summaryrefslogtreecommitdiff
path: root/hostnix/elmo/web.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-16 13:33:47 -0400
committerJoe Mou <dev@mou.fo>2025-06-16 13:58:57 -0400
commitf10c3ba0ea43a1ae3385a91bc4ebbcb3aeb2a462 (patch)
tree0ab456eb5fa701aa89d3ec9374ed7d1ef69cabb9 /hostnix/elmo/web.nix
parent278f61844675775af9532e9812f8138ba1deabb8 (diff)
Try setting up glauth LDAP, for some reason
If we wanted an LDAP server, glauth seems like a pretty good pick. It's lightweight and can be configured entirely by a stateless text config (it also supports a sqlite backend; it doesn't appear they can be used together though). But do we really benefit from an LDAP server? It could help set up services that have LDAP authentication but not OIDC (most services that use oauth2-proxy). Perhaps we'll revisit this. glauth docs are spotty, but these are relevant for the config file: - https://glauth.github.io/docs/file.html - https://github.com/glauth/glauth/blob/master/v2/sample-simple.cfg Nix has envsubst and replace-secret to include secrets in the config. Information on setting up MFA: https://www.couchbase.com/blog/multi-factor-authentication-mfa-2fa/ If we bind to an address besides localhost we should also set up LDAPS.
Diffstat (limited to 'hostnix/elmo/web.nix')
0 files changed, 0 insertions, 0 deletions