Files
notes/docs/home-server/authentication.md
T
2026-10-06 16:33:29 +01:00

2.8 KiB

schema_version, id, type, scope, sensitivity, last_reviewed, sources, related, update_triggers, unknowns
schema_version id type scope sensitivity last_reviewed sources related update_triggers unknowns
1 home-server.authentication reference
jupiter
authelia
forward-auth
secrets
private-infrastructure 2026-10-06
kind reference
owner-report Deployed Authelia file matches repository; Portainer supplies environment variables, 2026-10-06
kind reference
owner-report Portainer state added to Backrest plan, 2026-10-06
kind reference
owner-report All stack environment values/secrets managed in Portainer; GitHub access uses PAT, 2026-10-06
kind repository revision paths
repository jupiter-stacks 610e325ef6a98850511ce7a089b0b9a77bfecf15
stacks/authelia/configuration.yml
stacks/authelia/docker-compose.yml
home-server.reference
home-server.networking
home-server.portainer
home-server.backups
home-server.deployment
access-policy-change
authentication-change
secret-rotation
middleware-change
authelia-file-placeholder-expansion-mechanism
off-host-authelia-secret-and-user-database-recovery

Authentication

Component Configuration
Portal https://auth.umbra.mom
Backend File /config/users_database.yml; Argon2id
Second factor TOTP; issuer Jupiter
Policy Default deny; listed domains require two_factor
Session cookie domain umbra.mom
Default redirect https://sonarr.umbra.mom
Storage SQLite /data/db.sqlite3; storage encryption key
Notifications Filesystem /data/notification.txt

Two-factor domains: sonarr, radarr, prowlarr, logs, notes, backups under umbra.mom.

Enforcement

Protected routers attach authelia@docker:

Traefik -> http://authelia:9091/api/authz/forward-auth

trustForwardHeader=true; response headers: Remote-User, Remote-Groups, Remote-Email, Remote-Name.

Policy applies only to requests routed through forward-auth. It is not a global gate for every service or directly published port.

Configuration / secrets

Host /data/authelia/{configuration.yml,users_database.yml} mounts read-only under /config; /data/authelia also mounts read-write at /data.

Stack variable overrides/secrets are managed in Portainer; Compose retains non-secret configuration. Authelia environment:

AUTHELIA_SESSION_SECRET
AUTHELIA_STORAGE_ENCRYPTION_KEY
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET

Checked-in YAML also contains ${AUTHELIA_*} placeholders. Container environment injection alone does not prove mounted-file substitution; expansion mechanism unconfirmed.

Authelia data remains outside the supplied backup plan. Portainer state is covered; secret recovery remains untested. GitHub repository access uses a PAT; host SSH keys and tunnel credential files are separate from stack environment variables.