diff options
| author | Joe Mou <dev@mou.fo> | 2023-09-28 17:49:46 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2023-09-29 17:06:04 -0400 |
| commit | f266e0f5371c2157ea8833c5760c1ce613ea7e16 (patch) | |
| tree | 04f6099d33a88ef213e93653094f207b246fa502 /hostnix | |
| parent | 8391bd18f4f7cd80095c5f27abdf034db0ff5f3f (diff) | |
Add Keycloak
Diffstat (limited to 'hostnix')
| -rw-r--r-- | hostnix/weebnix/configuration.nix | 51 |
1 files changed, 51 insertions, 0 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix index 72b0523..f38148a 100644 --- a/hostnix/weebnix/configuration.nix +++ b/hostnix/weebnix/configuration.nix @@ -13,6 +13,11 @@ security.sudo.wheelNeedsPassword = false; + security.acme.acceptTerms = true; + security.acme.defaults.email = "hostmaster@mou.fo"; + # TODO switch to production certs + security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory"; + users.users.joe = { isNormalUser = true; extraGroups = [ "wheel" ]; @@ -30,7 +35,53 @@ services.openssh.enable = true; + services.keycloak = { + enable = true; + database.passwordFile = "/var/lib/secrets/keycloak.dbpass"; + settings = { + hostname = "kc.weebnix.mou.fo"; + http-host = "127.0.0.1"; + http-port = 7567; + proxy = "edge"; + }; + }; + + services.nginx = { + enable = true; + recommendedGzipSettings = true; + recommendedOptimisation = true; + recommendedProxySettings = true; + recommendedTlsSettings = true; + virtualHosts."kc.weebnix.mou.fo" = { + enableACME = true; + forceSSL = true; + locations."/".proxyPass = "http://127.0.0.1:7567"; + }; + # Slightly crazy setup to SNI reverse proxy HTTPS to multiple upstreams. + # We displace ourselves onto port 8443, and send requests that are not + # intended for us to weeber. This is done because Apache running on weeber + # cannot SNI reverse proxy, so we put weebnix in front of weeber on IPv4. + # TODO get rid of all this when replacing weeber or maybe consider HAProxy + defaultSSLListenPort = 8443; + streamConfig = '' + map $ssl_preread_server_name $selected_upstream { + hostnames; + weebnix.mou.fo self; + *.weebnix.mou.fo self; + default weeber; + } + upstream self { server 127.0.0.1:8443; } + upstream weeber { server 192.168.0.168:443; } + server { + listen 0.0.0.0:443; + listen [::0]:443; + proxy_pass $selected_upstream; + ssl_preread on; + } + ''; + }; + networking.firewall.allowedTCPPorts = [ 80 443 ]; # This value determines the NixOS release from which the default # settings for stateful data, like file locations and database versions |
