feat: domain list refactor + demo-gymburgdorf fixes
- Refactor: collapse `*_domain` + `*_extra_domains` into a single `*_domains` list across authentik, collabora, garage and nextcloud roles. First entry is the canonical FQDN (used for OVERWRITEHOST, BASE_URL, notify_push setup and garage root_domain). - Authentik blueprint: guard the OAuth sources block so an empty `authentik_login_sources` no longer renders an invalid YAML key. - Nextcloud: introduce `nextcloud_collabora_public_domain` and set Collabora's `public_wopi_url` separately from the server-to-server `wopi_url` so browsers can reach Collabora via the public name while Nextcloud still talks to it on the internal one. - Nextcloud: URL-encode the postgres user/password in DATABASE_URL.
This commit is contained in:
parent
c11f019aae
commit
c3cf779532
12 changed files with 64 additions and 15 deletions
|
|
@ -12,7 +12,11 @@ authentik_docker_compose_dir: "{{ docker_compose_base_dir }}/{{ authentik_servic
|
|||
authentik_docker_volume_dir: "{{ docker_volume_base_dir }}/{{ authentik_service_name }}"
|
||||
|
||||
# Authentik service configuration
|
||||
authentik_domain: "authentik.local.test"
|
||||
# FQDNs the authentik router accepts. The first entry is the canonical
|
||||
# domain; further entries cover internal *.int.* names used for
|
||||
# server-to-server traffic so backend calls don't hairpin via DMZ.
|
||||
authentik_domains:
|
||||
- "authentik.local.test"
|
||||
authentik_image: "ghcr.io/goauthentik/server:2026.2.2"
|
||||
authentik_port: 9000
|
||||
authentik_secret_key: "changeme-generate-a-random-string"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue