feat(auth): migrate to folder-based stack layout
ci/woodpecker/push/deploy Pipeline was canceled

This commit is contained in:
2026-07-25 22:19:24 -07:00
parent 0dc7e915f3
commit 39c34c8923
+123
View File
@@ -0,0 +1,123 @@
services:
authentik-server:
image: ghcr.io/goauthentik/server:2026.5
command: server
hostname: authentik-server
stop_grace_period: 30s
environment:
AUTHENTIK_POSTGRESQL__HOST: postgresql
AUTHENTIK_POSTGRESQL__USER: PGadmin
AUTHENTIK_POSTGRESQL__NAME: authentik
AUTHENTIK_POSTGRESQL__PASSWORD: ${AUTH_PG_PASSWORD}
AUTHENTIK_POSTGRESQL__CONN_MAX_AGE: 0
AUTHENTIK_POSTGRESQL__DEFAULT_SCHEMA: public
AUTHENTIK_SECRET_KEY: ${AUTH_SECRET_KEY}
AUTHENTIK_ERROR_REPORTING__ENABLED: "false"
AUTHENTIK_DISABLE_UPDATE_CHECK: "false"
AUTHENTIK_LOG_LEVEL: "info"
volumes:
- /volume1/docker/authentik/data:/data
- /volume1/docker/authentik/media:/media
- /volume1/docker/authentik/templates:/templates
- /var/run/docker.sock:/var/run/docker.sock
networks:
- authentik_backend
- traefik_backend
healthcheck:
test: ["CMD-SHELL", "ak healthcheck"]
start_period: 90s
interval: 30s
timeout: 10s
deploy:
replicas: 1
placement:
max_replicas_per_node: 1
update_config:
parallelism: 1
delay: 30s
failure_action: rollback
resources:
limits:
memory: 1G
reservations:
memory: 512M
labels:
- traefik.enable=true
- traefik.http.routers.authentik.rule=Host(`auth.${DOMAIN}`)
- traefik.http.routers.authentik.tls=true
- traefik.http.routers.authentik.tls.certresolver=letsencrypt
- traefik.http.routers.authentik.entrypoints=websecure
- traefik.http.services.authentik.loadbalancer.server.port=9443
- traefik.http.services.authentik.loadbalancer.server.scheme=https
- traefik.http.middlewares.authentik.forwardauth.trustForwardHeader=true
- traefik.http.middlewares.authentik.forwardauth.authResponseHeaders=X-authentik-username,X-authentik-groups,X-authentik-email,X-authentik-name,X-authentik-uid,X-authentik-jwt,X-authentik-meta-jwks,X-authentik-meta-outpost,X-authentik-meta-provider,X-authentik-meta-app,X-authentik-meta-version
- traefik.http.services.authentik.loadBalancer.sticky.cookie=true
- traefik.http.services.authentik.loadBalancer.sticky.cookie.name=authentik-server-sticky-session
- traefik.swarm.network=traefik_backend
- traefik.http.routers.authentik.middlewares=crowdsec@file
- traefik.http.routers.authentik-forward.rule=Host(`auth.${DOMAIN}`) && PathPrefix(`/outpost.goauthentik.io/`)
- traefik.http.routers.authentik-forward.entrypoints=websecure
- traefik.http.routers.authentik-forward.tls=true
- traefik.http.routers.authentik-forward.tls.certresolver=letsencrypt
- traefik.http.routers.authentik-forward.service=authentik
- traefik.http.middlewares.authentik.forwardauth.address=https://auth.${DOMAIN}/outpost.goauthentik.io/auth/traefik
authentik-worker:
image: ghcr.io/goauthentik/server:2026.5
command: worker
hostname: authentik-worker
stop_grace_period: 30s
user: root
environment:
AUTHENTIK_POSTGRESQL__HOST: postgresql
AUTHENTIK_POSTGRESQL__USER: PGadmin
AUTHENTIK_POSTGRESQL__NAME: authentik
AUTHENTIK_POSTGRESQL__PASSWORD: ${AUTH_PG_PASSWORD}
AUTHENTIK_POSTGRESQL__CONN_MAX_AGE: 0
AUTHENTIK_POSTGRESQL__DEFAULT_SCHEMA: public
AUTHENTIK_SECRET_KEY: ${AUTH_SECRET_KEY}
AUTHENTIK_ERROR_REPORTING__ENABLED: "false"
AUTHENTIK_DISABLE_UPDATE_CHECK: "false"
AUTHENTIK_LOG_LEVEL: "info"
volumes:
- /volume1/docker/authentik/data:/data
- /volume1/docker/authentik/media:/media
- /volume1/docker/authentik/templates:/templates
- /var/run/docker.sock:/var/run/docker.sock
networks:
- authentik_backend
- traefik_backend
healthcheck:
test: ["CMD-SHELL", "ak healthcheck"]
start_period: 120s
interval: 60s
timeout: 15s
deploy:
replicas: 1
placement:
max_replicas_per_node: 1
restart_policy:
condition: on-failure
delay: 15s
window: 120s
update_config:
parallelism: 1
delay: 30s
failure_action: rollback
resources:
limits:
memory: 2G
reservations:
memory: 512M
networks:
authentik_backend:
driver: overlay
driver_opts:
com.docker.network.driver.mtu: "9000"
attachable: true
name: authentik_backend
postgresql_db-backend:
external: true
traefik_backend:
external: true