summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--hostnix/elmo/configuration.nix2
-rw-r--r--hostnix/elmo/home-assistant.nix1
-rw-r--r--hostnix/elmo/oidc.nix85
3 files changed, 55 insertions, 33 deletions
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix
index f203447..056f2cf 100644
--- a/hostnix/elmo/configuration.nix
+++ b/hostnix/elmo/configuration.nix
@@ -65,6 +65,8 @@
localuser = null; # silence warning
};
+ services.postgresql.enable = true;
+
services.nginx = {
enable = true;
recommendedGzipSettings = true;
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index 9e39d8c..a62fcd5 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -2,7 +2,6 @@
{
services.postgresql = {
- enable = true;
ensureDatabases = [ "hass" ];
ensureUsers = [{
name = "hass";
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index b24b070..00d2fcf 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -1,38 +1,61 @@
-{ config, ... }:
+{ lib, pkgs, ... }:
{
- services.kanidm = {
- enableClient = true;
- enableServer = true;
- clientSettings = {
- uri = "https://ki.mou.fo";
- };
- serverSettings = {
- origin = "https://ki.mou.fo";
- domain = "ki.mou.fo";
- bindaddress = "[::1]:7368";
- trust_x_forward_for = true;
- # Kanidm requires TLS even behind a reverse proxy.
- tls_chain = "/run/credentials/kanidm.service/fullchain.pem";
- tls_key = "/run/credentials/kanidm.service/key.pem";
+ services.postgresql = {
+ ensureDatabases = [ "zitadel" ];
+ ensureUsers = [{
+ name = "zitadel";
+ ensureDBOwnership = true;
+ }];
+ };
+
+ # CVE-2024-41952 as of 24.05. Leaks existence of usernames.
+ nixpkgs.config.permittedInsecurePackages = [
+ "zitadel"
+ ];
+
+ services.zitadel = {
+ enable = true;
+ settings = {
+ # We seem to be unable to bind Zitadel to only the loopback interface.
+ Port = 9068;
+ ExternalPort = 443;
+ ExternalDomain = "zd.mou.fo";
+ Database.postgres = {
+ Host = "127.0.0.1";
+ Port = 5432;
+ Database = "zitadel";
+ User.Username = "zitadel";
+ User.SSL.Mode = "disable";
+ };
};
+ masterKeyFile = "/run/credentials/zitadel.service/master.key";
+ # Zitadel only connects to Postgres over the network, so we need to
+ # configure passwords here and manually for the zitadel Postgres user.
+ extraSettingsPaths = [ "/run/credentials/zitadel.service/secrets.yaml" ];
};
- systemd.services.kanidm = {
- # Kanidm runs as an unprivileged user that needs access to certificates.
- serviceConfig.LoadCredential = let
- certDir = config.security.acme.certs."ki.mou.fo".directory;
- in
- [
- "fullchain.pem:${certDir}/fullchain.pem"
- "key.pem:${certDir}/key.pem"
+ systemd.services.zitadel = {
+ # Shim into PATH to avoid start-from-init which requires Postgres admin
+ # credentials. See https://github.com/zitadel/zitadel/issues/4304
+ path = let
+ wrapper = pkgs.writeShellScriptBin "zitadel"
+ ''
+ shift
+ exec ${pkgs.zitadel}/bin/zitadel start-from-setup "$@"
+ '';
+ in lib.mkBefore [ wrapper ];
+ # Allow unprivileged zitadel user selective access to secrets.
+ serviceConfig.LoadCredential = [
+ "master.key:/var/secrets/zitadel.key"
+ "secrets.yaml:/var/secrets/zitadel.yaml"
];
};
- services.nginx.virtualHosts."ki.mou.fo" = {
+ services.nginx.virtualHosts."zd.mou.fo" = {
enableACME = true;
forceSSL = true;
- locations."/".proxyPass = "https://[::1]:7368";
+ locations."/".proxyPass = "http://127.0.0.1:9068";
};
# The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites
@@ -46,20 +69,18 @@
nginx.domain = "op.mou.fo";
setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email
reverseProxy = true;
- # Example nestled in https://kanidm.github.io/kanidm/stable/examples/kubernetes_ingress.html
provider = "oidc";
- clientID = "oauth2-proxy";
- oidcIssuerUrl = "https://ki.mou.fo/oauth2/openid/oauth2-proxy";
+ clientID = "288565372746006652@mou.fo";
+ oidcIssuerUrl = "https://zd.mou.fo";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/secrets/oauth2-proxy.env";
# Ignore e-mail address.
- scope = "openid profile";
email.domains = [ "*" ];
extraConfig = {
- "code-challenge-method" = "S256";
- "whitelist-domain" = ".mou.fo"; # allowed redirects after authentication
+ code-challenge-method = "S256";
+ whitelist-domain = ".mou.fo"; # allowed redirects after authentication
# https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
- "oidc-email-claim" = "sub";
+ oidc-email-claim = "sub";
};
};