170 lines
6.2 KiB
YAML
170 lines
6.2 KiB
YAML
---
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: authelia
|
|
namespace: argo-cd
|
|
spec:
|
|
destination:
|
|
name: ''
|
|
namespace: apps-roboces
|
|
server: https://kubernetes.default.svc
|
|
sources:
|
|
- chart: authelia
|
|
repoURL: https://charts.authelia.com
|
|
targetRevision: 0.11.6
|
|
helm:
|
|
valuesObject:
|
|
enabled: true
|
|
pod:
|
|
autoscaling:
|
|
enabled: true
|
|
kind: Deployment
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 128Mi
|
|
limits:
|
|
cpu: 1
|
|
memory: 1024Mi
|
|
service:
|
|
type: LoadBalancer
|
|
port: 9091
|
|
ingress:
|
|
enabled: true
|
|
className: traefik
|
|
annotations:
|
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
|
traefik.ingress.kubernetes.io/router.tls: "true"
|
|
secret:
|
|
existingSecret: secrets-authelia
|
|
mountPath: /secrets
|
|
additionalSecrets:
|
|
secrets-authelia:
|
|
path: secrets-authelia
|
|
items:
|
|
- key: authentication.ldap.password.txt
|
|
path: authentication.ldap.password.txt
|
|
- key: identity_validation.reset_password.jwt.hmac.key
|
|
path: identity_validation.reset_password.jwt.hmac.key
|
|
- key: session.encryption.key
|
|
path: session.encryption.key
|
|
- key: smtp_password.txt
|
|
path: smtp_password.txt
|
|
- key: storage.encryption.key
|
|
path: storage.encryption.key
|
|
- key: oidc.audiobookshelf.client_secret
|
|
path: oidc.audiobookshelf.client_secret
|
|
- key: identity_providers.oidc.jwks.key.pem
|
|
path: identity_providers.oidc.jwks.key.pem
|
|
persistence:
|
|
enabled: true
|
|
existingClaim: authelia-data
|
|
configMap:
|
|
log:
|
|
level: info
|
|
session:
|
|
name: authelia_session
|
|
same_site: lax
|
|
expiration: 1 hour
|
|
inactivity: 5 minutes
|
|
remember_me: 1 month
|
|
cookies:
|
|
- domain: roboces.dev
|
|
subdomain: auth
|
|
- domain: auth.fuku
|
|
subdomain: ''
|
|
authentication_backend:
|
|
ldap:
|
|
enabled: true
|
|
implementation: lldap
|
|
address: ldap://lldap.apps-fuku.svc.cluster.local:3890
|
|
base_dn: dc=fuku,dc=local
|
|
additional_users_dn: ou=people
|
|
users_filter: (&({username_attribute}={input})(objectClass=person))
|
|
additional_groups_dn: ou=groups
|
|
groups_filter: (member={dn})
|
|
user: uid=admin,ou=people,dc=fuku,dc=local
|
|
attributes:
|
|
distinguished_name: dn
|
|
username: uid
|
|
display_name: cn
|
|
mail: mail
|
|
member_of: memberOf
|
|
group_name: cn
|
|
password:
|
|
disabled: false
|
|
secret_name: secrets-authelia
|
|
path: authentication.ldap.password.txt
|
|
storage:
|
|
local:
|
|
enabled: true
|
|
path: /config/db.sqlite3
|
|
notifier:
|
|
smtp:
|
|
enabled: true
|
|
address: submissions://mail.fukurokuju.dev:465
|
|
sender: Authelia <auth@fukurokuju.dev>
|
|
subject: "Your verification code is {code}"
|
|
identifier: auth.fuku
|
|
startup_check_address: test@authelia.com
|
|
disable_html_emails: false
|
|
disable_require_tls: false
|
|
disable_starttls: false
|
|
username: auth@fukurokuju.dev
|
|
password:
|
|
disabled: false
|
|
secret_name: secrets-authelia
|
|
path: smtp_password.txt
|
|
tls:
|
|
server_name: mail.fukurokuju.dev
|
|
skip_verify: false
|
|
minimum_version: TLS1.2
|
|
access_control:
|
|
default_policy: two_factor
|
|
identity_providers:
|
|
oidc:
|
|
enabled: true
|
|
hmac_secret:
|
|
path: identity_providers.oidc.hmac.key
|
|
jwks:
|
|
- key_id: authelia
|
|
algorithm: RS256
|
|
use: sig
|
|
key:
|
|
path: /secrets/secrets-authelia/identity_providers.oidc.jwks.key.pem
|
|
clients:
|
|
- client_id: audiobookshelf
|
|
client_name: Audiobookshelf
|
|
client_secret:
|
|
path: /secrets/secrets-authelia/oidc.audiobookshelf.client_secret
|
|
public: false
|
|
authorization_policy: two_factor
|
|
require_pkce: true
|
|
pkce_challenge_method: S256
|
|
redirect_uris:
|
|
- https://audiobooks.roboces.dev/audiobookshelf/auth/openid/callback
|
|
- https://audiobooks.roboces.dev/audiobookshelf/auth/openid/mobile-redirect
|
|
- https://audiobooks.fuku/audiobookshelf/auth/openid/callback
|
|
- https://audiobooks.fuku/audiobookshelf/auth/openid/mobile-redirect
|
|
- audiobookshelf://oauth
|
|
scopes:
|
|
- openid
|
|
- profile
|
|
- groups
|
|
- email
|
|
response_types:
|
|
- code
|
|
grant_types:
|
|
- authorization_code
|
|
access_token_signed_response_alg: none
|
|
userinfo_signed_response_alg: none
|
|
token_endpoint_auth_method: client_secret_basic
|
|
- repoURL: https://git.roboces.dev/catalin/fukuops.git
|
|
path: k8s/services/authelia
|
|
targetRevision: main
|
|
project: roboces
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|