mirror of
https://github.com/rubenhensen/k8scd.git
synced 2026-09-17 02:12:55 +02:00
Extend authentik + FreshRSS session lifetimes
Authentik's default-authentication-login stage ships with session_duration: seconds=0, so the SSO session died with the browser. New blueprint raises it to 30 days for every app on that flow. FreshRSS runs OIDC through Apache mod_auth_openidc, whose defaults are a 5 minute inactivity timeout and a ~7.5 hour max duration in a non-persistent cookie. Bumped to a 30 day sliding inactivity window (refreshed on every request) with a 90 day hard cap, and made the cookie persistent so it survives a browser restart.
This commit is contained in:
@@ -11,6 +11,22 @@ Authentik is deployed as the central identity provider, providing OIDC and LDAP
|
||||
- `blueprint-ldap.yaml` — LDAP provider (base DN: `DC=ldap,DC=goauthentik,DC=io`)
|
||||
- `blueprint-mail-oidc.yaml` — OAuth2/OIDC provider for Stalwart mail
|
||||
- `blueprint-vault-oidc.yaml` — OIDC provider for Vault
|
||||
- `blueprint-argocd-oidc.yaml` — OIDC provider for ArgoCD
|
||||
- `blueprint-freshrss-oidc.yaml` — OIDC provider for FreshRSS
|
||||
- `blueprint-actualbudget-proxy.yaml` — Proxy provider for Actual Budget
|
||||
- `blueprint-session-duration.yaml` — Session lifetime of the default authentication flow
|
||||
|
||||
## Session lifetime
|
||||
|
||||
Authentik ships the login stage of `default-authentication-flow` with
|
||||
`session_duration: seconds=0`, i.e. the SSO session dies when the browser closes.
|
||||
`blueprint-session-duration.yaml` raises this to 30 days for every app that uses
|
||||
that flow (FreshRSS, ArgoCD, Vault, Actual Budget, mail).
|
||||
|
||||
The expiry is **absolute** — Authentik does not extend a session on activity. A
|
||||
sliding window has to come from the application itself; FreshRSS does this via
|
||||
`OIDC_SESSION_INACTIVITY_TIMEOUT` (see `freshrss/freshrss-deployment.yaml`), which
|
||||
Apache mod_auth_openidc refreshes on every request.
|
||||
|
||||
## LDAP Outpost
|
||||
|
||||
|
||||
@@ -0,0 +1,27 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: authentik-blueprint-session
|
||||
data:
|
||||
session-duration.yaml: |
|
||||
version: 1
|
||||
metadata:
|
||||
name: Session duration
|
||||
entries:
|
||||
# Overrides the login stage of the built-in `default-authentication-flow`,
|
||||
# which every OIDC/proxy provider in this cluster authenticates against.
|
||||
# authentik ships this stage with `session_duration: seconds=0`, which means
|
||||
# "until the browser is closed" — that is why re-logins were so frequent.
|
||||
#
|
||||
# Note: authentik's session expiry is absolute (counted from login), it does
|
||||
# not slide on activity. The sliding window lives in the applications, e.g.
|
||||
# OIDC_SESSION_INACTIVITY_TIMEOUT in freshrss/freshrss-deployment.yaml.
|
||||
- model: authentik_stages_user_login.userloginstage
|
||||
state: present
|
||||
identifiers:
|
||||
name: default-authentication-login
|
||||
attrs:
|
||||
session_duration: days=30
|
||||
# Uncomment to show a "Remember me on this device" checkbox that adds
|
||||
# this offset on top of session_duration when ticked (0 = hidden).
|
||||
# remember_me_offset: days=60
|
||||
Reference in New Issue
Block a user