2.8 KiB
schema_version, id, type, scope, sensitivity, last_reviewed, sources, related, update_triggers, unknowns
| schema_version | id | type | scope | sensitivity | last_reviewed | sources | related | update_triggers | unknowns | |||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | home-server.authentication | reference |
|
private-infrastructure | 2026-10-06 |
|
|
|
|
Authentication
| Component | Configuration |
|---|---|
| Portal | https://auth.umbra.mom |
| Backend | File /config/users_database.yml; Argon2id |
| Second factor | TOTP; issuer Jupiter |
| Policy | Default deny; listed domains require two_factor |
| Session cookie domain | umbra.mom |
| Default redirect | https://sonarr.umbra.mom |
| Storage | SQLite /data/db.sqlite3; storage encryption key |
| Notifications | Filesystem /data/notification.txt |
Two-factor domains: sonarr, radarr, prowlarr, logs, notes, backups
under umbra.mom.
Enforcement
Protected routers attach authelia@docker:
Traefik -> http://authelia:9091/api/authz/forward-auth
trustForwardHeader=true; response headers:
Remote-User, Remote-Groups, Remote-Email, Remote-Name.
Policy applies only to requests routed through forward-auth. It is not a global gate for every service or directly published port.
Configuration / secrets
Host /data/authelia/{configuration.yml,users_database.yml} mounts read-only
under /config; /data/authelia also mounts read-write at /data.
Stack variable overrides/secrets are managed in Portainer; Compose retains non-secret configuration. Authelia environment:
AUTHELIA_SESSION_SECRET
AUTHELIA_STORAGE_ENCRYPTION_KEY
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET
Checked-in YAML also contains ${AUTHELIA_*} placeholders. Container environment
injection alone does not prove mounted-file substitution; expansion mechanism
unconfirmed.
Authelia data remains outside the supplied backup plan. Portainer state is covered; secret recovery remains untested. GitHub repository access uses a PAT; host SSH keys and tunnel credential files are separate from stack environment variables.