summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2024-04-25 12:58:55 -0400
committerJoe Mou <dev@mou.fo>2024-04-26 16:30:07 -0400
commit96b949393cfa64f8b44e16d269d9148696e44299 (patch)
tree70cb58987e4ab071a830c02effe42226be88ce1f /hostnix/elmo/oidc.nix
parent3cb2738e79273af715380fadc6bb21584bc19c5a (diff)
elmo: Move secrets to /var/secrets
Clarifies that they are not managed by a distribution package.
Diffstat (limited to 'hostnix/elmo/oidc.nix')
-rw-r--r--hostnix/elmo/oidc.nix4
1 files changed, 2 insertions, 2 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 7648e8c..bff769e 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -3,7 +3,7 @@
{
services.keycloak = {
enable = true;
- database.passwordFile = "/var/lib/secrets/keycloak.dbpass";
+ database.passwordFile = "/var/secrets/keycloak.dbpass";
settings = {
hostname = "kc.elmo.mou.fo";
http-host = "127.0.0.1";
@@ -41,7 +41,7 @@
provider = "keycloak-oidc";
clientID = "oauth2-proxy";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
- keyFile = "/var/lib/secrets/oauth2-proxy.env";
+ keyFile = "/var/secrets/oauth2-proxy.env";
redirectURL = "https://kc.elmo.mou.fo/oauth2/callback";
extraConfig = {
"oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod";