summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/oidc.nix')
-rw-r--r--hostnix/elmo/oidc.nix48
1 files changed, 4 insertions, 44 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 4421eb9..d7c6f0e 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -1,48 +1,6 @@
{ lib, pkgs, ... }:
{
- systemd.services.glauth = {
- wantedBy = [ "multi-user.target" ];
- serviceConfig = {
- DynamicUser = true;
- };
- script = "${pkgs.glauth}/bin/glauth -c ${./glauth/glauth.toml}";
- };
-
- services.dex = {
- enable = true;
- settings = {
- issuer = "https://op.mou.fo/dex";
- storage = {
- # TODO persistence?
- type = "memory";
- };
- web = {
- # TODO port
- http = "0.0.0.0:5556";
- };
- enablePasswordDB = true;
- staticPasswords = [
- {
- email = "joe";
- username = "joe";
- hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii";
- # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18";
- userID = "joe";
- }
- ];
- staticClients = [
- {
- id = "288565372746006652@mou.fo";
- name = "oauth2-proxy";
- redirectURIs = [ "https://op.mou.fo/oauth2/callback" ];
- # TODO consolidate w/ oauth2-proxy.env?
- secretFile = "/var/secrets/oauth2-proxy.secret";
- }
- ];
- };
- };
-
services.postgresql = {
ensureDatabases = [ "zitadel" ];
ensureUsers = [{
@@ -77,6 +35,7 @@
extraSettingsPaths = [ "/run/credentials/zitadel.service/secrets.yaml" ];
};
+ # TODO should be delayed after postgres
systemd.services.zitadel = {
# Shim into PATH to avoid start-from-init which requires Postgres admin
# credentials. See https://github.com/zitadel/zitadel/issues/4304
@@ -113,7 +72,7 @@
reverseProxy = true;
provider = "oidc";
clientID = "288565372746006652@mou.fo";
- oidcIssuerUrl = "https://op.mou.fo/dex";
+ oidcIssuerUrl = "https://zd.mou.fo";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/secrets/oauth2-proxy.env";
# Ignore e-mail address.
@@ -121,6 +80,8 @@
extraConfig = {
code-challenge-method = "S256";
whitelist-domain = ".mou.fo"; # allowed redirects after authentication
+ # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
+ oidc-email-claim = "sub";
};
};
@@ -137,6 +98,5 @@
services.nginx.virtualHosts."op.mou.fo" = {
enableACME = true;
forceSSL = true;
- locations."/dex".proxyPass = "http://127.0.0.1:5556";
};
}