summaryrefslogtreecommitdiff
path: root/hostnix/elmo
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2024-04-27 01:47:45 -0400
committerJoe Mou <dev@mou.fo>2024-04-27 01:47:45 -0400
commitf9c27964706773a7a30cb636b2b17ceab2446c53 (patch)
treea409ca3be1b5cd8284134454126661782c9e4814 /hostnix/elmo
parent07a7baeb6bf21ce2018fc558fb849ba17669fb89 (diff)
elmo: Hoist subdomains and issue production certificates
Diffstat (limited to 'hostnix/elmo')
-rw-r--r--hostnix/elmo/acme.nix7
-rw-r--r--hostnix/elmo/dyndns.nix3
-rw-r--r--hostnix/elmo/home-assistant.nix4
-rw-r--r--hostnix/elmo/oidc.nix12
-rw-r--r--hostnix/elmo/privacy-frontends.nix2
-rw-r--r--hostnix/elmo/syncthing.nix4
-rw-r--r--hostnix/elmo/usenet.nix4
7 files changed, 13 insertions, 23 deletions
diff --git a/hostnix/elmo/acme.nix b/hostnix/elmo/acme.nix
index 597b781..fccd5c8 100644
--- a/hostnix/elmo/acme.nix
+++ b/hostnix/elmo/acme.nix
@@ -14,13 +14,6 @@
security.acme.acceptTerms = true;
security.acme.defaults.email = "hostmaster@mou.fo";
- # TODO remove to switch to production certs
- security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
- services.oauth2_proxy.extraConfig = {
- "ssl-insecure-skip-verify" = true;
- "ssl-upstream-insecure-skip-verify" = true;
- };
-
# https://go-acme.github.io/lego/dns/exec/
security.acme.defaults.dnsProvider = "exec";
security.acme.defaults.credentialFiles = {
diff --git a/hostnix/elmo/dyndns.nix b/hostnix/elmo/dyndns.nix
index 5bfde47..5abe98c 100644
--- a/hostnix/elmo/dyndns.nix
+++ b/hostnix/elmo/dyndns.nix
@@ -66,9 +66,6 @@
''${IP6:+update add $RR. 300 AAAA $IP6}
update delete $RR. TXT
update add $RR. 300 TXT "v=spf1 include:_spf.mou.fo ~all"
- ; Wildcard all subdomains.
- update delete \\*.$1.$RR. CNAME
- update add \\*.$1.$RR. 300 CNAME $RR.
send
.
'';
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index a392dfc..5b29a10 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -684,7 +684,7 @@
};
};
- services.nginx.virtualHosts."ha.elmo.mou.fo" = {
+ services.nginx.virtualHosts."ha.mou.fo" = {
enableACME = true;
forceSSL = true;
locations."/" = {
@@ -716,5 +716,5 @@
};
};
- services.oauth2_proxy.nginx.virtualHosts = [ "ha.elmo.mou.fo" ];
+ services.oauth2_proxy.nginx.virtualHosts = [ "ha.mou.fo" ];
}
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index bff769e..8447aa0 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -5,14 +5,14 @@
enable = true;
database.passwordFile = "/var/secrets/keycloak.dbpass";
settings = {
- hostname = "kc.elmo.mou.fo";
+ hostname = "kc.mou.fo";
http-host = "127.0.0.1";
http-port = 7567;
proxy = "edge";
};
};
- services.nginx.virtualHosts."kc.elmo.mou.fo" = {
+ services.nginx.virtualHosts."kc.mou.fo" = {
enableACME = true;
forceSSL = true;
locations."/".proxyPass = "http://127.0.0.1:7567";
@@ -34,7 +34,7 @@
# module magic will fail open (auth_request unset).
services.oauth2_proxy = {
enable = true;
- cookie.domain = "elmo.mou.fo";
+ cookie.domain = "mou.fo";
setXauthrequest = true; # include claims
email.domains = [ "*" ]; # allow any authenticated user
# https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc
@@ -42,10 +42,10 @@
clientID = "oauth2-proxy";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/secrets/oauth2-proxy.env";
- redirectURL = "https://kc.elmo.mou.fo/oauth2/callback";
+ redirectURL = "https://kc.mou.fo/oauth2/callback";
extraConfig = {
- "oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod";
- "whitelist-domain" = ".elmo.mou.fo";
+ "oidc-issuer-url" = "https://kc.mou.fo/realms/prod";
+ "whitelist-domain" = ".mou.fo";
# https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
"insecure-oidc-allow-unverified-email" = true;
"oidc-email-claim" = "sub";
diff --git a/hostnix/elmo/privacy-frontends.nix b/hostnix/elmo/privacy-frontends.nix
index b5fcba0..6030d96 100644
--- a/hostnix/elmo/privacy-frontends.nix
+++ b/hostnix/elmo/privacy-frontends.nix
@@ -18,7 +18,7 @@
};
};
- services.nginx.virtualHosts."lr.elmo.mou.fo" = {
+ services.nginx.virtualHosts."lr.mou.fo" = {
enableACME = true;
forceSSL = true;
locations."/".proxyPass = "http://[::1]:7682";
diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix
index 63b540e..3b60027 100644
--- a/hostnix/elmo/syncthing.nix
+++ b/hostnix/elmo/syncthing.nix
@@ -127,7 +127,7 @@ in
};
};
- services.nginx.virtualHosts."st.elmo.mou.fo" = {
+ services.nginx.virtualHosts."st.mou.fo" = {
enableACME = true;
forceSSL = true;
locations."/" = {
@@ -137,5 +137,5 @@ in
};
};
- services.oauth2_proxy.nginx.virtualHosts = [ "st.elmo.mou.fo" ];
+ services.oauth2_proxy.nginx.virtualHosts = [ "st.mou.fo" ];
}
diff --git a/hostnix/elmo/usenet.nix b/hostnix/elmo/usenet.nix
index ab381a9..26d7a7b 100644
--- a/hostnix/elmo/usenet.nix
+++ b/hostnix/elmo/usenet.nix
@@ -42,11 +42,11 @@ in
};
};
- services.nginx.virtualHosts."ng.elmo.mou.fo" = {
+ services.nginx.virtualHosts."ng.mou.fo" = {
enableACME = true;
forceSSL = true;
locations."/".proxyPass = "http://[::1]:6789";
};
- services.oauth2_proxy.nginx.virtualHosts = [ "ng.elmo.mou.fo" ];
+ services.oauth2_proxy.nginx.virtualHosts = [ "ng.mou.fo" ];
}