diff options
| author | Joe Mou <dev@mou.fo> | 2023-10-01 14:55:42 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2023-10-01 16:12:56 -0400 |
| commit | 1f1535546e51db3c0a83c406744de21d4a479e53 (patch) | |
| tree | a08aef26aa2a014f80d82a123732ec941521b518 /hostnix/weebnix/oidc.nix | |
| parent | 1facb5ee013282419b8d5629f46acf54b9bb02cc (diff) | |
Adjust OpenId Connect / OAuth2 config for use across subdomains
Diffstat (limited to 'hostnix/weebnix/oidc.nix')
| -rw-r--r-- | hostnix/weebnix/oidc.nix | 51 |
1 files changed, 51 insertions, 0 deletions
diff --git a/hostnix/weebnix/oidc.nix b/hostnix/weebnix/oidc.nix new file mode 100644 index 0000000..bf70882 --- /dev/null +++ b/hostnix/weebnix/oidc.nix @@ -0,0 +1,51 @@ +{ ... }: + +{ + services.keycloak = { + enable = true; + database.passwordFile = "/var/lib/secrets/keycloak.dbpass"; + settings = { + hostname = "kc.weebnix.mou.fo"; + http-host = "127.0.0.1"; + http-port = 7567; + proxy = "edge"; + }; + }; + + services.nginx.virtualHosts."kc.weebnix.mou.fo" = { + enableACME = true; + forceSSL = true; + locations."/".proxyPass = "http://127.0.0.1:7567"; + # We can handle oauth2-proxy callbacks on any subdomain, but the Keycloak + # subdomain is the least arbitrary. + locations."/oauth2/".proxyPass = "http://127.0.0.1:4180"; + }; + + # Work around "upstream sent too big header" because of large tokens. + services.nginx.appendHttpConfig = '' + proxy_buffers 8 16k; + proxy_buffer_size 16k; + ''; + + # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites + # nginx configs. It's mostly unhelpful, but we use it for brevity. In + # particular, it configures Traefik-like ForwardAuth authentication with + # auth_request. Note if this resource is missing for whatever reason, the + # module magic will fail open (auth_request unset). + services.oauth2_proxy = { + enable = true; + cookie.domain = "weebnix.mou.fo"; + setXauthrequest = true; # include claims + email.domains = [ "*" ]; # allow any authenticated user + # https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#keycloak-oidc-auth-provider + provider = "keycloak-oidc"; + clientID = "weebnix.mou.fo"; + # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. + keyFile = "/var/lib/secrets/oauth2-proxy.env"; + redirectURL = "https://kc.weebnix.mou.fo/oauth2/callback"; + extraConfig = { + "oidc-issuer-url" = "https://kc.weebnix.mou.fo/realms/staging"; + "whitelist-domain" = ".weebnix.mou.fo"; + }; + }; +} |
