summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2024-04-27 01:47:45 -0400
committerJoe Mou <dev@mou.fo>2024-04-27 01:47:45 -0400
commitf9c27964706773a7a30cb636b2b17ceab2446c53 (patch)
treea409ca3be1b5cd8284134454126661782c9e4814 /hostnix/elmo/oidc.nix
parent07a7baeb6bf21ce2018fc558fb849ba17669fb89 (diff)
elmo: Hoist subdomains and issue production certificates
Diffstat (limited to 'hostnix/elmo/oidc.nix')
-rw-r--r--hostnix/elmo/oidc.nix12
1 files changed, 6 insertions, 6 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index bff769e..8447aa0 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -5,14 +5,14 @@
enable = true;
database.passwordFile = "/var/secrets/keycloak.dbpass";
settings = {
- hostname = "kc.elmo.mou.fo";
+ hostname = "kc.mou.fo";
http-host = "127.0.0.1";
http-port = 7567;
proxy = "edge";
};
};
- services.nginx.virtualHosts."kc.elmo.mou.fo" = {
+ services.nginx.virtualHosts."kc.mou.fo" = {
enableACME = true;
forceSSL = true;
locations."/".proxyPass = "http://127.0.0.1:7567";
@@ -34,7 +34,7 @@
# module magic will fail open (auth_request unset).
services.oauth2_proxy = {
enable = true;
- cookie.domain = "elmo.mou.fo";
+ cookie.domain = "mou.fo";
setXauthrequest = true; # include claims
email.domains = [ "*" ]; # allow any authenticated user
# https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc
@@ -42,10 +42,10 @@
clientID = "oauth2-proxy";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/secrets/oauth2-proxy.env";
- redirectURL = "https://kc.elmo.mou.fo/oauth2/callback";
+ redirectURL = "https://kc.mou.fo/oauth2/callback";
extraConfig = {
- "oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod";
- "whitelist-domain" = ".elmo.mou.fo";
+ "oidc-issuer-url" = "https://kc.mou.fo/realms/prod";
+ "whitelist-domain" = ".mou.fo";
# https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
"insecure-oidc-allow-unverified-email" = true;
"oidc-email-claim" = "sub";