michael 457db3ced2 ansible: implement install + policy + pending tasks
Adds the apt_repository / apt steps that pull authforge-daemon, -pam,
and -cli (with -gui gated behind authforge_install_gui), the template
step that renders /etc/authforge/policy.d/90-fleet.conf and notifies the
restart handler, and a loop that calls `authforgectl pending set` for
each entry in authforge_pending_users.

The template emits TOML that round-trips through tomllib for both the
empty-stacks default and a populated multi-stack config.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 08:35:28 -07:00

authforge

Turnkey U2F / FIDO2 passkey / TOTP MFA for Linux desktops. v1 ships on Ubuntu LTS + GNOME; Debian and KDE Plasma are on the roadmap.

Install (end users)

sudo add-apt-repository ppa:dangerousthings/authforge
sudo apt install authforge

Build from source

See docs/BUILDING.md.

Status

Pre-alpha. Phases 03, 6, 7 code complete (workspace scaffold, D-Bus daemon, storage layer, FIDO2 backend with mock+real authenticator, PAM pending-flag backstop, authforgectl CLI). Phase 4+5 (policy apply via pam-auth-update + lockout simulator) is next. See docs/plans/ for design, roadmap, and per-phase implementation plans.

Copyright 2026 Dangerous Things, LLC. Licensed under the Apache License, Version 2.0.

Description
mfa support and related user management and policy tools for linux
Readme 398 KiB
Languages
Rust 95.9%
C 3.6%
Jinja 0.3%
Makefile 0.2%