This commit is contained in:
암냥 2026-09-07 11:16:13 +09:00
commit 006bcb47ce
3 changed files with 27 additions and 7 deletions

View file

@ -2,6 +2,7 @@
let
inherit (config.virtualisation.quadlet) containers networks;
authentikVersion = "2026.5.6";
authentikEnv = config.sops.secrets."containers/authentik.env".path;
outpostEnv = config.sops.secrets."containers/authentik-outpost.env".path;
in
@ -53,7 +54,7 @@ in
authentik-server = {
containerConfig = {
image = "ghcr.io/goauthentik/server:2026.5.0";
image = "ghcr.io/goauthentik/server:${authentikVersion}";
exec = "server";
networks = [ networks.authentik.ref ];
publishPorts = [
@ -65,6 +66,11 @@ in
"/home/imnyang/Docker/authentik/custom-templates:/templates:Z"
];
environmentFiles = [ authentikEnv ];
environments = {
# Authentik 2026.5 defaults to [::], but hako is reached over IPv4.
AUTHENTIK_LISTEN__HTTP = "0.0.0.0:9000";
AUTHENTIK_LISTEN__HTTPS = "0.0.0.0:9443";
};
};
unitConfig = {
@ -77,7 +83,7 @@ in
authentik-worker = {
containerConfig = {
image = "ghcr.io/goauthentik/server:2026.5.0";
image = "ghcr.io/goauthentik/server:${authentikVersion}";
exec = "worker";
user = "root";
networks = [ networks.authentik.ref ];
@ -85,9 +91,11 @@ in
"/home/imnyang/Docker/authentik/certs:/certs:Z"
"/home/imnyang/Docker/authentik/media:/media:Z"
"/home/imnyang/Docker/authentik/custom-templates:/templates:Z"
"/var/run/docker.sock:/var/run/docker.sock"
];
environmentFiles = [ authentikEnv ];
environments = {
AUTHENTIK_LISTEN__HTTP = "0.0.0.0:9000";
};
};
unitConfig = {
@ -100,7 +108,7 @@ in
authentik-outpost-ldap = {
containerConfig = {
image = "ghcr.io/goauthentik/ldap:2026.5.0";
image = "ghcr.io/goauthentik/ldap:${authentikVersion}";
entrypoint = [ "/ldap" ];
user = "1000";
networks = [ networks.authentik.ref ];
@ -109,6 +117,15 @@ in
"636:6636"
];
environmentFiles = [ outpostEnv ];
environments = {
# Keep the outpost-to-core API traffic on the private Podman network.
# The public hostname resolves through Cloudflare and hairpins back
# through the reverse proxy, which currently returns 502 from hako.
AUTHENTIK_HOST = "http://authentik-server:9000";
AUTHENTIK_INSECURE = "true";
AUTHENTIK_LISTEN__LDAP = "0.0.0.0:3389";
AUTHENTIK_LISTEN__LDAPS = "0.0.0.0:6636";
};
};
unitConfig = {