diff options
| author | Joe Mou <dev@mou.fo> | 2024-04-25 12:58:55 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2024-04-26 16:30:07 -0400 |
| commit | 96b949393cfa64f8b44e16d269d9148696e44299 (patch) | |
| tree | 70cb58987e4ab071a830c02effe42226be88ce1f /hostnix/elmo/oidc.nix | |
| parent | 3cb2738e79273af715380fadc6bb21584bc19c5a (diff) | |
elmo: Move secrets to /var/secrets
Clarifies that they are not managed by a distribution package.
Diffstat (limited to 'hostnix/elmo/oidc.nix')
| -rw-r--r-- | hostnix/elmo/oidc.nix | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 7648e8c..bff769e 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -3,7 +3,7 @@ { services.keycloak = { enable = true; - database.passwordFile = "/var/lib/secrets/keycloak.dbpass"; + database.passwordFile = "/var/secrets/keycloak.dbpass"; settings = { hostname = "kc.elmo.mou.fo"; http-host = "127.0.0.1"; @@ -41,7 +41,7 @@ provider = "keycloak-oidc"; clientID = "oauth2-proxy"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. - keyFile = "/var/lib/secrets/oauth2-proxy.env"; + keyFile = "/var/secrets/oauth2-proxy.env"; redirectURL = "https://kc.elmo.mou.fo/oauth2/callback"; extraConfig = { "oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod"; |
