summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/oidc.nix')
-rw-r--r--hostnix/elmo/oidc.nix54
1 files changed, 54 insertions, 0 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
new file mode 100644
index 0000000..b2c34e5
--- /dev/null
+++ b/hostnix/elmo/oidc.nix
@@ -0,0 +1,54 @@
+{ ... }:
+
+{
+ services.keycloak = {
+ enable = true;
+ database.passwordFile = "/var/lib/secrets/keycloak.dbpass";
+ settings = {
+ hostname = "kc.elmo.mou.fo";
+ http-host = "127.0.0.1";
+ http-port = 7567;
+ proxy = "edge";
+ };
+ };
+
+ services.nginx.virtualHosts."kc.elmo.mou.fo" = {
+ enableACME = true;
+ forceSSL = true;
+ locations."/".proxyPass = "http://127.0.0.1:7567";
+ # We can handle oauth2-proxy callbacks on any subdomain, but the Keycloak
+ # subdomain is the least arbitrary.
+ locations."/oauth2/".proxyPass = "http://127.0.0.1:4180";
+ };
+
+ # Work around "upstream sent too big header" because of large tokens.
+ services.nginx.appendHttpConfig = ''
+ proxy_buffers 8 16k;
+ proxy_buffer_size 16k;
+ '';
+
+ # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites
+ # nginx configs. It's mostly unhelpful, but we use it for brevity. In
+ # particular, it configures Traefik-like ForwardAuth authentication with
+ # auth_request. Note if this resource is missing for whatever reason, the
+ # module magic will fail open (auth_request unset).
+ services.oauth2_proxy = {
+ enable = true;
+ cookie.domain = "elmo.mou.fo";
+ setXauthrequest = true; # include claims
+ email.domains = [ "*" ]; # allow any authenticated user
+ # https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc
+ provider = "keycloak-oidc";
+ clientID = "oauth2-proxy";
+ # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
+ keyFile = "/var/lib/secrets/oauth2-proxy.env";
+ redirectURL = "https://kc.elmo.mou.fo/oauth2/callback";
+ extraConfig = {
+ "oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod";
+ "whitelist-domain" = ".elmo.mou.fo";
+ # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
+ "insecure-oidc-allow-unverified-email" = true;
+ "oidc-email-claim" = "sub";
+ };
+ };
+}