summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/oidc.nix')
-rw-r--r--hostnix/elmo/oidc.nix7
1 files changed, 4 insertions, 3 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 8447aa0..0ed170e 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -27,14 +27,15 @@
proxy_buffer_size 16k;
'';
- # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites
+ # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites
# nginx configs. It's mostly unhelpful, but we use it for brevity. In
# particular, it configures Traefik-like ForwardAuth authentication with
# auth_request. Note if this resource is missing for whatever reason, the
# module magic will fail open (auth_request unset).
- services.oauth2_proxy = {
+ services.oauth2-proxy = {
enable = true;
cookie.domain = "mou.fo";
+ nginx.domain = "kc.mou.fo";
setXauthrequest = true; # include claims
email.domains = [ "*" ]; # allow any authenticated user
# https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc
@@ -55,5 +56,5 @@
# Kludge to bring up after KeyCloak (otherwise OIDC discovery fails). A simple
# ordering dependency isn't enough because keycloak.service is active before
# KeyCloak responds to requests.
- systemd.services.oauth2_proxy.serviceConfig.RestartSec = 5;
+ systemd.services.oauth2-proxy.serviceConfig.RestartSec = 5;
}