summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
AgeCommit message (Collapse)Author
2025-12-31Replace Zitadel with Pocket IDJoe Mou
Much simpler to configure and use.
2025-12-24Upgrade to NixOS 25.11Joe Mou
The auth_header Home Assistant custom component has been removed. For now we use the last package from: https://github.com/NixOS/nixpkgs/blob/7f88a8b9efaf0e08e63e3806b2b3f42fd83fde91/pkgs/servers/home-assistant/custom-components/auth-header/package.nix
2025-06-16Revert auth to ZitadelJoe Mou
Still don't love it but let's get things into a working state. Promising next steps: - Authlib (Python) - oidc-provider (Javascript) - Vouch Proxy, Ory Oauthkeeper, or IdP built-in forward auth Look at [[Authentication]]
2025-06-16Try setting up glauth LDAP, for some reasonJoe Mou
If we wanted an LDAP server, glauth seems like a pretty good pick. It's lightweight and can be configured entirely by a stateless text config (it also supports a sqlite backend; it doesn't appear they can be used together though). But do we really benefit from an LDAP server? It could help set up services that have LDAP authentication but not OIDC (most services that use oauth2-proxy). Perhaps we'll revisit this. glauth docs are spotty, but these are relevant for the config file: - https://glauth.github.io/docs/file.html - https://github.com/glauth/glauth/blob/master/v2/sample-simple.cfg Nix has envsubst and replace-secret to include secrets in the config. Information on setting up MFA: https://www.couchbase.com/blog/multi-factor-authentication-mfa-2fa/ If we bind to an address besides localhost we should also set up LDAPS.
2025-06-16In progress attempt to use Dex for OIDCJoe Mou
Dex really doesn't want to be the authoritative identity provider. Static users are not very configurable. The sub claim is a base64 internal representation that we can't use in backends directly. We could jury rig email, but never got that working. Basic authentication works, but Home Assistant fails to login the user.
2024-10-18Use Zitadel to replace KanidmJoe Mou
Kanidm development is kind of slow and conservative. Their frontend is lacking. The hope was Zitadel would solve some issues logging in to the Home Assistant app behind oauth2-proxy, but it doesn't really help. In particular, KeePassium is unable to password complete (login page reloads to username entry?). In any case, we probably prefer Zitadel so let's at least record it for now. Pocket ID is an interesting minimal alternative, but the Home Assistant app doesn't support passkeys. $ sudo rm -r /var/lib/kanidm/
2024-10-09Replace Keycloak with KanidmJoe Mou
Keycloak has always been heavyweight and cumbersome. Kanidm is meant to be an all-in-one Rust identity provider instead. $ sudo kanidmd recover-account idm_admin $ kanidm login --name idm_admin $ kanidm group account-policy credential-type-minimum idm_all_persons any $ kanidm person create joe Joe $ kanidm person credential update joe $ kanidm system oauth2 create oauth2-proxy 'OAuth2 Proxy' https://op.mou.fo $ kanidm system oauth2 update-scope-map oauth2-proxy idm_all_persons openid profile email $ kanidm system oauth2 show-basic-secret oauth2-proxy Passkeys don't work with KeePassXC on Firefox. They might work with Chrome or BitWarden. We disable TOTP for password authentication. Kanidm itself has considered and rejected forward auth support per https://github.com/kanidm/kanidm/issues/2774 With this arrangement session cookies are about 2k. While large these should fit within the default nginx buffers. Dex can be used as a simple identity provider, although it is more designed to facilitate app authentication. It can be configured to have a workable configuration with no persistent state and only staticClients and staticPasswords for resource servers and users. Vouch Proxy is comparable with oauth2-proxy. Both assume the user has an e-mail which we don't use. However oauth2-proxy seems to have better workarounds and is somewhat more actively maintained. Vouch Proxy also lacks a NixOS module. https://discourse.nixos.org/t/configuring-vouch-proxy-or-oauth2-proxy-nginx-nix/19337/2 https://github.com/vouch/vouch-proxy/issues/309
2024-10-09Upgrade to NixOS 24.05Joe Mou
To resolve database collation version mismatches ("The database was created using collation version 2.38, but the operating system provides version 2.39."): $ sudo -u postgres psql > \c hass > REINDEX DATABASE hass; > ALTER DATABASE hass REFRESH COLLATION VERSION; [ Repeat for all databases (except special database template0) ]
2024-04-27elmo: Hoist subdomains and issue production certificatesJoe Mou
2024-04-26elmo: Move secrets to /var/secretsJoe Mou
Clarifies that they are not managed by a distribution package.
2024-02-15Kludgy fix for oauth2_proxy on bootJoe Mou
2024-02-15Port configs from weebnixJoe Mou