| Age | Commit message (Collapse) | Author |
|
|
|
Much simpler to configure and use.
|
|
The auth_header Home Assistant custom component has been removed. For
now we use the last package from:
https://github.com/NixOS/nixpkgs/blob/7f88a8b9efaf0e08e63e3806b2b3f42fd83fde91/pkgs/servers/home-assistant/custom-components/auth-header/package.nix
|
|
Still don't love it but let's get things into a working state.
Promising next steps:
- Authlib (Python)
- oidc-provider (Javascript)
- Vouch Proxy, Ory Oauthkeeper, or IdP built-in forward auth
Look at [[Authentication]]
|
|
If we wanted an LDAP server, glauth seems like a pretty good pick. It's
lightweight and can be configured entirely by a stateless text config
(it also supports a sqlite backend; it doesn't appear they can be used
together though).
But do we really benefit from an LDAP server? It could help set up
services that have LDAP authentication but not OIDC (most services that
use oauth2-proxy). Perhaps we'll revisit this.
glauth docs are spotty, but these are relevant for the config file:
- https://glauth.github.io/docs/file.html
- https://github.com/glauth/glauth/blob/master/v2/sample-simple.cfg
Nix has envsubst and replace-secret to include secrets in the config.
Information on setting up MFA:
https://www.couchbase.com/blog/multi-factor-authentication-mfa-2fa/
If we bind to an address besides localhost we should also set up LDAPS.
|
|
Dex really doesn't want to be the authoritative identity provider.
Static users are not very configurable. The sub claim is a base64
internal representation that we can't use in backends directly. We could
jury rig email, but never got that working.
Basic authentication works, but Home Assistant fails to login the user.
|
|
Kanidm development is kind of slow and conservative. Their frontend is
lacking.
The hope was Zitadel would solve some issues logging in to the Home
Assistant app behind oauth2-proxy, but it doesn't really help. In
particular, KeePassium is unable to password complete (login page
reloads to username entry?).
In any case, we probably prefer Zitadel so let's at least record it for
now. Pocket ID is an interesting minimal alternative, but the Home
Assistant app doesn't support passkeys.
$ sudo rm -r /var/lib/kanidm/
|
|
Keycloak has always been heavyweight and cumbersome. Kanidm is meant to
be an all-in-one Rust identity provider instead.
$ sudo kanidmd recover-account idm_admin
$ kanidm login --name idm_admin
$ kanidm group account-policy credential-type-minimum idm_all_persons any
$ kanidm person create joe Joe
$ kanidm person credential update joe
$ kanidm system oauth2 create oauth2-proxy 'OAuth2 Proxy' https://op.mou.fo
$ kanidm system oauth2 update-scope-map oauth2-proxy idm_all_persons openid profile email
$ kanidm system oauth2 show-basic-secret oauth2-proxy
Passkeys don't work with KeePassXC on Firefox. They might work with
Chrome or BitWarden. We disable TOTP for password authentication.
Kanidm itself has considered and rejected forward auth support per
https://github.com/kanidm/kanidm/issues/2774
With this arrangement session cookies are about 2k. While large these
should fit within the default nginx buffers.
Dex can be used as a simple identity provider, although it is more
designed to facilitate app authentication. It can be configured to have
a workable configuration with no persistent state and only staticClients
and staticPasswords for resource servers and users.
Vouch Proxy is comparable with oauth2-proxy. Both assume the user has an
e-mail which we don't use. However oauth2-proxy seems to have better
workarounds and is somewhat more actively maintained. Vouch Proxy also
lacks a NixOS module.
https://discourse.nixos.org/t/configuring-vouch-proxy-or-oauth2-proxy-nginx-nix/19337/2
https://github.com/vouch/vouch-proxy/issues/309
|
|
To resolve database collation version mismatches ("The database was
created using collation version 2.38, but the operating system provides
version 2.39."):
$ sudo -u postgres psql
> \c hass
> REINDEX DATABASE hass;
> ALTER DATABASE hass REFRESH COLLATION VERSION;
[ Repeat for all databases (except special database template0) ]
|
|
|
|
Clarifies that they are not managed by a distribution package.
|
|
|
|
|