<feed xmlns='http://www.w3.org/2005/Atom'>
<title>mono.git/hostnix/elmo/glauth, branch main</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<id>http://git.mou.fo/2026/mono.git/atom/hostnix/elmo/glauth?h=main</id>
<link rel='self' href='http://git.mou.fo/2026/mono.git/atom/hostnix/elmo/glauth?h=main'/>
<link rel='alternate' type='text/html' href='http://git.mou.fo/2026/mono.git/'/>
<updated>2025-06-16T18:02:30Z</updated>
<entry>
<title>Revert auth to Zitadel</title>
<updated>2025-06-16T18:02:30Z</updated>
<author>
<name>Joe Mou</name>
<email>dev@mou.fo</email>
</author>
<published>2024-12-23T21:42:33Z</published>
<link rel='alternate' type='text/html' href='http://git.mou.fo/2026/mono.git/commit/?id=ecfccebdeb0c59df6a43243879a6eb42b007a1b6'/>
<id>urn:sha1:ecfccebdeb0c59df6a43243879a6eb42b007a1b6</id>
<content type='text'>
Still don't love it but let's get things into a working state.

Promising next steps:
- Authlib (Python)
- oidc-provider (Javascript)
- Vouch Proxy, Ory Oauthkeeper, or IdP built-in forward auth

Look at [[Authentication]]
</content>
</entry>
<entry>
<title>Try setting up glauth LDAP, for some reason</title>
<updated>2025-06-16T17:58:57Z</updated>
<author>
<name>Joe Mou</name>
<email>dev@mou.fo</email>
</author>
<published>2025-04-16T17:33:47Z</published>
<link rel='alternate' type='text/html' href='http://git.mou.fo/2026/mono.git/commit/?id=f10c3ba0ea43a1ae3385a91bc4ebbcb3aeb2a462'/>
<id>urn:sha1:f10c3ba0ea43a1ae3385a91bc4ebbcb3aeb2a462</id>
<content type='text'>
If we wanted an LDAP server, glauth seems like a pretty good pick. It's
lightweight and can be configured entirely by a stateless text config
(it also supports a sqlite backend; it doesn't appear they can be used
together though).

But do we really benefit from an LDAP server? It could help set up
services that have LDAP authentication but not OIDC (most services that
use oauth2-proxy). Perhaps we'll revisit this.

glauth docs are spotty, but these are relevant for the config file:
- https://glauth.github.io/docs/file.html
- https://github.com/glauth/glauth/blob/master/v2/sample-simple.cfg

Nix has envsubst and replace-secret to include secrets in the config.

Information on setting up MFA:
https://www.couchbase.com/blog/multi-factor-authentication-mfa-2fa/

If we bind to an address besides localhost we should also set up LDAPS.
</content>
</entry>
</feed>
