From 2f1e0c381e04b25b8c64f260967691f4cf841127 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Thu, 28 Sep 2023 21:12:24 -0400 Subject: Initial configuration of Home Assistant w/ oauth2-proxy for KeyCloak authentication --- hostnix/weebnix/home-assistant.nix | 108 +++++++++++++++++++++++++++++++++++++ 1 file changed, 108 insertions(+) create mode 100644 hostnix/weebnix/home-assistant.nix (limited to 'hostnix/weebnix/home-assistant.nix') diff --git a/hostnix/weebnix/home-assistant.nix b/hostnix/weebnix/home-assistant.nix new file mode 100644 index 0000000..500ff10 --- /dev/null +++ b/hostnix/weebnix/home-assistant.nix @@ -0,0 +1,108 @@ +{ pkgs, ... }: + +let + # Being cleaned up; see https://github.com/NixOS/nixpkgs/pull/160346 + customComponentFromGitHub = { name, ... }@attrs: + { stdenv, fetchFromGitHub }: + stdenv.mkDerivation { + inherit name; + src = fetchFromGitHub (removeAttrs attrs [ "name" ]); + dontUnpack = true; + installPhase = "cp -r $src/custom_components/${name} $out"; + }; + mapComponentTmpfile = map (package: + let drv = pkgs.callPackage package { }; + in "L+ /var/lib/hass/custom_components/${drv.name} - - - - ${drv}/"); +in { + systemd.tmpfiles.rules = + [ "d /var/lib/hass/custom_components 0700 hass hass" ] + ++ mapComponentTmpfile [ + (customComponentFromGitHub { + name = "auth_header"; + owner = "BeryJu"; + repo = "hass-auth-header"; + rev = "v1.10"; + hash = "sha256-dSmY3d8Kx0pXl+20dTGAYgjSH6OhNh53jPX7VLCZs7Y="; + }) + (customComponentFromGitHub { + name = "tuya_local"; + owner = "make-all"; + repo = "tuya-local"; + rev = "2023.9.1"; + hash = "sha256-uHImitvHFU7JoBx+aKzZuvpKl2tJCXwsxxk+sJ1+igk="; + }) + ]; + + services.postgresql = { + enable = true; + ensureDatabases = [ "hass" ]; + ensureUsers = [{ + name = "hass"; + ensurePermissions = { "DATABASE hass" = "ALL PRIVILEGES"; }; + }]; + }; + + services.home-assistant = { + enable = true; + extraPackages = ps: with ps; [ psycopg2 ]; + extraComponents = [ + "androidtv_remote" + "apple_tv" + "cast" + "homekit_controller" + "hue" + "spotify" + "esphome" + "met" + "radio_browser" + ]; + config = { + default_config = { }; + http = { + server_host = "::1"; + trusted_proxies = [ "::1" ]; + use_x_forwarded_for = true; + }; + recorder.db_url = "postgresql://@/hass"; + auth_header = { }; + }; + }; + + services.nginx.virtualHosts."ha.weebnix.mou.fo" = { + enableACME = true; + forceSSL = true; + locations."/" = { + proxyPass = "http://[::1]:8123"; + proxyWebsockets = true; + extraConfig = '' + # This is frequently used in examples but without clear explanation. It + # might help with WebSockets. + proxy_buffering off; + # oauth2_proxy NixOS module sets some non-standard headers, but we need + # the preferred_username claim. + auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username; + proxy_set_header X-Forwarded-Preferred-Username $preferred_username; + ''; + }; + }; + + # TODO how to configure for multiple domains? + services.oauth2_proxy = { + enable = true; + nginx.virtualHosts = [ "ha.weebnix.mou.fo" ]; + setXauthrequest = true; + # https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#keycloak-oidc-auth-provider + provider = "keycloak-oidc"; + clientID = "ha.weebnix.mou.fo"; + # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. + keyFile = "/var/lib/secrets/oauth2-proxy.env"; + redirectURL = "https://ha.weebnix.mou.fo/oauth2/callback"; + email.domains = [ "*" ]; + extraConfig = { + "oidc-issuer-url" = "https://kc.weebnix.mou.fo/realms/staging"; + "code-challenge-method" = "S256"; + # TODO this is specific to HA. move to nginx config? + "skip-auth-route" = "^/api/"; + }; + }; +} -- cgit v1.3.1