summaryrefslogtreecommitdiff
path: root/hostnix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix')
-rw-r--r--hostnix/elmo/home-assistant.nix17
-rw-r--r--hostnix/elmo/oidc.nix39
2 files changed, 52 insertions, 4 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index 7c66951..0b23db0 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -63,7 +63,14 @@
use_x_forwarded_for = true;
};
recorder.db_url = "postgresql://@/hass";
- auth_header = { };
+ # FIXME doesn't authenticate
+ # auth_header.username_header = "X-Email";
+ auth_header.debug = true;
+ logger = {
+ default = "info";
+ logs."custom_components.auth_header" = "debug";
+ };
+
#binary_sensor:
# - platform: template
@@ -651,6 +658,14 @@
auth_request off;
'';
};
+ # FIXME testing shim
+ locations."/test" = {
+ proxyPass = "http://127.0.0.1:8000";
+ extraConfig = ''
+ proxy_set_header X-User $user;
+ proxy_set_header X-Email $email;
+ '';
+ };
# Disable service worker caching that works improperly with reverse proxy.
# https://github.com/home-assistant/frontend/issues/14836
# https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 00d2fcf..88f8e9a 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -1,6 +1,40 @@
{ lib, pkgs, ... }:
{
+ services.dex = {
+ enable = true;
+ settings = {
+ issuer = "https://op.mou.fo/dex";
+ storage = {
+ # TODO persistence?
+ type = "memory";
+ };
+ web = {
+ # TODO port
+ http = "0.0.0.0:5556";
+ };
+ enablePasswordDB = true;
+ staticPasswords = [
+ {
+ email = "joe";
+ username = "joe";
+ hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii";
+ # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18";
+ userID = "joe";
+ }
+ ];
+ staticClients = [
+ {
+ id = "288565372746006652@mou.fo";
+ name = "oauth2-proxy";
+ redirectURIs = [ "https://op.mou.fo/oauth2/callback" ];
+ # TODO consolidate w/ oauth2-proxy.env?
+ secretFile = "/var/secrets/oauth2-proxy.secret";
+ }
+ ];
+ };
+ };
+
services.postgresql = {
ensureDatabases = [ "zitadel" ];
ensureUsers = [{
@@ -71,7 +105,7 @@
reverseProxy = true;
provider = "oidc";
clientID = "288565372746006652@mou.fo";
- oidcIssuerUrl = "https://zd.mou.fo";
+ oidcIssuerUrl = "https://op.mou.fo/dex";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/secrets/oauth2-proxy.env";
# Ignore e-mail address.
@@ -79,8 +113,6 @@
extraConfig = {
code-challenge-method = "S256";
whitelist-domain = ".mou.fo"; # allowed redirects after authentication
- # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
- oidc-email-claim = "sub";
};
};
@@ -97,5 +129,6 @@
services.nginx.virtualHosts."op.mou.fo" = {
enableACME = true;
forceSSL = true;
+ locations."/dex".proxyPass = "http://127.0.0.1:5556";
};
}