# A STARTING POINT for Authelia in front of the private apps. Copy to # configuration.yml, replace every <...>, and read Authelia's docs on session # cookies and domains before exposing any of this beyond this machine. # # Generate each secret with: openssl rand -hex 32 theme: dark server: address: tcp://0.0.0.0:9091 log: level: info identity_validation: reset_password: jwt_secret: authentication_backend: file: path: /config/users_database.yml # Everything behind this stack is admin surface, so the default is the strict # one. Loosen deliberately, per rule, not by changing this line. access_control: default_policy: two_factor session: secret: cookies: # `domain` must match the hostname you actually type in the browser, and # `authelia_url` must be reachable from that browser — the login page is # a redirect target, not an internal call. - domain: localhost authelia_url: http://localhost:8085 default_redirection_url: http://localhost:8081 storage: encryption_key: local: path: /data/db.sqlite3 # Writes "emails" to a file. Enough to complete a first-time 2FA registration # without configuring SMTP; swap for a real notifier when you have one. notifier: filesystem: filename: /data/notification.txt