# ============================================ # Authelia — TrueNAS Compose # ============================================ # Target: TrueNAS regular Docker / Portainer Git-backed Compose deployment. # Source pattern: # - TrueNAS Docker data root: /mnt/HomeStorage02/Docker/Authelia/... # - Runtime secrets are supplied through Portainer stack environment variables. # - The one-shot init service writes initial config/users files only when missing. # # Deploy: # docker compose --env-file authelia-truenas.env -f authelia-truenas-compose.yml up -d # # Validate: # docker compose --env-file authelia-truenas.env.example -f authelia-truenas-compose.yml config # # Notes: # - Do not commit real JWT/session/storage secrets or password hashes. # - Redis is used for sessions; SQLite is used for Authelia storage. # - Initial policy protects guide.wheelz.lab for admins only. # ============================================ services: authelia-init: image: alpine:3.20 container_name: authelia-init restart: "no" environment: AUTHELIA_BOOTSTRAP_USER: ${AUTHELIA_BOOTSTRAP_USER:-wheelz} AUTHELIA_BOOTSTRAP_DISPLAY_NAME: ${AUTHELIA_BOOTSTRAP_DISPLAY_NAME:-Wheelz} AUTHELIA_BOOTSTRAP_EMAIL: ${AUTHELIA_BOOTSTRAP_EMAIL:-wheelz@example.invalid} AUTHELIA_BOOTSTRAP_PASSWORD_HASH: ${AUTHELIA_BOOTSTRAP_PASSWORD_HASH:?set AUTHELIA_BOOTSTRAP_PASSWORD_HASH in runtime env} volumes: - ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config command: - /bin/sh - -ec - | mkdir -p /config chmod 700 /config if [ ! -f /config/configuration.yml ]; then cat > /config/configuration.yml <<'EOF' server: address: tcp://0.0.0.0:9091/ log: level: info theme: dark totp: issuer: wheelytho.com authentication_backend: ldap: implementation: custom address: ldap://lldap:3890 timeout: 5 seconds start_tls: false base_dn: dc=wheelz,dc=lab additional_users_dn: ou=people users_filter: (&({username_attribute}={input})(objectClass=person)) additional_groups_dn: ou=groups groups_filter: (member={dn}) group_search_mode: filter user: uid=admin,ou=people,dc=wheelz,dc=lab attributes: username: uid display_name: displayName mail: mail group_name: cn access_control: default_policy: deny rules: - domain: guide.wheelz.lab policy: two_factor subject: - group:Authelia-Admin - domain: games-dashboard.wheelz.lab policy: two_factor subject: - group:Authelia-Admin - group:Authelia-Friends - domain: guide.wheelytho.com policy: two_factor subject: - group:Authelia-Admin session: name: authelia_session same_site: lax redis: host: authelia-redis port: 6379 cookies: - domain: wheelz.lab authelia_url: https://auth.wheelz.lab default_redirection_url: https://guide.wheelz.lab - domain: wheelytho.com authelia_url: https://auth.wheelytho.com default_redirection_url: https://guide.wheelytho.com storage: local: path: /config/db.sqlite3 notifier: smtp: {} identity_validation: reset_password: jwt_lifespan: 5 minutes jwt_algorithm: HS256 EOF fi if [ ! -f /config/users_database.yml ]; then : "$${AUTHELIA_BOOTSTRAP_PASSWORD_HASH:?AUTHELIA_BOOTSTRAP_PASSWORD_HASH is required}" cat > /config/users_database.yml < AUTHELIA_NOTIFIER_SMTP_IDENTIFIER: ${SMTP2GO_IDENTIFIER:-auth.wheelz.lab} AUTHELIA_NOTIFIER_SMTP_SUBJECT: ${SMTP2GO_SUBJECT_PREFIX:-[Obin Auth]} {title} volumes: - ${TRUENAS_DOCKER_ROOT:-/mnt/HomeStorage02/Docker}/Authelia/config:/config security_opt: - no-new-privileges:true