forked from coop-cloud/authentik
Compare commits
2 Commits
password_b
...
patch_kima
Author | SHA1 | Date | |
---|---|---|---|
18aca9d362 | |||
ba779c430e |
@ -30,7 +30,6 @@ steps:
|
|||||||
SECRET_ADMIN_TOKEN_VERSION: v1
|
SECRET_ADMIN_TOKEN_VERSION: v1
|
||||||
SECRET_ADMIN_PASS_VERSION: v1
|
SECRET_ADMIN_PASS_VERSION: v1
|
||||||
SECRET_EMAIL_PASS_VERSION: v1
|
SECRET_EMAIL_PASS_VERSION: v1
|
||||||
DB_ENTRYPOINT_VERSION: v1
|
|
||||||
trigger:
|
trigger:
|
||||||
branch:
|
branch:
|
||||||
- main
|
- main
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
TYPE=authentik
|
TYPE=authentik
|
||||||
TIMEOUT=900
|
TIMEOUT=900
|
||||||
ENABLE_AUTO_UPDATE=true
|
ENABLE_AUTO_UPDATE=true
|
||||||
# POST_DEPLOY_CMDS="worker worker apply_blueprints|worker add_applications"
|
# POST_DEPLOY_CMDS="worker set_admin_pass|worker apply_blueprints|worker add_applications"
|
||||||
LETS_ENCRYPT_ENV=production
|
LETS_ENCRYPT_ENV=production
|
||||||
|
|
||||||
DOMAIN=authentik.example.com
|
DOMAIN=authentik.example.com
|
||||||
@ -34,6 +34,7 @@ SECRET_ADMIN_PASS_VERSION=v1
|
|||||||
SECRET_EMAIL_PASS_VERSION=v1
|
SECRET_EMAIL_PASS_VERSION=v1
|
||||||
|
|
||||||
# X_FRAME_OPTIONS_ALLOW_FROM=dashboard.example.org
|
# X_FRAME_OPTIONS_ALLOW_FROM=dashboard.example.org
|
||||||
|
AUTHENTIK_COLOR_BACKGROUND_LIGHT=#1c1e21
|
||||||
|
|
||||||
## FLOW OPTIONS
|
## FLOW OPTIONS
|
||||||
# WELCOME_MESSAGE="Welcome to Authentik"
|
# WELCOME_MESSAGE="Welcome to Authentik"
|
||||||
@ -46,12 +47,6 @@ COPY_ASSETS="flow_background.jpg|app:/web/dist/assets/images/"
|
|||||||
COPY_ASSETS="$COPY_ASSETS icon_left_brand.svg|app:/web/dist/assets/icons/"
|
COPY_ASSETS="$COPY_ASSETS icon_left_brand.svg|app:/web/dist/assets/icons/"
|
||||||
COPY_ASSETS="$COPY_ASSETS icon.png|app:/web/dist/assets/icons/"
|
COPY_ASSETS="$COPY_ASSETS icon.png|app:/web/dist/assets/icons/"
|
||||||
|
|
||||||
# Default CSS customisation, just background colour
|
|
||||||
COMPOSE_FILE="$COMPOSE_FILE:compose.css.yml"
|
|
||||||
AUTHENTIK_COLOR_BACKGROUND_LIGHT=#1c1e21
|
|
||||||
# Custommise the entire custom CSS file
|
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.css.yml"
|
|
||||||
|
|
||||||
# COMPOSE_FILE="$COMPOSE_FILE:compose.nextcloud.yml"
|
# COMPOSE_FILE="$COMPOSE_FILE:compose.nextcloud.yml"
|
||||||
# NEXTCLOUD_DOMAIN=nextcloud.example.com
|
# NEXTCLOUD_DOMAIN=nextcloud.example.com
|
||||||
# SECRET_NEXTCLOUD_ID_VERSION=v1
|
# SECRET_NEXTCLOUD_ID_VERSION=v1
|
||||||
|
@ -35,6 +35,7 @@ abra app secret generate -a <app_name>
|
|||||||
abra app undeploy <app_name>
|
abra app undeploy <app_name>
|
||||||
abra app deploy <app_name>
|
abra app deploy <app_name>
|
||||||
abra app cmd <app_name> db rotate_db_pass
|
abra app cmd <app_name> db rotate_db_pass
|
||||||
|
abra app cmd <app_name> app set_admin_pass
|
||||||
```
|
```
|
||||||
|
|
||||||
## Add SSO for Nextcloud
|
## Add SSO for Nextcloud
|
||||||
|
46
abra.sh
46
abra.sh
@ -56,24 +56,43 @@ with open('/tmp/$1', newline='') as file:
|
|||||||
email = row[2].strip()
|
email = row[2].strip()
|
||||||
groups = row[3].split(';')
|
groups = row[3].split(';')
|
||||||
if User.objects.filter(username=username):
|
if User.objects.filter(username=username):
|
||||||
print(f'{username} already exists')
|
|
||||||
continue
|
continue
|
||||||
new_user = User.objects.create(name=name, username=username, email=email)
|
new_user = User.objects.create(name=name, username=username, email=email)
|
||||||
print(f'{username} created')
|
|
||||||
for group_name in groups:
|
for group_name in groups:
|
||||||
group_name = group_name.strip()
|
group_name = group_name.strip()
|
||||||
if Group.objects.filter(name=group_name):
|
if Group.objects.filter(name=group_name):
|
||||||
group = Group.objects.get(name=group_name)
|
group = Group.objects.get(name=group_name)
|
||||||
else:
|
else:
|
||||||
group = Group.objects.create(name=group_name)
|
group = Group.objects.create(name=group_name)
|
||||||
print(f'{group_name} created')
|
|
||||||
group.users.add(new_user)
|
group.users.add(new_user)
|
||||||
print(f'add {username} to group {group_name}')
|
|
||||||
""" 2>&1 | quieten
|
""" 2>&1 | quieten
|
||||||
}
|
}
|
||||||
|
|
||||||
set_admin_pass() {
|
set_admin_pass() {
|
||||||
echo "The set_admin_pass function is depricated"
|
password=$(cat /run/secrets/admin_pass)
|
||||||
|
token=$(cat /run/secrets/admin_token)
|
||||||
|
/manage.py shell -c """
|
||||||
|
akadmin = User.objects.get(username='akadmin')
|
||||||
|
akadmin.set_password('$password')
|
||||||
|
akadmin.save()
|
||||||
|
print('Changed akadmin password')
|
||||||
|
|
||||||
|
from authentik.core.models import TokenIntents
|
||||||
|
key='$token'
|
||||||
|
if (token:= Token.objects.filter(identifier='authentik-bootstrap-token').first()):
|
||||||
|
token.key=key
|
||||||
|
token.save()
|
||||||
|
print('Changed authentik-bootstrap-token')
|
||||||
|
else:
|
||||||
|
Token.objects.create(
|
||||||
|
identifier='authentik-bootstrap-token',
|
||||||
|
user=akadmin,
|
||||||
|
intent=TokenIntents.INTENT_API,
|
||||||
|
expiring=False,
|
||||||
|
key=key,
|
||||||
|
)
|
||||||
|
print('Created authentik-bootstrap-token')
|
||||||
|
""" 2>&1 | quieten
|
||||||
}
|
}
|
||||||
|
|
||||||
rotate_db_pass() {
|
rotate_db_pass() {
|
||||||
@ -153,9 +172,7 @@ for name, url in applications.items():
|
|||||||
|
|
||||||
|
|
||||||
quieten(){
|
quieten(){
|
||||||
# 'SyntaxWarning|version_regex|"http\['
|
grep -v -e '{"event"' -e '{"action"'
|
||||||
# is a workaround to get rid of some verbose syntax warnings, this might be fixed with another version
|
|
||||||
grep -Pv '"level": "(info|debug)"|SyntaxWarning|version_regex|"http\[|RuntimeWarning:'
|
|
||||||
}
|
}
|
||||||
|
|
||||||
add_email_templates(){
|
add_email_templates(){
|
||||||
@ -206,16 +223,3 @@ Brand.objects.filter(default=True).delete()
|
|||||||
""" 2>&1 | quieten
|
""" 2>&1 | quieten
|
||||||
apply_blueprints
|
apply_blueprints
|
||||||
}
|
}
|
||||||
|
|
||||||
get_certificate() {
|
|
||||||
/manage.py shell -c """
|
|
||||||
provider_name='$1'
|
|
||||||
if not provider_name:
|
|
||||||
print('no Provider Name given')
|
|
||||||
exit(1)
|
|
||||||
provider = Provider.objects.filter(name=provider_name).first()
|
|
||||||
saml = provider.samlprovider
|
|
||||||
cert = saml.signing_kp
|
|
||||||
print(''.join(cert.certificate_data.splitlines()[1:-1]))
|
|
||||||
""" 2>&1 | quieten
|
|
||||||
}
|
|
||||||
|
@ -1,76 +0,0 @@
|
|||||||
nextcloud:
|
|
||||||
uncomment:
|
|
||||||
- compose.nextcloud.yml
|
|
||||||
- NEXTCLOUD_DOMAIN
|
|
||||||
- SECRET_NEXTCLOUD_ID_VERSION
|
|
||||||
- SECRET_NEXTCLOUD_SECRET_VERSION
|
|
||||||
- nextcloud.png
|
|
||||||
wordpress:
|
|
||||||
uncomment:
|
|
||||||
- compose.wordpress.yml
|
|
||||||
- WORDPRESS_DOMAIN
|
|
||||||
- WORDPRESS_GROUP
|
|
||||||
- SECRET_WORDPRESS_ID_VERSION
|
|
||||||
- SECRET_WORDPRESS_SECRET_VERSION
|
|
||||||
- wordpress.png
|
|
||||||
matrix-synapse:
|
|
||||||
uncomment:
|
|
||||||
- compose.matrix.yml
|
|
||||||
- ELEMENT_DOMAIN
|
|
||||||
- SECRET_MATRIX_ID_VERSION
|
|
||||||
- SECRET_MATRIX_SECRET_VERSION
|
|
||||||
- matrix.svg
|
|
||||||
secrets:
|
|
||||||
matrix_id: matrix
|
|
||||||
wekan:
|
|
||||||
uncomment:
|
|
||||||
- compose.wekan.yml
|
|
||||||
- WEKAN_DOMAIN
|
|
||||||
- SECRET_WEKAN_ID_VERSION
|
|
||||||
- SECRET_WEKAN_SECRET_VERSION
|
|
||||||
- wekan.png
|
|
||||||
secrets:
|
|
||||||
wekan_id: wekan
|
|
||||||
vikunja:
|
|
||||||
uncomment:
|
|
||||||
- compose.vikunja.yml
|
|
||||||
- VIKUNJA_DOMAIN
|
|
||||||
- SECRET_VIKUNJA_ID_VERSION
|
|
||||||
- SECRET_VIKUNJA_SECRET_VERSION
|
|
||||||
- vikunja.svg
|
|
||||||
secrets:
|
|
||||||
vikunja_id: vikunja
|
|
||||||
monitoring:
|
|
||||||
uncomment:
|
|
||||||
- compose.monitoring.yml
|
|
||||||
- MONITORING_DOMAIN
|
|
||||||
- SECRET_MONITORING_ID_VERSION
|
|
||||||
- SECRET_MONITORING_SECRET_VERSION
|
|
||||||
- monitoring.png
|
|
||||||
outline:
|
|
||||||
uncomment:
|
|
||||||
- compose.outline.yml
|
|
||||||
- OUTLINE_DOMAIN
|
|
||||||
- SECRET_OUTLINE_ID_VERSION
|
|
||||||
- SECRET_OUTLINE_SECRET_VERSION
|
|
||||||
- outline.png
|
|
||||||
secrets:
|
|
||||||
outline_id: outline
|
|
||||||
rallly:
|
|
||||||
uncomment:
|
|
||||||
- compose.rallly.yml
|
|
||||||
- RALLLY_DOMAIN
|
|
||||||
- SECRET_RALLLY_ID_VERSION
|
|
||||||
- SECRET_RALLLY_SECRET_VERSION
|
|
||||||
- rallly.png
|
|
||||||
secrets:
|
|
||||||
rallly_id: rallly
|
|
||||||
hedgedoc:
|
|
||||||
uncomment:
|
|
||||||
- compose.hedgedoc.yml
|
|
||||||
- HEDGEDOC_DOMAIN
|
|
||||||
- SECRET_HEDGEDOC_ID_VERSION
|
|
||||||
- SECRET_HEDGEDOC_SECRET_VERSION
|
|
||||||
- hedgedoc.png
|
|
||||||
secrets:
|
|
||||||
hedgedoc_id: hedgedoc
|
|
@ -1,14 +0,0 @@
|
|||||||
---
|
|
||||||
version: '3.8'
|
|
||||||
|
|
||||||
services:
|
|
||||||
app:
|
|
||||||
configs:
|
|
||||||
- source: custom_css
|
|
||||||
target: /web/dist/custom.css
|
|
||||||
|
|
||||||
configs:
|
|
||||||
custom_css:
|
|
||||||
name: ${STACK_NAME}_custom_css_${CUSTOM_CSS_VERSION}
|
|
||||||
file: custom.css.tmpl
|
|
||||||
template_driver: golang
|
|
17
compose.yml
17
compose.yml
@ -8,8 +8,6 @@ x-env: &env
|
|||||||
- AUTHENTIK_REDIS__HOST=redis
|
- AUTHENTIK_REDIS__HOST=redis
|
||||||
- AUTHENTIK_ERROR_REPORTING__ENABLED
|
- AUTHENTIK_ERROR_REPORTING__ENABLED
|
||||||
- AUTHENTIK_SECRET_KEY=file:///run/secrets/secret_key
|
- AUTHENTIK_SECRET_KEY=file:///run/secrets/secret_key
|
||||||
- AUTHENTIK_BOOTSTRAP_PASSWORD=file:///run/secrets/admin_pass
|
|
||||||
- AUTHENTIK_BOOTSTRAP_TOKEN=file:///run/secrets/admin_token
|
|
||||||
- AUTHENTIK_EMAIL__HOST
|
- AUTHENTIK_EMAIL__HOST
|
||||||
- AUTHENTIK_EMAIL__PORT
|
- AUTHENTIK_EMAIL__PORT
|
||||||
- AUTHENTIK_EMAIL__USERNAME
|
- AUTHENTIK_EMAIL__USERNAME
|
||||||
@ -34,7 +32,7 @@ x-env: &env
|
|||||||
version: '3.8'
|
version: '3.8'
|
||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
image: ghcr.io/goauthentik/server:2024.4.2
|
image: ghcr.io/goauthentik/server:2024.2.3
|
||||||
command: server
|
command: server
|
||||||
depends_on:
|
depends_on:
|
||||||
- db
|
- db
|
||||||
@ -49,6 +47,9 @@ services:
|
|||||||
- media:/media
|
- media:/media
|
||||||
- assets:/web/dist/assets
|
- assets:/web/dist/assets
|
||||||
- templates:/templates
|
- templates:/templates
|
||||||
|
configs:
|
||||||
|
- source: custom_css
|
||||||
|
target: /web/dist/custom.css
|
||||||
networks:
|
networks:
|
||||||
- internal
|
- internal
|
||||||
- proxy
|
- proxy
|
||||||
@ -75,11 +76,11 @@ services:
|
|||||||
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
|
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
|
||||||
- "traefik.http.middlewares.${STACK_NAME}-frameOptions.headers.customFrameOptionsValue=SAMEORIGIN"
|
- "traefik.http.middlewares.${STACK_NAME}-frameOptions.headers.customFrameOptionsValue=SAMEORIGIN"
|
||||||
- "traefik.http.middlewares.${STACK_NAME}-frameOptions.headers.contentSecurityPolicy=frame-ancestors ${X_FRAME_OPTIONS_ALLOW_FROM}"
|
- "traefik.http.middlewares.${STACK_NAME}-frameOptions.headers.contentSecurityPolicy=frame-ancestors ${X_FRAME_OPTIONS_ALLOW_FROM}"
|
||||||
- "coop-cloud.${STACK_NAME}.version=6.1.1+2024.4.2"
|
- "coop-cloud.${STACK_NAME}.version=5.1.2+2024.2.3"
|
||||||
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
|
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
|
||||||
|
|
||||||
worker:
|
worker:
|
||||||
image: ghcr.io/goauthentik/server:2024.4.2
|
image: ghcr.io/goauthentik/server:2024.2.3
|
||||||
command: worker
|
command: worker
|
||||||
depends_on:
|
depends_on:
|
||||||
- db
|
- db
|
||||||
@ -114,7 +115,7 @@ services:
|
|||||||
environment: *env
|
environment: *env
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: postgres:15.7
|
image: postgres:15.5
|
||||||
secrets:
|
secrets:
|
||||||
- db_password
|
- db_password
|
||||||
configs:
|
configs:
|
||||||
@ -185,6 +186,10 @@ volumes:
|
|||||||
database:
|
database:
|
||||||
|
|
||||||
configs:
|
configs:
|
||||||
|
custom_css:
|
||||||
|
name: ${STACK_NAME}_custom_css_${CUSTOM_CSS_VERSION}
|
||||||
|
file: custom.css.tmpl
|
||||||
|
template_driver: golang
|
||||||
flow_authentication:
|
flow_authentication:
|
||||||
name: ${STACK_NAME}_flow_authentication_${FLOW_AUTHENTICATION_VERSION}
|
name: ${STACK_NAME}_flow_authentication_${FLOW_AUTHENTICATION_VERSION}
|
||||||
file: flow_authentication.yaml.tmpl
|
file: flow_authentication.yaml.tmpl
|
||||||
|
@ -1 +0,0 @@
|
|||||||
Alerta! ⚠️ If you are using AUTHENTIK_COLOR_BACKGROUND_LIGHT, you will need to set COMPOSE_FILE="$COMPOSE_FILE:compose.css.yml"
|
|
@ -1 +0,0 @@
|
|||||||
Blueprint for Kimai SSO integration added
|
|
Reference in New Issue
Block a user