From 2e55f3bb2fbf1d9f1dbfa4548b010adf3bf138cb Mon Sep 17 00:00:00 2001 From: FoxxMD Date: Wed, 16 Apr 2025 11:35:32 -0400 Subject: [PATCH] feat: Add Authentik --- authentik/.env.example | 5 ++ authentik/compose.yaml | 142 +++++++++++++++++++++++++++++++++++++++++ 2 files changed, 147 insertions(+) create mode 100644 authentik/.env.example create mode 100644 authentik/compose.yaml diff --git a/authentik/.env.example b/authentik/.env.example new file mode 100644 index 0000000..715208b --- /dev/null +++ b/authentik/.env.example @@ -0,0 +1,5 @@ +AUTHENTIK_TAG=2025.2 +PG_PASS=[[AUTHENTIK_PG_PASS]] +AUTHENTIK_SECRET_KEY=[[AUTHENTIK_SECRET_KEY]] +AUTHENTIK_TRAEFIK_OUTPUT_TOKEN=[[AUTHENTIK_TRAEFIK_OUTPUT_TOKEN]] +AUTHENTIK_TRAEFIK_EXT_OUTPOST_TOKEN=[[AUTHENTIK_TRAEFIK_EXT_OUTPOST_TOKEN]] diff --git a/authentik/compose.yaml b/authentik/compose.yaml new file mode 100644 index 0000000..8a60cdf --- /dev/null +++ b/authentik/compose.yaml @@ -0,0 +1,142 @@ +services: + authentik-postgresql: + image: docker.io/library/postgres:16-alpine + restart: unless-stopped + healthcheck: + test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"] + start_period: 20s + interval: 30s + retries: 5 + timeout: 5s + volumes: + - ./database:/var/lib/postgresql/data + environment: + POSTGRES_PASSWORD: ${PG_PASS:?database password required} + POSTGRES_USER: ${PG_USER:-authentik} + POSTGRES_DB: ${PG_DB:-authentik} + env_file: + - .env + networks: + - authentik_overlay + + authentik-redis: + image: docker.io/library/redis:alpine + command: --save 60 1 --loglevel warning + restart: unless-stopped + healthcheck: + test: ["CMD-SHELL", "redis-cli ping | grep PONG"] + start_period: 20s + interval: 30s + retries: 5 + timeout: 3s + volumes: + - redis_authentik:/data + networks: + - authentik_overlay + authentik-server: + image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2024.10.5} + restart: unless-stopped + command: server + environment: + AUTHENTIK_REDIS__HOST: authentik-redis + AUTHENTIK_POSTGRESQL__HOST: authentik-postgresql + AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik} + AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik} + AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS} + volumes: + - ./authentik/media:/media + - ./authentik/custom-templates:/templates + # - /var/run/docker.sock:/var/run/docker.sock + env_file: + - .env + # ports: + # - "${COMPOSE_PORT_HTTP:-9000}:9000" + # - "${COMPOSE_PORT_HTTPS:-9443}:9443" + networks: + - public_overlay + - authentik_overlay + depends_on: + authentik-postgresql: + condition: service_healthy + authentik-redis: + condition: service_healthy + labels: + homepage.group: Networking + homepage.name: Authentik + homepage.icon: authentik + homepage.href: "https://auth.CHANGEME.com" + traefik.enable: true + traefik.http.routers.authentik.rule: Host(`auth.CHANGEME.com`) + traefik.http.services.authentik.loadbalancer.server.port: 9000 + traefik.docker.network: public_overlay + traefik.public: true + authentik-proxy: + image: ghcr.io/goauthentik/proxy:${AUTHENTIK_TAG:-2024.10.5} + # ports: + # - 9000:9000 + # - 9443:9443 + networks: + - public_overlay + - authentik_overlay + environment: + AUTHENTIK_REDIS__HOST: authentik-redis + AUTHENTIK_HOST: http://authentik-server:9000 + AUTHENTIK_INSECURE: "true" + AUTHENTIK_TOKEN: ${AUTHENTIK_TRAEFIK_EXT_OUTPOST_TOKEN} + # Starting with 2021.9, you can optionally set this too + # when authentik_host for internal communication doesn't match the public URL + AUTHENTIK_HOST_BROWSER: https://auth.CHANGEME.com + # for logging edit log_level in outpost config from ui + labels: + traefik.enable: true + traefik.port: 9000 + traefik.http.routers.authentik-proxy.rule: Host(`CHANGEME.com`) && PathPrefix(`/outpost.goauthentik.io/`) + # `authentik-proxy` refers to the service name in the compose file. + traefik.http.middlewares.authentik-proxy.forwardauth.address: http://authentik-proxy:9000/outpost.goauthentik.io/auth/traefik + traefik.http.middlewares.authentik-proxy.forwardauth.trustForwardHeader: true + traefik.http.middlewares.authentik-proxy.forwardauth.authResponseHeaders: X-authentik-username,X-authentik-groups,X-authentik-entitlements,X-authentik-email,X-authentik-name,X-authentik-uid,X-authentik-jwt,X-authentik-meta-jwks,X-authentik-meta-outpost,X-authentik-meta-provider,X-authentik-meta-app,X-authentik-meta-version + traefik.public: true + kop.namespace: none + + restart: unless-stopped + worker: + image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2024.10.5} + restart: unless-stopped + command: worker + environment: + AUTHENTIK_REDIS__HOST: authentik-redis + AUTHENTIK_POSTGRESQL__HOST: authentik-postgresql + AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik} + AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik} + AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS} + # `user: root` and the docker socket volume are optional. + # See more for the docker socket integration here: + # https://goauthentik.io/docs/outposts/integrations/docker + # Removing `user: root` also prevents the worker from fixing the permissions + # on the mounted folders, so when removing this make sure the folders have the correct UID/GID + # (1000:1000 by default) + user: root + volumes: + - /var/run/docker.sock:/var/run/docker.sock + - .authentik/media:/media + - ./authentik/certs:/certs + - ./authentik/custom-templates:/templates + env_file: + - .env + depends_on: + authentik-postgresql: + condition: service_healthy + authentik-redis: + condition: service_healthy + networks: + - authentik_overlay + +networks: + authentik_overlay: + external: true + public_overlay: + external: true + +volumes: + redis_authentik: + driver: local \ No newline at end of file -- 2.51.2