<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.nixos.org/w/index.php?action=history&amp;feed=atom&amp;title=Authelia</id>
	<title>Authelia - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.nixos.org/w/index.php?action=history&amp;feed=atom&amp;title=Authelia"/>
	<link rel="alternate" type="text/html" href="https://wiki.nixos.org/w/index.php?title=Authelia&amp;action=history"/>
	<updated>2026-05-17T05:45:29Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.0</generator>
	<entry>
		<id>https://wiki.nixos.org/w/index.php?title=Authelia&amp;diff=31896&amp;oldid=prev</id>
		<title>Zeal: Added example Authelia module</title>
		<link rel="alternate" type="text/html" href="https://wiki.nixos.org/w/index.php?title=Authelia&amp;diff=31896&amp;oldid=prev"/>
		<updated>2026-05-16T23:12:09Z</updated>

		<summary type="html">&lt;p&gt;Added example Authelia module&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Minimal Configuration Example ==&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;nix&amp;quot;&amp;gt;&lt;br /&gt;
{ config, pkgs, ... }:&lt;br /&gt;
{&lt;br /&gt;
  age.secrets.&amp;quot;authelia_jwt-secret-file&amp;quot; = {&lt;br /&gt;
    file = ../../secrets/authelia_jwt-secret-file.age;&lt;br /&gt;
    owner = &amp;quot;authelia-main&amp;quot;;&lt;br /&gt;
  };&lt;br /&gt;
  age.secrets.&amp;quot;authelia_storage-encryption-key-file&amp;quot; = {&lt;br /&gt;
    file = ../../secrets/authelia_storage-encryption-key-file.age;&lt;br /&gt;
    owner = &amp;quot;authelia-main&amp;quot;;&lt;br /&gt;
  };&lt;br /&gt;
&lt;br /&gt;
  services.authelia.instances.main = {&lt;br /&gt;
    enable = true;&lt;br /&gt;
    package = pkgs.authelia;&lt;br /&gt;
    secrets = {&lt;br /&gt;
      jwtSecretFile = config.age.secrets.&amp;quot;authelia_jwt-secret-file&amp;quot;.path;&lt;br /&gt;
      storageEncryptionKeyFile = config.age.secrets.&amp;quot;authelia_storage-encryption-key-file&amp;quot;.path;&lt;br /&gt;
    };&lt;br /&gt;
    settings = {&lt;br /&gt;
      theme = &amp;quot;auto&amp;quot;;&lt;br /&gt;
      default_2fa_method = &amp;quot;totp&amp;quot;;&lt;br /&gt;
      log.level = &amp;quot;info&amp;quot;;&lt;br /&gt;
      server.address = &amp;quot;tcp://:9091/&amp;quot;;&lt;br /&gt;
      session = {&lt;br /&gt;
        cookies = [&lt;br /&gt;
          {&lt;br /&gt;
            domain = &amp;quot;domain.tld&amp;quot;;&lt;br /&gt;
            authelia_url = &amp;quot;https://auth.domain.tld&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
        ];&lt;br /&gt;
      };&lt;br /&gt;
      access_control = {&lt;br /&gt;
        default_policy = &amp;quot;deny&amp;quot;;&lt;br /&gt;
        rules = [ &lt;br /&gt;
          {&lt;br /&gt;
            domain = &amp;quot;auth.domain.tld&amp;quot;;&lt;br /&gt;
            policy = &amp;quot;bypass&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
          {&lt;br /&gt;
            domain = &amp;quot;*.domain.tld&amp;quot;;&lt;br /&gt;
            policy = &amp;quot;one_factor&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
        ];&lt;br /&gt;
      };&lt;br /&gt;
      storage.local.path = &amp;quot;/var/lib/authelia-main/db.sqlite&amp;quot;;&lt;br /&gt;
      notifier.filesystem.filename = &amp;quot;/var/lib/authelia-main/notifications.yml&amp;quot;;&lt;br /&gt;
      authentication_backend.file.path = &amp;quot;/etc/authelia/users.yml&amp;quot;;&lt;br /&gt;
    };&lt;br /&gt;
  };&lt;br /&gt;
  environment.etc.&amp;quot;authelia/users.yml&amp;quot; = {&lt;br /&gt;
    mode = &amp;quot;0400&amp;quot;;&lt;br /&gt;
    user = &amp;quot;authelia-main&amp;quot;;&lt;br /&gt;
    text = &amp;#039;&amp;#039;&lt;br /&gt;
      users:&lt;br /&gt;
        john:&lt;br /&gt;
          password: &amp;quot;$argon...&amp;quot; # generate with `authelia -c authelia crypto hash generate`&lt;br /&gt;
          displayname: &amp;quot;John&amp;quot;&lt;br /&gt;
          email: &amp;quot;&amp;lt;your_email&amp;gt;&amp;quot;&lt;br /&gt;
          groups: [&amp;quot;admins&amp;quot;]&lt;br /&gt;
    &amp;#039;&amp;#039;;&lt;br /&gt;
  };&lt;br /&gt;
  services.nginx.virtualHosts.&amp;quot;auth.domain.tld&amp;quot; = {&lt;br /&gt;
    forceSSL = true;&lt;br /&gt;
    locations.&amp;quot;/&amp;quot;.proxyPass = &amp;quot;http://127.0.0.1:9091&amp;quot;;&lt;br /&gt;
  };&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;</summary>
		<author><name>Zeal</name></author>
	</entry>
</feed>