Files
homelab-infra/apps/authelia/secret.example.yaml
T
panxiao81 88a02ababa
lint / yaml (push) Has been cancelled
lint / ansible (push) Has been cancelled
lint / terraform (push) Has been cancelled
Establish clean homelab infrastructure baseline
Reorganize the brownfield repository, remove retired and generated artifacts, harden ignore rules, and record the GitOps/IaC redesign.
2026-09-09 16:47:20 +00:00

38 lines
1.7 KiB
YAML

# Template. Copy to secret.yaml, fill in real values, apply, then `helm upgrade`.
# secret.yaml is gitignored — same convention as ../../platform/cert-manager, ../netbox,
# ../smtp-relay, ../../infrastructure/cloudflared and ../gitea.
#
# values.yaml sets `secret.existingSecret: authelia-secrets`, so the chart mounts
# THIS Secret instead of generating one from inline `value:` fields. Every
# `path:` in values.yaml resolves against it.
#
# ⚠ The mount path is /secrets/internal, NOT /secrets/authelia-secrets. Relative
# paths in values.yaml are composed by the chart; the one absolute path (the JWKS
# key) must say /secrets/internal explicitly.
#
# Key names below are exactly the ones the chart generates by default, so they
# must not be renamed without changing the matching `path:` in values.yaml.
#
# ⚠ identity_providers.oidc.jwks.main.pem is the OIDC SIGNING KEY. Replacing it
# invalidates every issued token estate-wide. It lives here rather than as a
# `value:` in values.yaml because the chart inlines `value:` jwks keys into the
# ConfigMap in plaintext.
---
apiVersion: v1
kind: Secret
metadata:
name: authelia-secrets
namespace: authelia
type: Opaque
stringData:
authentication.ldap.password.txt: REPLACE_WITH_SVC_AUTHELIA_LDAP_PASSWORD
storage.postgres.password.txt: REPLACE_WITH_AUTHELIA_DB_PASSWORD
storage.encryption.key: REPLACE_WITH_64_HEX_CHARS
session.encryption.key: REPLACE_WITH_RANDOM_SECRET
identity_validation.reset_password.jwt.hmac.key: REPLACE_WITH_RANDOM_SECRET
identity_providers.oidc.hmac.key: REPLACE_WITH_RANDOM_SECRET
identity_providers.oidc.jwks.main.pem: |
-----BEGIN PRIVATE KEY-----
REPLACE_WITH_RS256_PRIVATE_KEY
-----END PRIVATE KEY-----