Adds a deliberate extra sign-in layer covering the entire nginx gateway (portal page + every proxied web UI) via a shared htpasswd credential generated on the FreeIPA container and published to nginx through a new portal-auth volume. FreeIPA, CheckMK and Keycloak still each enforce their own login behind it — two prompts beats one attacker who only had to beat one lock. Healthcheck updated to treat 401 as healthy accordingly. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| ansipa-administration.md | ||
| ansipa-setup.md | ||
| archiso.md | ||
| editors.md | ||
| freeipa-ansible.md | ||
| hyprland.md | ||
| index.md | ||
| installation.md | ||
| modules.md | ||
| niri.md | ||
| theming.md | ||
| utilities.md | ||