Adds a deliberate extra sign-in layer covering the entire nginx gateway (portal page + every proxied web UI) via a shared htpasswd credential generated on the FreeIPA container and published to nginx through a new portal-auth volume. FreeIPA, CheckMK and Keycloak still each enforce their own login behind it — two prompts beats one attacker who only had to beat one lock. Healthcheck updated to treat 401 as healthy accordingly. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Desktop-Environments | ||
| FreeipaAnsible | ||
| lib | ||
| optional-Modules/apps | ||
| core-packages.sh | ||
| core.sh | ||
| package-managers.sh | ||
| shell-setup.sh | ||