#!/bin/bash set -e # ============================================ # install-authelia.sh # Installs and configures Authelia IDP for NextWks # ============================================ # ========================================== # 1. CONFIGURATION / VARIABLES # ========================================== DOMAIN="sechpoint.app" AUTH_SUBDOMAIN="auth.${DOMAIN}" SMTP_HOST="smtp.openxchange.eu" SMTP_PORT=587 SMTP_USER="post@sechpoint.app" SMTP_PASS="0@pYAY14mB" # Initial Admin Setup ADMIN_USER="admin" ADMIN_EMAIL="cl@${DOMAIN}" ADMIN_PASSWORD="ueM8tLARi5v3orIzvd56w6u6!" # This will be hashed automatically # Bulk Onboarding List (Format: "username:DisplayName:email") USER_LIST=( "clohmar:Claus Lohmar:cl@${DOMAIN}" ) # Paths AUTHELIA_DIR="/opt/authelia" AUTHELIA_VERSION="v4.38.0" # ========================================== # 2. INSTALLATION & PREPARATION # ========================================== echo "Installing prerequisites and downloading Authelia..." apt-get update && apt-get install -y wget curl tar openssl jq mkdir -p "$AUTHELIA_DIR" wget -q "https://github.com/authelia/authelia/releases/download/${AUTHELIA_VERSION}/authelia-${AUTHELIA_VERSION}-linux-amd64.tar.gz" -O /tmp/authelia.tar.gz tar -xzf /tmp/authelia.tar.gz -C "$AUTHELIA_DIR" mv "$AUTHELIA_DIR/authelia-linux-amd64" "$AUTHELIA_DIR/authelia" chmod +x "$AUTHELIA_DIR/authelia" # Generate Secrets JWT_SECRET=$(openssl rand -base64 32) SESSION_SECRET=$(openssl rand -base64 32) STORAGE_ENCRYPTION_KEY=$(openssl rand -base64 32) # Generate Hash for the Initial Admin ADMIN_HASH=$("$AUTHELIA_DIR/authelia" crypto hash generate --password "$ADMIN_PASSWORD" | awk '{print $NF}') # ========================================== # 3. GENERATE USER DATABASE (BULK ONBOARDING) # ========================================== echo "Generating user database..." cat < "${AUTHELIA_DIR}/users_database.yml" users: ${ADMIN_USER}: displayname: "System Administrator" password: "${ADMIN_HASH}" email: "${ADMIN_EMAIL}" groups: [admins] EOF for entry in "${USER_LIST[@]}"; do IFS=":" read -r uname dname uemail <<< "$entry" cat <> "${AUTHELIA_DIR}/users_database.yml" ${uname}: displayname: "${dname}" password: "${ADMIN_HASH}" # Everyone starts with the same temp password email: "${uemail}" groups: [users] EOF done # ========================================== # 4. GENERATE MAIN CONFIGURATION # ========================================== echo "Generating Authelia configuration..." cat < "${AUTHELIA_DIR}/configuration.yml" theme: light jwt_secret: "${JWT_SECRET}" default_redirection_url: "https://${DOMAIN}" server: host: 0.0.0.0 port: 9091 authentication_backend: password_reset: disable: false file: path: "${AUTHELIA_DIR}/users_database.yml" watch: true session: name: authelia_session secret: "${SESSION_SECRET}" domain: "${DOMAIN}" expiration: 1h inactivity: 5m notifier: smtp: host: "${SMTP_HOST}" port: ${SMTP_PORT} username: "${SMTP_USER}" password: "${SMTP_PASS}" sender: "Authelia <${SMTP_USER}>" storage: encryption_key: "${STORAGE_ENCRYPTION_KEY}" local: path: "${AUTHELIA_DIR}/db.sqlite3" access_control: default_policy: deny rules: - domain: "${AUTH_SUBDOMAIN}" policy: bypass - domain: "*.${DOMAIN}" policy: two_factor totp: issuer: authelia.com EOF # ========================================== # 5. SYSTEMD & PERMISSIONS # ========================================== chown -R root:root "$AUTHELIA_DIR" chmod 600 "${AUTHELIA_DIR}/configuration.yml" chmod 600 "${AUTHELIA_DIR}/users_database.yml" cat < /etc/systemd/system/authelia.service [Unit] Description=Authelia Identity Provider After=network.target [Service] Type=simple WorkingDirectory=${AUTHELIA_DIR} ExecStart=${AUTHELIA_DIR}/authelia --config ${AUTHELIA_DIR}/configuration.yml Restart=always User=root [Install] WantedBy=multi-user.target EOF systemctl daemon-reload systemctl enable --now authelia echo "-------------------------------------------------------" echo "Authelia Installation Complete!" echo "Authelia is running on port 9091" echo "Config: ${AUTHELIA_DIR}/configuration.yml" echo "Users: ${AUTHELIA_DIR}/users_database.yml" echo "Next step: Configure your Reverse Proxy for ${AUTH_SUBDOMAIN}" echo "-------------------------------------------------------"