diff options
| author | Joe Mou <dev@mou.fo> | 2026-07-02 00:20:01 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2026-08-11 07:17:05 -0400 |
| commit | 56fb1fc9807ad5aeba428a19762796688c80c8b5 (patch) | |
| tree | eab595b1888c591892a63f8a44ab97e2f9b051cd /hostnix | |
| parent | 3d06200aff7594e597a9c450bec52bf7cf6ede56 (diff) | |
Upgrade to NixOS 26.05
Diffstat (limited to 'hostnix')
| -rw-r--r-- | hostnix/elmo/flake.lock | 8 | ||||
| -rw-r--r-- | hostnix/elmo/flake.nix | 2 | ||||
| -rw-r--r-- | hostnix/elmo/oidc.nix | 3 |
3 files changed, 8 insertions, 5 deletions
diff --git a/hostnix/elmo/flake.lock b/hostnix/elmo/flake.lock index 6d86e86..fcfffe6 100644 --- a/hostnix/elmo/flake.lock +++ b/hostnix/elmo/flake.lock @@ -2,16 +2,16 @@ "nodes": { "nixpkgs": { "locked": { - "lastModified": 1776067740, - "narHash": "sha256-B35lpsqnSZwn1Lmz06BpwF7atPgFmUgw1l8KAV3zpVQ=", + "lastModified": 1782847225, + "narHash": "sha256-JC9PjqKYG9ve5U8aDOLQipp3+KLANBHUvGdLZlxzdKI=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "7e495b747b51f95ae15e74377c5ce1fe69c1765f", + "rev": "95ca1e203c0750115fd4a6f17d5a245dfe6b1edd", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-25.11", + "ref": "nixos-26.05", "repo": "nixpkgs", "type": "github" } diff --git a/hostnix/elmo/flake.nix b/hostnix/elmo/flake.nix index 3928b11..0a3ccc1 100644 --- a/hostnix/elmo/flake.nix +++ b/hostnix/elmo/flake.nix @@ -1,6 +1,6 @@ { inputs = { - nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11"; + nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; }; outputs = { self, nixpkgs }: { diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 40a0528..ebdd19a 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -11,6 +11,7 @@ # - PKCE services.pocket-id = { enable = true; + credentials.ENCRYPTION_KEY = "/var/secrets/pocket-id.key"; settings = { APP_URL = "https://pi.mou.fo"; TRUST_PROXY = true; @@ -46,6 +47,7 @@ nginx.domain = "op.mou.fo"; setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email reverseProxy = true; + trustedProxyIP = [ "127.0.0.1" ]; provider = "oidc"; clientID = "39edd929-8983-4cb6-b1cd-dc08e2e3358f"; oidcIssuerUrl = "https://pi.mou.fo"; @@ -56,6 +58,7 @@ extraConfig = { code-challenge-method = "S256"; whitelist-domain = ".mou.fo"; # allowed redirects after authentication + insecure-oidc-allow-unverified-email = true; }; }; |
