--- schema_version: 1 id: home-server.authentication type: reference scope: [jupiter, authelia, forward-auth, secrets] sensitivity: private-infrastructure last_reviewed: "2026-10-06" sources: - kind: owner-report reference: "Deployed Authelia file matches repository; Portainer supplies environment variables, 2026-10-06" - kind: owner-report reference: "Portainer state added to Backrest plan, 2026-10-06" - kind: owner-report reference: "All stack environment values/secrets managed in Portainer; GitHub access uses PAT, 2026-10-06" - kind: owner-report reference: "No independent credential recovery except restic key, 2026-10-06" - kind: repository repository: jupiter-stacks revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15 paths: - stacks/authelia/configuration.yml - stacks/authelia/docker-compose.yml related: [home-server.reference, home-server.networking, home-server.portainer, home-server.backups, home-server.deployment] update_triggers: [access-policy-change, authentication-change, secret-rotation, middleware-change] unknowns: - authelia-file-placeholder-expansion-mechanism --- # Authentication | Component | Configuration | | --- | --- | | Portal | `https://auth.umbra.mom` | | Backend | File `/config/users_database.yml`; Argon2id | | Second factor | TOTP; issuer `Jupiter` | | Policy | Default deny; listed domains require `two_factor` | | Session cookie domain | `umbra.mom` | | Default redirect | `https://sonarr.umbra.mom` | | Storage | SQLite `/data/db.sqlite3`; storage encryption key | | Notifications | Filesystem `/data/notification.txt` | Two-factor domains: `sonarr`, `radarr`, `prowlarr`, `logs`, `notes`, `backups` under `umbra.mom`. ## Enforcement Protected routers attach `authelia@docker`: ```text Traefik -> http://authelia:9091/api/authz/forward-auth ``` `trustForwardHeader=true`; response headers: `Remote-User, Remote-Groups, Remote-Email, Remote-Name`. Policy applies only to requests routed through forward-auth. It is not a global gate for every service or directly published port. ## Configuration / secrets Host `/data/authelia/{configuration.yml,users_database.yml}` mounts read-only under `/config`; `/data/authelia` also mounts read-write at `/data`. Stack variable overrides/secrets are managed in Portainer; Compose retains non-secret configuration. Authelia environment: ```text AUTHELIA_SESSION_SECRET AUTHELIA_STORAGE_ENCRYPTION_KEY AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET ``` Checked-in YAML also contains `${AUTHELIA_*}` placeholders. Container environment injection alone does not prove mounted-file substitution; expansion mechanism unconfirmed. Authelia data remains outside the supplied backup plan. [Portainer state](portainer.md) is covered; secret recovery remains untested. No independent recovery arrangement exists for stack secrets. GitHub repository access uses a PAT; host SSH keys and tunnel credential files are separate from stack environment variables.