summaryrefslogtreecommitdiff
path: root/hostnix/elmo
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-12-29 21:47:11 -0800
committerJoe Mou <dev@mou.fo>2025-12-31 01:05:59 -0800
commit013d42ffafb9dcd05b1bd8511a720d173fbd5c2f (patch)
tree1cf4f3c282a7415f4e7051a8165fcee2accb288c /hostnix/elmo
parent7da4fcc2a0f4103892abc33881978addfbaf3409 (diff)
Replace Zitadel with Pocket ID
Much simpler to configure and use.
Diffstat (limited to 'hostnix/elmo')
-rw-r--r--hostnix/elmo/oidc.nix83
1 files changed, 29 insertions, 54 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index c3c2c0d..40a0528 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -1,57 +1,38 @@
{ lib, pkgs, ... }:
{
- services.postgresql = {
- ensureDatabases = [ "zitadel" ];
- ensureUsers = [{
- name = "zitadel";
- ensureDBOwnership = true;
- }];
- };
+ systemd.tmpfiles.rules = [
+ "d /run/pocket-id 750 pocket-id nginx"
+ ];
- services.zitadel = {
+ # - Create user joe
+ # - Create OIDC Client: oauth2-proxy
+ # - Callback URLs: https://op.mou.fo/oauth2/callback
+ # - PKCE
+ services.pocket-id = {
enable = true;
settings = {
- # We seem to be unable to bind Zitadel to only the loopback interface.
- Port = 9068;
- ExternalPort = 443;
- ExternalDomain = "zd.mou.fo";
- Database.postgres = {
- Host = "127.0.0.1";
- Port = 5432;
- Database = "zitadel";
- User.Username = "zitadel";
- User.SSL.Mode = "disable";
- };
- };
- masterKeyFile = "/run/credentials/zitadel.service/master.key";
- # Zitadel only connects to Postgres over the network, so we need to
- # configure passwords here and manually for the zitadel Postgres user.
- extraSettingsPaths = [ "/run/credentials/zitadel.service/secrets.yaml" ];
- };
+ APP_URL = "https://pi.mou.fo";
+ TRUST_PROXY = true;
+ UNIX_SOCKET = "/run/pocket-id/socket";
+ UNIX_SOCKET_MODE = "0777";
- # TODO should be delayed after postgres
- systemd.services.zitadel = {
- # Shim into PATH to avoid start-from-init which requires Postgres admin
- # credentials. See https://github.com/zitadel/zitadel/issues/4304
- path = let
- wrapper = pkgs.writeShellScriptBin "zitadel"
- ''
- shift
- exec ${pkgs.zitadel}/bin/zitadel start-from-setup "$@"
- '';
- in lib.mkBefore [ wrapper ];
- # Allow unprivileged zitadel user selective access to secrets.
- serviceConfig.LoadCredential = [
- "master.key:/var/secrets/zitadel.key"
- "secrets.yaml:/var/secrets/zitadel.yaml"
- ];
+ # https://pocket-id.org/docs/configuration/environment-variables#overriding-the-ui-configuration
+ UI_CONFIG_DISABLED = true;
+ EMAILS_VERIFIED = true; # needed by oauth2-proxy
+ SMTP_HOST = "localhost";
+ SMTP_PORT = 25;
+ SMTP_FROM = "noreply@pi.mou.fo";
+ EMAIL_LOGIN_NOTIFICATION_ENABLED = true;
+ EMAIL_API_KEY_EXPIRATION_ENABLED = true;
+ EMAIL_ONE_TIME_ACCESS_AS_UNAUTHENTICATED_ENABLED = true;
+ };
};
- services.nginx.virtualHosts."zd.mou.fo" = {
+ services.nginx.virtualHosts."pi.mou.fo" = {
enableACME = true;
forceSSL = true;
- locations."/".proxyPass = "http://127.0.0.1:9068";
+ locations."/".proxyPass = "http://unix:/run/pocket-id/socket";
};
# The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites
@@ -63,28 +44,22 @@
enable = true;
cookie.domain = "mou.fo";
nginx.domain = "op.mou.fo";
- setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email
+ setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email
reverseProxy = true;
provider = "oidc";
- clientID = "288565372746006652@mou.fo";
- oidcIssuerUrl = "https://zd.mou.fo";
+ clientID = "39edd929-8983-4cb6-b1cd-dc08e2e3358f";
+ oidcIssuerUrl = "https://pi.mou.fo";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/secrets/oauth2-proxy.env";
# Ignore e-mail address.
email.domains = [ "*" ];
extraConfig = {
code-challenge-method = "S256";
- whitelist-domain = ".mou.fo"; # allowed redirects after authentication
- # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
- oidc-email-claim = "sub";
+ whitelist-domain = ".mou.fo"; # allowed redirects after authentication
};
};
- # Kludge to bring up after Kanidm (otherwise OIDC discovery fails). A simple
- # ordering dependency isn't enough because kandim.service is active before
- # Kanidm responds to requests. Kanidm starts up quickly enough that boot up
- # may work without this.
- systemd.services.oauth2-proxy.serviceConfig.RestartSec = 5;
+ systemd.services.oauth2-proxy.after = [ "pocket-id.service" ];
# It's somewhat overkill to assign oauth2-proxy its own domain. We can't use
# Kanidm's though, because it uses the /oauth2 path which the oauth2-proxy