Each of the four cases in access_control.rules now carries an inline,
clearly-labeled "ALSO PASTE INTO CADDYFILE" block above the
uncommentable Authelia rule, so the user editing configuration.yml
sees both halves of the gate in one place. Case 2a additionally shows
the matching frigate_config/config.yml edit; case 4 has no Authelia
rule but still shows the Caddy block to make the absence explicit.
Caddy blocks use {env.DOMAIN}, Authelia rules use {{ env "DOMAIN" }} --
matching what's already in caddy/snippets.caddyfile and the
configuration.yml header.
https://claude.ai/code/session_013XZ1vmgk78k2PEQ5DmJhF3
The bootstrap and add-user docs passed --password 'plaintext' on the
docker compose run command line, leaking the plaintext into shell
history (~/.bash_history, ~/.zsh_history) and the process list
(ps aux). Switched all three call sites to the interactive form
(no --password flag), which makes Authelia prompt for the password
and a confirmation without echoing.
Affected:
- README.md "Create your first user" step
- README.md "Add a user" section
- authelia/users_database.yml.example header comment
https://claude.ai/code/session_013XZ1vmgk78k2PEQ5DmJhF3
Previously every example.com had to be found and replaced manually.
Now a single DOMAIN=yourdomain.com in .env propagates everywhere:
- .env.example: add DOMAIN=example.com with explanation
- docker-compose.yml: pass DOMAIN into authelia container environment
- authelia/configuration.yml: use {{ env "DOMAIN" }} in totp.issuer,
access_control.rules, and all four session.cookies[] fields
(Authelia 4.38+ Go template substitution)
- caddy/Caddyfile: use {env.DOMAIN} in all site block addresses
(Caddy native env substitution); update header comment explaining
how to set DOMAIN for system vs dockerized Caddy
- README.md: update step 3 to explain DOMAIN is the only change needed;
update step 4 to say just uncomment the right rule; update Caddy
wiring section with DOMAIN env var instructions for both Caddy modes
https://claude.ai/code/session_012eTokAaGiZo7aGt1T2W9BC
Keeps this as a standalone authelia+fail2ban stack (no Frigate services).
Changes:
- docker-compose.yml: fail2ban depends_on authelia with service_healthy
condition so authelia.log exists before fail2ban tries to bind-mount it;
add inline note about pre-creating the log file
- authelia/configuration.yml: expand access_control comment block to cover
all 4 cases (added Case 3: app keeps own auth + Authelia as 2FA gate,
and Case 4: app handles auth alone); clearer per-case commented rules
- caddy/Caddyfile (replaces snippet.example.caddyfile): complete Caddyfile
with all 4 auth-case examples; (accesslog) imported in every block so
fail2ban caddy-4xx jail covers all subdomains, not just gated ones;
full inline docs for enabling Frigate proxy auth
- README.md: expand "Which sites" from 3 to 4 cases; add proxy-auth service
compatibility table (Frigate, Grafana, Gitea, Nextcloud, HA, Portainer
etc.); clarify fail2ban covers all sites via single caddy-4xx jail;
add touch authelia/authelia.log to first-run; add troubleshooting entries
for authelia.log bind-mount directory bug and fail2ban chain verification
https://claude.ai/code/session_012eTokAaGiZo7aGt1T2W9BC
- Pin AUTHELIA_VERSION=4.39.19 (current stable, released 2026-04-12) and
FAIL2BAN_VERSION=1.1.0-r0 in .env.example + docker-compose.yml.
- Reshape access_control.rules and the Caddyfile snippet around a
three-case decision tree: no app auth (Authelia is the gate), app with
proxy-auth support (switch FROM app login TO Authelia headers), and
apps that keep their own login (skip Authelia entirely).
- Document Frigate 0.14+ proxy auth specifically: auth.enabled: False,
proxy.header_map (remote-user / remote-groups), trusted_proxies for
the caddy_net subnet, optional X-Proxy-Secret for cross-VLAN trust.
https://claude.ai/code/session_013XZ1vmgk78k2PEQ5DmJhF3
Self-hosted SSO portal with file-based users, SQLite storage, filesystem
notifier, and an iptables-banning fail2ban sidecar. Designed to drop into
a DotheEvo-style ~/docker layout next to a dockerized Caddy on the main
server, joining the same external caddy_net so Caddy reaches Authelia by
container name. fail2ban runs in host network mode with NET_ADMIN/NET_RAW
caps so its bans hit DOCKER-USER and actually drop packets at the edge.
Includes a Caddy snippet (caddy/snippet.example.caddyfile) to merge into
the user's real Caddyfile -- this repo doesn't manage Caddy itself.
https://claude.ai/code/session_013XZ1vmgk78k2PEQ5DmJhF3