From d1dd864df4f2b8acb0082b1198639cc5d7d9a7f9 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Thu, 15 Feb 2024 02:31:58 -0500 Subject: Port configs from weebnix --- hostnix/elmo/oidc.nix | 54 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 54 insertions(+) create mode 100644 hostnix/elmo/oidc.nix (limited to 'hostnix/elmo/oidc.nix') diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix new file mode 100644 index 0000000..b2c34e5 --- /dev/null +++ b/hostnix/elmo/oidc.nix @@ -0,0 +1,54 @@ +{ ... }: + +{ + services.keycloak = { + enable = true; + database.passwordFile = "/var/lib/secrets/keycloak.dbpass"; + settings = { + hostname = "kc.elmo.mou.fo"; + http-host = "127.0.0.1"; + http-port = 7567; + proxy = "edge"; + }; + }; + + services.nginx.virtualHosts."kc.elmo.mou.fo" = { + enableACME = true; + forceSSL = true; + locations."/".proxyPass = "http://127.0.0.1:7567"; + # We can handle oauth2-proxy callbacks on any subdomain, but the Keycloak + # subdomain is the least arbitrary. + locations."/oauth2/".proxyPass = "http://127.0.0.1:4180"; + }; + + # Work around "upstream sent too big header" because of large tokens. + services.nginx.appendHttpConfig = '' + proxy_buffers 8 16k; + proxy_buffer_size 16k; + ''; + + # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites + # nginx configs. It's mostly unhelpful, but we use it for brevity. In + # particular, it configures Traefik-like ForwardAuth authentication with + # auth_request. Note if this resource is missing for whatever reason, the + # module magic will fail open (auth_request unset). + services.oauth2_proxy = { + enable = true; + cookie.domain = "elmo.mou.fo"; + setXauthrequest = true; # include claims + email.domains = [ "*" ]; # allow any authenticated user + # https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc + provider = "keycloak-oidc"; + clientID = "oauth2-proxy"; + # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. + keyFile = "/var/lib/secrets/oauth2-proxy.env"; + redirectURL = "https://kc.elmo.mou.fo/oauth2/callback"; + extraConfig = { + "oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod"; + "whitelist-domain" = ".elmo.mou.fo"; + # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 + "insecure-oidc-allow-unverified-email" = true; + "oidc-email-claim" = "sub"; + }; + }; +} -- cgit v1.3.1