82 lines
2.9 KiB
Markdown
82 lines
2.9 KiB
Markdown
---
|
|
schema_version: 1
|
|
id: home-server.authentication
|
|
type: reference
|
|
scope: [jupiter, authelia, forward-auth, secrets]
|
|
sensitivity: private-infrastructure
|
|
last_reviewed: "2026-10-06"
|
|
sources:
|
|
- kind: owner-report
|
|
reference: "Deployed Authelia file matches repository; Portainer supplies environment variables, 2026-10-06"
|
|
- kind: owner-report
|
|
reference: "Portainer state added to Backrest plan, 2026-10-06"
|
|
- kind: owner-report
|
|
reference: "All stack environment values/secrets managed in Portainer; GitHub access uses PAT, 2026-10-06"
|
|
- kind: owner-report
|
|
reference: "No independent credential recovery except restic key, 2026-10-06"
|
|
- kind: repository
|
|
repository: jupiter-stacks
|
|
revision: 610e325ef6a98850511ce7a089b0b9a77bfecf15
|
|
paths:
|
|
- stacks/authelia/configuration.yml
|
|
- stacks/authelia/docker-compose.yml
|
|
related: [home-server.reference, home-server.networking, home-server.portainer, home-server.backups, home-server.deployment]
|
|
update_triggers: [access-policy-change, authentication-change, secret-rotation, middleware-change]
|
|
unknowns:
|
|
- authelia-file-placeholder-expansion-mechanism
|
|
---
|
|
|
|
# Authentication
|
|
|
|
| Component | Configuration |
|
|
| --- | --- |
|
|
| Portal | `https://auth.umbra.mom` |
|
|
| Backend | File `/config/users_database.yml`; Argon2id |
|
|
| Second factor | TOTP; issuer `Jupiter` |
|
|
| Policy | Default deny; listed domains require `two_factor` |
|
|
| Session cookie domain | `umbra.mom` |
|
|
| Default redirect | `https://sonarr.umbra.mom` |
|
|
| Storage | SQLite `/data/db.sqlite3`; storage encryption key |
|
|
| Notifications | Filesystem `/data/notification.txt` |
|
|
|
|
Two-factor domains: `sonarr`, `radarr`, `prowlarr`, `logs`, `notes`, `backups`
|
|
under `umbra.mom`.
|
|
|
|
## Enforcement
|
|
|
|
Protected routers attach `authelia@docker`:
|
|
|
|
```text
|
|
Traefik -> http://authelia:9091/api/authz/forward-auth
|
|
```
|
|
|
|
`trustForwardHeader=true`; response headers:
|
|
`Remote-User, Remote-Groups, Remote-Email, Remote-Name`.
|
|
|
|
Policy applies only to requests routed through forward-auth. It is not a
|
|
global gate for every service or directly published port.
|
|
|
|
## Configuration / secrets
|
|
|
|
Host `/data/authelia/{configuration.yml,users_database.yml}` mounts read-only
|
|
under `/config`; `/data/authelia` also mounts read-write at `/data`.
|
|
|
|
Stack variable overrides/secrets are managed in Portainer; Compose retains
|
|
non-secret configuration. Authelia environment:
|
|
|
|
```text
|
|
AUTHELIA_SESSION_SECRET
|
|
AUTHELIA_STORAGE_ENCRYPTION_KEY
|
|
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET
|
|
```
|
|
|
|
Checked-in YAML also contains `${AUTHELIA_*}` placeholders. Container environment
|
|
injection alone does not prove mounted-file substitution; expansion mechanism
|
|
unconfirmed.
|
|
|
|
Authelia data remains outside the supplied backup plan.
|
|
[Portainer state](portainer.md) is covered; secret recovery remains untested.
|
|
No independent recovery arrangement exists for stack secrets.
|
|
GitHub repository access uses a PAT; host SSH keys and tunnel credential files
|
|
are separate from stack environment variables.
|