- Pin AUTHELIA_VERSION=4.39.19 (current stable, released 2026-04-12) and
FAIL2BAN_VERSION=1.1.0-r0 in .env.example + docker-compose.yml.
- Reshape access_control.rules and the Caddyfile snippet around a
three-case decision tree: no app auth (Authelia is the gate), app with
proxy-auth support (switch FROM app login TO Authelia headers), and
apps that keep their own login (skip Authelia entirely).
- Document Frigate 0.14+ proxy auth specifically: auth.enabled: False,
proxy.header_map (remote-user / remote-groups), trusted_proxies for
the caddy_net subnet, optional X-Proxy-Secret for cross-VLAN trust.
https://claude.ai/code/session_013XZ1vmgk78k2PEQ5DmJhF3