hive-forge: a first authelia login creates the forge account

[oauth2_client] turns on auto-registration through the authelia login
source, with the account named after authelia's preferred_username.
DISABLE_REGISTRATION stays true: forgejo 16's auto-registration checks
only ALLOW_ONLY_INTERNAL_REGISTRATION, so local sign-up stays off.

ACCOUNT_LINKING is `login`, forgejo's default, set explicitly. With
`auto`, an SSO login whose name matches an existing local account would
be handed that account, and agents, `core` and `swarm-controller` all
have one. `login` asks for that account's own password instead.

Refs #3782
This commit is contained in:
atlas 2026-09-24 23:53:15 +02:00 • committed by mara
commit 113f3fe6e2
2 changed files with 49 additions and 3 deletions

View file

@ -775,13 +775,33 @@ in
# the custom theme CSS baked straight into the nix store.
STATIC_ROOT_PATH = staticRootWithTheme;
};
# Registration off — operator seeds agent users via
# `nixos-container run hive-forge -- forgejo admin
# user create …`.
# Local sign-up off. An agent's account is made by
# swarm-controller over the admin API, a human's by their
# first authelia login (`oauth2_client` below), which this
# does not block: forgejo's auto-registration checks only
# `ALLOW_ONLY_INTERNAL_REGISTRATION`
# (`routers/web/auth/oauth.go`, 16.0.5).
service = {
DISABLE_REGISTRATION = true;
REQUIRE_SIGNIN_VIEW = false;
};
# A first login through the authelia source creates the
# account, named after authelia's `preferred_username` — the
# authelia username, not the opaque `sub`.
#
# ⚠️ `ACCOUNT_LINKING = login`, never `auto`. A login whose
# name is already taken does not create an account; `auto`
# would then hand the SSO user the existing one. Agents,
# `core` and `swarm-controller` all have local accounts here,
# the last two site admins, and `swarmctl user add` refuses
# none of those names. `login` asks for the existing
# account's own password instead, which an agent's or a
# service account's never leaves the forge.
oauth2_client = {
ENABLE_AUTO_REGISTRATION = true;
USERNAME = "preferred_username";
ACCOUNT_LINKING = "login";
};
repository = {
DEFAULT_BRANCH = "main";
DEFAULT_PRIVATE = "private";