Ingress auth
Enable hub Authelia with inventory:
| Variable | Purpose |
|---|---|
fleet_ingress_auth_enabled: true |
Hub Authelia forward-auth |
fleet_lldap_admin_password_vault |
Required (≥12 chars) |
Cluster ingress auth uses separate secrets per cluster (fleet-ingress-auth-<cluster>). Keep fleet_fcj_default_ingress_auth_enabled: false when clusters need different LLDAP passwords.
Prerequisites for cluster ingress auth: FCJ Ready, ingress enabled (port_forward / reverse_proxy), site DNS zone for auth.<zone>.
ansible-playbook $INV fleet-site-controller.yml -l hub \ -t fleet_site_seed_infrastructure \ --vault-password-file ~/.umkim-vault-pass