# Drop-in: Authelia in front of the private apps. # # cp docker/authelia/configuration.yml.example docker/authelia/configuration.yml # cp docker/authelia/users_database.yml.example docker/authelia/users_database.yml # # edit both, then: # docker compose -f docker-compose.yml -f docker-compose.authelia.yml up -d # # Authelia is the established forward-auth standard and Apache-2.0 licensed. It # is also the heavier of the two options on purpose: it wants a YAML config file # and a database (SQLite is the smallest supported), so it is not a one-variable # setup the way Tinyauth is. Pick it if you already run it, or if you want 2FA # and per-app access rules that outlive this stack. # # Set in .env: # # ARCHILYZER_AUTH_MODE=forward # # The config file in docker/authelia/ is a STARTING POINT, not a hardened # deployment: read Authelia's docs on session/domain settings before exposing # any of this beyond your own machine. services: authelia: image: authelia/authelia:4.39 restart: unless-stopped networks: [archilyzer] volumes: - ./docker/authelia:/config - authelia-data:/data environment: X_AUTHELIA_CONFIG: /config/configuration.yml ports: - "${AUTHELIA_BIND:-127.0.0.1}:${AUTHELIA_HTTP_PORT:-8085}:9091" caddy: environment: ARCHILYZER_AUTH_MODE: forward ARCHILYZER_FORWARD_AUTH_UPSTREAM: authelia:9091 ARCHILYZER_FORWARD_AUTH_URI: /api/authz/forward-auth volumes: authelia-data: