summaryrefslogtreecommitdiff
path: root/hostnix/weebnix/home-assistant.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/weebnix/home-assistant.nix')
-rw-r--r--hostnix/weebnix/home-assistant.nix28
1 files changed, 9 insertions, 19 deletions
diff --git a/hostnix/weebnix/home-assistant.nix b/hostnix/weebnix/home-assistant.nix
index 500ff10..ee443ee 100644
--- a/hostnix/weebnix/home-assistant.nix
+++ b/hostnix/weebnix/home-assistant.nix
@@ -84,25 +84,15 @@ in {
proxy_set_header X-Forwarded-Preferred-Username $preferred_username;
'';
};
- };
-
- # TODO how to configure for multiple domains?
- services.oauth2_proxy = {
- enable = true;
- nginx.virtualHosts = [ "ha.weebnix.mou.fo" ];
- setXauthrequest = true;
- # https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#keycloak-oidc-auth-provider
- provider = "keycloak-oidc";
- clientID = "ha.weebnix.mou.fo";
- # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
- keyFile = "/var/lib/secrets/oauth2-proxy.env";
- redirectURL = "https://ha.weebnix.mou.fo/oauth2/callback";
- email.domains = [ "*" ];
- extraConfig = {
- "oidc-issuer-url" = "https://kc.weebnix.mou.fo/realms/staging";
- "code-challenge-method" = "S256";
- # TODO this is specific to HA. move to nginx config?
- "skip-auth-route" = "^/api/";
+ # Duplicate relevant parts of root route to skip oauth2-proxy module magic.
+ locations."/api/" = {
+ proxyPass = "http://[::1]:8123";
+ proxyWebsockets = true;
+ extraConfig = ''
+ proxy_buffering off;
+ '';
};
};
+
+ services.oauth2_proxy.nginx.virtualHosts = [ "ha.weebnix.mou.fo" ];
}