From 70a6d533227ea2284bdcc1514b794f99d7eb5361 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Tue, 11 Jun 2024 16:34:08 -0400 Subject: Upgrade to NixOS 24.05 To resolve database collation version mismatches ("The database was created using collation version 2.38, but the operating system provides version 2.39."): $ sudo -u postgres psql > \c hass > REINDEX DATABASE hass; > ALTER DATABASE hass REFRESH COLLATION VERSION; [ Repeat for all databases (except special database template0) ] --- hostnix/elmo/oidc.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) (limited to 'hostnix/elmo/oidc.nix') diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 8447aa0..0ed170e 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -27,14 +27,15 @@ proxy_buffer_size 16k; ''; - # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites + # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites # nginx configs. It's mostly unhelpful, but we use it for brevity. In # particular, it configures Traefik-like ForwardAuth authentication with # auth_request. Note if this resource is missing for whatever reason, the # module magic will fail open (auth_request unset). - services.oauth2_proxy = { + services.oauth2-proxy = { enable = true; cookie.domain = "mou.fo"; + nginx.domain = "kc.mou.fo"; setXauthrequest = true; # include claims email.domains = [ "*" ]; # allow any authenticated user # https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc @@ -55,5 +56,5 @@ # Kludge to bring up after KeyCloak (otherwise OIDC discovery fails). A simple # ordering dependency isn't enough because keycloak.service is active before # KeyCloak responds to requests. - systemd.services.oauth2_proxy.serviceConfig.RestartSec = 5; + systemd.services.oauth2-proxy.serviceConfig.RestartSec = 5; } -- cgit v1.3.1