theme: grey log: file_path: /config/authelia.log keep_stdout: true # Stockage (fichier SQLite local) – suffisant pour commencer storage: local: path: /config/db.sqlite3 # Base de données des utilisateurs (fichier) authentication_backend: file: path: /config/users.yml # Accès par défaut (à ajuster selon tes besoins) access_control: default_policy: 'one_factor' rules: - domain: - "paperless.crenam.space" - "git.crenam.space" - "task.crenam.space" - "seafile.crenam.space" policy: one_factor # Session et cookie session: cookies: - name: authelia_session domain: crenam.space authelia_url: "https://auth.crenam.space" default_redirection_url: "https://dashboard.crenam.space" expiration: "16h" remember_me: "1 month" # sercret # Notifications (par mail – on laisse vide pour le moment, pas de SMTP) notifier: disable_startup_check: true filesystem: filename: /config/notifications.yml # ban regulation if attempt to penetrate the network without authorization regulation: modes: - "user" max_retries: 5 ban_time: '10m' find_time: '2m' # identity_validation: # definitions: # user_attributes: # username # email # nickname # if needed, it will be lldap # ldap: http://localhost:111 # # identity_providers: # oidc: # # hmac secret is used for OAuth2 tokens # hmac_secret: # # jwks issuer is needed to configure multiple jwk. Must be based on RS256 algorithm # # or on 2048 bit RSA/PA key # jwks: # # recommended not to configure this # - key_id: {{ secret "/secrets/private.pem" | mindent 10 "|" | msquote }} # # key algorithm # algorithm: "RS256" # use: "sig" # key: | # -----BEGIN PRIVATE KEY----- # -----END PRIVATE KEY----- # # Optionnally matchin certificate in PEM DER form # certificate_chain: {{ secret "/secrets/public.crt" | mindent 10 "|" | msquote }} # # the signing algorithm used for signing discovery and metdata responses # # most client ignore this so set it to none # discovery_signed_response_alg: 'none' # # the signing key used for signing discovery and metdata responses # # most client ignore this so set it to '' # discovery_signed_response_key_id: '' # # authorization policies # authorization_policy: # policy_name: # default_policy: 'two_factor' # rules: # - policy: 'one_factor' # subject: 'group:services' # clients: ######################################### # sso configuration for vikunja # ######################################### # - client_id: 'vikunja' # client_name: 'Vikunja' # # generated with # client_secret: '$pbkdf2-sha512$310000$hPnUYU6BCaRSZYulOiWXwA$5hsAJD494cyoQ/X9JlAbsMF//yGDg009lfDe2WhGQ> # public: false # redirect_uris: # - 'https://task.crenam.space/auth/openid/authelia' # - 'https://task.crenam.space/login?redirectToProvider=authentik' # # # audience this client is allowed to request # audience: [] # # scopes this client is allowed to request # scopes: # - # # # list of response modes the client support # response_modes: # - 'form_post' # - 'query' # # the policy required for this client # # can also be the key names fot eh authorization policies section # authorization_policy: 'one_factor' # require_pkce: false # pkce_challenge_method: '' # scopes: # - 'openid' # - 'profile' # - 'email' # response_types: # - 'code' # grant_types: # - 'authorization_code' # access_token_signed_response_alg: 'none' # userinfo_signed_response_alg: 'none' # token_endpoint_auth_method: 'client_secret_post' ######################################### # config sso for gitea # ######################################### # - client_id: 'gitea' # client_name: 'Gitea' # client_secret: '$pbkdf2-sha512$310000$pJR7colZSiWF7SWIfUsoqg$IGGqIZGVqcpXpzVCBgptZ3zBMqpFk4oaIKvOZPa1f> # public: false # authorization_policy: 'one_factor' # require_pkce: false # pkce_challenge_method: '' # redirect_uris: # - 'https://git.crenam.space/user/oauth2/authelia/callback' # scopes: # - 'openid' # - 'email' # - 'profile' # response_types: # - 'code' # grant_types: # - 'authorization_code' # access_token_signed_response_alg: 'none' # userinfo_signed_response_alg: 'none' # token_endpoint_auth_method: 'client_secret_basic'