summaryrefslogtreecommitdiff
path: root/hostnix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2023-10-01 14:55:42 -0400
committerJoe Mou <dev@mou.fo>2023-10-01 16:12:56 -0400
commit1f1535546e51db3c0a83c406744de21d4a479e53 (patch)
treea08aef26aa2a014f80d82a123732ec941521b518 /hostnix
parent1facb5ee013282419b8d5629f46acf54b9bb02cc (diff)
Adjust OpenId Connect / OAuth2 config for use across subdomains
Diffstat (limited to 'hostnix')
-rw-r--r--hostnix/weebnix/configuration.nix17
-rw-r--r--hostnix/weebnix/home-assistant.nix28
-rw-r--r--hostnix/weebnix/oidc.nix51
3 files changed, 61 insertions, 35 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix
index 1669b8a..a879185 100644
--- a/hostnix/weebnix/configuration.nix
+++ b/hostnix/weebnix/configuration.nix
@@ -5,6 +5,7 @@
./dyndns.nix
./hardware-configuration.nix
./home-assistant.nix
+ ./oidc.nix
./syncthing.nix
./system.nix
];
@@ -34,28 +35,12 @@
services.openssh.enable = true;
- services.keycloak = {
- enable = true;
- database.passwordFile = "/var/lib/secrets/keycloak.dbpass";
- settings = {
- hostname = "kc.weebnix.mou.fo";
- http-host = "127.0.0.1";
- http-port = 7567;
- proxy = "edge";
- };
- };
-
services.nginx = {
enable = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
- virtualHosts."kc.weebnix.mou.fo" = {
- enableACME = true;
- forceSSL = true;
- locations."/".proxyPass = "http://127.0.0.1:7567";
- };
# Slightly crazy setup to SNI reverse proxy HTTPS to multiple upstreams.
# We displace ourselves onto port 8443, and send requests that are not
# intended for us to weeber. This is done because Apache running on weeber
diff --git a/hostnix/weebnix/home-assistant.nix b/hostnix/weebnix/home-assistant.nix
index 500ff10..ee443ee 100644
--- a/hostnix/weebnix/home-assistant.nix
+++ b/hostnix/weebnix/home-assistant.nix
@@ -84,25 +84,15 @@ in {
proxy_set_header X-Forwarded-Preferred-Username $preferred_username;
'';
};
- };
-
- # TODO how to configure for multiple domains?
- services.oauth2_proxy = {
- enable = true;
- nginx.virtualHosts = [ "ha.weebnix.mou.fo" ];
- setXauthrequest = true;
- # https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#keycloak-oidc-auth-provider
- provider = "keycloak-oidc";
- clientID = "ha.weebnix.mou.fo";
- # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
- keyFile = "/var/lib/secrets/oauth2-proxy.env";
- redirectURL = "https://ha.weebnix.mou.fo/oauth2/callback";
- email.domains = [ "*" ];
- extraConfig = {
- "oidc-issuer-url" = "https://kc.weebnix.mou.fo/realms/staging";
- "code-challenge-method" = "S256";
- # TODO this is specific to HA. move to nginx config?
- "skip-auth-route" = "^/api/";
+ # Duplicate relevant parts of root route to skip oauth2-proxy module magic.
+ locations."/api/" = {
+ proxyPass = "http://[::1]:8123";
+ proxyWebsockets = true;
+ extraConfig = ''
+ proxy_buffering off;
+ '';
};
};
+
+ services.oauth2_proxy.nginx.virtualHosts = [ "ha.weebnix.mou.fo" ];
}
diff --git a/hostnix/weebnix/oidc.nix b/hostnix/weebnix/oidc.nix
new file mode 100644
index 0000000..bf70882
--- /dev/null
+++ b/hostnix/weebnix/oidc.nix
@@ -0,0 +1,51 @@
+{ ... }:
+
+{
+ services.keycloak = {
+ enable = true;
+ database.passwordFile = "/var/lib/secrets/keycloak.dbpass";
+ settings = {
+ hostname = "kc.weebnix.mou.fo";
+ http-host = "127.0.0.1";
+ http-port = 7567;
+ proxy = "edge";
+ };
+ };
+
+ services.nginx.virtualHosts."kc.weebnix.mou.fo" = {
+ enableACME = true;
+ forceSSL = true;
+ locations."/".proxyPass = "http://127.0.0.1:7567";
+ # We can handle oauth2-proxy callbacks on any subdomain, but the Keycloak
+ # subdomain is the least arbitrary.
+ locations."/oauth2/".proxyPass = "http://127.0.0.1:4180";
+ };
+
+ # Work around "upstream sent too big header" because of large tokens.
+ services.nginx.appendHttpConfig = ''
+ proxy_buffers 8 16k;
+ proxy_buffer_size 16k;
+ '';
+
+ # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites
+ # nginx configs. It's mostly unhelpful, but we use it for brevity. In
+ # particular, it configures Traefik-like ForwardAuth authentication with
+ # auth_request. Note if this resource is missing for whatever reason, the
+ # module magic will fail open (auth_request unset).
+ services.oauth2_proxy = {
+ enable = true;
+ cookie.domain = "weebnix.mou.fo";
+ setXauthrequest = true; # include claims
+ email.domains = [ "*" ]; # allow any authenticated user
+ # https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#keycloak-oidc-auth-provider
+ provider = "keycloak-oidc";
+ clientID = "weebnix.mou.fo";
+ # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
+ keyFile = "/var/lib/secrets/oauth2-proxy.env";
+ redirectURL = "https://kc.weebnix.mou.fo/oauth2/callback";
+ extraConfig = {
+ "oidc-issuer-url" = "https://kc.weebnix.mou.fo/realms/staging";
+ "whitelist-domain" = ".weebnix.mou.fo";
+ };
+ };
+}