diff options
Diffstat (limited to 'hostnix')
| -rw-r--r-- | hostnix/elmo/glauth/glauth.toml | 23 | ||||
| -rw-r--r-- | hostnix/elmo/home-assistant.nix | 17 | ||||
| -rw-r--r-- | hostnix/elmo/oidc.nix | 48 |
3 files changed, 5 insertions, 83 deletions
diff --git a/hostnix/elmo/glauth/glauth.toml b/hostnix/elmo/glauth/glauth.toml deleted file mode 100644 index 5efcf97..0000000 --- a/hostnix/elmo/glauth/glauth.toml +++ /dev/null @@ -1,23 +0,0 @@ -[ldap] - enabled = true - listen = "[::1]:3893" -[ldaps] - enabled = false -[backend] - datastore = "config" - baseDN = "dc=elmo,dc=mou,dc=fo" - anonymousdse = false -[[users]] - name = "hackers" - uidnumber = 5001 - primarygroup = 5501 - passsha256 = "6478579e37aff45f013e14eeb30b3cc56c72ccdc310123bcdf53e0333e3f416a" # dogood - sshkeys = [ "ssh-dss AAAAB3..." ] -[[users]] - name = "uberhackers" - uidnumber = 5006 - primarygroup = 5501 - passbcrypt = "243261243130244B62463462656F7265504F762E794F324957746D656541326B4B46596275674A79336A476845764B616D65446169784E41384F4432" # dogood -[[groups]] - name = "superheros" - gidnumber = 5501 diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index 0b23db0..7c66951 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -63,14 +63,7 @@ use_x_forwarded_for = true; }; recorder.db_url = "postgresql://@/hass"; - # FIXME doesn't authenticate - # auth_header.username_header = "X-Email"; - auth_header.debug = true; - logger = { - default = "info"; - logs."custom_components.auth_header" = "debug"; - }; - + auth_header = { }; #binary_sensor: # - platform: template @@ -658,14 +651,6 @@ auth_request off; ''; }; - # FIXME testing shim - locations."/test" = { - proxyPass = "http://127.0.0.1:8000"; - extraConfig = '' - proxy_set_header X-User $user; - proxy_set_header X-Email $email; - ''; - }; # Disable service worker caching that works improperly with reverse proxy. # https://github.com/home-assistant/frontend/issues/14836 # https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082 diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 4421eb9..d7c6f0e 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -1,48 +1,6 @@ { lib, pkgs, ... }: { - systemd.services.glauth = { - wantedBy = [ "multi-user.target" ]; - serviceConfig = { - DynamicUser = true; - }; - script = "${pkgs.glauth}/bin/glauth -c ${./glauth/glauth.toml}"; - }; - - services.dex = { - enable = true; - settings = { - issuer = "https://op.mou.fo/dex"; - storage = { - # TODO persistence? - type = "memory"; - }; - web = { - # TODO port - http = "0.0.0.0:5556"; - }; - enablePasswordDB = true; - staticPasswords = [ - { - email = "joe"; - username = "joe"; - hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii"; - # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18"; - userID = "joe"; - } - ]; - staticClients = [ - { - id = "288565372746006652@mou.fo"; - name = "oauth2-proxy"; - redirectURIs = [ "https://op.mou.fo/oauth2/callback" ]; - # TODO consolidate w/ oauth2-proxy.env? - secretFile = "/var/secrets/oauth2-proxy.secret"; - } - ]; - }; - }; - services.postgresql = { ensureDatabases = [ "zitadel" ]; ensureUsers = [{ @@ -77,6 +35,7 @@ extraSettingsPaths = [ "/run/credentials/zitadel.service/secrets.yaml" ]; }; + # TODO should be delayed after postgres systemd.services.zitadel = { # Shim into PATH to avoid start-from-init which requires Postgres admin # credentials. See https://github.com/zitadel/zitadel/issues/4304 @@ -113,7 +72,7 @@ reverseProxy = true; provider = "oidc"; clientID = "288565372746006652@mou.fo"; - oidcIssuerUrl = "https://op.mou.fo/dex"; + oidcIssuerUrl = "https://zd.mou.fo"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/secrets/oauth2-proxy.env"; # Ignore e-mail address. @@ -121,6 +80,8 @@ extraConfig = { code-challenge-method = "S256"; whitelist-domain = ".mou.fo"; # allowed redirects after authentication + # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 + oidc-email-claim = "sub"; }; }; @@ -137,6 +98,5 @@ services.nginx.virtualHosts."op.mou.fo" = { enableACME = true; forceSSL = true; - locations."/dex".proxyPass = "http://127.0.0.1:5556"; }; } |
