Authelia is an open-source authentication and authorization server and portal fulfilling the identity and access management (IAM) role of information security in providing multi-factor authentication and single sign-on (SSO) for your applications via a web portal. It acts as a companion for common reverse proxies.
Install with:
helm repo add app-template oci://ghcr.io/bjw-s-labs/charts/
helm install authelia app-template/app-template -f values.yamlSee examples from other people.
| Name | Repo | Stars | Version | Timestamp |
|---|---|---|---|---|
| authelia | Diaoul/home-ops | 115 | 5.0.0 | a month ago |
| authelia | mchestr/home-cluster | 169 | 5.0.1 | 2 months ago |
See the most popular values for this chart:
| Key | Types |
|---|---|
persistence.config.name (21) authelia-configmap | string |
persistence.config.type (21) configMap | string |
persistence.config.globalMounts[].path (18) /config/configuration.yaml | string |
persistence.config.globalMounts[].subPath (18) configuration.yaml | string |
| boolean | |
| boolean | |
persistence.config.advancedMounts.authelia.app[].path (2) /config/configuration.yaml | string |
| boolean | |
persistence.config.advancedMounts.authelia.app[].subPath (2) configuration.yaml | string |
persistence.config.mountPath (1) /config/configuration.yaml | string |
| boolean | |
persistence.config.subPath (1) configuration.yaml | string |
persistence.secret-files.name (5) authelia-files | string |
| string | |
| boolean | |
persistence.secret-files.globalMounts[].path (3) /config/secret | string |
| string | |
persistence.secrets.globalMounts[].path (3) /config/secrets | string |
| boolean | |
persistence.secrets.name (3) authelia | string |
| string | |
| boolean | |
persistence.clients.globalMounts[].path (2) /secrets/clients.yml | string |
| string | |
persistence.clients.name (2) authelia-secret | string |
| string | |
persistence.data.existingClaim (2) ${PVC_NAME} | string |
| string | |
persistence.jwks.globalMounts[].path (2) /secrets/jwks.yml | string |
| string | |
persistence.jwks.name (2) authelia-secret | string |
| string | |
| string | |
persistence.tmp.type (2) emptyDir | string |
persistence.trusted-certs.advancedMounts.authelia.app[].path (2) /trusted_certs/letsencrypt-certs.pem | string |
| boolean | |
persistence.trusted-certs.advancedMounts.authelia.app[].subPath (2) letsencrypt-certs.pem | string |
persistence.trusted-certs.name (2) letsencrypt-certs | string |
persistence.trusted-certs.type (2) configMap | string |
persistence.dbsecret.globalMounts[].path (1) /config/pgsqlsecret | string |
| boolean | |
persistence.dbsecret.name (1) pgsql-authelia | string |
| string | |
| string | |
persistence.oidc-cert.name (1) authelia-oidc-tls | string |
| string | |
| string | |
persistence.oidc-client-secrets.name (1) authelia-oidc-client-secrets | string |
| string | |
persistence.oidc-config.advancedMounts.authelia.app[].path (1) /config/authelia.oidc.yaml | string |
| boolean | |
persistence.oidc-config.advancedMounts.authelia.app[].subPath (1) authelia.oidc.yaml | string |
persistence.oidc-config.name (1) default-oidc | string |
| string | |
| boolean | |
persistence.secret-keys.globalMounts[].path (1) /config/secret | string |
persistence.secret-keys.name (1) authelia-secret-keys | string |
| string | |
persistence.users.globalMounts[].path (1) /config/users.yaml | string |
| boolean | |
| string | |
persistence.users.name (1) authelia-users | string |
| string | |
| string | |
controllers.authelia.containers.app.image.repository (17) ghcr.io/authelia/authelia | string |
controllers.authelia.containers.app.image.tag (17) 4.39.20@sha256:1b363e9279e742397966333f364e0876ae02bf5c876de73e83af6d48c57ff51b | string |
| string | |
| string | |
| string | |
| string | |
| boolean | |
| boolean | |
| number | |
| string | |
| number | |
| number | |
| number | |
| number | |
| boolean | |
| boolean | |
| number | |
| string | |
| number | |
| number | |
| number | |
| number | |
| boolean | |
| boolean | |
| number | |
| string | |
| number | |
| number | |
| number | |
| number | |
| string, boolean | |
| string | |
| string | |
| string, boolean | |
| string | |
controllers.authelia.containers.app.env.X_AUTHELIA_CONFIG (11) /config/configuration.yaml | string |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_AUTHENTICATION_BACKEND_LDAP_PASSWORD_FILE (3) /app/secrets/AUTHELIA_AUTHENTICATION_BACKEND_LDAP_PASSWORD | string |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_SESSION_SECRET_FILE (3) /app/secrets/AUTHELIA_SESSION_SECRET | string |
controllers.authelia.containers.app.env.AUTHELIA_STORAGE_ENCRYPTION_KEY_FILE (3) /app/secrets/AUTHELIA_STORAGE_ENCRYPTION_KEY | string |
| string | |
| string | |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_DUO_API_INTEGRATION_KEY_FILE (2) /app/secrets/AUTHELIA_DUO_API_INTEGRATION_KEY | string |
controllers.authelia.containers.app.env.AUTHELIA_DUO_API_SECRET_KEY_FILE (2) /app/secrets/AUTHELIA_DUO_API_SECRET_KEY | string |
controllers.authelia.containers.app.env.AUTHELIA_IDENTITY_PROVIDERS_OIDC_HMAC_SECRET_FILE (2) /app/secrets/AUTHELIA_IDENTITY_PROVIDERS_OIDC_HMAC_SECRET | string |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_NOTIFIER_SMTP_ADDRESS (2) smtp.${SECRET_DOMAIN}:25 | string |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_NOTIFIER_SMTP_PASSWORD_FILE (2) /app/secrets/AUTHELIA_NOTIFIER_SMTP_PASSWORD | string |
| number | |
controllers.authelia.containers.app.env.AUTHELIA_STORAGE_POSTGRES_PASSWORD_FILE (2) /app/secrets/AUTHELIA_STORAGE_POSTGRES_PASSWORD | string |
| string | |
| string | |
| string | |
| string | |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_AUTHENTICATION_BACKEND_LDAP_ADDRESS (1) ldap://lldap.security.svc.cluster.local:389 | string |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_AUTHENTICATION_BACKEND_LDAP_USER.secretKeyRef.key (1) AUTHELIA_AUTHENTICATION_BACKEND_LDAP_USER | string |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_AUTHENTICATION_BACKEND_LDAP_USER (1) uid=admin,ou=people,dc=home,dc=arpa | string |
controllers.authelia.containers.app.env.AUTHELIA_AUTHENTICATION_BACKEND_LDAP_USERS_FILTER (1) (&({username_attribute}={input})(objectClass=person)) | string |
| string | |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET_FILE (1) /config/secrets/AUTHELIA_JWT_SECRET | string |
controllers.authelia.containers.app.env.AUTHELIA_NOTIFIER_SMTP_SENDER (1) Authelia <authelia@${SECRET_DOMAIN}> | string |
| string | |
| string | |
controllers.authelia.containers.app.env.AUTHELIA_STORAGE_POSTGRES_ADDRESS (1) authelia-primary.default.svc | string |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
controllers.authelia.containers.app.env.SECRET_DOMAIN (1) ${SECRET_DOMAIN} | string |
controllers.authelia.containers.app.env.SECRET_PUBLIC_DOMAIN (1) ${SECRET_PUBLIC_DOMAIN} | string |
| boolean | |
| string | |
| boolean | |
controllers.authelia.containers.app.args[] (5) - --config | string |
controllers.authelia.containers.authelia.env.X_AUTHELIA_CONFIG (2) /config/configuration.yaml | string |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
controllers.authelia.containers.authelia.envFrom[].secretRef.name (2) authelia-secret | string |
controllers.authelia.containers.authelia.image.repository (2) ghcr.io/authelia/authelia | string |
| string | |
| boolean | |
| boolean | |
| number | |
| string | |
| number | |
| number | |
| number | |
| number | |
| boolean | |
| boolean | |
| number | |
| string | |
| number | |
| number | |
| number | |
| number | |
| string | |
| string | |
| string | |
| boolean | |
| string | |
| boolean | |
| string | |
| string | |
| string | |
| string | |
| string | |
controllers.authelia.containers.anubis.env.TARGET (1) http://localhost:80 | string |
| string | |
controllers.authelia.containers.anubis.image.repository (1) ghcr.io/techarohq/anubis | string |
| string | |
| number | |
controllers.authelia.containers.anubis.ports[].name (1) authelia | string |
| string | |
| string | |
| string | |
| boolean | |
| string | |
| boolean | |
| number | |
controllers.authelia.strategy (14) RollingUpdate | string |
| string | |
controllers.authelia.initContainers.init-db.image.repository (8) ghcr.io/home-operations/postgres-init | string |
controllers.authelia.initContainers.init-db.image.tag (8) 18.4.0@sha256:ebd9d30add17acdf935d73eb004758c7dfd9388aaa605fda70ad74378ab92aec | string, number |
| string | |
| string | |
controllers.authelia.initContainers.01-init-db.image.repository (2) ghcr.io/home-operations/postgres-init | string |
controllers.authelia.initContainers.01-init-db.image.tag (2) 18.4.0@sha256:ebd9d30add17acdf935d73eb004758c7dfd9388aaa605fda70ad74378ab92aec | string |
| number | |
| boolean | |
| number | |
| string | |
| number | |
| string | |
| string | |
| number | |
controllers.authelia.pod.topologySpreadConstraints[].topologyKey (4) kubernetes.io/hostname | string |
| string | |
| boolean | |
| string | |
controllers.authelia.type (2) deployment | string |
| string | |
controllers.main.containers.main.env.AUTHELIA_SERVER_ADDRESS (1) tcp://0.0.0.0:9191 | string |
| string | |
controllers.main.containers.main.env.X_AUTHELIA_CONFIG (1) /config/configuration.yaml | string |
| string | |
controllers.main.containers.main.image.repository (1) ghcr.io/authelia/authelia | string |
controllers.main.containers.main.image.tag (1) 4.39.20@sha256:1b363e9279e742397966333f364e0876ae02bf5c876de73e83af6d48c57ff51b | string |
| boolean | |
| boolean | |
| number | |
| string | |
| number | |
| number | |
| number | |
| number | |
| boolean | |
| boolean | |
| number | |
| string | |
| number | |
| number | |
| number | |
| number | |
| boolean | |
| string | |
| string | |
| string | |
| string | |
controllers.main.initContainers.01-init-db.env.INIT_POSTGRES_HOST (1) postgres-lb.storage.svc.cluster.local | string |
controllers.main.initContainers.01-init-db.env.INIT_POSTGRES_PASS (1) ${AUTHELIA_STORAGE_POSTGRES_PASSWORD} | string |
controllers.main.initContainers.01-init-db.env.INIT_POSTGRES_SUPER_PASS (1) ${POSTGRES_SUPER_PASS} | string |
controllers.main.initContainers.01-init-db.env.INIT_POSTGRES_USER (1) ${AUTHELIA_STORAGE_POSTGRES_USERNAME} | string |
| string | |
controllers.main.initContainers.01-init-db.image.repository (1) ghcr.io/home-operations/postgres-init | string |
| number | |
| boolean | |
| number | |
| string | |
| number | |
| number | |
| string | |
| number | |
controllers.main.pod.topologySpreadConstraints[].topologyKey (1) kubernetes.io/hostname | string |
| string | |
| number | |
controllers.main.strategy (1) RollingUpdate | string |
| number | |
| boolean | |
| number | |
| boolean | |
service.app.controller (15) authelia | string |
service.app.ipFamilyPolicy (3) PreferDualStack | string |
| number | |
| boolean | |
| string | |
| number | |
| string | |
| number | |
service.authelia.controller (1) authelia | string |
| number | |
| boolean | |
| number | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| boolean | |
| string | |
| string | |
| string | |
| boolean | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
route.app.hostnames[] (14) - auth.${SECRET_DOMAIN} | string |
route.app.parentRefs[].name (14) envoy-external | string |
| string | |
| string | |
| number, string | |
| string | |
| string | |
route.app.rules[].filters[].type (2) ResponseHeaderModifier | string |
route.app.rules[].filters[].requestHeaderModifier.set[].name (1) Cache-Control | string |
route.app.rules[].filters[].requestHeaderModifier.set[].value (1) no-store | string |
route.app.rules[].filters[].responseHeaderModifier.set[].name (1) X-Frame-Options | string |
route.app.rules[].filters[].responseHeaderModifier.set[].value (1) SAMEORIGIN | string |
| string | |
route.app.annotations.glance/icon (2) https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/authelia.png | string |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
route.app.annotations."gethomepage.dev/icon" (1) authelia.svg | string |
| string | |
route.authelia.hostnames[] (2) - auth.${CLUSTER_DOMAIN} | string |
route.authelia.parentRefs[].name (2) envoy-external | string |
| string | |
| string | |
route.authelia.annotations."gethomepage.dev/description" (1) Open-source authentication and authorization server | string |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
route.main.hostnames[] (2) - auth.${SECRET_DOMAIN} | string |
route.main.parentRefs[].name (2) envoy-external | string |
route.main.parentRefs[].namespace (2) networking | string |
| string | |
route.main.annotations."gatus.home-operations.com/endpoint" (1) group: infrastructure
| string |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
route.internal.hostnames[] (1) - auth.${SECRET_DOMAIN} | string |
route.internal.parentRefs[].name (1) envoy-internal | string |
| string | |
| number | |
| number | |
| boolean | |
| string | |
| number | |
| string | |
| boolean | |
| string | |
| number | |
defaultPodOptions.topologySpreadConstraints[].topologyKey (5) kubernetes.io/hostname | string |
| string | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
ingress.app.className (2) external | string |
ingress.app.hosts[].host (2) auth.${SECRET_DOMAIN} | string |
| string | |
| string | |
| string | |
ingress.app.annotations."external-dns.alpha.kubernetes.io/target" (1) external.${SECRET_DOMAIN} | string |
ingress.app.annotations."nginx.ingress.kubernetes.io/configuration-snippet" (1) add_header Cache-Control "no-store";
add_header Pragma "no-cache";
add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
| string |
ingress.main.annotations."external-dns.alpha.kubernetes.io/target" (1) ingress.${ORG_DOMAIN} | string |
ingress.main.annotations."hajimari.io/icon" (1) mdi:shield-account | string |
ingress.main.annotations."nginx.ingress.kubernetes.io/configuration-snippet" (1) add_header Cache-Control "no-store";
add_header Pragma "no-cache";
add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
| string |
| boolean | |
ingress.main.hosts[].host (1) auth.${ORG_DOMAIN} | string |
| string | |
| string | |
| string | |
ingress.main.tls[].hosts[] (1) - auth.${ORG_DOMAIN} | string |
args[] (1) - --config | string |
| string | |
| number | |
controller.strategy (1) RollingUpdate | string |
| string | |
| string | |
env.AUTHELIA_AUTHENTICATION_BACKEND_LDAP_ADDRESS (1) ldap://lldap.auth.svc.cluster.local:389 | string |
| string | |
| string | |
| string | |
| string | |
env.AUTHELIA_AUTHENTICATION_BACKEND_LDAP_BASE_DN (1) dc=home,dc=arpa | string |
| string | |
| string | |
| string | |
| string | |
env.AUTHELIA_AUTHENTICATION_BACKEND_LDAP_USER (1) uid=admin,ou=people,dc=home,dc=arpa | string |
env.AUTHELIA_AUTHENTICATION_BACKEND_LDAP_USERS_FILTER (1) (&({username_attribute}={input})(objectClass=person)) | string |
| string | |
env.AUTHELIA_DEFAULT_REDIRECTION_URL (1) https://auth.${ORG_DOMAIN} | string |
| string | |
| string | |
| string | |
env.AUTHELIA_NOTIFIER_SMTP_SENDER (1) Authelia <noreply@${NET_DOMAIN}> | string |
env.AUTHELIA_SERVER_ADDRESS (1) tcp://:80 | string |
| string | |
env.AUTHELIA_SESSION_DOMAIN (1) ${ORG_DOMAIN} | string |
| number | |
env.AUTHELIA_SESSION_REDIS_HOST (1) redis.default.svc.cluster.local | string |
env.AUTHELIA_STORAGE_POSTGRES_ADDRESS (1) postgres.database.svc.cluster.local:5432 | string |
| string | |
env.AUTHELIA_STORAGE_POSTGRES_DATABASE.valueFrom.secretKeyRef.name (1) database-authelia-user | string |
| string | |
env.AUTHELIA_STORAGE_POSTGRES_PASSWORD.valueFrom.secretKeyRef.name (1) database-authelia-user | string |
| string | |
env.AUTHELIA_STORAGE_POSTGRES_USERNAME.valueFrom.secretKeyRef.name (1) database-authelia-user | string |
env.AUTHELIA_TELEMETRY_METRICS_ADDRESS (1) tcp://0.0.0.0:8080 | string |
| string | |
| string | |
env.AUTHELIA_TOTP_ISSUER (1) authelia.com | string |
| string | |
envFrom[].secretRef.name (1) authelia-secret | string |
image.repository (1) ghcr.io/authelia/authelia | string |
image.tag (1) master@sha256:c1a838724e95a3ebc9ca210f0d81fc25a77e47e0b583f146c5781e1701a4199f | string |
| number | |
podSecurityContext.fsGroupChangePolicy (1) OnRootMismatch | string |
| number | |
| number | |
| boolean | |
| boolean | |
| number | |
probes.liveness.spec.httpGet.path (1) /api/health | string |
| number | |
| number | |
| number | |
| number | |
| boolean | |
| boolean | |
| number | |
probes.readiness.spec.httpGet.path (1) /api/health | string |
| number | |
| number | |
| number | |
| number | |
| boolean | |
| string | |
| string | |
| string | |
| string | |
| number | |
topologySpreadConstraints[].topologyKey (1) kubernetes.io/hostname | string |
topologySpreadConstraints[].whenUnsatisfiable (1) DoNotSchedule | string |