diff options
| author | Joe Mou <dev@mou.fo> | 2025-04-15 22:26:50 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-06-16 13:58:57 -0400 |
| commit | 278f61844675775af9532e9812f8138ba1deabb8 (patch) | |
| tree | 08c86ac883cb0c2f201d8c41216d5459775f02b1 /hostnix/elmo/oidc.nix | |
| parent | ab1be6d042aba753dbb0041a0316ac3541c4daf2 (diff) | |
In progress attempt to use Dex for OIDC
Dex really doesn't want to be the authoritative identity provider.
Static users are not very configurable. The sub claim is a base64
internal representation that we can't use in backends directly. We could
jury rig email, but never got that working.
Basic authentication works, but Home Assistant fails to login the user.
Diffstat (limited to 'hostnix/elmo/oidc.nix')
| -rw-r--r-- | hostnix/elmo/oidc.nix | 39 |
1 files changed, 36 insertions, 3 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 00d2fcf..88f8e9a 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -1,6 +1,40 @@ { lib, pkgs, ... }: { + services.dex = { + enable = true; + settings = { + issuer = "https://op.mou.fo/dex"; + storage = { + # TODO persistence? + type = "memory"; + }; + web = { + # TODO port + http = "0.0.0.0:5556"; + }; + enablePasswordDB = true; + staticPasswords = [ + { + email = "joe"; + username = "joe"; + hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii"; + # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18"; + userID = "joe"; + } + ]; + staticClients = [ + { + id = "288565372746006652@mou.fo"; + name = "oauth2-proxy"; + redirectURIs = [ "https://op.mou.fo/oauth2/callback" ]; + # TODO consolidate w/ oauth2-proxy.env? + secretFile = "/var/secrets/oauth2-proxy.secret"; + } + ]; + }; + }; + services.postgresql = { ensureDatabases = [ "zitadel" ]; ensureUsers = [{ @@ -71,7 +105,7 @@ reverseProxy = true; provider = "oidc"; clientID = "288565372746006652@mou.fo"; - oidcIssuerUrl = "https://zd.mou.fo"; + oidcIssuerUrl = "https://op.mou.fo/dex"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/secrets/oauth2-proxy.env"; # Ignore e-mail address. @@ -79,8 +113,6 @@ extraConfig = { code-challenge-method = "S256"; whitelist-domain = ".mou.fo"; # allowed redirects after authentication - # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 - oidc-email-claim = "sub"; }; }; @@ -97,5 +129,6 @@ services.nginx.virtualHosts."op.mou.fo" = { enableACME = true; forceSSL = true; + locations."/dex".proxyPass = "http://127.0.0.1:5556"; }; } |
