Where Does Authelia Store Config and Users?
Authelia reads configuration.yml plus users_database.yml, with sessions in SQLite, Redis, or Postgres. Keep all three.
Last updated
Authelia keeps policy and identity apart. configuration.yml holds rules, domains, and secrets. users_database.yml holds the user list with password hashes. A third backend holds sessions and 2FA registrations.
Backups miss the third piece most often. The YAML files copy easily, the session store needs its own dump. Without it, restores work but every user re-enrolls their second factor.
Where Authelia stores this, by platform
/config/configuration.yml + users_database.yml
Main config with rules and secrets plus the users file. Mount both into the container. Secrets belong in env or vault, not chat.
Frequently asked questions
How do I back up Authelia?
Copy configuration.yml, users_database.yml, and the storage backend (SQLite file or DB dump). Lose the storage and every user re-registers devices and 2FA.
Can Authelia use SQLite?
Yes for small setups. Point storage to a local SQLite path. Redis and Postgres suit multi-instance runs. The users file stays separate either way.
How do I log out every Authelia user?
Rotate jwt_secret in configuration.yml and restart. Every session invalidates at once. Do this if the secret ever leaks.
Notice an outdated path? Let us know.