Files
dockerserver-scott/reverseproxy/authelia/config/configuration.yml
2025-01-26 17:53:35 -06:00

121 lines
2.3 KiB
YAML
Executable File

theme: dark
jwt_secret: yyArMUrcQx4KXJLZm454NS
default_redirection_url: https://auth.wettsten.com
server:
host: 0.0.0.0
port: 9091
path: ""
read_buffer_size: 4096
write_buffer_size: 4096
enable_pprof: false
enable_expvars: false
disable_healthcheck: false
tls:
key: ""
certificate: ""
ntp:
address: "0.debian.pool.ntp.org:123"
version: 3
max_desync: 3s
disable_startup_check: true
disable_failure: true
log:
level: info
totp:
disable: false
issuer: wettsten.com
algorithm: sha1
digits: 6
period: 30
skew: 1
secret_size: 32
authentication_backend:
disable_reset_password: true
refresh_interval: 5m
file:
path: /config/users_database.yml
password:
algorithm: argon2id
iterations: 1
salt_length: 16
parallelism: 8
memory: 65536
access_control:
default_policy: deny
networks:
- name: internal
networks:
- '10.8.0.0/24'
- '172.16.0.0/12'
- '192.168.0.0/16'
rules:
## bypass all domains and subdomains from local ips
- domain:
- wettsten.com
- "*.wettsten.com"
networks:
- 'internal'
policy: bypass
## bypass api for subdomains
- domain:
- "*.wettsten.com"
resources:
- "^/api([/?].*)?$"
- "^/add([/?].*)?$"
- "^/public([/?].*)?$"
policy: bypass
# bypass subdomains
- domain:
- auth.wettsten.com
- bitwarden.wettsten.com
- jellyfin.wettsten.com
policy: bypass
# two_factor subdomains
- domain:
- wettsten.com
- "*.wettsten.com"
policy: two_factor
session:
name: authelia_session
domain: wettsten.com
same_site: lax
secret: MEMPBs5aRRDfWNRJLX6E
expiration: 6h
inactivity: 5m
remember_me_duration: 1w
regulation:
max_retries: 3
find_time: 10m
ban_time: 12h
storage:
local:
path: /config/db.sqlite3
encryption_key: iY7wSMosjZFQDAunYob3oShTcYCHtXx9
notifier:
disable_startup_check: true
smtp:
username: scott.wettstein@gmail.com
password: bwvvimaufuencerd
host: smtp.gmail.com
port: 587
sender: scott.wettstein@gmail.com
identifier: dockerserver
subject: "[Authelia] {title}"
startup_check_address: scott.wettstein@gmail.com
disable_require_tls: false
disable_html_emails: false
tls:
skip_verify: false
minimum_version: TLS1.2