELIA_BOOTSTRAP_PASSWORD_HASH: ${AUTHELIA_BOOTSTRAP_PASSWORD_HASH:?set AUTHELIA_BOOTSTRAP_PASSWORD_HASH in runtime env}
volumes:
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config
command:
- /bin/sh
- -ec
- |
mkdir -p /config
chmod 700 /config
if [ ! -f /config/configuration.yml ]; then
cat > /config/configuration.yml <<'EOF'
server:
address: tcp://0.0.0.0:9091/
log:
level: info
theme: dark
totp:
issuer: wheelytho.com
authentication_backend:
file:
path: /config/users_database.yml
watch: true
password:
algorithm: bcrypt
access_control:
default_policy: deny
rules:
- domain: guide.wheelz.lab
policy: two_factor
subject:
- group:admins
session:
name: authelia_session
same_site: lax
redis:
host: authelia-redis
port: 6379
cookies:
- domain: wheelz.lab
authelia_url: https://auth.wheelz.lab
default_redirection_url: https://guide.wheelz.lab
storage:
local:
path: /config/db.sqlite3
notifier:
filesystem:
filename: /config/notification.txt
identity_validation:
reset_password:
jwt_lifespan: 5 minutes
jwt_algorithm: HS256
EOF
fi
if [ ! -f /config/users_database.yml ]; then
: "${AUTHELIA_BOOTSTRAP_PASSWORD_HASH:?AUTHELIA_BOOTSTRAP_PASSWORD_HASH is required}"
cat > /config/users_database.yml <<EOF
users:
${AUTHELIA_BOOTSTRAP_USER:-wheelz}:
disabled: false
displayname: "${AUTHELIA_BOOTSTRAP_DISPLAY_NAME:-Wheelz}"
password: "${AUTHELIA_BOOTSTRAP_PASSWORD_HASH}"
email: "${AUTHELIA_BOOTSTRAP_EMAIL:-wheelz@example.invalid}"
groups:
- admins
- family
EOF
chmod 600 /config/users_database.yml
fi
authelia-redis:
image: redis:7-alpine
container_name: authelia-redis
restart: unless-stopped
command: ["redis-server", "--appendonly", "yes"]
volumes:
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/redis:/data
security_opt:
- no-new-privileges:true
authelia:
image: ${AUTHELIA_IMAGE:-authelia/authelia}:${AUTHELIA_TAG:-4.39.10}
container_name: authelia
restart: unless-stopped
depends_on:
authelia-init:
condition: service_completed_successfully
authelia-redis:
condition: service_started
ports:
- "${AUTHELIA_HTTP_PORT:-9091}:9091"
environment:
TZ: ${TZ:-America/Chicago}
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET: ${AUTHELIA_JWT_SECRET:?set AUTHELIA_JWT_SECRET in runtime env}
AUTHELIA_SESSION_SECRET: ${AUTHELIA_SESSION_SECRET:?set AUTHELIA_SESSION_SECRET in runtime env}
AUTHELIA_STORAGE_ENCRYPTION_KEY: ${AUTHELIA_STORAGE_ENCRYPTION_KEY:?set AUTHELIA_STORAGE_ENCRYPTION_KEY in runtime env}
volumes:
- ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config
security_opt:
- no-new-privileges:true
+22
View File
@@ -0,0 +1,22 @@
# Authelia TrueNAS environment example for Wheelz's HomeLab.
# Copy to authelia-truenas.env on TrueNAS/Portainer and adjust runtime values there.
# Do not commit real secrets, password hashes, recovery codes, or user passwords.
AUTHELIA_IMAGE=authelia/authelia
AUTHELIA_TAG=4.39.10
AUTHELIA_HTTP_PORT=9091
TZ=America/Chicago
# Wheelz TrueNAS Docker directory pattern.
TRUENAS_DOCKER_ROOT=/mnt/HomeStorage02/Docker
# Bootstrap user written to /config/users_database.yml only when that file does not exist.
AUTHELIA_BOOTSTRAP_USER=wheelz
AUTHELIA_BOOTSTRAP_DISPLAY_NAME=Wheelz
AUTHELIA_BOOTSTRAP_EMAIL=wheelz@example.invalid
AUTHELIA_BOOTSTRAP_PASSWORD_HASH=replace_with_real_bcrypt_hash_generated_from_a_private_bootstrap_password
# Runtime secrets. Generate long random values and keep them stable after first deployment.
AUTHELIA_JWT_SECRET=replace_with_long_random_secret
AUTHELIA_SESSION_SECRET=replace_with_long_random_secret
AUTHELIA_STORAGE_ENCRYPTION_KEY=replace_with_long_random_secret