summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
AgeCommit message (Collapse)Author
2024-10-18Use Zitadel to replace KanidmJoe Mou
Kanidm development is kind of slow and conservative. Their frontend is lacking. The hope was Zitadel would solve some issues logging in to the Home Assistant app behind oauth2-proxy, but it doesn't really help. In particular, KeePassium is unable to password complete (login page reloads to username entry?). In any case, we probably prefer Zitadel so let's at least record it for now. Pocket ID is an interesting minimal alternative, but the Home Assistant app doesn't support passkeys. $ sudo rm -r /var/lib/kanidm/
2024-10-09Replace Keycloak with KanidmJoe Mou
Keycloak has always been heavyweight and cumbersome. Kanidm is meant to be an all-in-one Rust identity provider instead. $ sudo kanidmd recover-account idm_admin $ kanidm login --name idm_admin $ kanidm group account-policy credential-type-minimum idm_all_persons any $ kanidm person create joe Joe $ kanidm person credential update joe $ kanidm system oauth2 create oauth2-proxy 'OAuth2 Proxy' https://op.mou.fo $ kanidm system oauth2 update-scope-map oauth2-proxy idm_all_persons openid profile email $ kanidm system oauth2 show-basic-secret oauth2-proxy Passkeys don't work with KeePassXC on Firefox. They might work with Chrome or BitWarden. We disable TOTP for password authentication. Kanidm itself has considered and rejected forward auth support per https://github.com/kanidm/kanidm/issues/2774 With this arrangement session cookies are about 2k. While large these should fit within the default nginx buffers. Dex can be used as a simple identity provider, although it is more designed to facilitate app authentication. It can be configured to have a workable configuration with no persistent state and only staticClients and staticPasswords for resource servers and users. Vouch Proxy is comparable with oauth2-proxy. Both assume the user has an e-mail which we don't use. However oauth2-proxy seems to have better workarounds and is somewhat more actively maintained. Vouch Proxy also lacks a NixOS module. https://discourse.nixos.org/t/configuring-vouch-proxy-or-oauth2-proxy-nginx-nix/19337/2 https://github.com/vouch/vouch-proxy/issues/309
2024-10-09Upgrade to NixOS 24.05Joe Mou
To resolve database collation version mismatches ("The database was created using collation version 2.38, but the operating system provides version 2.39."): $ sudo -u postgres psql > \c hass > REINDEX DATABASE hass; > ALTER DATABASE hass REFRESH COLLATION VERSION; [ Repeat for all databases (except special database template0) ]
2024-04-27elmo: Hoist subdomains and issue production certificatesJoe Mou
2024-04-26elmo: Move secrets to /var/secretsJoe Mou
Clarifies that they are not managed by a distribution package.
2024-02-15Kludgy fix for oauth2_proxy on bootJoe Mou
2024-02-15Port configs from weebnixJoe Mou