Files
homelab-v/k8s/infra/auth/authelia/values.yaml
T
renovate[bot]Vegard Hagenrenovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
6fd4d4b15c chore(deps): renovate 2025-09-28
chore(deps): update dependency grafana/grafana-operator to v5.19.4 (#368)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update dependency unpoller/unpoller to v2.15.4 (#380)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update github actions (#369)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Vegard Stenhjem Hagen <[email protected]>

chore(deps): update helm release kube-prometheus-stack to v75.18.1 (#370)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update terraform google to ~> 6.50.0 (#372)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update netbird (#373)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update sealed-secrets docker tag to v2.5.19 (#374)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update cloudflare/cloudflared docker tag to v2025.9.1 (#375)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update cilium (#379)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update media containers (#377)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update docker.io/adguard/adguardhome docker tag to v0.107.66 (#381)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update docker.io/lldap/lldap docker tag to v0.6.2 (#382)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update ghcr.io/authelia/authelia docker tag to v4.39.10 (#383)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update helm release authelia to v0.10.46 (#384)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update helm release node-feature-discovery to v0.17.4 (#385)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update proxmox-csi-plugin docker tag to v0.3.14 (#386)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update dependency kubernetes/kubernetes to v1.34.1 (#387)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update dependency siderolabs/talos to v1.11.2 (#388)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update docker.io/grafana/grafana docker tag to v12.2.0 (#389)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update ghcr.io/advplyr/audiobookshelf docker tag to v2.29.0 (#390)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update helm release argo-cd to v8.5.7 (#391)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update helm release cloudnative-pg to v0.26.0 (#392)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update intel device plugins to v0.34.0 (#393)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update registry.k8s.io/git-sync/git-sync docker tag to v4.5.0 (#394)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update terraform proxmox to v0.84.0 (#395)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update terraform talos to v0.9.0 (#396)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update actions/checkout action to v5 (#397)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update ghcr.io/home-operations/radarr docker tag to v6 (#398)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update helm release kube-prometheus-stack to v77 (#399)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore(deps): update terraform google to v7 (#400)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: Vegard Hagen <[email protected]>
2025-09-28 17:59:30 +02:00

245 lines
8.8 KiB
YAML

# https://github.com/authelia/chartrepo/blob/master/charts/authelia/values.yaml
image:
registry: ghcr.io
repository: authelia/authelia
tag: 4.39.10 # renovate: docker=ghcr.io/authelia/authelia
pullPolicy: IfNotPresent
pod:
kind: Deployment
env:
- name: TZ
value: Europe/Oslo
- name: AUTHELIA_NOTIFIER_SMTP_USERNAME
valueFrom:
secretKeyRef: { name: smtp-credentials, key: username }
extraVolumeMounts:
- name: consent
mountPath: /config/assets/locales/en/consent.json
subPath: consent.json
extraVolumes:
- name: consent
configMap:
defaultMode: 0644
name: consent
configMap:
default_2fa_method: totp
theme: dark
log:
level: info
telemetry:
metrics:
enabled: true
port: 9959
serviceMonitor:
enabled: true
access_control:
default_policy: deny
rules:
- domain_regex: ^.*\.stonegarden.dev$
policy: two_factor
session:
cookies: [ { domain: stonegarden.dev } ]
server:
asset_path: /config/assets/
storage:
postgres:
enabled: true
deploy: false
address: tcp://authelia-postgres-rw:5432
database: authelia
username: authelia
password: { secret_name: authelia-postgres-app }
notifier:
smtp:
enabled: true
address: smtp://smtp.mailersend.net:587
sender: Authelia <[email protected]>
disable_html_emails: false
password: { secret_name: smtp-credentials }
authentication_backend:
ldap:
enabled: true
implementation: lldap
address: ldaps://lldap.stonegarden.dev
base_dn: DC=stonegarden,DC=dev
user: UID=authelia,OU=people,DC=stonegarden,DC=dev
password: { secret_name: lldap-credentials }
attributes:
extra:
argocd: { multi_valued: true, value_type: string }
audiobookshelf: { multi_valued: true, value_type: string }
grafana: { multi_valued: true, value_type: string }
identity_providers:
oidc:
## Currently in beta stage. See https://www.authelia.com/r/openid-connect/
enabled: true
jwks:
- key_id: default
algorithm: RS256
use: sig
key: { path: /secrets/jwk-rsa/tls.key }
certificate_chain: { path: /secrets/jwk-rsa/tls.crt }
- key_id: ecdsa256
algorithm: ES256
use: sig
key: { path: /secrets/jwk-ecdsa/tls.key }
certificate_chain: { path: /secrets/jwk-ecdsa/tls.crt }
cors:
allowed_origins_from_client_redirect_uris: true
endpoints: [ userinfo, authorization, token, revocation, introspection ]
claims_policies:
argocd_policy:
custom_claims: { argocd_claim: { attribute: argocd } }
# Argo CD requires the claims other than `groups` to be in the ID Token https://github.com/argoproj/argo-cd/issues/23768
id_token: [ email, email_verified, alt_emails, name, preferred_username, argocd_claim ]
audiobookshelf:
custom_claims: { audiobookshelf: { attribute: audiobookshelf } }
grafana:
custom_claims: { grafana: { attribute: grafana } }
legacy:
# https://www.authelia.com/integration/openid-connect/openid-connect-1.0-claims/#restore-functionality-prior-to-claims-parameter
id_token: [ email, email_verified, alt_emails, name, preferred_username, groups ]
username_email:
id_token: [ email, email_verified, alt_emails, name, preferred_username ]
scopes:
argocd_scope:
claims: [ argocd_claim ]
audiobookshelf:
claims: [ audiobookshelf ]
grafana:
claims: [ grafana ]
clients:
- client_id: argocd
client_secret: { path: /secrets/client-argocd/client_secret.txt }
client_name: Argo CD
public: false
authorization_policy: two_factor
claims_policy: argocd_policy
pre_configured_consent_duration: 3 months
require_pkce: false
redirect_uris:
- https://argocd.stonegarden.dev/auth/callback
- https://argocd.stonegarden.dev/applications
scopes: [ openid, email, profile, offline_access, argocd_scope ]
grant_types: [ authorization_code, refresh_token ]
userinfo_signed_response_alg: none
id_token_signed_response_alg: ES256
access_token_signed_response_alg: ES256
- client_id: argocd-cli
client_name: Argo CD (CLI)
public: true
authorization_policy: two_factor
claims_policy: argocd_policy
pre_configured_consent_duration: 3 months
redirect_uris: [ http://localhost:8085/auth/callback ]
scopes: [ openid, email, profile, offline_access, argocd_scope ]
id_token_signed_response_alg: ES256
access_token_signed_response_alg: ES256
revocation_endpoint_auth_method: none
introspection_endpoint_auth_method: none
pushed_authorization_request_endpoint_auth_method: none
- client_id: audiobookshelf
client_secret: { path: /secrets/client-audiobookshelf/client_secret.txt }
client_name: Audiobookshelf
public: false
authorization_policy: one_factor
claims_policy: audiobookshelf
pre_configured_consent_duration: 3 months
require_pkce: true
redirect_uris:
- https://abs.stonegarden.dev/audiobookshelf/auth/openid/callback
- https://abs.stonegarden.dev/audiobookshelf/auth/openid/mobile-redirect
- audiobookshelf://oauth
scopes: [ openid, email, profile, offline_access, audiobookshelf ]
grant_types: [ authorization_code, refresh_token ]
id_token_signed_response_alg: ES256
access_token_signed_response_alg: ES256
- client_id: grafana
client_secret: { path: /secrets/client-grafana/client_secret.txt }
client_name: Grafana
public: false
authorization_policy: two_factor
claims_policy: grafana
pre_configured_consent_duration: 3 months
require_pkce: true
pkce_challenge_method: S256
redirect_uris: [ https://grafana.stonegarden.dev/login/generic_oauth ]
scopes: [ openid, email, profile, offline_access, grafana ]
response_types: [ code ]
grant_types: [ authorization_code, refresh_token ]
userinfo_signed_response_alg: none
id_token_signed_response_alg: ES256
access_token_signed_response_alg: ES256
token_endpoint_auth_method: client_secret_basic
- client_id: kubectl
client_name: kubectl
public: true
authorization_policy: two_factor
claims_policy: legacy
pre_configured_consent_duration: 3 months
require_pkce: true
redirect_uris: [ http://localhost:8000, http://localhost:18000 ]
scopes: [ openid, email, profile, offline_access, groups ]
grant_types: [ authorization_code, refresh_token ]
revocation_endpoint_auth_method: none
introspection_endpoint_auth_method: none
pushed_authorization_request_endpoint_auth_method: none
- client_id: netbird
client_secret: { path: /secrets/client-netbird/client_secret.txt }
client_name: NetBird
public: false
authorization_policy: two_factor
claims_policy: username_email
pre_configured_consent_duration: 3 months
require_pkce: true
pkce_challenge_method: S256
audience: [ netbird ]
redirect_uris:
- http://localhost:53000
- https://netbird.stonegarden.dev/callback
- https://netbird.stonegarden.dev/silent-callback
scopes: [ openid, profile, email, offline_access ]
grant_types: [ authorization_code, refresh_token ]
token_endpoint_auth_method: client_secret_post
secret:
existingSecret: crypto
additionalSecrets:
authelia-postgres-app:
items: [ { key: password, path: storage.postgres.password.txt } ]
lldap-credentials:
items: [ { key: password, path: authentication.ldap.password.txt } ]
smtp-credentials:
items: [ { key: password, path: notifier.smtp.password.txt } ]
jwk-rsa:
items:
- { key: tls.key, path: tls.key }
- { key: tls.crt, path: tls.crt }
jwk-ecdsa:
items:
- { key: tls.key, path: tls.key }
- { key: tls.crt, path: tls.crt }
client-argocd:
items: [ { key: clientSecret, path: client_secret.txt } ]
client-audiobookshelf:
items: [ { key: clientSecret, path: client_secret.txt } ]
client-grafana:
items: [ { key: clientSecret, path: client_secret.txt } ]
client-netbird:
items: [ { key: clientSecret, path: client_secret.txt } ]