diff options
Diffstat (limited to 'hostnix/elmo/oidc.nix')
| -rw-r--r-- | hostnix/elmo/oidc.nix | 75 |
1 files changed, 75 insertions, 0 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix new file mode 100644 index 0000000..ebdd19a --- /dev/null +++ b/hostnix/elmo/oidc.nix @@ -0,0 +1,75 @@ +{ lib, pkgs, ... }: + +{ + systemd.tmpfiles.rules = [ + "d /run/pocket-id 750 pocket-id nginx" + ]; + + # - Create user joe + # - Create OIDC Client: oauth2-proxy + # - Callback URLs: https://op.mou.fo/oauth2/callback + # - PKCE + services.pocket-id = { + enable = true; + credentials.ENCRYPTION_KEY = "/var/secrets/pocket-id.key"; + settings = { + APP_URL = "https://pi.mou.fo"; + TRUST_PROXY = true; + UNIX_SOCKET = "/run/pocket-id/socket"; + UNIX_SOCKET_MODE = "0777"; + + # https://pocket-id.org/docs/configuration/environment-variables#overriding-the-ui-configuration + UI_CONFIG_DISABLED = true; + EMAILS_VERIFIED = true; # needed by oauth2-proxy + SMTP_HOST = "localhost"; + SMTP_PORT = 25; + SMTP_FROM = "noreply@pi.mou.fo"; + EMAIL_LOGIN_NOTIFICATION_ENABLED = true; + EMAIL_API_KEY_EXPIRATION_ENABLED = true; + EMAIL_ONE_TIME_ACCESS_AS_UNAUTHENTICATED_ENABLED = true; + }; + }; + + services.nginx.virtualHosts."pi.mou.fo" = { + enableACME = true; + forceSSL = true; + locations."/".proxyPass = "http://unix:/run/pocket-id/socket"; + }; + + # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites + # nginx configs. It can be heavy handed, but we use it for brevity. In + # particular, it configures Traefik-like ForwardAuth authentication with + # auth_request. Note if this resource is missing for whatever reason, the + # module magic will fail open (auth_request unset). + services.oauth2-proxy = { + enable = true; + cookie.domain = "mou.fo"; + nginx.domain = "op.mou.fo"; + setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email + reverseProxy = true; + trustedProxyIP = [ "127.0.0.1" ]; + provider = "oidc"; + clientID = "39edd929-8983-4cb6-b1cd-dc08e2e3358f"; + oidcIssuerUrl = "https://pi.mou.fo"; + # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. + keyFile = "/var/secrets/oauth2-proxy.env"; + # Ignore e-mail address. + email.domains = [ "*" ]; + extraConfig = { + code-challenge-method = "S256"; + whitelist-domain = ".mou.fo"; # allowed redirects after authentication + insecure-oidc-allow-unverified-email = true; + }; + }; + + systemd.services.oauth2-proxy.after = [ "pocket-id.service" ]; + + # It's somewhat overkill to assign oauth2-proxy its own domain. We can't use + # Kanidm's though, because it uses the /oauth2 path which the oauth2-proxy + # nginx module is hardcoded for (proxyPrefix is ignored); this module magic is + # also why we do not need to explicitly specify proxyPass. + services.nginx.virtualHosts."op.mou.fo" = { + enableACME = true; + forceSSL = true; + }; +} |
