diff options
| author | Joe Mou <dev@mou.fo> | 2025-04-16 13:33:47 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-06-16 13:58:57 -0400 |
| commit | f10c3ba0ea43a1ae3385a91bc4ebbcb3aeb2a462 (patch) | |
| tree | 0ab456eb5fa701aa89d3ec9374ed7d1ef69cabb9 /hostnix/elmo/oidc.nix | |
| parent | 278f61844675775af9532e9812f8138ba1deabb8 (diff) | |
Try setting up glauth LDAP, for some reason
If we wanted an LDAP server, glauth seems like a pretty good pick. It's
lightweight and can be configured entirely by a stateless text config
(it also supports a sqlite backend; it doesn't appear they can be used
together though).
But do we really benefit from an LDAP server? It could help set up
services that have LDAP authentication but not OIDC (most services that
use oauth2-proxy). Perhaps we'll revisit this.
glauth docs are spotty, but these are relevant for the config file:
- https://glauth.github.io/docs/file.html
- https://github.com/glauth/glauth/blob/master/v2/sample-simple.cfg
Nix has envsubst and replace-secret to include secrets in the config.
Information on setting up MFA:
https://www.couchbase.com/blog/multi-factor-authentication-mfa-2fa/
If we bind to an address besides localhost we should also set up LDAPS.
Diffstat (limited to 'hostnix/elmo/oidc.nix')
| -rw-r--r-- | hostnix/elmo/oidc.nix | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 88f8e9a..4421eb9 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -1,6 +1,14 @@ { lib, pkgs, ... }: { + systemd.services.glauth = { + wantedBy = [ "multi-user.target" ]; + serviceConfig = { + DynamicUser = true; + }; + script = "${pkgs.glauth}/bin/glauth -c ${./glauth/glauth.toml}"; + }; + services.dex = { enable = true; settings = { |
