diff options
| author | Joe Mou <dev@mou.fo> | 2023-10-01 14:55:42 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2023-10-01 16:12:56 -0400 |
| commit | 1f1535546e51db3c0a83c406744de21d4a479e53 (patch) | |
| tree | a08aef26aa2a014f80d82a123732ec941521b518 /hostnix/weebnix/home-assistant.nix | |
| parent | 1facb5ee013282419b8d5629f46acf54b9bb02cc (diff) | |
Adjust OpenId Connect / OAuth2 config for use across subdomains
Diffstat (limited to 'hostnix/weebnix/home-assistant.nix')
| -rw-r--r-- | hostnix/weebnix/home-assistant.nix | 28 |
1 files changed, 9 insertions, 19 deletions
diff --git a/hostnix/weebnix/home-assistant.nix b/hostnix/weebnix/home-assistant.nix index 500ff10..ee443ee 100644 --- a/hostnix/weebnix/home-assistant.nix +++ b/hostnix/weebnix/home-assistant.nix @@ -84,25 +84,15 @@ in { proxy_set_header X-Forwarded-Preferred-Username $preferred_username; ''; }; - }; - - # TODO how to configure for multiple domains? - services.oauth2_proxy = { - enable = true; - nginx.virtualHosts = [ "ha.weebnix.mou.fo" ]; - setXauthrequest = true; - # https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#keycloak-oidc-auth-provider - provider = "keycloak-oidc"; - clientID = "ha.weebnix.mou.fo"; - # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. - keyFile = "/var/lib/secrets/oauth2-proxy.env"; - redirectURL = "https://ha.weebnix.mou.fo/oauth2/callback"; - email.domains = [ "*" ]; - extraConfig = { - "oidc-issuer-url" = "https://kc.weebnix.mou.fo/realms/staging"; - "code-challenge-method" = "S256"; - # TODO this is specific to HA. move to nginx config? - "skip-auth-route" = "^/api/"; + # Duplicate relevant parts of root route to skip oauth2-proxy module magic. + locations."/api/" = { + proxyPass = "http://[::1]:8123"; + proxyWebsockets = true; + extraConfig = '' + proxy_buffering off; + ''; }; }; + + services.oauth2_proxy.nginx.virtualHosts = [ "ha.weebnix.mou.fo" ]; } |
