diff options
| author | Joe Mou <dev@mou.fo> | 2025-12-29 21:47:11 -0800 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-12-31 01:05:59 -0800 |
| commit | 013d42ffafb9dcd05b1bd8511a720d173fbd5c2f (patch) | |
| tree | 1cf4f3c282a7415f4e7051a8165fcee2accb288c /hostnix/elmo/oidc.nix | |
| parent | 7da4fcc2a0f4103892abc33881978addfbaf3409 (diff) | |
Replace Zitadel with Pocket ID
Much simpler to configure and use.
Diffstat (limited to 'hostnix/elmo/oidc.nix')
| -rw-r--r-- | hostnix/elmo/oidc.nix | 83 |
1 files changed, 29 insertions, 54 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index c3c2c0d..40a0528 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -1,57 +1,38 @@ { lib, pkgs, ... }: { - services.postgresql = { - ensureDatabases = [ "zitadel" ]; - ensureUsers = [{ - name = "zitadel"; - ensureDBOwnership = true; - }]; - }; + systemd.tmpfiles.rules = [ + "d /run/pocket-id 750 pocket-id nginx" + ]; - services.zitadel = { + # - Create user joe + # - Create OIDC Client: oauth2-proxy + # - Callback URLs: https://op.mou.fo/oauth2/callback + # - PKCE + services.pocket-id = { enable = true; settings = { - # We seem to be unable to bind Zitadel to only the loopback interface. - Port = 9068; - ExternalPort = 443; - ExternalDomain = "zd.mou.fo"; - Database.postgres = { - Host = "127.0.0.1"; - Port = 5432; - Database = "zitadel"; - User.Username = "zitadel"; - User.SSL.Mode = "disable"; - }; - }; - masterKeyFile = "/run/credentials/zitadel.service/master.key"; - # Zitadel only connects to Postgres over the network, so we need to - # configure passwords here and manually for the zitadel Postgres user. - extraSettingsPaths = [ "/run/credentials/zitadel.service/secrets.yaml" ]; - }; + APP_URL = "https://pi.mou.fo"; + TRUST_PROXY = true; + UNIX_SOCKET = "/run/pocket-id/socket"; + UNIX_SOCKET_MODE = "0777"; - # TODO should be delayed after postgres - systemd.services.zitadel = { - # Shim into PATH to avoid start-from-init which requires Postgres admin - # credentials. See https://github.com/zitadel/zitadel/issues/4304 - path = let - wrapper = pkgs.writeShellScriptBin "zitadel" - '' - shift - exec ${pkgs.zitadel}/bin/zitadel start-from-setup "$@" - ''; - in lib.mkBefore [ wrapper ]; - # Allow unprivileged zitadel user selective access to secrets. - serviceConfig.LoadCredential = [ - "master.key:/var/secrets/zitadel.key" - "secrets.yaml:/var/secrets/zitadel.yaml" - ]; + # https://pocket-id.org/docs/configuration/environment-variables#overriding-the-ui-configuration + UI_CONFIG_DISABLED = true; + EMAILS_VERIFIED = true; # needed by oauth2-proxy + SMTP_HOST = "localhost"; + SMTP_PORT = 25; + SMTP_FROM = "noreply@pi.mou.fo"; + EMAIL_LOGIN_NOTIFICATION_ENABLED = true; + EMAIL_API_KEY_EXPIRATION_ENABLED = true; + EMAIL_ONE_TIME_ACCESS_AS_UNAUTHENTICATED_ENABLED = true; + }; }; - services.nginx.virtualHosts."zd.mou.fo" = { + services.nginx.virtualHosts."pi.mou.fo" = { enableACME = true; forceSSL = true; - locations."/".proxyPass = "http://127.0.0.1:9068"; + locations."/".proxyPass = "http://unix:/run/pocket-id/socket"; }; # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites @@ -63,28 +44,22 @@ enable = true; cookie.domain = "mou.fo"; nginx.domain = "op.mou.fo"; - setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email + setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email reverseProxy = true; provider = "oidc"; - clientID = "288565372746006652@mou.fo"; - oidcIssuerUrl = "https://zd.mou.fo"; + clientID = "39edd929-8983-4cb6-b1cd-dc08e2e3358f"; + oidcIssuerUrl = "https://pi.mou.fo"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/secrets/oauth2-proxy.env"; # Ignore e-mail address. email.domains = [ "*" ]; extraConfig = { code-challenge-method = "S256"; - whitelist-domain = ".mou.fo"; # allowed redirects after authentication - # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 - oidc-email-claim = "sub"; + whitelist-domain = ".mou.fo"; # allowed redirects after authentication }; }; - # Kludge to bring up after Kanidm (otherwise OIDC discovery fails). A simple - # ordering dependency isn't enough because kandim.service is active before - # Kanidm responds to requests. Kanidm starts up quickly enough that boot up - # may work without this. - systemd.services.oauth2-proxy.serviceConfig.RestartSec = 5; + systemd.services.oauth2-proxy.after = [ "pocket-id.service" ]; # It's somewhat overkill to assign oauth2-proxy its own domain. We can't use # Kanidm's though, because it uses the /oauth2 path which the oauth2-proxy |
