diff options
Diffstat (limited to 'hostnix/elmo/oidc.nix')
| -rw-r--r-- | hostnix/elmo/oidc.nix | 7 |
1 files changed, 4 insertions, 3 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 8447aa0..0ed170e 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -27,14 +27,15 @@ proxy_buffer_size 16k; ''; - # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites + # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites # nginx configs. It's mostly unhelpful, but we use it for brevity. In # particular, it configures Traefik-like ForwardAuth authentication with # auth_request. Note if this resource is missing for whatever reason, the # module magic will fail open (auth_request unset). - services.oauth2_proxy = { + services.oauth2-proxy = { enable = true; cookie.domain = "mou.fo"; + nginx.domain = "kc.mou.fo"; setXauthrequest = true; # include claims email.domains = [ "*" ]; # allow any authenticated user # https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc @@ -55,5 +56,5 @@ # Kludge to bring up after KeyCloak (otherwise OIDC discovery fails). A simple # ordering dependency isn't enough because keycloak.service is active before # KeyCloak responds to requests. - systemd.services.oauth2_proxy.serviceConfig.RestartSec = 5; + systemd.services.oauth2-proxy.serviceConfig.RestartSec = 5; } |
