| Age | Commit message (Collapse) | Author |
|
If we wanted an LDAP server, glauth seems like a pretty good pick. It's
lightweight and can be configured entirely by a stateless text config
(it also supports a sqlite backend; it doesn't appear they can be used
together though).
But do we really benefit from an LDAP server? It could help set up
services that have LDAP authentication but not OIDC (most services that
use oauth2-proxy). Perhaps we'll revisit this.
glauth docs are spotty, but these are relevant for the config file:
- https://glauth.github.io/docs/file.html
- https://github.com/glauth/glauth/blob/master/v2/sample-simple.cfg
Nix has envsubst and replace-secret to include secrets in the config.
Information on setting up MFA:
https://www.couchbase.com/blog/multi-factor-authentication-mfa-2fa/
If we bind to an address besides localhost we should also set up LDAPS.
|
|
Dex really doesn't want to be the authoritative identity provider.
Static users are not very configurable. The sub claim is a base64
internal representation that we can't use in backends directly. We could
jury rig email, but never got that working.
Basic authentication works, but Home Assistant fails to login the user.
|
|
Disable home directory creation, which clobbers directory permissions.
Interestingly, after the ACLs are added the classic directory
permissions appear as 770; but happily it works fine.
Tip off was from https://discourse.nixos.org/t/home-facl-is-always-reset-in-21-05/13408
Also tried setting the ACL mask which wasn't the issue.
|
|
|
|
Heavyweight for what I need and too opinionated about organization. OPDS
layout is overcomplicated. Also tried Kavita but didn't like it (don't
remember why).
Still needs SSO. May try a simple OPDS-only server or build.
|
|
ModuleNotFoundError: No module named 'aiohomekit'
|
|
We still want SSO. It seems most promising to register Miniflux as an
OIDC client, but this is pending switching to a different identity
provider.
Alternatively we could use oauth2-proxy and configure AUTH_PROXY_HEADER.
We would want to bypass for API endpoints:
- /accounts/ClientLogin
- /reader/api/
|
|
|
|
We don't want to use Nix for deployment because it's slow. Code must be
manually deployed to /opt/garage.
|
|
Probably won't keep this, but playing with OCI containers and XSLT were
interesting.
Converting Feedly OPML to feeds.txt:
$ nomad @xmlstarlet select -T -t -m '//outline[@type="rss"]' -v ./@xmlUrl -o $'\t' -v ./@title -o $'\t#' -v ../@text -o $'\n' Downloads/feedly-093988c0-b9a0-4bb7-97dc-6946128b509e-2025-03-30-d63a70cb-archive/subscriptions.opml | awk -F'\t' -v OFS=' ' '{gsub(/ /, "_", $2); gsub(/ /, "-", $3); $1=$1; print}'
|
|
Have not allocated the mf.mou.fo subdomain yet while testing the app.
BASE_URL seems nonessential, but at least fixes the API endpoint given.
To create the initial admin user:
$ sudo -u miniflux env DATABASE_URL='user=miniflux host=/run/postgresql dbname=miniflux' miniflux -create-admin
The UI is quite clunky. In particular it is very easy to get lost
navigating between article list and detail views. It would also be nice
to force opening articles on the external site (for Phoronix). Fetching
original content (instead of using the RSS content) is nice though.
To integrate with oauth2-proxy, probably need to set AUTH_PROXY_HEADER.
|
|
Still need to remove Möbius and migrate iPhone to Synctrain also.
This should also properly set /srv/syncthing group permissions.
|
|
Cooler midday color temperature and throttle reinitialization.
|
|
Add ACLs for nginx that only allow read access. This is more limited
than allowing all users read access to /srv/syncthing, or adding nginx
as a writable user to the syncthing group.
|
|
Untested but ported from old HA config in
commit 25f26a29a6255c5fe3ccf0ffa11f630bd63c60df
|
|
|
|
|
|
Deduplicate btrfs files.
|
|
|
|
|
|
|
|
Despite moving the original log files, reading historic logs does not
appear to work.
|
|
|
|
Fixes https://github.com/redlib-org/redlib/issues/229
Overrides Rust package per https://blog.mplanchard.com/posts/installing-a-specific-version-of-a-package-with-nix.html
It appears packageOverrides are actually deprecated by overlays. See https://nixos.wiki/wiki/Overlays
|
|
Quick fix for .dotfiles scripts
|
|
Simpler to enable compression on an entire filesystem; we use it for
magnetic storage.
|
|
Jellyfin uses its own authentication; it's probably not worthwhile to
try to consolidate with SSO (and may break Jellyfin clients). We don't
bother to allow UDP for DLNA nor Jellyfin auto detection.
|
|
Kanidm development is kind of slow and conservative. Their frontend is
lacking.
The hope was Zitadel would solve some issues logging in to the Home
Assistant app behind oauth2-proxy, but it doesn't really help. In
particular, KeePassium is unable to password complete (login page
reloads to username entry?).
In any case, we probably prefer Zitadel so let's at least record it for
now. Pocket ID is an interesting minimal alternative, but the Home
Assistant app doesn't support passkeys.
$ sudo rm -r /var/lib/kanidm/
|
|
|
|
Fixes /api to skip oauth2-proxy
Not thoroughly tested; there are probably some issues.
|
|
Keycloak has always been heavyweight and cumbersome. Kanidm is meant to
be an all-in-one Rust identity provider instead.
$ sudo kanidmd recover-account idm_admin
$ kanidm login --name idm_admin
$ kanidm group account-policy credential-type-minimum idm_all_persons any
$ kanidm person create joe Joe
$ kanidm person credential update joe
$ kanidm system oauth2 create oauth2-proxy 'OAuth2 Proxy' https://op.mou.fo
$ kanidm system oauth2 update-scope-map oauth2-proxy idm_all_persons openid profile email
$ kanidm system oauth2 show-basic-secret oauth2-proxy
Passkeys don't work with KeePassXC on Firefox. They might work with
Chrome or BitWarden. We disable TOTP for password authentication.
Kanidm itself has considered and rejected forward auth support per
https://github.com/kanidm/kanidm/issues/2774
With this arrangement session cookies are about 2k. While large these
should fit within the default nginx buffers.
Dex can be used as a simple identity provider, although it is more
designed to facilitate app authentication. It can be configured to have
a workable configuration with no persistent state and only staticClients
and staticPasswords for resource servers and users.
Vouch Proxy is comparable with oauth2-proxy. Both assume the user has an
e-mail which we don't use. However oauth2-proxy seems to have better
workarounds and is somewhat more actively maintained. Vouch Proxy also
lacks a NixOS module.
https://discourse.nixos.org/t/configuring-vouch-proxy-or-oauth2-proxy-nginx-nix/19337/2
https://github.com/vouch/vouch-proxy/issues/309
|
|
DISABLE_REGISTRATION needs to be set after the initial administrator
account is manually registered.
Considered the Forgejo community fork, but it doesn't seem to have
attracted very much of the developer community. Despite concerns about
copyright claims, Gitea does not have a CLA; it is MIT licensed. Still
considering even lighter weight options that may be easier to
programmatically control (just an HTTP server that speaks the smart
protocol?).
For managing groups of repositories, can use labels or organizations.
Neither seem particularly convenient.
Gitea defaults to public repositories.
|
|
|
|
Based on https://github.com/nathan-gs/nix-conf/blob/main/lib/ha.nix
(which goes further in using the module system; see
https://nathan.gs/2023/12/09/adding-helper-functions-to-nixos/ )
|
|
|
|
|
|
|
|
|
|
|
|
|
|
- Populate OAuth tokens using justajoedoe.
- Use binary cache build of Nitter.
|
|
|
|
|
|
To resolve database collation version mismatches ("The database was
created using collation version 2.38, but the operating system provides
version 2.39."):
$ sudo -u postgres psql
> \c hass
> REINDEX DATABASE hass;
> ALTER DATABASE hass REFRESH COLLATION VERSION;
[ Repeat for all databases (except special database template0) ]
|
|
|
|
|
|
|
|
|
|
Also fixes missing component errors.
|
|
mailutils (but not sendmail) addresses from the unqualified hostname
|