# Authelia TrueNAS environment example for Wheelz's HomeLab. # Copy to authelia-truenas.env on TrueNAS/Portainer and adjust runtime values there. # Do not commit real secrets, password hashes, recovery codes, or user passwords. AUTHELIA_IMAGE=authelia/authelia AUTHELIA_TAG=4.39.10 AUTHELIA_HTTP_PORT=9091 TZ=America/Chicago # Wheelz TrueNAS Docker directory pattern. TRUENAS_DOCKER_ROOT=/mnt/HomeStorage02/Docker # Bootstrap user written to /config/users_database.yml only when that file does not exist. AUTHELIA_BOOTSTRAP_USER=wheelz AUTHELIA_BOOTSTRAP_DISPLAY_NAME=Wheelz AUTHELIA_BOOTSTRAP_EMAIL=wheelz@example.invalid AUTHELIA_BOOTSTRAP_PASSWORD_HASH=replace_with_real_bcrypt_hash_generated_from_a_private_bootstrap_password # Runtime secrets. Generate long random values and keep them stable after first deployment. AUTHELIA_JWT_SECRET=replace_with_long_random_secret AUTHELIA_SESSION_SECRET=replace_with_long_random_secret AUTHELIA_STORAGE_ENCRYPTION_KEY=replace_with_long_random_secret # LLDAP user/group management GUI for Authelia LDAP backend. LLDAP_IMAGE=lldap/lldap LLDAP_TAG=stable LLDAP_HTTP_PORT=17170 LLDAP_UID=1000 LLDAP_GID=1000 LLDAP_LDAP_BASE_DN=dc=wheelz,dc=lab LLDAP_LDAP_USER_EMAIL=wheelz@example.invalid LLDAP_LDAP_USER_PASS=replace_with_private_lldap_admin_password LLDAP_JWT_SECRET=replace-with-random-secret LLDAP_KEY_SEED=replace-with-random-secret # Active Directory LDAP backend used by Authelia after AD cutover. # Keep the real bind password only in Portainer/runtime secrets, never in Gitea. AD_BIND_PASSWORD=replace-with-ad-bind-password # SMTP2GO notifier used by Authelia for MFA/device-registration and identity emails. # Keep the real SMTP password only in Portainer/runtime secrets, never in Gitea. SMTP2GO_HOST=mail.smtp2go.com SMTP2GO_PORT=587 SMTP2GO_USERNAME=replace-with-smtp2go-smtp-username SMTP2GO_PASSWORD=replace-with-smtp2go-smtp-password SMTP2GO_SENDER_ADDRESS=auth@wheelytho.com SMTP2GO_SENDER_NAME=Obin Auth SMTP2GO_IDENTIFIER=auth.wheelz.lab SMTP2GO_SUBJECT_PREFIX=[Obin Auth]