Files
notes/docs/home-server/authentication.md
T

82 lines
2.9 KiB
Markdown

---
schema_version: 1
id: home-server.authentication
type: reference
scope: [jupiter, authelia, forward-auth, secrets]
sensitivity: private-infrastructure
last_reviewed: "2026-10-06"
sources:
- kind: owner-report
reference: "Deployed Authelia file matches repository; Portainer supplies environment variables, 2026-10-06"
- kind: owner-report
reference: "Portainer state added to Backrest plan, 2026-10-06"
- kind: owner-report
reference: "All stack environment values/secrets managed in Portainer; GitHub access uses PAT, 2026-10-06"
- kind: owner-report
reference: "No independent credential recovery except restic key, 2026-10-06"
- kind: repository
repository: jupiter-stacks
revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15
paths:
- stacks/authelia/configuration.yml
- stacks/authelia/docker-compose.yml
related: [home-server.reference, home-server.networking, home-server.portainer, home-server.backups, home-server.deployment]
update_triggers: [access-policy-change, authentication-change, secret-rotation, middleware-change]
unknowns:
- authelia-file-placeholder-expansion-mechanism
---
# Authentication
| Component | Configuration |
| --- | --- |
| Portal | `https://auth.umbra.mom` |
| Backend | File `/config/users_database.yml`; Argon2id |
| Second factor | TOTP; issuer `Jupiter` |
| Policy | Default deny; listed domains require `two_factor` |
| Session cookie domain | `umbra.mom` |
| Default redirect | `https://sonarr.umbra.mom` |
| Storage | SQLite `/data/db.sqlite3`; storage encryption key |
| Notifications | Filesystem `/data/notification.txt` |
Two-factor domains: `sonarr`, `radarr`, `prowlarr`, `logs`, `notes`, `backups`
under `umbra.mom`.
## Enforcement
Protected routers attach `authelia@docker`:
```text
Traefik -> http://authelia:9091/api/authz/forward-auth
```
`trustForwardHeader=true`; response headers:
`Remote-User, Remote-Groups, Remote-Email, Remote-Name`.
Policy applies only to requests routed through forward-auth. It is not a
global gate for every service or directly published port.
## Configuration / secrets
Host `/data/authelia/{configuration.yml,users_database.yml}` mounts read-only
under `/config`; `/data/authelia` also mounts read-write at `/data`.
Stack variable overrides/secrets are managed in Portainer; Compose retains
non-secret configuration. Authelia environment:
```text
AUTHELIA_SESSION_SECRET
AUTHELIA_STORAGE_ENCRYPTION_KEY
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET
```
Checked-in YAML also contains `${AUTHELIA_*}` placeholders. Container environment
injection alone does not prove mounted-file substitution; expansion mechanism
unconfirmed.
Authelia data remains outside the supplied backup plan.
[Portainer state](portainer.md) is covered; secret recovery remains untested.
No independent recovery arrangement exists for stack secrets.
GitHub repository access uses a PAT; host SSH keys and tunnel credential files
are separate from stack environment variables.