auth01: add lldap password to secrets
Some checks failed
Run nix flake check / flake-check (push) Has been cancelled

This commit is contained in:
2025-12-06 11:02:43 +01:00
parent f2963a150b
commit 25b786915c
2 changed files with 15 additions and 9 deletions

View File

@@ -2,11 +2,8 @@ authelia_ldap_password: ENC[AES256_GCM,data:x2UDMpqQKoRVSlDSmK5XiC9x4/WWzmjk7cwt
authelia_jwt_secret: ENC[AES256_GCM,data:9ZHkT2o5KZLmml95g8HZce8fNBmaWtRn+175Gaz0KhsndNl3zdgGq3hydRuoZuEgLVsherJImVmb5DQAZpv04lUEsDKCYeFNwAyYl4Go2jCp1fI53fdcRCKlNVZA37pMi4AYaCoe8vIl/cwPOOBDEwK5raOBnklCzVERoO0B8a0=,iv:9CTWCw0ImZR0OSrl2znbhpRHlzAxA5Cpcy98JeH9Z+Y=,tag:L+0xKqiwXTi7XiDYWA1Bcw==,type:str]
authelia_storage_encryption_key_file: ENC[AES256_GCM,data:RfbcQK8+rrW/Krd2rbDfgo7YI2YvQKqpLuDtk5DZJNNhw4giBh5nFp/8LNeo8r39/oiJLYTe6FjTLBu72TZz2wWrJFsBqjwQ/3TfATQGdLUsaXXRDr88ezHLTiYvEHIHJhUS5qsr7VMwBam5e7YGWBe5sGZCE/nX41ijyPUjtOY=,iv:sayYcAC38cApAtL+cDhgGNjWaHn+furKRowKL6AmfdU=,tag:1IZpnlpvDWGLLpZyU9iJUw==,type:str]
authelia_session_secret: ENC[AES256_GCM,data:4PaLv4RRA7/9Z8QzETXLwo3OctJ0mvzQkYmHsGGF97nq9QeB3eo0xj4FyuCbkJGGZ/huAyRgmFBTyscY3wgxoc4t+8BdlYcSbefEk1/xRFjmG8ooXLKhvGJ5c6t72KJRcqsEGTiC0l9CFJWQ2qYcjM4dPwG8z0tjUZ6j25Zfx4M=,iv:QORJkf0w6iyuRHM/xuql1s7K75Qa49ygq+lwHfrm9rk=,tag:/HZ/qI80fKjmuTRwIwmX8g==,type:str]
ldap_user_pass: ENC[AES256_GCM,data:954+/DX5EvXIbPYvhVIA5w==,iv:sl6XxzmXyKpGqzZSY/S6qpFD2GVCqrx+JaryblUE3ec=,tag:vZEtFrqrCIKH12MQf6LAAg==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age1lznyk4ee7e7x8n92cq2n87kz9920473ks5u9jlhd3dczfzq4wamqept56u
enc: |
@@ -26,8 +23,7 @@ sops:
RW5HRjA3cERCUU1CVWZhck12SGhTRUkK6k/zQ87TIETYouRBby7ujtwgpqIPKKv+
2aLJW6lSWMVzL/f3ZrIeg12tJjHs3f44EXR6j3tfLfSKog2iL8Y57w==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2025-04-01T21:37:33Z"
mac: ENC[AES256_GCM,data:4stf2UFt1ogH8pIJCUwMvbXG7YzyehbDEi6Qsfi5s3Kmx/AQAC6SpE31HL3qgYNdi10vbZEVH1lrFljPWs4YdnevzM2z9l3mfiR5D10vp2z/Nvw/+IDNheXxQfgO82QdVZ6qfo83zxYPoda+PmdFatmHTB00V9lNm6DF4unRy60=,iv:byyo1297YoxFO6S9TVzlPHR082IugZHSHCiT5sZE2T0=,tag:dtSxGNVxjR77gnegIHw1Sw==,type:str]
pgp: []
lastmodified: "2025-12-06T09:59:50Z"
mac: ENC[AES256_GCM,data:ioEp5RORyWx0WWReO9lqJYN6Pm9vFAmPfiYNDfcNjEgPDWsC7FSoCX0GjKWSsSOl2sfKmRPh/So1nTh2GOOO8e8DpucN3Daeu2GJs5XcbyJzdXSkgAsiPQp+FSz0ZIGLwlRQ+a1qz+SowEc7KAr8mguQ7+3x26OaLxKxJbX6Wds=,iv:nC+kELG1st0wNr20ty+uEcBLMSbGTOhe6eK8IpHmsqo=,tag:wSTee6q6FdNJhQ4keK2I6g==,type:str]
unencrypted_suffix: _unencrypted
version: 3.9.4
version: 3.11.0

View File

@@ -1,11 +1,21 @@
{ ... }:
{ config, ... }:
{
sops.secrets.lldap_user_pass = {
format = "yaml";
key = "lldap_user_pass";
sopsFile = ../../secrets/auth01/secrets.yaml;
restartUnits = [ "lldap.service" ];
owner = "lldap";
group = "lldap";
};
services.lldap = {
enable = true;
settings = {
ldap_base_dn = "dc=home,dc=2rjus,dc=net";
ldap_user_email = "admin@home.2rjus.net";
ldap_user_dn = "admin";
ldap_user_pass_file = config.sops.secrets.authelia_ldap_password.path;
ldaps_options = {
enabled = true;
port = 6360;