summaryrefslogtreecommitdiff
path: root/hostnix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-12-31 00:10:33 -0800
committerJoe Mou <dev@mou.fo>2025-12-31 01:05:59 -0800
commite125179918501d806e87dc170ab85d89db1f7795 (patch)
tree391917d385b65c3c96b13a65d342a68d74dc17ff /hostnix
parent013d42ffafb9dcd05b1bd8511a720d173fbd5c2f (diff)
Configure OIDC for Home Assistant
Replaces unmaintained header authentication behind oauth2-proxy. Add OIDC client for Home Assistant: - Callback URLs: https://ha.mou.fo/auth/oidc/callback - Public Client To link OIDC credentials with the existing joe user, temporarily set: auth_oidc.features.automatic_user_linking = true; See https://github.com/christiaangoossens/hass-oidc-auth/blob/main/docs/configuration.md#migrating-from-ha-usernamepassword-users-to-oidc-users Must login through either: - https://ha.mou.fo/auth/oidc/welcome - https://ha.mou.fo/auth/oidc/redirect Injecting directly into the landing login page is pending https://github.com/christiaangoossens/hass-oidc-auth/issues/19
Diffstat (limited to 'hostnix')
-rw-r--r--hostnix/elmo/home-assistant.nix23
-rw-r--r--hostnix/elmo/home-assistant/auth_header.nix29
2 files changed, 5 insertions, 47 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index a3cc2f1..3c62fd4 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -22,8 +22,7 @@
];
customComponents = with pkgs.home-assistant-custom-components; [
adaptive_lighting
- # TODO replace with auth_oidc https://github.com/christiaangoossens/hass-oidc-auth
- (pkgs.callPackage ./home-assistant/auth_header.nix {})
+ auth_oidc
tuya_local
];
@@ -64,7 +63,10 @@
use_x_forwarded_for = true;
};
recorder.db_url = "postgresql://@/hass";
- auth_header = { };
+ auth_oidc = {
+ client_id = "9332ad56-1917-4f12-a0ef-f6ff69994cf4";
+ discovery_url = "https://pi.mou.fo/.well-known/openid-configuration";
+ };
#binary_sensor:
# - platform: template
@@ -637,19 +639,6 @@
# This is frequently used in examples but without clear explanation. It
# might help with WebSockets.
proxy_buffering off;
- # oauth2-proxy NixOS module sets some non-standard headers, but we need
- # the preferred_username claim.
- auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username;
- proxy_set_header X-Forwarded-Preferred-Username $preferred_username;
- '';
- };
- # Duplicate relevant parts of root route to skip oauth2-proxy module magic.
- locations."/api/" = {
- proxyPass = "http://[::1]:8123";
- proxyWebsockets = true;
- extraConfig = ''
- proxy_buffering off;
- auth_request off;
'';
};
# Disable service worker caching that works improperly with reverse proxy.
@@ -659,6 +648,4 @@
return = ''410 "Service worker disabled: https://github.com/home-assistant/frontend/issues/14836"'';
};
};
-
- services.oauth2-proxy.nginx.virtualHosts = { "ha.mou.fo" = {}; };
}
diff --git a/hostnix/elmo/home-assistant/auth_header.nix b/hostnix/elmo/home-assistant/auth_header.nix
deleted file mode 100644
index 480598e..0000000
--- a/hostnix/elmo/home-assistant/auth_header.nix
+++ /dev/null
@@ -1,29 +0,0 @@
-{
- lib,
- buildHomeAssistantComponent,
- fetchFromGitHub,
-}:
-
-buildHomeAssistantComponent rec {
- owner = "BeryJu";
- domain = "auth_header";
- version = "1.12";
-
- src = fetchFromGitHub {
- inherit owner;
- repo = "hass-auth-header";
- tag = "v${version}";
- hash = "sha256-BPG/G6IM95g9ip2OsPmcAebi2ZvKHUpFzV4oquOFLPM=";
- };
-
- # isort: command not found
- dontBuild = true;
-
- meta = with lib; {
- changelog = "https://github.com/BeryJu/hass-auth-header/releases/tag/v${version}";
- description = "Home Assistant custom component which allows you to delegate authentication to a reverse proxy";
- homepage = "https://github.com/BeryJu/hass-auth-header";
- maintainers = with maintainers; [ mjm ];
- license = licenses.gpl3;
- };
-}