diff --git a/incubator/authelia/0.0.1/CONFIG.md b/incubator/authelia/0.0.1/CONFIG.md new file mode 100644 index 0000000000..e69de29bb2 diff --git a/incubator/authelia/0.0.1/Chart.lock b/incubator/authelia/0.0.1/Chart.lock new file mode 100644 index 0000000000..ea635c7cae --- /dev/null +++ b/incubator/authelia/0.0.1/Chart.lock @@ -0,0 +1,12 @@ +dependencies: +- name: common + repository: https://truecharts.org/ + version: 6.10.6 +- name: postgresql + repository: https://truecharts.org/ + version: 1.2.3 +- name: redis + repository: https://charts.bitnami.com/bitnami + version: 14.8.11 +digest: sha256:0e70ad08e8bd5ef4d2d42581e20e3b18ed42c61f59fb1b27888c5d985a89d0df +generated: "2021-08-28T11:44:37.508050366Z" diff --git a/incubator/authelia/0.0.1/Chart.yaml b/incubator/authelia/0.0.1/Chart.yaml new file mode 100644 index 0000000000..29d3ebfdc6 --- /dev/null +++ b/incubator/authelia/0.0.1/Chart.yaml @@ -0,0 +1,41 @@ +apiVersion: v2 +appVersion: auto +dependencies: +- name: common + repository: https://truecharts.org/ + version: 6.10.6 +- condition: postgresql.enabled + name: postgresql + repository: https://truecharts.org/ + version: 1.2.3 +- condition: redis.enabled + name: redis + repository: https://charts.bitnami.com/bitnami + version: 14.8.11 +deprecated: false +description: Authelia is a Single Sign-On Multi-Factor portal for web apps +home: https://github.com/truecharts/apps/tree/master/charts/stable/authelia +icon: https://avatars2.githubusercontent.com/u/59122411?s=200&v=4 +keywords: +- authelia +- authentication +- login +- SSO +- Authentication +- Security +- Two-Factor +- U2F +- YubiKey +- Push Notifications +- LDAP +kubeVersion: '>=1.16.0-0' +maintainers: +- email: info@truecharts.org + name: TrueCharts + url: truecharts.org +name: authelia +sources: +- https://github.com/authelia/chartrepo +- https://github.com/authelia/authelia +type: application +version: 0.0.1 diff --git a/incubator/authelia/0.0.1/README.md b/incubator/authelia/0.0.1/README.md new file mode 100644 index 0000000000..e69de29bb2 diff --git a/incubator/authelia/0.0.1/app-readme.md b/incubator/authelia/0.0.1/app-readme.md new file mode 100644 index 0000000000..535996cc7a --- /dev/null +++ b/incubator/authelia/0.0.1/app-readme.md @@ -0,0 +1 @@ +Authelia is a Single Sign-On Multi-Factor portal for web apps diff --git a/incubator/authelia/0.0.1/charts/common-6.10.6.tgz b/incubator/authelia/0.0.1/charts/common-6.10.6.tgz new file mode 100644 index 0000000000..dc2df28bb2 Binary files /dev/null and b/incubator/authelia/0.0.1/charts/common-6.10.6.tgz differ diff --git a/incubator/authelia/0.0.1/charts/postgresql-1.2.3.tgz b/incubator/authelia/0.0.1/charts/postgresql-1.2.3.tgz new file mode 100644 index 0000000000..db11cc1b85 Binary files /dev/null and b/incubator/authelia/0.0.1/charts/postgresql-1.2.3.tgz differ diff --git a/incubator/authelia/0.0.1/charts/redis-14.8.11.tgz b/incubator/authelia/0.0.1/charts/redis-14.8.11.tgz new file mode 100644 index 0000000000..a9e0ad225b Binary files /dev/null and b/incubator/authelia/0.0.1/charts/redis-14.8.11.tgz differ diff --git a/incubator/authelia/0.0.1/ix_values.yaml b/incubator/authelia/0.0.1/ix_values.yaml new file mode 100644 index 0000000000..32637a28ee --- /dev/null +++ b/incubator/authelia/0.0.1/ix_values.yaml @@ -0,0 +1,231 @@ +## +# This file contains Values.yaml content that gets added to the output of questions.yaml +# It's ONLY meant for content that the user is NOT expected to change. +# Example: Everything under "image" is not included in questions.yaml but is included here. +## + +image: + repository: ghcr.io/authelia/authelia + pullPolicy: IfNotPresent + tag: "4.30.4" + +# Enabled postgres +postgresql: + enabled: true + postgresqlUsername: authelia + postgresqlDatabase: authelia + existingSecret: "{{ .Release.Name }}-dbcreds" + persistence: + db: + storageClass: "SCALE-ZFS" + dbbackups: + storageClass: "SCALE-ZFS" + +# Enabled redis +# ... for more options see https://github.com/bitnami/charts/tree/master/bitnami/redis +redis: + volumePermissions: + enabled: true + architecture: standalone + enabled: true + auth: + existingSecret: rediscreds + existingSecretPasswordKey: redis-password + master: + persistence: + enabled: false + existingClaim: redismaster + replica: + replicaCount: 0 + persistence: + enabled: false + +envFrom: + - configMapRef: + name: '{{ include "common.names.fullname" . }}-paths' + +probes: + liveness: + type: HTTP + path: /api/health" + + readiness: + type: HTTP + path: "/api/health" + + startup: + type: HTTP + path: "/api/health" + +## +## Storage Provider Configuration +## +## The available providers are: `local`, `mysql`, `postgres`. You must use one and only one of these providers. +storage: + ## + ## PostgreSQL (Storage Provider) + ## + postgres: + port: 5432 + database: authelia + username: authelia + sslmode: disable + timeout: 5s + +## +## Server Configuration +## +server: + ## + ## Port sets the configured port for the daemon, service, and the probes. + ## Default is 9091 and should not need to be changed. + ## + port: 9091 + + ## Buffers usually should be configured to be the same value. + ## Explanation at https://www.authelia.com/docs/configuration/server.html + ## Read buffer size adjusts the server's max incoming request size in bytes. + ## Write buffer size does the same for outgoing responses. + read_buffer_size: 4096 + write_buffer_size: 4096 + ## Set the single level path Authelia listens on. + ## Must be alphanumeric chars and should not contain any slashes. + path: "" + +## +## Redis Provider +## +## Important: Kubernetes (or HA) users must read https://www.authelia.com/docs/features/statelessness.html +## +## The redis connection details +redisProvider: + port: 6379 + + ## Optional username to be used with authentication. + # username: authelia + username: "" + + ## This is the Redis DB Index https://redis.io/commands/select (sometimes referred to as database number, DB, etc). + database_index: 0 + + ## The maximum number of concurrent active connections to Redis. + maximum_active_connections: 8 + + ## The target number of idle connections to have open ready for work. Useful when opening connections is slow. + minimum_idle_connections: 0 + + ## The Redis TLS configuration. If defined will require a TLS connection to the Redis instance(s). + tls: + enabled: false + + ## Server Name for certificate validation (in case you are using the IP or non-FQDN in the host option). + server_name: "" + + ## Skip verifying the server certificate (to allow a self-signed certificate). + ## In preference to setting this we strongly recommend you add the public portion of the certificate to the + ## certificates directory which is defined by the `certificates_directory` option at the top of the config. + skip_verify: false + + ## Minimum TLS version for the connection. + minimum_version: TLS1.2 + + ## The Redis HA configuration options. + ## This provides specific options to Redis Sentinel, sentinel_name must be defined (Master Name). + high_availability: + enabled: false + enabledSecret: false + ## Sentinel Name / Master Name + sentinel_name: mysentinel + + ## The additional nodes to pre-seed the redis provider with (for sentinel). + ## If the host in the above section is defined, it will be combined with this list to connect to sentinel. + ## For high availability to be used you must have either defined; the host above or at least one node below. + nodes: [] + # nodes: + # - host: sentinel-0.databases.svc.cluster.local + # port: 26379 + # - host: sentinel-1.databases.svc.cluster.local + # port: 26379 + + ## Choose the host with the lowest latency. + route_by_latency: false + + ## Choose the host randomly. + route_randomly: false + +identity_providers: + oidc: + ## Enables this in the config map. Currently in beta stage. + ## See https://www.authelia.com/docs/configuration/identity-providers/oidc.html#roadmap + enabled: false + + access_token_lifespan: 1h + authorize_code_lifespan: 1m + id_token_lifespan: 1h + refresh_token_lifespan: 90m + + enable_client_debug_messages: false + + ## SECURITY NOTICE: It's not recommended changing this option, and highly discouraged to have it below 8 for + ## security reasons. + minimum_parameter_entropy: 8 + + clients: [] + # clients: + # - + ## The ID is the OpenID Connect ClientID which is used to link an application to a configuration. + # id: myapp + + ## The description to show to users when they end up on the consent screen. Defaults to the ID above. + # description: My Application + + ## The client secret is a shared secret between Authelia and the consumer of this client. + # secret: apple123 + + ## Sets the client to public. This should typically not be set, please see the documentation for usage. + # public: false + + ## The policy to require for this client; one_factor or two_factor. + # authorization_policy: two_factor + + ## Audience this client is allowed to request. + # audience: [] + + ## Scopes this client is allowed to request. + # scopes: + # - openid + # - profile + # - email + # - groups + + ## Redirect URI's specifies a list of valid case-sensitive callbacks for this client. + # redirect_uris: + # - https://oidc.example.com/oauth2/callback + + ## Grant Types configures which grants this client can obtain. + ## It's not recommended to configure this unless you know what you're doing. + # grant_types: + # - refresh_token + # - authorization_code + + ## Response Types configures which responses this client can be sent. + ## It's not recommended to configure this unless you know what you're doing. + # response_types: + # - code + + ## Response Modes configures which response modes this client supports. + ## It's not recommended to configure this unless you know what you're doing. + # response_modes: + # - form_post + # - query + # - fragment + + ## The algorithm used to sign userinfo endpoint responses for this client, either none or RS256. + # userinfo_signing_algorithm: none + + + +## +# Most other defaults are set in questions.yaml +# For other options please refer to the wiki, default_values.yaml or the common library chart +## diff --git a/incubator/authelia/0.0.1/questions.yaml b/incubator/authelia/0.0.1/questions.yaml new file mode 100644 index 0000000000..2230c5a32a --- /dev/null +++ b/incubator/authelia/0.0.1/questions.yaml @@ -0,0 +1,1390 @@ +groups: + - name: "Container Image" + description: "Image to be used for container" + - name: "Controller" + description: "Configure workload deployment" + - name: "Container Configuration" + description: "additional container configuration" + - name: "App Configuration" + description: "App specific config options" + - name: "Networking and Services" + description: "Configure Network and Services for container" + - name: "Storage and Persistence" + description: "Persist and share data that is separate from the container" + - name: "Ingress" + description: "Ingress Configuration" + - name: "Security and Permissions" + description: "Configure security context and permissions" + - name: "Resources and Devices" + description: "Specify resources/devices to be allocated to workload" + - name: "Advanced" + description: "Advanced Configuration" +portals: + web_portal: + protocols: + - "$kubernetes-resource_configmap_portal_protocol" + host: + - "$kubernetes-resource_configmap_portal_host" + ports: + - "$kubernetes-resource_configmap_portal_port" +questions: + - variable: portal + group: "Container Image" + label: "Configure Portal Button" + schema: + type: dict + hidden: true + attrs: + - variable: enabled + label: "Enable" + description: "enable the portal button" + schema: + hidden: true + editable: false + type: boolean + default: true + - variable: controller + group: "Controller" + label: "" + schema: + type: dict + attrs: + - variable: type + description: "Please specify type of workload to deploy" + label: "(Advanced) Controller Type" + schema: + type: string + default: "deployment" + required: true + enum: + - value: "deployment" + description: "Deployment" + - value: "statefulset" + description: "Statefulset" + - value: "daemonset" + description: "Daemonset" + - variable: replicas + description: "Number of desired pod replicas" + label: "Desired Replicas" + schema: + type: int + default: 1 + required: true + - variable: strategy + description: "Please specify type of workload to deploy" + label: "(Advanced) Update Strategy" + schema: + type: string + default: "Recreate" + required: true + enum: + - value: "Recreate" + description: "Recreate: Kill existing pods before creating new ones" + - value: "RollingUpdate" + description: "RollingUpdate: Create new pods and then kill old ones" + - value: "OnDelete" + description: "(Legacy) OnDelete: ignore .spec.template changes" + + + - variable: env + group: "Container Configuration" + label: "Image Environment" + schema: + type: dict + attrs: + - variable: TZ + label: "Timezone" + schema: + type: string + default: "Etc/UTC" + $ref: + - "definitions/timezone" + - variable: UMASK + label: "UMASK" + description: "Sets the UMASK env var for LinuxServer.io (compatible) containers" + schema: + type: string + default: "002" + # Configure Enviroment Variables + - variable: envList + label: "Image environment" + group: "Container Configuration" + schema: + type: list + default: [] + items: + - variable: envItem + label: "Environment Variable" + schema: + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + + - variable: domain + group: "App Configuration" + label: "Domain" + description: "The highest domain level possible, for example: domain.com when using app.domain.com" + schema: + type: string + default: "" + required: true + + - variable: default_redirection_url + group: "App Configuration" + label: "Default Redirection Url" + description: "If user tries to authenticate without any referer, this is used" + schema: + type: string + default: "" + required: false + + - variable: theme + group: "App Configuration" + label: "Theme" + schema: + type: string + default: "light" + enum: + - value: "light" + description: "info" + - value: "gray" + description: "gray" + - value: "dark" + description: "dark" + + - variable: log + group: "App Configuration" + label: "Log Configuration " + schema: + type: dict + attrs: + - variable: level + label: "Log Level" + schema: + type: string + default: "info" + enum: + - value: "info" + description: "info" + - value: "debug" + description: "debug" + - value: "trace" + description: "trace" + - variable: format + label: "Log Format" + schema: + type: string + default: "text" + enum: + - value: "json" + description: "json" + - value: "text" + description: "text" + + - variable: totp + group: "App Configuration" + label: "TOTP Configuration" + schema: + type: dict + attrs: + - variable: issuer + label: "Issuer" + description: "The issuer name displayed in the Authenticator application of your choice" + schema: + type: string + default: "" + - variable: period + label: "Period" + description: "The period in seconds a one-time password is current for" + schema: + type: int + default: 30 + - variable: skew + label: "skew" + description: "Controls number of one-time passwords either side of the current one that are valid." + schema: + type: int + default: 1 + + - variable: duo_api + group: "App Configuration" + label: "DUO API Configuration" + description: "Parameters used to contact the Duo API." + schema: + type: dict + attrs: + - variable: enabled + label: "Enable" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: hostname + label: "Hostname" + schema: + type: string + required: true + default: "" + + - variable: integration_key + label: "integration_key" + schema: + type: string + defaults: "" + required: true + - variable: plain_api_key + label: "plain_api_key" + schema: + type: string + defaults: "" + required: true + + - variable: session + group: "App Configuration" + label: "Session Provider" + description: "The session cookies identify the user once logged in." + schema: + type: dict + attrs: + - variable: name + label: "Cookie Name" + description: "The name of the session cookie." + schema: + type: string + required: true + default: "authelia_session" + - variable: same_site + label: "SameSite Value" + description: "Sets the Cookie SameSite value" + schema: + type: string + default: "lax" + enum: + - value: "lax" + description: "lax" + - value: "strict" + description: "strict" + - variable: expiration + label: "Expiration Time" + description: "The time in seconds before the cookie expires and session is reset." + schema: + type: string + defaults: "1h" + required: true + - variable: inactivity + label: "Inactivity Time" + description: "The inactivity time in seconds before the session is reset." + schema: + type: string + defaults: "5m" + required: true + - variable: inactivity + label: "Remember-Me duration" + description: "The remember me duration" + schema: + type: string + defaults: "5M" + required: true + + - variable: regulation + group: "App Configuration" + label: "Regulation Configuration" + description: "his mechanism prevents attackers from brute forcing the first factor." + schema: + type: dict + attrs: + - variable: max_retries + label: "Maximum Retries" + description: "The number of failed login attempts before user is banned. Set it to 0 to disable regulation." + schema: + type: int + default: 3 + - variable: find_time + label: "Find Time" + description: "The time range during which the user can attempt login before being banned." + schema: + type: string + defaults: "2m" + required: true + - variable: ban_time + label: "Ban Duration" + description: "The length of time before a banned user can login again" + schema: + type: string + defaults: "5m" + required: true + + + - variable: authentication_backend + group: "App Configuration" + label: "Authentication Backend Provider" + description: "sed for verifying user passwords and retrieve information such as email address and groups users belong to." + schema: + type: dict + attrs: + - variable: disable_reset_password + label: "Disable Reset Password" + description: "Disable both the HTML element and the API for reset password functionality" + schema: + type: boolean + default: false + - variable: refresh_interval + label: "Reset Interval" + description: "The amount of time to wait before we refresh data from the authentication backend" + schema: + type: string + defaults: "5m" + required: true + - variable: ldap + label: "LDAP backend configuration" + description: "Used for verifying user passwords and retrieve information such as email address and groups users belong to" + schema: + type: dict + attrs: + - variable: enabled + label: "Enable" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: implementation + label: "Implementation" + description: "The LDAP implementation, this affects elements like the attribute utilised for resetting a password" + schema: + type: string + default: "custom" + enum: + - value: "activedirectory" + description: "activedirectory" + - value: "custom" + description: "custom" + - variable: url + label: "URL" + description: "The url to the ldap server. Format: ://
[:]" + schema: + type: string + default: "ldap://openldap.default.svc.cluster.local" + required: true + - variable: timeout + label: "Connection Timeout" + schema: + type: string + default: "5s" + required: true + - variable: start_tls + label: "Start TLS" + description: "Use StartTLS with the LDAP connection" + schema: + type: boolean + default: false + - variable: tls + label: "TLS Settings" + schema: + type: dict + attrs: + - variable: server_name + label: "Server Name" + description: "Server Name for certificate validation (in case it's not set correctly in the URL)." + schema: + type: string + default: "" + - variable: skip_verify + label: "Skip Certificate Verification" + description: "Skip verifying the server certificate (to allow a self-signed certificate)" + schema: + type: boolean + default: false + - variable: minimum_version + label: "Minimum TLS version" + description: "Minimum TLS version for either Secure LDAP or LDAP StartTLS." + schema: + type: string + default: "TLS1.2" + enum: + - value: "TLS1.0" + description: "TLS1.0" + - value: "TLS1.1" + description: "TLS1.1" + - value: "TLS1.2" + description: "TLS1.2" + - value: "TLS1.3" + description: "TLS1.3" + - variable: base_dn + label: "Base DN" + description: "The base dn for every LDAP query." + schema: + type: string + defaults: "DC=example,DC=com" + required: true + - variable: username_attribute + label: "Username Attribute" + description: "The attribute holding the username of the user" + schema: + type: string + defaults: "" + required: true + - variable: additional_users_dn + label: "Additional Users DN" + description: "An additional dn to define the scope to all users." + schema: + type: string + defaults: "OU=Users" + required: true + - variable: users_filter + label: "Users Filter" + description: "The groups filter used in search queries to find the groups of the user." + schema: + type: string + defaults: "" + required: true + - variable: additional_groups_dn + label: "Additional Groups DN" + description: "An additional dn to define the scope of groups." + schema: + type: string + defaults: "OU=Groups" + required: true + - variable: groups_filter + label: "Groups Filter" + description: "The groups filter used in search queries to find the groups of the user." + schema: + type: string + defaults: "" + required: true + - variable: group_name_attribute + label: "Group name Attribute" + description: "The attribute holding the name of the group" + schema: + type: string + defaults: "" + required: true + - variable: mail_attribute + label: "Mail Attribute" + description: "The attribute holding the primary mail address of the user" + schema: + type: string + defaults: "" + required: true + - variable: display_name_attribute + label: "Display Name Attribute" + description: "he attribute holding the display name of the user. This will be used to greet an authenticated user." + schema: + type: string + defaults: "" + - variable: user + label: "Admin User" + description: "The username of the admin user used to connect to LDAP." + schema: + type: string + defaults: "CN=Authelia,DC=example,DC=com" + required: true + - variable: plain_password + label: "Password" + schema: + type: string + defaults: "" + required: true + - variable: file + label: "File backend configuration" + description: "With this backend, the users database is stored in a file which is updated when users reset their passwords." + schema: + type: dict + attrs: + - variable: enabled + label: "Enable" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: path + label: "Path" + schema: + type: string + defaults: "/config/users_database.yml" + required: true + - variable: password + label: "Password Settings" + schema: + type: dict + attrs: + - variable: algorithm + label: "Algorithm" + schema: + type: string + default: "argon2id" + enum: + - value: "argon2id" + description: "argon2id" + - value: "sha512" + description: "sha512" + - variable: iterations + label: "Iterations" + schema: + type: int + default: 1 + required: true + - variable: key_length + label: "Key Length" + schema: + type: int + default: 32 + required: true + - variable: salt_length + label: "Salt Length" + schema: + type: int + default: 16 + required: true + - variable: memory + label: "Memory" + schema: + type: int + default: 1024 + required: true + - variable: parallelism + label: "Parallelism" + schema: + type: int + default: 8 + required: true + + + - variable: notifier + group: "App Configuration" + label: "Notifier Configuration" + description: "otifications are sent to users when they require a password reset, a u2f registration or a TOTP registration." + schema: + type: dict + attrs: + - variable: disable_startup_check + label: "Disable Startup Check" + schema: + type: boolean + default: false + - variable: filesystem + label: "Filesystem Provider" + schema: + type: dict + attrs: + - variable: enabled + label: "Enable" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: filename + label: "File Path" + schema: + type: string + defaults: "/config/notification.txt" + required: true + - variable: smtp + label: "SMTP Provider" + description: "Use a SMTP server for sending notifications. Authelia uses the PLAIN or LOGIN methods to authenticate." + schema: + type: dict + attrs: + - variable: enabled + label: "Enable" + schema: + type: boolean + default: true + show_subquestions_if: true + subquestions: + - variable: host + label: "Host" + schema: + type: string + defaults: "smtp.mail.svc.cluster.local" + required: true + - variable: port + label: "Port" + schema: + type: int + defaults: 25 + required: true + - variable: timeout + label: "Timeout" + schema: + type: string + defaults: "5s" + required: true + - variable: username + label: "Username" + schema: + type: string + defaults: "" + required: true + - variable: plain_password + label: "Password" + schema: + type: string + defaults: "" + required: true + - variable: sender + label: "Sender" + schema: + type: string + defaults: "" + required: true + - variable: identifier + label: "Identifier" + description: "HELO/EHLO Identifier. Some SMTP Servers may reject the default of localhost." + schema: + type: string + defaults: "localhost" + required: true + - variable: subject + label: "Subject" + description: "Subject configuration of the emails sent, {title} is replaced by the text from the notifier" + schema: + type: string + defaults: "[Authelia] {title}" + required: true + - variable: startup_check_address + label: "Startup Check Address" + description: "This address is used during the startup check to verify the email configuration is correct." + schema: + type: string + defaults: "test@authelia.com" + required: true + - variable: disable_require_tls + label: "Disable Require TLS" + schema: + type: boolean + default: false + - variable: disable_html_emails + label: "Disable HTML emails" + schema: + type: boolean + default: false + - variable: tls + label: "TLS Settings" + schema: + type: dict + attrs: + - variable: server_name + label: "Server Name" + description: "Server Name for certificate validation (in case it's not set correctly in the URL)." + schema: + type: string + default: "" + - variable: skip_verify + label: "Skip Certificate Verification" + description: "Skip verifying the server certificate (to allow a self-signed certificate)" + schema: + type: boolean + default: false + - variable: minimum_version + label: "Minimum TLS version" + description: "Minimum TLS version for either Secure LDAP or LDAP StartTLS." + schema: + type: string + default: "TLS1.2" + enum: + - value: "TLS1.0" + description: "TLS1.0" + - value: "TLS1.1" + description: "TLS1.1" + - value: "TLS1.2" + description: "TLS1.2" + - value: "TLS1.3" + description: "TLS1.3" + - variable: access_control + group: "App Configuration" + label: "Access Control Configuration" + description: "Access control is a list of rules defining the authorizations applied for one resource to users or group of users." + schema: + type: dict + attrs: + - variable: default_policy + label: "Default Policy" + description: "Default policy can either be 'bypass', 'one_factor', 'two_factor' or 'deny'." + schema: + type: string + default: "two_factor" + enum: + - value: "bypass" + description: "bypass" + - value: "one_factor" + description: "one_factor" + - value: "two_factor" + description: "two_factor" + - value: "deny" + description: "deny" + + - variable: networks + label: "Networks" + schema: + type: list + default: [] + items: + - variable: networkItem + label: "Network Item" + schema: + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + default: "" + required: true + - variable: networks + label: "Networks" + schema: + type: list + default: [] + items: + - variable: network + label: "network" + schema: + type: string + default: "" + required: true + + - variable: rules + label: "Rules" + schema: + type: list + default: [] + items: + - variable: rulesItem + label: "Rule" + schema: + type: dict + attrs: + - variable: domain + label: "Domain" + description: "defines which domain or set of domains the rule applies to." + schema: + type: string + default: "" + required: true + - variable: policy + label: "Policy" + description: "The policy to apply to resources. It must be either 'bypass', 'one_factor', 'two_factor' or 'deny'." + schema: + type: string + default: "two_factor" + enum: + - value: "bypass" + description: "bypass" + - value: "one_factor" + description: "one_factor" + - value: "two_factor" + description: "two_factor" + - value: "deny" + description: "two_factor" + - variable: subject + label: "Subject" + description: "defines the subject to apply authorizations to. This parameter is optional and matching any user if not provided" + schema: + type: list + default: [] + items: + - variable: subjectitem + label: "Subject" + schema: + type: string + default: "" + required: true + - variable: networks + label: "Networks" + schema: + type: list + default: [] + items: + - variable: network + label: "Network" + schema: + type: string + default: "" + required: true + - variable: resources + label: "Resources" + description: "is a list of regular expressions that matches a set of resources to apply the policy to" + schema: + type: list + default: [] + items: + - variable: resource + label: "Resource" + schema: + type: string + default: "" + required: true + + - variable: hostNetwork + group: "Networking and Services" + label: "Enable Host Networking" + schema: + type: boolean + default: false + + - variable: service + group: "Networking and Services" + label: "Configure Service(s)" + schema: + type: dict + attrs: + - variable: main + label: "Main Service" + description: "The Primary service on which the healthcheck runs, often the webUI" + schema: + type: dict + attrs: + - variable: enabled + label: "Enable the service" + schema: + type: boolean + default: true + hidden: true + - variable: type + label: "Service Type" + description: "ClusterIP's are only internally available, nodePorts expose the container to the host node System, Loadbalancer exposes the service using the system loadbalancer" + schema: + type: string + default: "NodePort" + enum: + - value: "NodePort" + description: "NodePort" + - value: "ClusterIP" + description: "ClusterIP" + - value: "LoadBalancer" + description: "LoadBalancer" + - variable: loadBalancerIP + label: "LoadBalancer IP" + description: "LoadBalancerIP" + schema: + show_if: [["type", "=", "LoadBalancer"]] + type: string + default: "" + - variable: externalIPs + label: "External IP's" + description: "External IP's" + schema: + show_if: [["type", "=", "LoadBalancer"]] + type: list + default: [] + items: + - variable: externalIP + label: "External IP" + schema: + type: string + - variable: ports + label: "Service's Port(s) Configuration" + schema: + type: dict + attrs: + - variable: main + label: "Main Service Port Configuration" + schema: + type: dict + attrs: + - variable: enabled + label: "Enable the port" + schema: + type: boolean + default: true + hidden: true + - variable: protocol + label: "Port Type" + schema: + type: string + default: "HTTP" + enum: + - value: HTTP + description: "HTTP" + - value: "HTTPS" + description: "HTTPS" + - value: TCP + description: "TCP" + - value: "UDP" + description: "UDP" + - variable: port + label: "Container Port" + schema: + type: int + default: 9091 + editable: false + hidden: true + - variable: targetport + label: "Target Port" + description: "This port exposes the container port on the service" + schema: + type: int + default: 9091 + editable: true + required: true + - variable: nodePort + label: "Node Port (Optional)" + description: "This port gets exposed to the node. Only considered when service type is NodePort" + schema: + type: int + min: 9000 + max: 65535 + default: 36000 + required: true + + - variable: persistence + label: "Integrated Persistent Storage" + description: "Integrated Persistent Storage" + group: "Storage and Persistence" + schema: + type: dict + attrs: + - variable: config + label: "App Config Storage" + description: "Stores the Application Configuration." + schema: + type: dict + attrs: + - variable: enabled + label: "Enable the storage" + schema: + type: boolean + default: true + - variable: type + label: "(Advanced) Type of Storage" + description: "Sets the persistence type" + schema: + type: string + default: "pvc" + enum: + - value: "pvc" + description: "pvc" + - value: "emptyDir" + description: "emptyDir" + - value: "hostPath" + description: "hostPath" + - variable: storageClass + label: "(Advanced) storageClass" + description: " Warning: Anything other than SCALE-ZFS will break rollback!" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "SCALE-ZFS" + - variable: setPermissions + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "hostPath"]] + type: boolean + default: true + - variable: readOnly + label: "readOnly" + schema: + type: boolean + default: false + - variable: hostPath + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "hostPath"]] + type: hostpath + - variable: hostPathType + label: "hostPath Type" + schema: + show_if: [["type", "=", "hostPath"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "DirectoryOrCreate" + description: "DirectoryOrCreate" + - value: "Directory" + description: "Directory" + - value: "FileOrCreate" + description: "FileOrCreate" + - value: "File" + description: "File" + - value: "Socket" + description: "Socket" + - value: "CharDevice" + description: "CharDevice" + - value: "BlockDevice" + description: "BlockDevice" + - variable: mountPath + label: "mountPath" + description: "Path inside the container the storage is mounted" + schema: + type: string + default: "/config" + hidden: true + - variable: medium + label: "EmptyDir Medium" + schema: + show_if: [["type", "=", "emptyDir"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "Memory" + description: "Memory" + - variable: accessMode + label: "Access Mode (Advanced)" + description: "Allow or disallow multiple PVC's writhing to the same PV" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "ReadWriteOnce" + enum: + - value: "ReadWriteOnce" + description: "ReadWriteOnce" + - value: "ReadOnlyMany" + description: "ReadOnlyMany" + - value: "ReadWriteMany" + description: "ReadWriteMany" + - variable: size + label: "Size quotum of storage" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "100Gi" + + - variable: persistenceList + label: "Additional app storage" + group: "Storage and Persistence" + schema: + type: list + default: [] + items: + - variable: persistenceListEntry + label: "Custom Storage" + schema: + type: dict + attrs: + - variable: enabled + label: "Enable the storage" + schema: + type: boolean + default: true + - variable: type + label: "(Advanced) Type of Storage" + description: "Sets the persistence type" + schema: + type: string + default: "hostPath" + enum: + - value: "pvc" + description: "pvc" + - value: "emptyDir" + description: "emptyDir" + - value: "hostPath" + description: "hostPath" + - variable: storageClass + label: "(Advanced) storageClass" + description: " Warning: Anything other than SCALE-ZFS will break rollback!" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "SCALE-ZFS" + - variable: setPermissions + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "hostPath"]] + type: boolean + default: true + - variable: readOnly + label: "readOnly" + schema: + type: boolean + default: false + - variable: hostPath + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "hostPath"]] + type: hostpath + - variable: hostPathType + label: "hostPath Type" + schema: + show_if: [["type", "=", "hostPath"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "DirectoryOrCreate" + description: "DirectoryOrCreate" + - value: "Directory" + description: "Directory" + - value: "FileOrCreate" + description: "FileOrCreate" + - value: "File" + description: "File" + - value: "Socket" + description: "Socket" + - value: "CharDevice" + description: "CharDevice" + - value: "BlockDevice" + description: "BlockDevice" + - variable: mountPath + label: "mountPath" + description: "Path inside the container the storage is mounted" + schema: + type: string + required: true + default: "" + - variable: medium + label: "EmptyDir Medium" + schema: + show_if: [["type", "=", "emptyDir"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "Memory" + description: "Memory" + - variable: accessMode + label: "Access Mode (Advanced)" + description: "Allow or disallow multiple PVC's writhing to the same PVC" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "ReadWriteOnce" + enum: + - value: "ReadWriteOnce" + description: "ReadWriteOnce" + - value: "ReadOnlyMany" + description: "ReadOnlyMany" + - value: "ReadWriteMany" + description: "ReadWriteMany" + - variable: size + label: "Size quotum of storage" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "100Gi" + + - variable: ingress + label: "" + group: "Ingress" + schema: + type: dict + attrs: + - variable: main + label: "Main Ingress" + schema: + type: dict + attrs: + - variable: enabled + label: "Enable Ingress" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: hosts + label: "Hosts" + schema: + type: list + default: [] + items: + - variable: hostEntry + label: "Host" + schema: + type: dict + attrs: + - variable: host + label: "HostName" + schema: + type: string + default: "" + required: true + - variable: paths + label: "Paths" + schema: + type: list + default: [] + items: + - variable: pathEntry + label: "Host" + schema: + type: dict + attrs: + - variable: path + label: "path" + schema: + type: string + required: true + default: "/" + - variable: pathType + label: "pathType" + schema: + type: string + required: true + default: "Prefix" + - variable: tls + label: "TLS-Settings" + schema: + type: list + default: [] + items: + - variable: tlsEntry + label: "Host" + schema: + type: dict + attrs: + - variable: hosts + label: "Certificate Hosts" + schema: + type: list + default: [] + items: + - variable: host + label: "Host" + schema: + type: string + default: "" + required: true + - variable: scaleCert + label: "Select TrueNAS SCALE Certificate" + schema: + type: int + $ref: + - "definitions/certificate" + - variable: entrypoint + label: "Traefik Entrypoint" + description: "Entrypoint used by Traefik when using Traefik as Ingress Provider" + schema: + type: string + default: "websecure" + required: true + - variable: middlewares + label: "Traefik Middlewares" + description: "Add previously created Traefik Middlewares to this Ingress" + schema: + type: list + default: [] + items: + - variable: name + label: "Name" + schema: + type: string + default: "" + required: true + + - variable: securityContext + group: "Security and Permissions" + label: "Security Context" + schema: + type: dict + attrs: + - variable: privileged + label: "Privileged mode" + schema: + type: boolean + default: false + - variable: readOnlyRootFilesystem + label: "ReadOnly Root Filesystem" + schema: + type: boolean + default: true + - variable: allowPrivilegeEscalation + label: "Allow Privilege Escalation" + schema: + type: boolean + default: false + + - variable: podSecurityContext + group: "Security and Permissions" + label: "Pod Security Context" + schema: + type: dict + attrs: + - variable: runAsNonRoot + label: "runAsNonRoot" + schema: + type: boolean + default: true + - variable: runAsUser + label: "runAsUser" + description: "The UserID of the user running the application" + schema: + type: int + default: 568 + - variable: runAsGroup + label: "runAsGroup" + description: The groupID this App of the user running the application" + schema: + type: int + default: 568 + - variable: fsGroup + label: "fsGroup" + description: "The group that should own ALL storage." + schema: + type: int + default: 568 + - variable: supplementalGroups + label: "When should we take ownership?" + schema: + type: list + default: [] + items: + - variable: supplementalGroupsEntry + label: "When should we take ownership?" + schema: + type: int + - variable: fsGroupChangePolicy + label: "When should we take ownership?" + schema: + type: string + default: "OnRootMismatch" + enum: + - value: "OnRootMismatch" + description: "OnRootMismatch" + - value: "Always" + description: "Always" + - variable: resources + group: "Resources and Devices" + label: "" + schema: + type: dict + attrs: + - variable: limits + label: "Advanced Limit Resource Consumption" + schema: + type: dict + attrs: + - variable: cpu + label: "CPU" + schema: + type: string + default: "2000m" + - variable: memory + label: "Memory RAM" + schema: + type: string + default: "2Gi" + - variable: requests + label: "Advanced Request minimum resources required" + schema: + type: dict + attrs: + - variable: cpu + label: "CPU" + schema: + type: string + default: "10m" + - variable: memory + label: "Memory RAM" + schema: + type: string + default: "50Mi" diff --git a/incubator/authelia/0.0.1/templates/_configmap.tpl b/incubator/authelia/0.0.1/templates/_configmap.tpl new file mode 100644 index 0000000000..4bdeefd71c --- /dev/null +++ b/incubator/authelia/0.0.1/templates/_configmap.tpl @@ -0,0 +1,245 @@ +{{/* Define the configmap */}} +{{- define "authelia.configmap" -}} +--- +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ include "common.names.fullname" . }}-paths +data: + AUTHELIA_SERVER_DISABLE_HEALTHCHECK: "true" + AUTHELIA_JWT_SECRET_FILE: "/secrets/JWT_TOKEN" + AUTHELIA_SESSION_SECRET_FILE: "/secrets/SESSION_ENCRYPTION_KEY" + AUTHELIA_STORAGE_POSTGRES_PASSWORD_FILE: "/secrets/STORAGE_PASSWORD" + {{- if .Values.authentication_backend.ldap.enabled }} + AUTHELIA_AUTHENTICATION_BACKEND_LDAP_PASSWORD_FILE: "/secrets/LDAP_PASSWORD" + {{- end }} + {{- if .Values.notifier.smtp.enabled }} + AUTHELIA_NOTIFIER_SMTP_PASSWORD_FILE: "/secrets/SMTP_PASSWORD" + {{- end }} + AUTHELIA_SESSION_REDIS_PASSWORD_FILE: "/secrets/REDIS_PASSWORD" + {{- if and .Values.redisProvider.high_availability.enabled}} + AUTHELIA_SESSION_REDIS_HIGH_AVAILABILITY_SENTINEL_PASSWORD_FILE: "/secrets/REDIS_SENTINEL_PASSWORD" + {{- end }} + {{- if .Values.duo_api.enabled }} + AUTHELIA_DUO_API_SECRET_KEY_FILE: "/secrets/DUO_API_KEY" + {{- end }} + {{- if .Values.identity_providers.oidc.enabled }} + AUTHELIA_IDENTITY_PROVIDERS_OIDC_HMAC_SECRET_FILE: "/secrets/OIDC_HMAC_SECRET" + AUTHELIA_IDENTITY_PROVIDERS_OIDC_ISSUER_PRIVATE_KEY_FILE: "/secrets/OIDC_PRIVATE_KEY" + {{- end }} + +--- + +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ include "common.names.fullname" . }}-configfile +data: + configuration.yaml: | + --- + theme: {{ default "light" .Values.theme }} + default_redirection_url: {{ default (printf "https://www.%s" .Values.domain) .Values.default_redirection_url }} + server: + host: 0.0.0.0 + port: {{ default 9091 .Values.server.port }} + {{- if not (eq "" (default "" .Values.server.path)) }} + path: {{ .Values.server.path }} + {{- end }} + read_buffer_size: {{ default 4096 .Values.server.read_buffer_size }} + write_buffer_size: {{ default 4096 .Values.server.write_buffer_size }} + enable_pprof: {{ default false .Values.server.enable_pprof }} + enable_expvars: {{ default false .Values.server.enable_expvars }} + log: + level: {{ default "info" .Values.log.level }} + format: {{ default "text" .Values.log.format }} + {{- if not (eq "" (default "" .Values.log.file_path)) }} + file_path: {{ .Values.log.file_path }} + keep_stdout: true + {{- end }} + totp: + issuer: {{ default .Values.domain .Values.totp.issuer }} + period: {{ default 30 .Values.totp.period }} + skew: {{ default 1 .Values.totp.skew }} + {{- if .Values.duo_api.enabled }} + duo_api: + hostname: {{ .Values.duo_api.hostname }} + integration_key: {{ .Values.duo_api.integration_key }} + {{- end }} + {{- with $auth := .Values.authentication_backend }} + authentication_backend: + disable_reset_password: {{ $auth.disable_reset_password }} + {{- if $auth.file.enabled }} + file: + path: {{ $auth.file.path }} + password: {{ toYaml $auth.file.password | nindent 10 }} + {{- end }} + {{- if $auth.ldap.enabled }} + ldap: + implementation: {{ default "custom" $auth.ldap.implementation }} + url: {{ $auth.ldap.url }} + timeout: {{ default "5s" $auth.ldap.timeout }} + start_tls: {{ $auth.ldap.start_tls }} + tls: + {{- if hasKey $auth.ldap.tls "server_name" }} + server_name: {{ default $auth.ldap.host $auth.ldap.tls.server_name }} + {{- end }} + minimum_version: {{ default "TLS1.2" $auth.ldap.tls.minimum_version }} + skip_verify: {{ default false $auth.ldap.tls.skip_verify }} + {{- if $auth.ldap.base_dn }} + base_dn: {{ $auth.ldap.base_dn }} + {{- end }} + {{- if $auth.ldap.username_attribute }} + username_attribute: {{ $auth.ldap.username_attribute }} + {{- end }} + {{- if $auth.ldap.additional_users_dn }} + additional_users_dn: {{ $auth.ldap.additional_users_dn }} + {{- end }} + {{- if $auth.ldap.users_filter }} + users_filter: {{ $auth.ldap.users_filter }} + {{- end }} + {{- if $auth.ldap.additional_groups_dn }} + additional_groups_dn: {{ $auth.ldap.additional_groups_dn }} + {{- end }} + {{- if $auth.ldap.groups_filter }} + groups_filter: {{ $auth.ldap.groups_filter }} + {{- end }} + {{- if $auth.ldap.group_name_attribute }} + group_name_attribute: {{ $auth.ldap.group_name_attribute }} + {{- end }} + {{- if $auth.ldap.mail_attribute }} + mail_attribute: {{ $auth.ldap.mail_attribute }} + {{- end }} + {{- if $auth.ldap.display_name_attribute }} + display_name_attribute: {{ $auth.ldap.display_name_attribute }} + {{- end }} + user: {{ $auth.ldap.user }} + {{- end }} + {{- end }} + {{- with $session := .Values.session }} + session: + name: {{ default "authelia_session" $session.name }} + domain: {{ required "A valid .Values.domain entry required!" $.Values.domain }} + same_site: {{ default "lax" $session.same_site }} + expiration: {{ default "1M" $session.expiration }} + inactivity: {{ default "5m" $session.inactivity }} + remember_me_duration: {{ default "1M" $session.remember_me_duration }} + {{- end }} + redis: + host: {{ ( printf "%v-%v" .Release.Name "redis-master" ) }} + {{- with $redis := .Values.redisProvider }} + port: {{ default 6379 $redis.port }} + {{- if not (eq $redis.username "") }} + username: {{ $redis.username }} + {{- end }} + maximum_active_connections: {{ default 8 $redis.maximum_active_connections }} + minimum_idle_connections: {{ default 0 $redis.minimum_idle_connections }} + {{- if $redis.tls.enabled }} + tls: + server_name: {{ $redis.tls.server_name }} + minimum_version: {{ default "TLS1.2" $redis.tls.minimum_version }} + skip_verify: {{ $redis.tls.skip_verify }} + {{- end }} + {{- if $redis.high_availability.enabled }} + high_availability: + sentinel_name: {{ $redis.high_availability.sentinel_name }} + {{- if $redis.high_availability.nodes }} + nodes: {{ toYaml $redis.high_availability.nodes | nindent 10 }} + {{- end }} + route_by_latency: {{ $redis.high_availability.route_by_latency }} + route_randomly: {{ $redis.high_availability.route_randomly }} + {{- end }} + {{- end }} + + regulation: {{ toYaml .Values.regulation | nindent 6 }} + storage: + postgres: + host: {{ printf "%v-%v" .Release.Name "postgresql" }} + {{- with $storage := .Values.storage }} + port: {{ default 5432 $storage.postgres.port }} + database: {{ default "authelia" $storage.postgres.database }} + username: {{ default "authelia" $storage.postgres.username }} + timeout: {{ default "5s" $storage.postgres.timeout }} + sslmode: {{ default "disable" $storage.postgres.sslmode }} + {{- end }} + {{- with $notifier := .Values.notifier }} + notifier: + disable_startup_check: {{ $.Values.notifier.disable_startup_check }} + {{- if $notifier.filesystem.enabled }} + filesystem: + filename: {{ $notifier.filesystem.filename }} + {{- end }} + {{- if $notifier.smtp.enabled }} + smtp: + host: {{ $notifier.smtp.host }} + port: {{ default 25 $notifier.smtp.port }} + timeout: {{ default "5s" $notifier.smtp.timeout }} + username: {{ $notifier.smtp.username }} + sender: {{ $notifier.smtp.sender }} + identifier: {{ $notifier.smtp.identifier }} + subject: {{ $notifier.smtp.subject | quote }} + startup_check_address: {{ $notifier.smtp.startup_check_address }} + disable_require_tls: {{ $notifier.smtp.disable_require_tls }} + disable_html_emails: {{ $notifier.smtp.disable_html_emails }} + tls: + server_name: {{ default $notifier.smtp.host $notifier.smtp.tls.server_name }} + minimum_version: {{ default "TLS1.2" $notifier.smtp.tls.minimum_version }} + skip_verify: {{ default false $notifier.smtp.tls.skip_verify }} + {{- end }} + {{- end }} + {{- if .Values.identity_providers.oidc.enabled }} + identity_providers: + oidc: + access_token_lifespan: {{ default "1h" .Values.identity_providers.oidc.access_token_lifespan }} + authorize_code_lifespan: {{ default "1m" .Values.identity_providers.oidc.authorize_code_lifespan }} + id_token_lifespan: {{ default "1h" .Values.identity_providers.oidc.id_token_lifespan }} + refresh_token_lifespan: {{ default "90m" .Values.identity_providers.oidc.refresh_token_lifespan }} + enable_client_debug_messages: {{ default false .Values.identity_providers.oidc.enable_client_debug_messages }} + minimum_parameter_entropy: {{ default 8 .Values.identity_providers.oidc.minimum_parameter_entropy }} + {{- if gt (len .Values.identity_providers.oidc.clients) 0 }} + clients: + {{- range $client := .Values.identity_providers.oidc.clients }} + - id: {{ $client.id }} + description: {{ default $client.id $client.description }} + secret: {{ default (randAlphaNum 128) $client.secret }} + {{- if hasKey $client "public" }} + public: {{ $client.public }} + {{- end }} + authorization_policy: {{ default "two_factor" $client.authorization_policy }} + redirect_uris: {{ toYaml $client.redirect_uris | nindent 10 }} + {{- if hasKey $client "audience" }} + audience: {{ toYaml $client.audience | nindent 10 }} + {{- end }} + scopes: {{ toYaml (default (list "openid" "profile" "email" "groups") $client.scopes) | nindent 10 }} + grant_types: {{ toYaml (default (list "refresh_token" "authorization_code") $client.grant_types) | nindent 10 }} + response_types: {{ toYaml (default (list "code") $client.response_types) | nindent 10 }} + {{- if hasKey $client "response_modes" }} + response_modes: {{ toYaml $client.response_modes | nindent 10 }} + {{- end }} + userinfo_signing_algorithm: {{ default "none" $client.userinfo_signing_algorithm }} + {{- end }} + {{- end }} + {{- end }} + access_control: + {{- if (eq (len .Values.access_control.rules) 0) }} + {{- if (eq .Values.access_control.default_policy "bypass") }} + default_policy: one_factor + {{- else if (eq .Values.access_control.default_policy "deny") }} + default_policy: two_factor + {{- else }} + default_policy: {{ .Values.access_control.default_policy }} + {{- end }} + {{- else }} + default_policy: {{ .Values.access_control.default_policy }} + {{- end }} + {{- if (eq (len .Values.access_control.networks) 0) }} + networks: [] + {{- else }} + networks: {{ toYaml .Values.access_control.networks | nindent 6 }} + {{- end }} + {{- if (eq (len .Values.access_control.rules) 0) }} + rules: [] + {{- else }} + rules: {{ toYaml .Values.access_control.rules | nindent 6 }} + {{- end }} + ... +{{- end -}} diff --git a/incubator/authelia/0.0.1/templates/_secrets.tpl b/incubator/authelia/0.0.1/templates/_secrets.tpl new file mode 100644 index 0000000000..44f8b0e154 --- /dev/null +++ b/incubator/authelia/0.0.1/templates/_secrets.tpl @@ -0,0 +1,112 @@ +{{/* Define the secrets */}} +{{- define "authelia.secrets" -}} +--- + +apiVersion: v1 +kind: Secret +metadata: + labels: + {{- include "common.labels" . | nindent 4 }} + name: {{ .Release.Name }}-dbcreds +{{- $dbprevious := lookup "v1" "Secret" .Release.Namespace ( ( printf "%v-%v" .Release.Name "dbcreds" ) | quote ) }} +{{- $dbPass := "" }} +data: +{{- if $dbprevious }} + postgresql-password: {{ ( index $dbprevious.data "postgresql-password" ) }} + postgresql-postgres-password: {{ ( index $dbprevious.data "postgresql-postgres-password" ) }} +{{- else }} + {{- $dbPass = randAlphaNum 50 }} + postgresql-password: {{ $dbPass | b64enc | quote }} + postgresql-postgres-password: {{ randAlphaNum 50 | b64enc | quote }} +{{- end }} + url: {{ ( printf "%v%v:%v@%v-%v:%v/%v" "postgresql://" .Values.postgresql.postgresqlUsername $dbPass .Release.Name "postgresql" "5432" .Values.postgresql.postgresqlDatabase ) | b64enc | quote }} +type: Opaque + + +--- + +apiVersion: v1 +kind: Secret +metadata: + labels: + {{- include "common.labels" . | nindent 4 }} + name: rediscreds +{{- $redisprevious := lookup "v1" "Secret" .Release.Namespace "rediscreds" }} +{{- $redisPass := "" }} +{{- $sentinelPass := "" }} +data: +{{- if $redisprevious }} + redis-password: {{ ( index $redisprevious.data "redis-password" ) }} + sentinel-password: {{ ( index $redisprevious.data "sentinel-password" ) }} +{{- else }} + {{- $redisPass = randAlphaNum 50 }} + {{- $sentinelPass = randAlphaNum 50 }} + redis-password: {{ $redisPass | b64enc | quote }} + sentinel-password: {{ $sentinelPass | b64enc | quote }} +{{- end }} + masterhost: {{ ( printf "%v-%v" .Release.Name "redis-master" ) | b64enc | quote }} + slavehost: {{ ( printf "%v-%v" .Release.Name "redis-master" ) | b64enc | quote }} +type: Opaque + + +--- + +apiVersion: v1 +kind: Secret +type: Opaque +metadata: + name: {{ include "common.names.fullname" . }}-secrets +{{- $autheliaprevious := lookup "v1" "Secret" .Release.Namespace ( ( printf "%v-%v" ( ( include "common.names.fullname" . ) | quote ) "-secrets" ) | quote ) }} +{{- $oidckey := "" }} +{{- $oidcsecret := "" }} +{{- $jwtsecret := "" }} +{{- $sessionsecret := "" }} +data: + {{- if $autheliaprevious }} + SESSION_ENCRYPTION_KEY: {{ index $autheliaprevious.data "SESSION_ENCRYPTION_KEY" }} + JWT_TOKEN: {{ index $autheliaprevious.data "JWT_TOKEN" }} + {{- else }} + {{- $jwtsecret := randAlphaNum 50 }} + {{- $sessionsecret := randAlphaNum 50 }} + SESSION_ENCRYPTION_KEY: {{ $jwtsecret | b64enc | quote }} + JWT_TOKEN: {{ $jwtsecret | b64enc | quote }} + {{- end }} + {{- if .Values.authentication_backend.ldap.enabled }} + LDAP_PASSWORD: {{ .Values.authentication_backend.ldap.plain_password }} + {{- end }} + {{- if .Values.notifier.smtp.enabled }} + SMTP_PASSWORD: {{ .Values.notifier.smtp.plain_password }} + {{- end }} + {{- if .Values.duo_api.enabled }} + DUO_API_KEY: {{ .Values.duo_api.plain_api_key | b64enc }} + {{- end }} + {{- if $dbprevious }} + STORAGE_PASSWORD: {{ ( index $dbprevious.data "postgresql-password" ) }} + {{- else }} + STORAGE_PASSWORD: {{ $dbPass | b64enc | quote }} + {{- end }} + {{- if $redisprevious }} + REDIS_PASSWORD: {{ ( index $redisprevious.data "redis-password" ) }} + {{- if .Values.redisProvider.high_availability.enabled}} + REDIS_SENTINEL_PASSWORD: {{ ( index $redisprevious.data "sentinel-password" ) }} + {{- end }} + {{- else }} + REDIS_PASSWORD: {{ $redisPass | b64enc | quote }} + {{- if .Values.redisProvider.high_availability.enabled}} + REDIS_SENTINEL_PASSWORD: {{ $sentinelPass | b64enc | quote }} + {{- end }} + {{- end }} + {{- if .Values.identity_providers.oidc.enabled }} + {{- if $autheliaprevious }} + OIDC_PRIVATE_KEY: {{ index $autheliaprevious.data "OIDC_PRIVATE_KEY" }} + OIDC_HMAC_SECRET: {{index $autheliaprevious.data "OIDC_HMAC_SECRET" }} + {{- else }} + {{- $oidckey := genPrivateKey "rsa" }} + {{- $oidcsecret := randAlphaNum 32 }} + OIDC_PRIVATE_KEY: {{ $oidckey | b64enc }} + OIDC_HMAC_SECRET: {{ $oidcsecret | b64enc }} + {{- end }} + {{- end }} + + +{{- end -}} diff --git a/incubator/authelia/0.0.1/templates/common.yaml b/incubator/authelia/0.0.1/templates/common.yaml new file mode 100644 index 0000000000..caa2c91f30 --- /dev/null +++ b/incubator/authelia/0.0.1/templates/common.yaml @@ -0,0 +1,72 @@ +{{/* Make sure all variables are set properly */}} +{{- include "common.values.setup" . }} + +{{/* Render configmap for authelia */}} +{{- include "authelia.configmap" . }} + +{{/* Render secrets for authelia */}} +{{- include "authelia.secrets" . }} + +{{/* Append the general configMap volume to the volumes */}} +{{- define "authelia.configmapVolume" -}} +enabled: "true" +mountPath: " /configuration.yaml" +readOnly: true +subPath: configuration.yaml +type: "custom" +volumeSpec: + configMap: + name: {{ include "common.names.fullname" . }}-configfile + items: + - key: configuration.yaml + path: configuration.yaml +{{- end -}} + +{{/* Append the general secret volumes to the volumes */}} +{{- define "authelia.secretVolumes" -}} +enabled: "true" +mountPath: " /secrets" +readOnly: true +type: "custom" +volumeSpec: + secret: + secretName: {{ include "common.names.fullname" . }}-secrets + items: + - key: "JWT_TOKEN" + path: JWT_TOKEN + - key: "SESSION_ENCRYPTION_KEY" + path: SESSION_ENCRYPTION_KEY + - key: "STORAGE_PASSWORD" + path: STORAGE_PASSWORD + {{- if .Values.authentication_backend.ldap.enabled }} + - key: "LDAP_PASSWORD" + path: LDAP_PASSWORD + {{- end }} + {{- if .Values.notifier.smtp.enabled }} + - key: "SMTP_PASSWORD" + path: SMTP_PASSWORD + {{- end }} + - key: "REDIS_PASSWORD" + path: REDIS_PASSWORD + {{- if .Values.redisProvider.high_availability.enabled}} + - key: "REDIS_SENTINEL_PASSWORD" + path: REDIS_SENTINEL_PASSWORD + {{- end }} + {{- if .Values.duo_api.enabled }} + - key: "DUO_API_KEY" + path: DUO_API_KEY + {{- end }} + {{- if .Values.identity_providers.oidc.enabled }} + - key: "OIDC_PRIVATE_KEY" + path: OIDC_PRIVATE_KEY + - key: "OIDC_HMAC_SECRET" + path: OIDC_HMAC_SECRET + {{- end }} +{{- end -}} + +{{- $_ := set .Values.persistence "authelia-configfile" (include "authelia.configmapVolume" . | fromYaml) -}} +{{- $_ := set .Values.persistence "authelia-secrets" (include "authelia.secretVolumes" . | fromYaml) -}} + + +{{/* Render the templates */}} +{{ include "common.all" . }} diff --git a/incubator/authelia/0.0.1/test_values.yaml b/incubator/authelia/0.0.1/test_values.yaml new file mode 100644 index 0000000000..f416a33a43 --- /dev/null +++ b/incubator/authelia/0.0.1/test_values.yaml @@ -0,0 +1,662 @@ +# Default values for Bitwarden. + +image: + repository: ghcr.io/authelia/authelia + pullPolicy: IfNotPresent + tag: "4.30.4" + +command: ["authelia"] +args: ["--config=/configuration.yaml"] + +strategy: + type: Recreate + +service: + main: + ports: + main: + port: 9091 + +persistence: + config: + enabled: true + mountPath: "/config" + type: pvc + accessMode: ReadWriteOnce + size: "100Gi" + redismaster: + noMount: true + forceName: "redismaster" + enabled: true + type: pvc + accessMode: ReadWriteOnce + size: "100Gi" + +# Enabled postgres +postgresql: + enabled: true + postgresqlUsername: authelia + postgresqlDatabase: authelia + existingSecret: "{{ .Release.Name }}-dbcreds" + +# Enabled redis +# ... for more options see https://github.com/bitnami/charts/tree/master/bitnami/redis +redis: + volumePermissions: + enabled: true + architecture: standalone + enabled: true + auth: + existingSecret: rediscreds + existingSecretPasswordKey: redis-password + master: + persistence: + enabled: false + existingClaim: redismaster + replica: + replicaCount: 0 + persistence: + enabled: false + + +podSecurityContext: + runAsUser: 568 + runAsGroup: 568 + fsGroup: 568 + +securityContext: + readOnlyRootFilesystem: true + allowPrivilegeEscalation: false + privileged: false + + +resources: + limits: {} + # limits: + # cpu: "4.00" + # memory: 125Mi + requests: {} + # requests: + # cpu: "0.25" + # memory: 50Mi + +envFrom: + - configMapRef: + name: '{{ include "common.names.fullname" . }}-paths' + +probes: + liveness: + type: HTTP + path: /api/health" + + readiness: + type: HTTP + path: "/api/health" + + startup: + type: HTTP + path: "/api/health" + +domain: example.com + +## +## Server Configuration +## +server: + ## + ## Port sets the configured port for the daemon, service, and the probes. + ## Default is 9091 and should not need to be changed. + ## + port: 9091 + + ## Buffers usually should be configured to be the same value. + ## Explanation at https://www.authelia.com/docs/configuration/server.html + ## Read buffer size adjusts the server's max incoming request size in bytes. + ## Write buffer size does the same for outgoing responses. + read_buffer_size: 4096 + write_buffer_size: 4096 + ## Set the single level path Authelia listens on. + ## Must be alphanumeric chars and should not contain any slashes. + path: "" + +log: + ## Level of verbosity for logs: info, debug, trace. + level: trace + + ## Format the logs are written as: json, text. + format: text + + ## TODO: Statefulness check should check if this is set, and the configMap should enable it. + ## File path where the logs will be written. If not set logs are written to stdout. + # file_path: /config/authelia.log + +## Default redirection URL +## +## If user tries to authenticate without any referer, Authelia does not know where to redirect the user to at the end +## of the authentication process. This parameter allows you to specify the default redirection URL Authelia will use +## in such a case. +## +## Note: this parameter is optional. If not provided, user won't be redirected upon successful authentication. +## Default is https://www. (value at the top of the values.yaml). +default_redirection_url: "" +# default_redirection_url: https://example.com + +theme: light + +## +## TOTP Configuration +## +## Parameters used for TOTP generation +totp: + ## The issuer name displayed in the Authenticator application of your choice + ## See: https://github.com/google/google-authenticator/wiki/Key-Uri-Format for more info on issuer names + ## Defaults to . + issuer: "" + ## The period in seconds a one-time password is current for. Changing this will require all users to register + ## their TOTP applications again. Warning: before changing period read the docs link below. + period: 30 + ## The skew controls number of one-time passwords either side of the current one that are valid. + ## Warning: before changing skew read the docs link below. + ## See: https://www.authelia.com/docs/configuration/one-time-password.html#period-and-skew to read the documentation. + skew: 1 + +## +## Duo Push API Configuration +## +## Parameters used to contact the Duo API. Those are generated when you protect an application of type +## "Partner Auth API" in the management panel. +duo_api: + enabled: false + hostname: api-123456789.example.com + integration_key: ABCDEF + plain_api_key: "" + +## +## Authentication Backend Provider Configuration +## +## Used for verifying user passwords and retrieve information such as email address and groups users belong to. +## +## The available providers are: `file`, `ldap`. You must use one and only one of these providers. +authentication_backend: + ## Disable both the HTML element and the API for reset password functionality + disable_reset_password: false + + ## The amount of time to wait before we refresh data from the authentication backend. Uses duration notation. + ## To disable this feature set it to 'disable', this will slightly reduce security because for Authelia, users will + ## always belong to groups they belonged to at the time of login even if they have been removed from them in LDAP. + ## To force update on every request you can set this to '0' or 'always', this will increase processor demand. + ## See the below documentation for more information. + ## Duration Notation docs: https://www.authelia.com/docs/configuration/index.html#duration-notation-format + ## Refresh Interval docs: https://www.authelia.com/docs/configuration/authentication/ldap.html#refresh-interval + refresh_interval: 5m + + ## LDAP backend configuration. + ## + ## This backend allows Authelia to be scaled to more + ## than one instance and therefore is recommended for + ## production. + ldap: + + ## Enable LDAP Backend. + enabled: false + + ## The LDAP implementation, this affects elements like the attribute utilised for resetting a password. + ## Acceptable options are as follows: + ## - 'activedirectory' - For Microsoft Active Directory. + ## - 'custom' - For custom specifications of attributes and filters. + ## This currently defaults to 'custom' to maintain existing behaviour. + ## + ## Depending on the option here certain other values in this section have a default value, notably all of the + ## attribute mappings have a default value that this config overrides, you can read more about these default values + ## at https://www.authelia.com/docs/configuration/authentication/ldap.html#defaults + implementation: activedirectory + + ## The url to the ldap server. Format: ://
[:]. + ## Scheme can be ldap or ldaps in the format (port optional). + url: ldap://openldap.default.svc.cluster.local + + ## Connection Timeout. + timeout: 5s + + ## Use StartTLS with the LDAP connection. + start_tls: false + + tls: + ## Server Name for certificate validation (in case it's not set correctly in the URL). + server_name: "" + + ## Skip verifying the server certificate (to allow a self-signed certificate). + ## In preference to setting this we strongly recommend you add the public portion of the certificate to the + ## certificates directory which is defined by the `certificates_directory` option at the top of the config. + skip_verify: false + + ## Minimum TLS version for either Secure LDAP or LDAP StartTLS. + minimum_version: TLS1.2 + + ## The base dn for every LDAP query. + base_dn: DC=example,DC=com + + ## The attribute holding the username of the user. This attribute is used to populate the username in the session + ## information. It was introduced due to #561 to handle case insensitive search queries. For you information, + ## Microsoft Active Directory usually uses 'sAMAccountName' and OpenLDAP usually uses 'uid'. Beware that this + ## attribute holds the unique identifiers for the users binding the user and the configuration stored in database. + ## Therefore only single value attributes are allowed and the value must never be changed once attributed to a user + ## otherwise it would break the configuration for that user. Technically, non-unique attributes like 'mail' can also + ## be used but we don't recommend using them, we instead advise to use the attributes mentioned above + ## (sAMAccountName and uid) to follow https://www.ietf.org/rfc/rfc2307.txt. + username_attribute: "" + + ## An additional dn to define the scope to all users. + additional_users_dn: OU=Users + + ## The users filter used in search queries to find the user profile based on input filled in login form. + ## Various placeholders are available in the user filter: + ## - {input} is a placeholder replaced by what the user inputs in the login form. + ## - {username_attribute} is a mandatory placeholder replaced by what is configured in `username_attribute`. + ## - {mail_attribute} is a placeholder replaced by what is configured in `mail_attribute`. + ## - DON'T USE - {0} is an alias for {input} supported for backward compatibility but it will be deprecated in later + ## versions, so please don't use it. + ## + ## Recommended settings are as follows: + ## - Microsoft Active Directory: (&({username_attribute}={input})(objectCategory=person)(objectClass=user)) + ## - OpenLDAP: + ## - (&({username_attribute}={input})(objectClass=person)) + ## - (&({username_attribute}={input})(objectClass=inetOrgPerson)) + ## + ## To allow sign in both with username and email, one can use a filter like + ## (&(|({username_attribute}={input})({mail_attribute}={input}))(objectClass=person)) + users_filter: "" + + ## An additional dn to define the scope of groups. + additional_groups_dn: OU=Groups + + ## The groups filter used in search queries to find the groups of the user. + ## - {input} is a placeholder replaced by what the user inputs in the login form. + ## - {username} is a placeholder replace by the username stored in LDAP (based on `username_attribute`). + ## - {dn} is a matcher replaced by the user distinguished name, aka, user DN. + ## - {username_attribute} is a placeholder replaced by what is configured in `username_attribute`. + ## - {mail_attribute} is a placeholder replaced by what is configured in `mail_attribute`. + ## - DON'T USE - {0} is an alias for {input} supported for backward compatibility but it will be deprecated in later + ## versions, so please don't use it. + ## - DON'T USE - {1} is an alias for {username} supported for backward compatibility but it will be deprecated in + ## later version, so please don't use it. + ## + ## If your groups use the `groupOfUniqueNames` structure use this instead: + ## (&(uniquemember={dn})(objectclass=groupOfUniqueNames)) + groups_filter: "" + + ## The attribute holding the name of the group + group_name_attribute: "" + + ## The attribute holding the mail address of the user. If multiple email addresses are defined for a user, only the + ## first one returned by the LDAP server is used. + mail_attribute: "" + + ## The attribute holding the display name of the user. This will be used to greet an authenticated user. + display_name_attribute: "" + + ## The username of the admin user. + user: CN=Authelia,DC=example,DC=com + plain_password: "" + + ## + ## File (Authentication Provider) + ## + ## With this backend, the users database is stored in a file which is updated when users reset their passwords. + ## Therefore, this backend is meant to be used in a dev environment and not in production since it prevents Authelia + ## to be scaled to more than one instance. The options under 'password' have sane defaults, and as it has security + ## implications it is highly recommended you leave the default values. Before considering changing these settings + ## please read the docs page below: + ## https://www.authelia.com/docs/configuration/authentication/file.html#password-hash-algorithm-tuning + ## + ## Important: Kubernetes (or HA) users must read https://www.authelia.com/docs/features/statelessness.html + ## + file: + enabled: true + path: /config/users_database.yml + password: + algorithm: argon2id + iterations: 1 + key_length: 32 + salt_length: 16 + memory: 1024 + parallelism: 8 + +## +## Access Control Configuration +## +## Access control is a list of rules defining the authorizations applied for one resource to users or group of users. +## +## If 'access_control' is not defined, ACL rules are disabled and the 'bypass' rule is applied, i.e., access is allowed +## to anyone. Otherwise restrictions follow the rules defined. +## +## Note: One can use the wildcard * to match any subdomain. +## It must stand at the beginning of the pattern. (example: *.mydomain.com) +## +## Note: You must put patterns containing wildcards between simple quotes for the YAML to be syntactically correct. +## +## Definition: A 'rule' is an object with the following keys: 'domain', 'subject', 'policy' and 'resources'. +## +## - 'domain' defines which domain or set of domains the rule applies to. +## +## - 'subject' defines the subject to apply authorizations to. This parameter is optional and matching any user if not +## provided. If provided, the parameter represents either a user or a group. It should be of the form +## 'user:' or 'group:'. +## +## - 'policy' is the policy to apply to resources. It must be either 'bypass', 'one_factor', 'two_factor' or 'deny'. +## +## - 'resources' is a list of regular expressions that matches a set of resources to apply the policy to. This parameter +## is optional and matches any resource if not provided. +## +## Note: the order of the rules is important. The first policy matching (domain, resource, subject) applies. +access_control: + ## Default policy can either be 'bypass', 'one_factor', 'two_factor' or 'deny'. It is the policy applied to any + ## resource if there is no policy to be applied to the user. + default_policy: deny + + networks: [] + # networks: + # - name: private + # networks: + # - 10.0.0.0/8 + # - 172.16.0.0/12 + # - 192.168.0.0/16 + # - name: vpn + # networks: + # - 10.9.0.0/16 + + rules: [] + # rules: + # - domain: public.example.com + # policy: bypass + # - domain: "*.example.com" + # policy: bypass + # methods: + # - OPTIONS + # - domain: secure.example.com + # policy: one_factor + # networks: + # - private + # - vpn + # - 192.168.1.0/24 + # - 10.0.0.1 + # - domain: + # - secure.example.com + # - private.example.com + # policy: two_factor + # - domain: singlefactor.example.com + # policy: one_factor + # - domain: "mx2.mail.example.com" + # subject: "group:admins" + # policy: deny + # - domain: "*.example.com" + # subject: + # - "group:admins" + # - "group:moderators" + # policy: two_factor + # - domain: dev.example.com + # resources: + # - "^/groups/dev/.*$" + # subject: "group:dev" + # policy: two_factor + # - domain: dev.example.com + # resources: + # - "^/users/john/.*$" + # subject: + # - ["group:dev", "user:john"] + # - "group:admins" + # policy: two_factor + # - domain: "{user}.example.com" + # policy: bypass + +## +## Session Provider Configuration +## +## The session cookies identify the user once logged in. +## The available providers are: `memory`, `redis`. Memory is the provider unless redis is defined. +session: + ## The name of the session cookie. (default: authelia_session). + name: authelia_session + + ## Sets the Cookie SameSite value. Possible options are none, lax, or strict. + ## Please read https://www.authelia.com/docs/configuration/session.html#same_site + same_site: lax + + ## The time in seconds before the cookie expires and session is reset. + expiration: 1h + + ## The inactivity time in seconds before the session is reset. + inactivity: 5m + + ## The remember me duration. + ## Value is in seconds, or duration notation. Value of 0 disables remember me. + ## See: https://www.authelia.com/docs/configuration/index.html#duration-notation-format + ## Longer periods are considered less secure because a stolen cookie will last longer giving attackers more time to + ## spy or attack. Currently the default is 1M or 1 month. + remember_me_duration: 1M + +## +## Redis Provider +## +## Important: Kubernetes (or HA) users must read https://www.authelia.com/docs/features/statelessness.html +## +## The redis connection details +redisProvider: + port: 6379 + + ## Optional username to be used with authentication. + # username: authelia + username: "" + + ## This is the Redis DB Index https://redis.io/commands/select (sometimes referred to as database number, DB, etc). + database_index: 0 + + ## The maximum number of concurrent active connections to Redis. + maximum_active_connections: 8 + + ## The target number of idle connections to have open ready for work. Useful when opening connections is slow. + minimum_idle_connections: 0 + + ## The Redis TLS configuration. If defined will require a TLS connection to the Redis instance(s). + tls: + enabled: false + + ## Server Name for certificate validation (in case you are using the IP or non-FQDN in the host option). + server_name: "" + + ## Skip verifying the server certificate (to allow a self-signed certificate). + ## In preference to setting this we strongly recommend you add the public portion of the certificate to the + ## certificates directory which is defined by the `certificates_directory` option at the top of the config. + skip_verify: false + + ## Minimum TLS version for the connection. + minimum_version: TLS1.2 + + ## The Redis HA configuration options. + ## This provides specific options to Redis Sentinel, sentinel_name must be defined (Master Name). + high_availability: + enabled: false + enabledSecret: false + ## Sentinel Name / Master Name + sentinel_name: mysentinel + + ## The additional nodes to pre-seed the redis provider with (for sentinel). + ## If the host in the above section is defined, it will be combined with this list to connect to sentinel. + ## For high availability to be used you must have either defined; the host above or at least one node below. + nodes: [] + # nodes: + # - host: sentinel-0.databases.svc.cluster.local + # port: 26379 + # - host: sentinel-1.databases.svc.cluster.local + # port: 26379 + + ## Choose the host with the lowest latency. + route_by_latency: false + + ## Choose the host randomly. + route_randomly: false + +## +## Regulation Configuration +## +## This mechanism prevents attackers from brute forcing the first factor. It bans the user if too many attempts are done +## in a short period of time. +regulation: + ## The number of failed login attempts before user is banned. Set it to 0 to disable regulation. + max_retries: 3 + + ## The time range during which the user can attempt login before being banned. The user is banned if the + ## authentication failed 'max_retries' times in a 'find_time' seconds window. Find Time accepts duration notation. + ## See: https://www.authelia.com/docs/configuration/index.html#duration-notation-format + find_time: 2m + + ## The length of time before a banned user can login again. Ban Time accepts duration notation. + ## See: https://www.authelia.com/docs/configuration/index.html#duration-notation-format + ban_time: 5m + + +## +## Storage Provider Configuration +## +## The available providers are: `local`, `mysql`, `postgres`. You must use one and only one of these providers. +storage: + ## + ## PostgreSQL (Storage Provider) + ## + postgres: + port: 5432 + database: authelia + username: authelia + sslmode: disable + timeout: 5s + +## +## Notification Provider +## +## +## Notifications are sent to users when they require a password reset, a u2f registration or a TOTP registration. +## The available providers are: filesystem, smtp. You must use one and only one of these providers. +notifier: + ## You can disable the notifier startup check by setting this to true. + disable_startup_check: false + + ## + ## File System (Notification Provider) + ## + ## Important: Kubernetes (or HA) users must read https://www.authelia.com/docs/features/statelessness.html + ## + filesystem: + enabled: true + filename: /config/notification.txt + + ## + ## SMTP (Notification Provider) + ## + ## Use a SMTP server for sending notifications. Authelia uses the PLAIN or LOGIN methods to authenticate. + ## [Security] By default Authelia will: + ## - force all SMTP connections over TLS including unauthenticated connections + ## - use the disable_require_tls boolean value to disable this requirement + ## (only works for unauthenticated connections) + ## - validate the SMTP server x509 certificate during the TLS handshake against the hosts trusted certificates + ## (configure in tls section) + smtp: + enabled: false + enabledSecret: false + host: smtp.mail.svc.cluster.local + port: 25 + timeout: 5s + username: test + plain_password: test + sender: admin@example.com + ## HELO/EHLO Identifier. Some SMTP Servers may reject the default of localhost. + identifier: localhost + ## Subject configuration of the emails sent. + ## {title} is replaced by the text from the notifier + subject: "[Authelia] {title}" + ## This address is used during the startup check to verify the email configuration is correct. + ## It's not important what it is except if your email server only allows local delivery. + startup_check_address: test@authelia.com + disable_require_tls: false + disable_html_emails: false + + tls: + ## Server Name for certificate validation (in case you are using the IP or non-FQDN in the host option). + server_name: "" + + ## Skip verifying the server certificate (to allow a self-signed certificate). + ## In preference to setting this we strongly recommend you add the public portion of the certificate to the + ## certificates directory which is defined by the `certificates_directory` option at the top of the config. + skip_verify: false + + ## Minimum TLS version for either StartTLS or SMTPS. + minimum_version: TLS1.2 + +identity_providers: + oidc: + ## Enables this in the config map. Currently in beta stage. + ## See https://www.authelia.com/docs/configuration/identity-providers/oidc.html#roadmap + enabled: false + + access_token_lifespan: 1h + authorize_code_lifespan: 1m + id_token_lifespan: 1h + refresh_token_lifespan: 90m + + enable_client_debug_messages: false + + ## SECURITY NOTICE: It's not recommended changing this option, and highly discouraged to have it below 8 for + ## security reasons. + minimum_parameter_entropy: 8 + + clients: [] + # clients: + # - + ## The ID is the OpenID Connect ClientID which is used to link an application to a configuration. + # id: myapp + + ## The description to show to users when they end up on the consent screen. Defaults to the ID above. + # description: My Application + + ## The client secret is a shared secret between Authelia and the consumer of this client. + # secret: apple123 + + ## Sets the client to public. This should typically not be set, please see the documentation for usage. + # public: false + + ## The policy to require for this client; one_factor or two_factor. + # authorization_policy: two_factor + + ## Audience this client is allowed to request. + # audience: [] + + ## Scopes this client is allowed to request. + # scopes: + # - openid + # - profile + # - email + # - groups + + ## Redirect URI's specifies a list of valid case-sensitive callbacks for this client. + # redirect_uris: + # - https://oidc.example.com/oauth2/callback + + ## Grant Types configures which grants this client can obtain. + ## It's not recommended to configure this unless you know what you're doing. + # grant_types: + # - refresh_token + # - authorization_code + + ## Response Types configures which responses this client can be sent. + ## It's not recommended to configure this unless you know what you're doing. + # response_types: + # - code + + ## Response Modes configures which response modes this client supports. + ## It's not recommended to configure this unless you know what you're doing. + # response_modes: + # - form_post + # - query + # - fragment + + ## The algorithm used to sign userinfo endpoint responses for this client, either none or RS256. + # userinfo_signing_algorithm: none diff --git a/incubator/authelia/0.0.1/values.yaml b/incubator/authelia/0.0.1/values.yaml new file mode 100644 index 0000000000..e69de29bb2 diff --git a/incubator/authelia/item.yaml b/incubator/authelia/item.yaml new file mode 100644 index 0000000000..1b9b90b597 --- /dev/null +++ b/incubator/authelia/item.yaml @@ -0,0 +1,3 @@ +categories: + - security +icon_url: https://avatars2.githubusercontent.com/u/59122411?s=200&v=4 diff --git a/incubator/nextcloud/2.3.2/Chart.lock b/incubator/nextcloud/2.3.2/Chart.lock index 161afc9382..fbfbc2fc46 100644 --- a/incubator/nextcloud/2.3.2/Chart.lock +++ b/incubator/nextcloud/2.3.2/Chart.lock @@ -9,4 +9,4 @@ dependencies: repository: https://charts.bitnami.com/bitnami version: 14.8.11 digest: sha256:71e8d9de7d736bd5b9a6a167b86e24b48884272e74a7769e038bf71ad90257d4 -generated: "2021-08-28T10:38:49.10680875Z" +generated: "2021-08-28T11:44:46.47094976Z" diff --git a/stable/airsonic/1.8.2/Chart.lock b/stable/airsonic/1.8.2/Chart.lock index 390c0d5e68..27ddff8386 100644 --- a/stable/airsonic/1.8.2/Chart.lock +++ b/stable/airsonic/1.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:33:56.039788522Z" +generated: "2021-08-28T11:39:05.925474793Z" diff --git a/stable/appdaemon/3.8.2/Chart.lock b/stable/appdaemon/3.8.2/Chart.lock index a8717aa095..b427230a75 100644 --- a/stable/appdaemon/3.8.2/Chart.lock +++ b/stable/appdaemon/3.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:33:59.423857492Z" +generated: "2021-08-28T11:39:09.792968434Z" diff --git a/stable/bazarr/6.8.2/Chart.lock b/stable/bazarr/6.8.2/Chart.lock index cf7aba4376..c9df1afd1e 100644 --- a/stable/bazarr/6.8.2/Chart.lock +++ b/stable/bazarr/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:34:02.740124507Z" +generated: "2021-08-28T11:39:13.570792852Z" diff --git a/stable/booksonic-air/1.6.2/Chart.lock b/stable/booksonic-air/1.6.2/Chart.lock index c7542a9185..0ccf30150f 100644 --- a/stable/booksonic-air/1.6.2/Chart.lock +++ b/stable/booksonic-air/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:34:06.033424384Z" +generated: "2021-08-28T11:39:17.26158671Z" diff --git a/stable/calibre-web/6.8.2/Chart.lock b/stable/calibre-web/6.8.2/Chart.lock index 52b1a1aa4d..507c11dff2 100644 --- a/stable/calibre-web/6.8.2/Chart.lock +++ b/stable/calibre-web/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:34:12.746234233Z" +generated: "2021-08-28T11:39:24.868601428Z" diff --git a/stable/calibre/1.6.2/Chart.lock b/stable/calibre/1.6.2/Chart.lock index 7cf81bfe7e..c27cb420f1 100644 --- a/stable/calibre/1.6.2/Chart.lock +++ b/stable/calibre/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:34:09.339310342Z" +generated: "2021-08-28T11:39:20.896174097Z" diff --git a/stable/collabora-online/6.8.2/Chart.lock b/stable/collabora-online/6.8.2/Chart.lock index ca3479a20a..c133d94c62 100644 --- a/stable/collabora-online/6.8.2/Chart.lock +++ b/stable/collabora-online/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:34:16.032859883Z" +generated: "2021-08-28T11:39:28.625693342Z" diff --git a/stable/deconz/1.6.2/Chart.lock b/stable/deconz/1.6.2/Chart.lock index 56aef98280..ff828932e5 100644 --- a/stable/deconz/1.6.2/Chart.lock +++ b/stable/deconz/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:34:19.331647091Z" +generated: "2021-08-28T11:39:32.28873189Z" diff --git a/stable/deepstack-cpu/4.8.2/Chart.lock b/stable/deepstack-cpu/4.8.2/Chart.lock index c3be021f3e..e3e9e39d51 100644 --- a/stable/deepstack-cpu/4.8.2/Chart.lock +++ b/stable/deepstack-cpu/4.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:34:22.612947794Z" +generated: "2021-08-28T11:39:35.958669852Z" diff --git a/stable/deluge/6.8.2/Chart.lock b/stable/deluge/6.8.2/Chart.lock index 2ee2a5be69..7a48ed7874 100644 --- a/stable/deluge/6.8.2/Chart.lock +++ b/stable/deluge/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:34:25.942404964Z" +generated: "2021-08-28T11:39:39.608332419Z" diff --git a/stable/dizquetv/1.6.2/Chart.lock b/stable/dizquetv/1.6.2/Chart.lock index 7974456766..f68c79aa37 100644 --- a/stable/dizquetv/1.6.2/Chart.lock +++ b/stable/dizquetv/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:34:29.240033197Z" +generated: "2021-08-28T11:39:43.228576981Z" diff --git a/stable/duplicati/1.6.2/Chart.lock b/stable/duplicati/1.6.2/Chart.lock index fa9600d258..cd64db48d1 100644 --- a/stable/duplicati/1.6.2/Chart.lock +++ b/stable/duplicati/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:34:32.531567462Z" +generated: "2021-08-28T11:39:47.170079867Z" diff --git a/stable/emby/6.8.2/Chart.lock b/stable/emby/6.8.2/Chart.lock index 0cee231574..2a397409e7 100644 --- a/stable/emby/6.8.2/Chart.lock +++ b/stable/emby/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:34:35.844133915Z" +generated: "2021-08-28T11:39:50.883034562Z" diff --git a/stable/esphome/6.8.2/Chart.lock b/stable/esphome/6.8.2/Chart.lock index 37a5fab499..f224935d6f 100644 --- a/stable/esphome/6.8.2/Chart.lock +++ b/stable/esphome/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:34:39.165666299Z" +generated: "2021-08-28T11:39:54.687451992Z" diff --git a/stable/external-service/1.1.3/Chart.lock b/stable/external-service/1.1.3/Chart.lock index f0022254eb..5b8ffc2c92 100644 --- a/stable/external-service/1.1.3/Chart.lock +++ b/stable/external-service/1.1.3/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:34:42.514890171Z" +generated: "2021-08-28T11:39:58.390037332Z" diff --git a/stable/fireflyiii/5.3.2/Chart.lock b/stable/fireflyiii/5.3.2/Chart.lock index 4574717d1d..1a8c62bd45 100644 --- a/stable/fireflyiii/5.3.2/Chart.lock +++ b/stable/fireflyiii/5.3.2/Chart.lock @@ -6,4 +6,4 @@ dependencies: repository: https://truecharts.org/ version: 1.1.0 digest: sha256:5c11909e46dde6b3c6ce8ff24e890146ef3f689da1fd86ccbc61da3dc6e079f4 -generated: "2021-08-28T10:34:46.411383873Z" +generated: "2021-08-28T11:40:02.824178521Z" diff --git a/stable/flaresolverr/1.6.2/Chart.lock b/stable/flaresolverr/1.6.2/Chart.lock index 8a890653e3..8d5879abe6 100644 --- a/stable/flaresolverr/1.6.2/Chart.lock +++ b/stable/flaresolverr/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:34:50.452863325Z" +generated: "2021-08-28T11:40:07.443345588Z" diff --git a/stable/flood/1.6.2/Chart.lock b/stable/flood/1.6.2/Chart.lock index b3125248a2..620132a708 100644 --- a/stable/flood/1.6.2/Chart.lock +++ b/stable/flood/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:34:53.753496136Z" +generated: "2021-08-28T11:40:11.216252167Z" diff --git a/stable/focalboard/1.6.2/Chart.lock b/stable/focalboard/1.6.2/Chart.lock index 5798295971..e7310e04d6 100644 --- a/stable/focalboard/1.6.2/Chart.lock +++ b/stable/focalboard/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:34:57.03819096Z" +generated: "2021-08-28T11:40:14.968942194Z" diff --git a/stable/freeradius/1.4.2/Chart.lock b/stable/freeradius/1.4.2/Chart.lock index ae0f188b23..ec474a9821 100644 --- a/stable/freeradius/1.4.2/Chart.lock +++ b/stable/freeradius/1.4.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:00.35148489Z" +generated: "2021-08-28T11:40:18.604916044Z" diff --git a/stable/freshrss/6.8.2/Chart.lock b/stable/freshrss/6.8.2/Chart.lock index c5ccd39123..728aed1ad7 100644 --- a/stable/freshrss/6.8.2/Chart.lock +++ b/stable/freshrss/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:03.662662091Z" +generated: "2021-08-28T11:40:22.428892227Z" diff --git a/stable/gaps/6.8.2/Chart.lock b/stable/gaps/6.8.2/Chart.lock index 362332ae9a..a4646244c4 100644 --- a/stable/gaps/6.8.2/Chart.lock +++ b/stable/gaps/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:06.96462831Z" +generated: "2021-08-28T11:40:26.12775443Z" diff --git a/stable/gonic/1.6.2/Chart.lock b/stable/gonic/1.6.2/Chart.lock index 69a3ea9152..33291bafe1 100644 --- a/stable/gonic/1.6.2/Chart.lock +++ b/stable/gonic/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:35:10.263103777Z" +generated: "2021-08-28T11:40:29.762460768Z" diff --git a/stable/grocy/6.8.2/Chart.lock b/stable/grocy/6.8.2/Chart.lock index 7864a3fcc8..03f65ae79e 100644 --- a/stable/grocy/6.8.2/Chart.lock +++ b/stable/grocy/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:13.575314952Z" +generated: "2021-08-28T11:40:33.422698691Z" diff --git a/stable/handbrake/6.8.2/Chart.lock b/stable/handbrake/6.8.2/Chart.lock index abf454c89e..85749e5f76 100644 --- a/stable/handbrake/6.8.2/Chart.lock +++ b/stable/handbrake/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:16.890086956Z" +generated: "2021-08-28T11:40:37.024279031Z" diff --git a/stable/haste-server/1.8.2/Chart.lock b/stable/haste-server/1.8.2/Chart.lock index 5d3ede5e06..51be7e33ec 100644 --- a/stable/haste-server/1.8.2/Chart.lock +++ b/stable/haste-server/1.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:20.20630098Z" +generated: "2021-08-28T11:40:40.748704245Z" diff --git a/stable/healthchecks/1.6.2/Chart.lock b/stable/healthchecks/1.6.2/Chart.lock index c94e24d5be..5f0d21ce53 100644 --- a/stable/healthchecks/1.6.2/Chart.lock +++ b/stable/healthchecks/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:35:23.515951131Z" +generated: "2021-08-28T11:40:44.34103548Z" diff --git a/stable/heimdall/6.8.2/Chart.lock b/stable/heimdall/6.8.2/Chart.lock index 1e11f23469..e909024994 100644 --- a/stable/heimdall/6.8.2/Chart.lock +++ b/stable/heimdall/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:26.82010231Z" +generated: "2021-08-28T11:40:47.957720223Z" diff --git a/stable/home-assistant/6.8.2/Chart.lock b/stable/home-assistant/6.8.2/Chart.lock index 93c9d50dc5..fad57a8728 100644 --- a/stable/home-assistant/6.8.2/Chart.lock +++ b/stable/home-assistant/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:30.125734534Z" +generated: "2021-08-28T11:40:51.693998187Z" diff --git a/stable/hyperion-ng/1.6.2/Chart.lock b/stable/hyperion-ng/1.6.2/Chart.lock index 20c4412a38..875fc69366 100644 --- a/stable/hyperion-ng/1.6.2/Chart.lock +++ b/stable/hyperion-ng/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:35:33.412908342Z" +generated: "2021-08-28T11:40:55.298513546Z" diff --git a/stable/jackett/6.8.2/Chart.lock b/stable/jackett/6.8.2/Chart.lock index 5a2ca4ed76..5484595d20 100644 --- a/stable/jackett/6.8.2/Chart.lock +++ b/stable/jackett/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:36.699581687Z" +generated: "2021-08-28T11:40:58.986822925Z" diff --git a/stable/jellyfin/6.8.2/Chart.lock b/stable/jellyfin/6.8.2/Chart.lock index 372552122f..60a604f30c 100644 --- a/stable/jellyfin/6.8.2/Chart.lock +++ b/stable/jellyfin/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:40.014433734Z" +generated: "2021-08-28T11:41:02.749666094Z" diff --git a/stable/kms/6.8.2/Chart.lock b/stable/kms/6.8.2/Chart.lock index 77dd7cde1b..745d29d7a7 100644 --- a/stable/kms/6.8.2/Chart.lock +++ b/stable/kms/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:43.32994829Z" +generated: "2021-08-28T11:41:06.400956704Z" diff --git a/stable/komga/1.6.2/Chart.lock b/stable/komga/1.6.2/Chart.lock index bb1c49ca30..661e77bc94 100644 --- a/stable/komga/1.6.2/Chart.lock +++ b/stable/komga/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:35:46.658161587Z" +generated: "2021-08-28T11:41:10.180086123Z" diff --git a/stable/lazylibrarian/6.8.2/Chart.lock b/stable/lazylibrarian/6.8.2/Chart.lock index fbc6f40d2d..86eb0a8f88 100644 --- a/stable/lazylibrarian/6.8.2/Chart.lock +++ b/stable/lazylibrarian/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:49.949656152Z" +generated: "2021-08-28T11:41:14.029359167Z" diff --git a/stable/librespeed/1.6.2/Chart.lock b/stable/librespeed/1.6.2/Chart.lock index f3e9bb794f..fc6715cdbb 100644 --- a/stable/librespeed/1.6.2/Chart.lock +++ b/stable/librespeed/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:35:53.3265703Z" +generated: "2021-08-28T11:41:17.659644222Z" diff --git a/stable/lidarr/6.8.2/Chart.lock b/stable/lidarr/6.8.2/Chart.lock index 66db042cec..38de4d9f71 100644 --- a/stable/lidarr/6.8.2/Chart.lock +++ b/stable/lidarr/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:56.632588511Z" +generated: "2021-08-28T11:41:21.343018508Z" diff --git a/stable/littlelink/1.2.2/Chart.lock b/stable/littlelink/1.2.2/Chart.lock index 3b7409c3b0..c9e47db852 100644 --- a/stable/littlelink/1.2.2/Chart.lock +++ b/stable/littlelink/1.2.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:35:59.922517597Z" +generated: "2021-08-28T11:41:25.037330231Z" diff --git a/stable/lychee/6.8.2/Chart.lock b/stable/lychee/6.8.2/Chart.lock index 9ddadd3e56..c91af06ce4 100644 --- a/stable/lychee/6.8.2/Chart.lock +++ b/stable/lychee/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:03.222691988Z" +generated: "2021-08-28T11:41:28.666266247Z" diff --git a/stable/mealie/1.8.2/Chart.lock b/stable/mealie/1.8.2/Chart.lock index 56cf957ba9..a0a207859c 100644 --- a/stable/mealie/1.8.2/Chart.lock +++ b/stable/mealie/1.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:06.518293213Z" +generated: "2021-08-28T11:41:32.453450729Z" diff --git a/stable/mosquitto/1.8.2/Chart.lock b/stable/mosquitto/1.8.2/Chart.lock index f566c90d11..7de6c49c8a 100644 --- a/stable/mosquitto/1.8.2/Chart.lock +++ b/stable/mosquitto/1.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:09.818975149Z" +generated: "2021-08-28T11:41:36.222715795Z" diff --git a/stable/mylar/1.6.2/Chart.lock b/stable/mylar/1.6.2/Chart.lock index b830ade108..668ea5f057 100644 --- a/stable/mylar/1.6.2/Chart.lock +++ b/stable/mylar/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:36:13.135154129Z" +generated: "2021-08-28T11:41:39.945778337Z" diff --git a/stable/navidrome/6.8.2/Chart.lock b/stable/navidrome/6.8.2/Chart.lock index 0bfec74add..abab38acbd 100644 --- a/stable/navidrome/6.8.2/Chart.lock +++ b/stable/navidrome/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:16.465679672Z" +generated: "2021-08-28T11:41:43.821921613Z" diff --git a/stable/node-red/6.8.2/Chart.lock b/stable/node-red/6.8.2/Chart.lock index a1298f96c8..be52362eb9 100644 --- a/stable/node-red/6.8.2/Chart.lock +++ b/stable/node-red/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:19.781940921Z" +generated: "2021-08-28T11:41:47.775403561Z" diff --git a/stable/nullserv/1.6.2/Chart.lock b/stable/nullserv/1.6.2/Chart.lock index da126fc4a6..b0a61cb350 100644 --- a/stable/nullserv/1.6.2/Chart.lock +++ b/stable/nullserv/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:36:23.097947266Z" +generated: "2021-08-28T11:41:51.46243096Z" diff --git a/stable/nzbget/6.8.2/Chart.lock b/stable/nzbget/6.8.2/Chart.lock index d67cbb9b74..98aeab13b1 100644 --- a/stable/nzbget/6.8.2/Chart.lock +++ b/stable/nzbget/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:26.394815593Z" +generated: "2021-08-28T11:41:55.21423404Z" diff --git a/stable/nzbhydra/6.8.2/Chart.lock b/stable/nzbhydra/6.8.2/Chart.lock index 39fe06c7a5..30eb3ee3df 100644 --- a/stable/nzbhydra/6.8.2/Chart.lock +++ b/stable/nzbhydra/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:29.868541838Z" +generated: "2021-08-28T11:41:58.902425488Z" diff --git a/stable/octoprint/1.6.2/Chart.lock b/stable/octoprint/1.6.2/Chart.lock index f773ca5df0..aae49a75e2 100644 --- a/stable/octoprint/1.6.2/Chart.lock +++ b/stable/octoprint/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:36:33.17773855Z" +generated: "2021-08-28T11:42:02.801917501Z" diff --git a/stable/omada-controller/1.6.2/Chart.lock b/stable/omada-controller/1.6.2/Chart.lock index de842cdbfb..dbd6b15677 100644 --- a/stable/omada-controller/1.6.2/Chart.lock +++ b/stable/omada-controller/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:36:36.510777221Z" +generated: "2021-08-28T11:42:06.840948994Z" diff --git a/stable/ombi/6.8.2/Chart.lock b/stable/ombi/6.8.2/Chart.lock index d3bcc5ca97..e3f2b8c491 100644 --- a/stable/ombi/6.8.2/Chart.lock +++ b/stable/ombi/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:39.819329692Z" +generated: "2021-08-28T11:42:10.876883682Z" diff --git a/stable/openldap/1.4.2/Chart.lock b/stable/openldap/1.4.2/Chart.lock index 43be72dad2..c4dc056c10 100644 --- a/stable/openldap/1.4.2/Chart.lock +++ b/stable/openldap/1.4.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:43.131667636Z" +generated: "2021-08-28T11:42:14.81916482Z" diff --git a/stable/organizr/6.8.2/Chart.lock b/stable/organizr/6.8.2/Chart.lock index b8d71e990e..e19a7b372f 100644 --- a/stable/organizr/6.8.2/Chart.lock +++ b/stable/organizr/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:46.452488206Z" +generated: "2021-08-28T11:42:18.610344192Z" diff --git a/stable/overseerr/1.6.2/Chart.lock b/stable/overseerr/1.6.2/Chart.lock index 6b2deabc2f..c1bc29c8d5 100644 --- a/stable/overseerr/1.6.2/Chart.lock +++ b/stable/overseerr/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:36:49.741349282Z" +generated: "2021-08-28T11:42:22.275711554Z" diff --git a/stable/owncast/1.6.2/Chart.lock b/stable/owncast/1.6.2/Chart.lock index 0f45501a93..e693d25b1e 100644 --- a/stable/owncast/1.6.2/Chart.lock +++ b/stable/owncast/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:36:53.048593003Z" +generated: "2021-08-28T11:42:25.979549031Z" diff --git a/stable/owncloud-ocis/1.6.2/Chart.lock b/stable/owncloud-ocis/1.6.2/Chart.lock index 1e4de05c3e..5bd58f6d01 100644 --- a/stable/owncloud-ocis/1.6.2/Chart.lock +++ b/stable/owncloud-ocis/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:36:56.351313159Z" +generated: "2021-08-28T11:42:29.696829605Z" diff --git a/stable/pgadmin/1.5.2/Chart.lock b/stable/pgadmin/1.5.2/Chart.lock index 2ffabf6267..44c91013c2 100644 --- a/stable/pgadmin/1.5.2/Chart.lock +++ b/stable/pgadmin/1.5.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:36:59.662549696Z" +generated: "2021-08-28T11:42:33.380746708Z" diff --git a/stable/photoprism/1.6.2/Chart.lock b/stable/photoprism/1.6.2/Chart.lock index 9845e7160b..4cb5426505 100644 --- a/stable/photoprism/1.6.2/Chart.lock +++ b/stable/photoprism/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:37:02.976791137Z" +generated: "2021-08-28T11:42:36.994222756Z" diff --git a/stable/phpldapadmin/1.5.2/Chart.lock b/stable/phpldapadmin/1.5.2/Chart.lock index 60304e7e37..75654f24bf 100644 --- a/stable/phpldapadmin/1.5.2/Chart.lock +++ b/stable/phpldapadmin/1.5.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:06.288326795Z" +generated: "2021-08-28T11:42:40.672275642Z" diff --git a/stable/piaware/1.6.2/Chart.lock b/stable/piaware/1.6.2/Chart.lock index 4e3bccc03e..c7388bbf90 100644 --- a/stable/piaware/1.6.2/Chart.lock +++ b/stable/piaware/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:37:09.603469168Z" +generated: "2021-08-28T11:42:44.331956613Z" diff --git a/stable/plex/5.8.2/Chart.lock b/stable/plex/5.8.2/Chart.lock index e6ed75fe6e..4ca5eb6fde 100644 --- a/stable/plex/5.8.2/Chart.lock +++ b/stable/plex/5.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:12.915379616Z" +generated: "2021-08-28T11:42:48.090737631Z" diff --git a/stable/podgrab/4.8.2/Chart.lock b/stable/podgrab/4.8.2/Chart.lock index 08f371f11f..362704e746 100644 --- a/stable/podgrab/4.8.2/Chart.lock +++ b/stable/podgrab/4.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:16.240646622Z" +generated: "2021-08-28T11:42:52.039416068Z" diff --git a/stable/postgresql/1.2.3/Chart.lock b/stable/postgresql/1.2.3/Chart.lock index fb493f7a68..c797af56a2 100644 --- a/stable/postgresql/1.2.3/Chart.lock +++ b/stable/postgresql/1.2.3/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:19.545689342Z" +generated: "2021-08-28T11:42:55.906328424Z" diff --git a/stable/pretend-youre-xyzzy/1.6.2/Chart.lock b/stable/pretend-youre-xyzzy/1.6.2/Chart.lock index 73397499a4..37f5bfa39c 100644 --- a/stable/pretend-youre-xyzzy/1.6.2/Chart.lock +++ b/stable/pretend-youre-xyzzy/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:37:22.836213916Z" +generated: "2021-08-28T11:42:59.639786542Z" diff --git a/stable/protonmail-bridge/1.6.2/Chart.lock b/stable/protonmail-bridge/1.6.2/Chart.lock index 0a1b764721..e5f9f23230 100644 --- a/stable/protonmail-bridge/1.6.2/Chart.lock +++ b/stable/protonmail-bridge/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:37:26.151863679Z" +generated: "2021-08-28T11:43:03.389001743Z" diff --git a/stable/prowlarr/1.8.2/Chart.lock b/stable/prowlarr/1.8.2/Chart.lock index 05f1252836..c195bfde34 100644 --- a/stable/prowlarr/1.8.2/Chart.lock +++ b/stable/prowlarr/1.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:29.445832569Z" +generated: "2021-08-28T11:43:06.991840582Z" diff --git a/stable/pyload/1.6.2/Chart.lock b/stable/pyload/1.6.2/Chart.lock index 45eb34d3da..8ae400ab9e 100644 --- a/stable/pyload/1.6.2/Chart.lock +++ b/stable/pyload/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:37:32.757984371Z" +generated: "2021-08-28T11:43:10.640202483Z" diff --git a/stable/qbittorrent/6.8.2/Chart.lock b/stable/qbittorrent/6.8.2/Chart.lock index 89643486e1..df621b7d5c 100644 --- a/stable/qbittorrent/6.8.2/Chart.lock +++ b/stable/qbittorrent/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:36.103960144Z" +generated: "2021-08-28T11:43:14.415089187Z" diff --git a/stable/radarr/6.8.2/Chart.lock b/stable/radarr/6.8.2/Chart.lock index 544d3ea812..656e2fec76 100644 --- a/stable/radarr/6.8.2/Chart.lock +++ b/stable/radarr/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:39.414448851Z" +generated: "2021-08-28T11:43:18.051474716Z" diff --git a/stable/readarr/6.8.2/Chart.lock b/stable/readarr/6.8.2/Chart.lock index 77867d440d..a02d03eb7e 100644 --- a/stable/readarr/6.8.2/Chart.lock +++ b/stable/readarr/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:42.700383081Z" +generated: "2021-08-28T11:43:21.807615959Z" diff --git a/stable/reg/1.8.2/Chart.lock b/stable/reg/1.8.2/Chart.lock index aa3c9368d0..f4198c248d 100644 --- a/stable/reg/1.8.2/Chart.lock +++ b/stable/reg/1.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:46.012788206Z" +generated: "2021-08-28T11:43:25.570283893Z" diff --git a/stable/resilio-sync/1.6.2/Chart.lock b/stable/resilio-sync/1.6.2/Chart.lock index ebab4788b0..04c69bae4b 100644 --- a/stable/resilio-sync/1.6.2/Chart.lock +++ b/stable/resilio-sync/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:37:49.32397625Z" +generated: "2021-08-28T11:43:29.216288112Z" diff --git a/stable/sabnzbd/6.8.2/Chart.lock b/stable/sabnzbd/6.8.2/Chart.lock index 91eca0afec..a73a59736e 100644 --- a/stable/sabnzbd/6.8.2/Chart.lock +++ b/stable/sabnzbd/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:52.616165039Z" +generated: "2021-08-28T11:43:32.876728955Z" diff --git a/stable/ser2sock/1.6.2/Chart.lock b/stable/ser2sock/1.6.2/Chart.lock index 0e3246bd2d..deedd24f98 100644 --- a/stable/ser2sock/1.6.2/Chart.lock +++ b/stable/ser2sock/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:37:55.947317101Z" +generated: "2021-08-28T11:43:36.576273615Z" diff --git a/stable/sonarr/6.8.2/Chart.lock b/stable/sonarr/6.8.2/Chart.lock index bbe3de3b1e..5bc76f06fb 100644 --- a/stable/sonarr/6.8.2/Chart.lock +++ b/stable/sonarr/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:37:59.265554585Z" +generated: "2021-08-28T11:43:40.232569256Z" diff --git a/stable/stash/1.6.2/Chart.lock b/stable/stash/1.6.2/Chart.lock index 10da3dbff2..6de6633e14 100644 --- a/stable/stash/1.6.2/Chart.lock +++ b/stable/stash/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:38:02.556496214Z" +generated: "2021-08-28T11:43:43.864582871Z" diff --git a/stable/syncthing/6.8.2/Chart.lock b/stable/syncthing/6.8.2/Chart.lock index ee264130ad..9c4a9a3406 100644 --- a/stable/syncthing/6.8.2/Chart.lock +++ b/stable/syncthing/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:05.859723225Z" +generated: "2021-08-28T11:43:47.560081336Z" diff --git a/stable/tautulli/6.8.2/Chart.lock b/stable/tautulli/6.8.2/Chart.lock index cfbb8a168d..7508561460 100644 --- a/stable/tautulli/6.8.2/Chart.lock +++ b/stable/tautulli/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:09.177835033Z" +generated: "2021-08-28T11:43:51.307739654Z" diff --git a/stable/thelounge/1.8.2/Chart.lock b/stable/thelounge/1.8.2/Chart.lock index 30dee243f2..a3b857dcc4 100644 --- a/stable/thelounge/1.8.2/Chart.lock +++ b/stable/thelounge/1.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:12.570880543Z" +generated: "2021-08-28T11:43:55.291812604Z" diff --git a/stable/traefik/6.10.2/Chart.lock b/stable/traefik/6.10.2/Chart.lock index c30e630554..6c51bac4b8 100644 --- a/stable/traefik/6.10.2/Chart.lock +++ b/stable/traefik/6.10.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:15.899531663Z" +generated: "2021-08-28T11:43:59.125443525Z" diff --git a/stable/transmission/6.8.2/Chart.lock b/stable/transmission/6.8.2/Chart.lock index b25ef6d492..8b7da5e739 100644 --- a/stable/transmission/6.8.2/Chart.lock +++ b/stable/transmission/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:19.205161623Z" +generated: "2021-08-28T11:44:03.1073008Z" diff --git a/stable/truecommand/6.8.2/Chart.lock b/stable/truecommand/6.8.2/Chart.lock index 5decf5ca8b..77ba6db562 100644 --- a/stable/truecommand/6.8.2/Chart.lock +++ b/stable/truecommand/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:22.546509966Z" +generated: "2021-08-28T11:44:07.030102496Z" diff --git a/stable/tvheadend/7.8.2/Chart.lock b/stable/tvheadend/7.8.2/Chart.lock index a38488d8bf..c5ad1031cb 100644 --- a/stable/tvheadend/7.8.2/Chart.lock +++ b/stable/tvheadend/7.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:25.864893813Z" +generated: "2021-08-28T11:44:10.864345823Z" diff --git a/stable/unifi/6.8.2/Chart.lock b/stable/unifi/6.8.2/Chart.lock index bcffdb09e7..fd96397b30 100644 --- a/stable/unifi/6.8.2/Chart.lock +++ b/stable/unifi/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:29.174545556Z" +generated: "2021-08-28T11:44:14.640263964Z" diff --git a/stable/unpackerr/1.8.2/Chart.lock b/stable/unpackerr/1.8.2/Chart.lock index caae3dadf6..2e03b3c275 100644 --- a/stable/unpackerr/1.8.2/Chart.lock +++ b/stable/unpackerr/1.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:32.601782522Z" +generated: "2021-08-28T11:44:18.312251171Z" diff --git a/stable/vaultwarden/4.3.2/Chart.lock b/stable/vaultwarden/4.3.2/Chart.lock index 8551a1589d..5e60259b05 100644 --- a/stable/vaultwarden/4.3.2/Chart.lock +++ b/stable/vaultwarden/4.3.2/Chart.lock @@ -6,4 +6,4 @@ dependencies: repository: https://truecharts.org/ version: 1.1.0 digest: sha256:5c11909e46dde6b3c6ce8ff24e890146ef3f689da1fd86ccbc61da3dc6e079f4 -generated: "2021-08-28T10:38:36.51538525Z" +generated: "2021-08-28T11:44:23.009854391Z" diff --git a/stable/xteve/1.6.2/Chart.lock b/stable/xteve/1.6.2/Chart.lock index d530d91fe5..a1142d82e9 100644 --- a/stable/xteve/1.6.2/Chart.lock +++ b/stable/xteve/1.6.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org version: 6.10.6 digest: sha256:9d26604a382118f9894ddbb7ab89c2d144a331d8fad534bdb2943269b48bb7c6 -generated: "2021-08-28T10:38:40.546648807Z" +generated: "2021-08-28T11:44:27.782264428Z" diff --git a/stable/zwavejs2mqtt/6.8.2/Chart.lock b/stable/zwavejs2mqtt/6.8.2/Chart.lock index dc1ae2fb25..d78f42c814 100644 --- a/stable/zwavejs2mqtt/6.8.2/Chart.lock +++ b/stable/zwavejs2mqtt/6.8.2/Chart.lock @@ -3,4 +3,4 @@ dependencies: repository: https://truecharts.org/ version: 6.10.6 digest: sha256:b4bf4983bf57b47bd2c23cfa38cf9ffbf029eb690a4c5a968c4580bf0ffe5b8d -generated: "2021-08-28T10:38:43.854499362Z" +generated: "2021-08-28T11:44:31.465690419Z"