summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/oidc.nix')
-rw-r--r--hostnix/elmo/oidc.nix75
1 files changed, 75 insertions, 0 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
new file mode 100644
index 0000000..ebdd19a
--- /dev/null
+++ b/hostnix/elmo/oidc.nix
@@ -0,0 +1,75 @@
+{ lib, pkgs, ... }:
+
+{
+ systemd.tmpfiles.rules = [
+ "d /run/pocket-id 750 pocket-id nginx"
+ ];
+
+ # - Create user joe
+ # - Create OIDC Client: oauth2-proxy
+ # - Callback URLs: https://op.mou.fo/oauth2/callback
+ # - PKCE
+ services.pocket-id = {
+ enable = true;
+ credentials.ENCRYPTION_KEY = "/var/secrets/pocket-id.key";
+ settings = {
+ APP_URL = "https://pi.mou.fo";
+ TRUST_PROXY = true;
+ UNIX_SOCKET = "/run/pocket-id/socket";
+ UNIX_SOCKET_MODE = "0777";
+
+ # https://pocket-id.org/docs/configuration/environment-variables#overriding-the-ui-configuration
+ UI_CONFIG_DISABLED = true;
+ EMAILS_VERIFIED = true; # needed by oauth2-proxy
+ SMTP_HOST = "localhost";
+ SMTP_PORT = 25;
+ SMTP_FROM = "noreply@pi.mou.fo";
+ EMAIL_LOGIN_NOTIFICATION_ENABLED = true;
+ EMAIL_API_KEY_EXPIRATION_ENABLED = true;
+ EMAIL_ONE_TIME_ACCESS_AS_UNAUTHENTICATED_ENABLED = true;
+ };
+ };
+
+ services.nginx.virtualHosts."pi.mou.fo" = {
+ enableACME = true;
+ forceSSL = true;
+ locations."/".proxyPass = "http://unix:/run/pocket-id/socket";
+ };
+
+ # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites
+ # nginx configs. It can be heavy handed, but we use it for brevity. In
+ # particular, it configures Traefik-like ForwardAuth authentication with
+ # auth_request. Note if this resource is missing for whatever reason, the
+ # module magic will fail open (auth_request unset).
+ services.oauth2-proxy = {
+ enable = true;
+ cookie.domain = "mou.fo";
+ nginx.domain = "op.mou.fo";
+ setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email
+ reverseProxy = true;
+ trustedProxyIP = [ "127.0.0.1" ];
+ provider = "oidc";
+ clientID = "39edd929-8983-4cb6-b1cd-dc08e2e3358f";
+ oidcIssuerUrl = "https://pi.mou.fo";
+ # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
+ keyFile = "/var/secrets/oauth2-proxy.env";
+ # Ignore e-mail address.
+ email.domains = [ "*" ];
+ extraConfig = {
+ code-challenge-method = "S256";
+ whitelist-domain = ".mou.fo"; # allowed redirects after authentication
+ insecure-oidc-allow-unverified-email = true;
+ };
+ };
+
+ systemd.services.oauth2-proxy.after = [ "pocket-id.service" ];
+
+ # It's somewhat overkill to assign oauth2-proxy its own domain. We can't use
+ # Kanidm's though, because it uses the /oauth2 path which the oauth2-proxy
+ # nginx module is hardcoded for (proxyPrefix is ignored); this module magic is
+ # also why we do not need to explicitly specify proxyPass.
+ services.nginx.virtualHosts."op.mou.fo" = {
+ enableACME = true;
+ forceSSL = true;
+ };
+}