diff options
Diffstat (limited to 'hostnix/weebnix')
| -rw-r--r-- | hostnix/weebnix/configuration.nix | 17 | ||||
| -rw-r--r-- | hostnix/weebnix/home-assistant.nix | 28 | ||||
| -rw-r--r-- | hostnix/weebnix/oidc.nix | 51 |
3 files changed, 61 insertions, 35 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix index 1669b8a..a879185 100644 --- a/hostnix/weebnix/configuration.nix +++ b/hostnix/weebnix/configuration.nix @@ -5,6 +5,7 @@ ./dyndns.nix ./hardware-configuration.nix ./home-assistant.nix + ./oidc.nix ./syncthing.nix ./system.nix ]; @@ -34,28 +35,12 @@ services.openssh.enable = true; - services.keycloak = { - enable = true; - database.passwordFile = "/var/lib/secrets/keycloak.dbpass"; - settings = { - hostname = "kc.weebnix.mou.fo"; - http-host = "127.0.0.1"; - http-port = 7567; - proxy = "edge"; - }; - }; - services.nginx = { enable = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedTlsSettings = true; - virtualHosts."kc.weebnix.mou.fo" = { - enableACME = true; - forceSSL = true; - locations."/".proxyPass = "http://127.0.0.1:7567"; - }; # Slightly crazy setup to SNI reverse proxy HTTPS to multiple upstreams. # We displace ourselves onto port 8443, and send requests that are not # intended for us to weeber. This is done because Apache running on weeber diff --git a/hostnix/weebnix/home-assistant.nix b/hostnix/weebnix/home-assistant.nix index 500ff10..ee443ee 100644 --- a/hostnix/weebnix/home-assistant.nix +++ b/hostnix/weebnix/home-assistant.nix @@ -84,25 +84,15 @@ in { proxy_set_header X-Forwarded-Preferred-Username $preferred_username; ''; }; - }; - - # TODO how to configure for multiple domains? - services.oauth2_proxy = { - enable = true; - nginx.virtualHosts = [ "ha.weebnix.mou.fo" ]; - setXauthrequest = true; - # https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#keycloak-oidc-auth-provider - provider = "keycloak-oidc"; - clientID = "ha.weebnix.mou.fo"; - # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. - keyFile = "/var/lib/secrets/oauth2-proxy.env"; - redirectURL = "https://ha.weebnix.mou.fo/oauth2/callback"; - email.domains = [ "*" ]; - extraConfig = { - "oidc-issuer-url" = "https://kc.weebnix.mou.fo/realms/staging"; - "code-challenge-method" = "S256"; - # TODO this is specific to HA. move to nginx config? - "skip-auth-route" = "^/api/"; + # Duplicate relevant parts of root route to skip oauth2-proxy module magic. + locations."/api/" = { + proxyPass = "http://[::1]:8123"; + proxyWebsockets = true; + extraConfig = '' + proxy_buffering off; + ''; }; }; + + services.oauth2_proxy.nginx.virtualHosts = [ "ha.weebnix.mou.fo" ]; } diff --git a/hostnix/weebnix/oidc.nix b/hostnix/weebnix/oidc.nix new file mode 100644 index 0000000..bf70882 --- /dev/null +++ b/hostnix/weebnix/oidc.nix @@ -0,0 +1,51 @@ +{ ... }: + +{ + services.keycloak = { + enable = true; + database.passwordFile = "/var/lib/secrets/keycloak.dbpass"; + settings = { + hostname = "kc.weebnix.mou.fo"; + http-host = "127.0.0.1"; + http-port = 7567; + proxy = "edge"; + }; + }; + + services.nginx.virtualHosts."kc.weebnix.mou.fo" = { + enableACME = true; + forceSSL = true; + locations."/".proxyPass = "http://127.0.0.1:7567"; + # We can handle oauth2-proxy callbacks on any subdomain, but the Keycloak + # subdomain is the least arbitrary. + locations."/oauth2/".proxyPass = "http://127.0.0.1:4180"; + }; + + # Work around "upstream sent too big header" because of large tokens. + services.nginx.appendHttpConfig = '' + proxy_buffers 8 16k; + proxy_buffer_size 16k; + ''; + + # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites + # nginx configs. It's mostly unhelpful, but we use it for brevity. In + # particular, it configures Traefik-like ForwardAuth authentication with + # auth_request. Note if this resource is missing for whatever reason, the + # module magic will fail open (auth_request unset). + services.oauth2_proxy = { + enable = true; + cookie.domain = "weebnix.mou.fo"; + setXauthrequest = true; # include claims + email.domains = [ "*" ]; # allow any authenticated user + # https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#keycloak-oidc-auth-provider + provider = "keycloak-oidc"; + clientID = "weebnix.mou.fo"; + # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. + keyFile = "/var/lib/secrets/oauth2-proxy.env"; + redirectURL = "https://kc.weebnix.mou.fo/oauth2/callback"; + extraConfig = { + "oidc-issuer-url" = "https://kc.weebnix.mou.fo/realms/staging"; + "whitelist-domain" = ".weebnix.mou.fo"; + }; + }; +} |
