Upload files to "authelia"

This commit is contained in:
2026-06-19 18:08:49 +01:00
parent 8d703c2142
commit f16dfb82ca
+33 -33
View File
@@ -21,7 +21,7 @@
# certificates_directory: '/config/certificates/' # certificates_directory: '/config/certificates/'
## The theme to display: light, dark, grey, auto. ## The theme to display: light, dark, grey, auto.
theme: 'grey' theme: 'dark'
## Set the default 2FA method for new users and for when a user has a preferred method configured that has been ## Set the default 2FA method for new users and for when a user has a preferred method configured that has been
## disabled. This setting must be a method that is enabled. ## disabled. This setting must be a method that is enabled.
@@ -121,7 +121,7 @@ server:
## ##
log: log:
## Level of verbosity for logs: info, debug, trace. ## Level of verbosity for logs: info, debug, trace.
level: 'info' level: 'debug'
## Format the logs are written as: json, text. ## Format the logs are written as: json, text.
format: 'text' format: 'text'
@@ -438,13 +438,13 @@ authentication_backend:
## This is the recommended Authentication Provider in production ## This is the recommended Authentication Provider in production
## because it allows Authelia to offload the stateful operations ## because it allows Authelia to offload the stateful operations
## onto the LDAP service. ## onto the LDAP service.
# ldap: ldap:
## The address of the directory server to connect to in the address common syntax. ## The address of the directory server to connect to in the address common syntax.
## Format: [<scheme>://]<hostname>[:<port>]. ## Format: [<scheme>://]<hostname>[:<port>].
## Square brackets indicate optional portions of the format. Scheme must be 'ldap', 'ldaps', or 'ldapi`. ## Square brackets indicate optional portions of the format. Scheme must be 'ldap', 'ldaps', or 'ldapi`.
## The default scheme is 'ldapi' if the address is an absolute path otherwise it's 'ldaps'. ## The default scheme is 'ldapi' if the address is an absolute path otherwise it's 'ldaps'.
## The default port is '636', unless the scheme is 'ldap' in which case it's '389'. ## The default port is '636', unless the scheme is 'ldap' in which case it's '389'.
# address: 'ldaps://127.0.0.1:636' # address: 'lldap_lldap:3890'
## The LDAP implementation, this affects elements like the attribute utilized for resetting a password. ## The LDAP implementation, this affects elements like the attribute utilized for resetting a password.
## Acceptable options are as follows: ## Acceptable options are as follows:
@@ -457,19 +457,19 @@ authentication_backend:
## Depending on the option here certain other values in this section have a default value, notably all of the ## Depending on the option here certain other values in this section have a default value, notably all of the
## attribute mappings have a default value that this config overrides, you can read more about these default values ## attribute mappings have a default value that this config overrides, you can read more about these default values
## at https://www.authelia.com/c/ldap#defaults ## at https://www.authelia.com/c/ldap#defaults
# implementation: 'custom' implementation: 'lldap'
address: 'ldap://lldap_lldap:3890'
## The dial timeout for LDAP in the duration common syntax. ## The dial timeout for LDAP in the duration common syntax.
# timeout: '20 seconds' timeout: '10 seconds'
## Use StartTLS with the LDAP connection. ## Use StartTLS with the LDAP connection.
# start_tls: false # start_tls: false
## TLS configuration. ## TLS configuration.
# tls: tls:
## The server subject name to check the servers certificate against during the validation process. ## The server subject name to check the servers certificate against during the validation process.
## This option is not required if the certificate has a SAN which matches the address options hostname. ## This option is not required if the certificate has a SAN which matches the address options hostname.
# server_name: 'ldap.example.com' server_name: 'lldap_lldap'
## Skip verifying the server certificate entirely. In preference to setting this we strongly recommend you add the ## Skip verifying the server certificate entirely. In preference to setting this we strongly recommend you add the
## certificate or the certificate of the authority signing the certificate to the certificates directory which is ## certificate or the certificate of the authority signing the certificate to the certificates directory which is
@@ -477,7 +477,7 @@ authentication_backend:
## It's important to note the public key should be added to the directory, not the private key. ## It's important to note the public key should be added to the directory, not the private key.
## This option is strongly discouraged but may be useful in some self-signed situations where validation is not ## This option is strongly discouraged but may be useful in some self-signed situations where validation is not
## important to the administrator. ## important to the administrator.
# skip_verify: false skip_verify: true
## Minimum TLS version for the connection. ## Minimum TLS version for the connection.
# minimum_version: 'TLS1.2' # minimum_version: 'TLS1.2'
@@ -518,7 +518,7 @@ authentication_backend:
## The distinguished name of the container searched for objects in the directory information tree. ## The distinguished name of the container searched for objects in the directory information tree.
## See also: additional_users_dn, additional_groups_dn. ## See also: additional_users_dn, additional_groups_dn.
# base_dn: 'dc=example,dc=com' base_dn: 'dc=johnsnexus,dc=click'
## The additional_users_dn is prefixed to base_dn and delimited by a comma when searching for users. ## The additional_users_dn is prefixed to base_dn and delimited by a comma when searching for users.
## i.e. with this set to OU=Users and base_dn set to DC=a,DC=com; OU=Users,DC=a,DC=com is searched for users. ## i.e. with this set to OU=Users and base_dn set to DC=a,DC=com; OU=Users,DC=a,DC=com is searched for users.
@@ -536,7 +536,7 @@ authentication_backend:
## ##
## To allow sign in both with username and email, one can use a filter like ## To allow sign in both with username and email, one can use a filter like
## (&(|({username_attribute}={input})({mail_attribute}={input}))(objectClass=person)) ## (&(|({username_attribute}={input})({mail_attribute}={input}))(objectClass=person))
# users_filter: '(&({username_attribute}={input})(objectClass=person))' users_filter: '(&(|({username_attribute}={input})({mail_attribute}={input}))(objectClass=person))'
## The additional_groups_dn is prefixed to base_dn and delimited by a comma when searching for groups. ## The additional_groups_dn is prefixed to base_dn and delimited by a comma when searching for groups.
## i.e. with this set to OU=Groups and base_dn set to DC=a,DC=com; OU=Groups,DC=a,DC=com is searched for groups. ## i.e. with this set to OU=Groups and base_dn set to DC=a,DC=com; OU=Groups,DC=a,DC=com is searched for groups.
@@ -548,27 +548,27 @@ authentication_backend:
## ##
## If your groups use the `groupOfUniqueNames` structure use this instead: ## If your groups use the `groupOfUniqueNames` structure use this instead:
## (&(uniqueMember={dn})(objectClass=groupOfUniqueNames)) ## (&(uniqueMember={dn})(objectClass=groupOfUniqueNames))
# groups_filter: '(&(member={dn})(objectClass=groupOfNames))' groups_filter: '(&(member={dn})(objectClass=groupOfNames))'
## The group search mode to use. Options are 'filter' or 'memberof'. It's essential to read the docs if you wish to ## The group search mode to use. Options are 'filter' or 'memberof'. It's essential to read the docs if you wish to
## use 'memberof'. Also 'filter' is the best choice for most use cases. ## use 'memberof'. Also 'filter' is the best choice for most use cases.
# group_search_mode: 'filter' group_search_mode: 'filter'
## Follow referrals returned by the server. ## Follow referrals returned by the server.
## This is especially useful for environments where read-only servers exist. Only implemented for write operations. ## This is especially useful for environments where read-only servers exist. Only implemented for write operations.
# permit_referrals: false # permit_referrals: false
## The username and password of the admin user. ## The username and password of the admin user.
# user: 'cn=admin,dc=example,dc=com' user: 'UID=heimdall,OU=people,DC=johnsnexus,DC=click'
## Password can also be set using a secret: https://www.authelia.com/c/secrets ## Password can also be set using a secret: https://www.authelia.com/c/secrets
# password: 'password' password: 'ragnarok'
## The attributes for users and objects from the directory server. ## The attributes for users and objects from the directory server.
# attributes: # attributes:
## The distinguished name attribute if your directory server supports it. Users should read the docs before ## The distinguished name attribute if your directory server supports it. Users should read the docs before
## configuring. Only used for the 'memberof' group search mode. ## configuring. Only used for the 'memberof' group search mode.
# distinguished_name: '' # distinguished_name: 'Administrator'
## The attribute holding the username of the user. This attribute is used to populate the username in the session ## The attribute holding the username of the user. This attribute is used to populate the username in the session
## information. For your information, Microsoft Active Directory usually uses 'sAMAccountName' and OpenLDAP ## information. For your information, Microsoft Active Directory usually uses 'sAMAccountName' and OpenLDAP
@@ -606,21 +606,21 @@ authentication_backend:
## ##
## Important: Kubernetes (or HA) users must read https://www.authelia.com/t/statelessness ## Important: Kubernetes (or HA) users must read https://www.authelia.com/t/statelessness
## ##
file: # file:
path: '/config/users_database.yml' # path: '/config/users_database.yml'
watch: false # watch: false
search: # search:
email: false # email: false
case_insensitive: false # case_insensitive: false
password: # password:
algorithm: 'argon2' # algorithm: 'argon2'
argon2: # argon2:
variant: 'argon2id' # variant: 'argon2id'
iterations: 3 # iterations: 3
memory: 65536 # memory: 65536
parallelism: 4 # parallelism: 4
key_length: 32 # key_length: 32
salt_length: 16 # salt_length: 16
# scrypt: # scrypt:
# variant: 'scrypt' # variant: 'scrypt'
# iterations: 16 # iterations: 16
@@ -829,7 +829,7 @@ session:
## - The above 'domain' option MUST either: ## - The above 'domain' option MUST either:
## - Match the host portion of this URI. ## - Match the host portion of this URI.
## - Match the suffix of the host portion when prefixed with '.'. ## - Match the suffix of the host portion when prefixed with '.'.
authelia_url: 'https://auth.johnsnexus.click' authelia_url: 'https://auth.home.johnsnexus.click'
## Optional. The fully qualified URI used as the redirection location if the portal is accessed directly. Not ## Optional. The fully qualified URI used as the redirection location if the portal is accessed directly. Not
## configuring this option disables the automatic redirection behavior. ## configuring this option disables the automatic redirection behavior.