From f9c27964706773a7a30cb636b2b17ceab2446c53 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Sat, 27 Apr 2024 01:47:45 -0400 Subject: elmo: Hoist subdomains and issue production certificates --- hostnix/elmo/oidc.nix | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) (limited to 'hostnix/elmo/oidc.nix') diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index bff769e..8447aa0 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -5,14 +5,14 @@ enable = true; database.passwordFile = "/var/secrets/keycloak.dbpass"; settings = { - hostname = "kc.elmo.mou.fo"; + hostname = "kc.mou.fo"; http-host = "127.0.0.1"; http-port = 7567; proxy = "edge"; }; }; - services.nginx.virtualHosts."kc.elmo.mou.fo" = { + services.nginx.virtualHosts."kc.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://127.0.0.1:7567"; @@ -34,7 +34,7 @@ # module magic will fail open (auth_request unset). services.oauth2_proxy = { enable = true; - cookie.domain = "elmo.mou.fo"; + cookie.domain = "mou.fo"; setXauthrequest = true; # include claims email.domains = [ "*" ]; # allow any authenticated user # https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc @@ -42,10 +42,10 @@ clientID = "oauth2-proxy"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/secrets/oauth2-proxy.env"; - redirectURL = "https://kc.elmo.mou.fo/oauth2/callback"; + redirectURL = "https://kc.mou.fo/oauth2/callback"; extraConfig = { - "oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod"; - "whitelist-domain" = ".elmo.mou.fo"; + "oidc-issuer-url" = "https://kc.mou.fo/realms/prod"; + "whitelist-domain" = ".mou.fo"; # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 "insecure-oidc-allow-unverified-email" = true; "oidc-email-claim" = "sub"; -- cgit v1.3.1