summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2024-12-23 13:42:33 -0800
committerJoe Mou <dev@mou.fo>2025-06-16 14:02:30 -0400
commitecfccebdeb0c59df6a43243879a6eb42b007a1b6 (patch)
tree8840838abe199da69763ed2fbd181c0e5950a867
parentf10c3ba0ea43a1ae3385a91bc4ebbcb3aeb2a462 (diff)
Revert auth to Zitadel
Still don't love it but let's get things into a working state. Promising next steps: - Authlib (Python) - oidc-provider (Javascript) - Vouch Proxy, Ory Oauthkeeper, or IdP built-in forward auth Look at [[Authentication]]
-rw-r--r--hostnix/elmo/glauth/glauth.toml23
-rw-r--r--hostnix/elmo/home-assistant.nix17
-rw-r--r--hostnix/elmo/oidc.nix48
3 files changed, 5 insertions, 83 deletions
diff --git a/hostnix/elmo/glauth/glauth.toml b/hostnix/elmo/glauth/glauth.toml
deleted file mode 100644
index 5efcf97..0000000
--- a/hostnix/elmo/glauth/glauth.toml
+++ /dev/null
@@ -1,23 +0,0 @@
-[ldap]
- enabled = true
- listen = "[::1]:3893"
-[ldaps]
- enabled = false
-[backend]
- datastore = "config"
- baseDN = "dc=elmo,dc=mou,dc=fo"
- anonymousdse = false
-[[users]]
- name = "hackers"
- uidnumber = 5001
- primarygroup = 5501
- passsha256 = "6478579e37aff45f013e14eeb30b3cc56c72ccdc310123bcdf53e0333e3f416a" # dogood
- sshkeys = [ "ssh-dss AAAAB3..." ]
-[[users]]
- name = "uberhackers"
- uidnumber = 5006
- primarygroup = 5501
- passbcrypt = "243261243130244B62463462656F7265504F762E794F324957746D656541326B4B46596275674A79336A476845764B616D65446169784E41384F4432" # dogood
-[[groups]]
- name = "superheros"
- gidnumber = 5501
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index 0b23db0..7c66951 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -63,14 +63,7 @@
use_x_forwarded_for = true;
};
recorder.db_url = "postgresql://@/hass";
- # FIXME doesn't authenticate
- # auth_header.username_header = "X-Email";
- auth_header.debug = true;
- logger = {
- default = "info";
- logs."custom_components.auth_header" = "debug";
- };
-
+ auth_header = { };
#binary_sensor:
# - platform: template
@@ -658,14 +651,6 @@
auth_request off;
'';
};
- # FIXME testing shim
- locations."/test" = {
- proxyPass = "http://127.0.0.1:8000";
- extraConfig = ''
- proxy_set_header X-User $user;
- proxy_set_header X-Email $email;
- '';
- };
# Disable service worker caching that works improperly with reverse proxy.
# https://github.com/home-assistant/frontend/issues/14836
# https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 4421eb9..d7c6f0e 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -1,48 +1,6 @@
{ lib, pkgs, ... }:
{
- systemd.services.glauth = {
- wantedBy = [ "multi-user.target" ];
- serviceConfig = {
- DynamicUser = true;
- };
- script = "${pkgs.glauth}/bin/glauth -c ${./glauth/glauth.toml}";
- };
-
- services.dex = {
- enable = true;
- settings = {
- issuer = "https://op.mou.fo/dex";
- storage = {
- # TODO persistence?
- type = "memory";
- };
- web = {
- # TODO port
- http = "0.0.0.0:5556";
- };
- enablePasswordDB = true;
- staticPasswords = [
- {
- email = "joe";
- username = "joe";
- hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii";
- # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18";
- userID = "joe";
- }
- ];
- staticClients = [
- {
- id = "288565372746006652@mou.fo";
- name = "oauth2-proxy";
- redirectURIs = [ "https://op.mou.fo/oauth2/callback" ];
- # TODO consolidate w/ oauth2-proxy.env?
- secretFile = "/var/secrets/oauth2-proxy.secret";
- }
- ];
- };
- };
-
services.postgresql = {
ensureDatabases = [ "zitadel" ];
ensureUsers = [{
@@ -77,6 +35,7 @@
extraSettingsPaths = [ "/run/credentials/zitadel.service/secrets.yaml" ];
};
+ # TODO should be delayed after postgres
systemd.services.zitadel = {
# Shim into PATH to avoid start-from-init which requires Postgres admin
# credentials. See https://github.com/zitadel/zitadel/issues/4304
@@ -113,7 +72,7 @@
reverseProxy = true;
provider = "oidc";
clientID = "288565372746006652@mou.fo";
- oidcIssuerUrl = "https://op.mou.fo/dex";
+ oidcIssuerUrl = "https://zd.mou.fo";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/secrets/oauth2-proxy.env";
# Ignore e-mail address.
@@ -121,6 +80,8 @@
extraConfig = {
code-challenge-method = "S256";
whitelist-domain = ".mou.fo"; # allowed redirects after authentication
+ # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
+ oidc-email-claim = "sub";
};
};
@@ -137,6 +98,5 @@
services.nginx.virtualHosts."op.mou.fo" = {
enableACME = true;
forceSSL = true;
- locations."/dex".proxyPass = "http://127.0.0.1:5556";
};
}