diff options
| author | Joe Mou <dev@mou.fo> | 2023-10-01 14:55:42 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2023-10-01 16:12:56 -0400 |
| commit | 1f1535546e51db3c0a83c406744de21d4a479e53 (patch) | |
| tree | a08aef26aa2a014f80d82a123732ec941521b518 /hostnix/weebnix/configuration.nix | |
| parent | 1facb5ee013282419b8d5629f46acf54b9bb02cc (diff) | |
Adjust OpenId Connect / OAuth2 config for use across subdomains
Diffstat (limited to 'hostnix/weebnix/configuration.nix')
| -rw-r--r-- | hostnix/weebnix/configuration.nix | 17 |
1 files changed, 1 insertions, 16 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix index 1669b8a..a879185 100644 --- a/hostnix/weebnix/configuration.nix +++ b/hostnix/weebnix/configuration.nix @@ -5,6 +5,7 @@ ./dyndns.nix ./hardware-configuration.nix ./home-assistant.nix + ./oidc.nix ./syncthing.nix ./system.nix ]; @@ -34,28 +35,12 @@ services.openssh.enable = true; - services.keycloak = { - enable = true; - database.passwordFile = "/var/lib/secrets/keycloak.dbpass"; - settings = { - hostname = "kc.weebnix.mou.fo"; - http-host = "127.0.0.1"; - http-port = 7567; - proxy = "edge"; - }; - }; - services.nginx = { enable = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedTlsSettings = true; - virtualHosts."kc.weebnix.mou.fo" = { - enableACME = true; - forceSSL = true; - locations."/".proxyPass = "http://127.0.0.1:7567"; - }; # Slightly crazy setup to SNI reverse proxy HTTPS to multiple upstreams. # We displace ourselves onto port 8443, and send requests that are not # intended for us to weeber. This is done because Apache running on weeber |
