-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathvariables.tf
More file actions
174 lines (149 loc) · 4.25 KB
/
Copy pathvariables.tf
File metadata and controls
174 lines (149 loc) · 4.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
################################################################################
# Authentik Terraform Variables
#
# Set these via:
# - GitHub Actions secrets (recommended)
# - terraform.tfvars (local dev only - never commit!)
# - Environment variables (TF_VAR_*)
################################################################################
# Authentik Connection
variable "authentik_url" {
type = string
description = "Authentik server URL (e.g., https://auth.example.com)"
}
variable "authentik_token" {
type = string
sensitive = true
description = "Authentik API token"
}
# Google OAuth (optional)
variable "google_client_id" {
type = string
default = ""
description = "Google OAuth client ID"
}
variable "google_client_secret" {
type = string
sensitive = true
default = ""
description = "Google OAuth client secret"
}
# Application URLs
variable "argocd_url" {
type = string
default = ""
description = "ArgoCD URL for SSO"
}
variable "grafana_url" {
type = string
default = ""
description = "Grafana URL for SSO"
}
variable "home_assistant_url" {
type = string
default = ""
description = "Home Assistant URL for proxy auth"
}
variable "immich_url" {
type = string
default = ""
description = "Immich URL for proxy auth"
}
variable "uptime_kuma_url" {
type = string
default = ""
description = "Uptime Kuma URL for proxy auth"
}
variable "sonarr_url" {
type = string
default = ""
description = "Sonarr URL for proxy auth"
}
variable "radarr_url" {
type = string
default = ""
description = "Radarr URL for proxy auth"
}
variable "prowlarr_url" {
type = string
default = ""
description = "Prowlarr URL for proxy auth"
}
variable "portainer_url" {
type = string
default = ""
description = "Portainer URL for SSO"
}
variable "proxmox_url" {
type = string
default = ""
description = "Proxmox VE URL for SSO (e.g., https://proxmox.example.com:8006)"
}
# LDAP Configuration
variable "ldap_base_dn" {
type = string
default = "dc=ldap,dc=example,dc=com"
description = "LDAP base DN"
}
# Security Configuration
variable "enable_mfa_flow" {
type = bool
default = false
description = "Use custom MFA authentication flow instead of default"
}
variable "mfa_enforcement" {
type = string
default = "configure"
description = "MFA enforcement mode: 'skip' (optional), 'configure' (prompt to set up), 'deny' (required)"
validation {
condition = contains(["skip", "configure", "deny"], var.mfa_enforcement)
error_message = "MFA enforcement must be one of: skip, configure, deny"
}
}
# Brand Configuration
variable "brand_domain" {
type = string
default = "auth.gregh.dev"
description = "Primary domain for Authentik brand configuration"
}
variable "brand_title" {
type = string
default = "Greg's Lab"
description = "Branding title displayed in Authentik UI"
}
# Session Security
variable "session_duration" {
type = string
default = "hours=24"
description = "Session duration before requiring re-authentication (e.g., hours=24, days=7)"
}
variable "remember_me_duration" {
type = string
default = "days=30"
description = "Duration for 'remember me' sessions"
}
# Outpost Configuration
variable "authentik_host" {
type = string
description = "Authentik host URL for outpost connection (e.g., https://authentik.walleye-frog.ts.net)"
default = ""
}
variable "authentik_host_insecure" {
type = bool
default = false
description = "Skip TLS verification for Authentik host (use only for self-signed certs in dev)"
}
variable "outpost_log_level" {
type = string
default = "info"
description = "Log level for outposts (debug, info, warning, error)"
validation {
condition = contains(["debug", "info", "warning", "error"], var.outpost_log_level)
error_message = "Log level must be one of: debug, info, warning, error"
}
}
variable "outpost_service_connection" {
type = string
default = null
description = "Service connection ID for outpost deployment (optional, for Docker/K8s integration)"
}