From f9c27964706773a7a30cb636b2b17ceab2446c53 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Sat, 27 Apr 2024 01:47:45 -0400 Subject: elmo: Hoist subdomains and issue production certificates --- hostnix/elmo/acme.nix | 7 ------- hostnix/elmo/dyndns.nix | 3 --- hostnix/elmo/home-assistant.nix | 4 ++-- hostnix/elmo/oidc.nix | 12 ++++++------ hostnix/elmo/privacy-frontends.nix | 2 +- hostnix/elmo/syncthing.nix | 4 ++-- hostnix/elmo/usenet.nix | 4 ++-- 7 files changed, 13 insertions(+), 23 deletions(-) (limited to 'hostnix') diff --git a/hostnix/elmo/acme.nix b/hostnix/elmo/acme.nix index 597b781..fccd5c8 100644 --- a/hostnix/elmo/acme.nix +++ b/hostnix/elmo/acme.nix @@ -14,13 +14,6 @@ security.acme.acceptTerms = true; security.acme.defaults.email = "hostmaster@mou.fo"; - # TODO remove to switch to production certs - security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory"; - services.oauth2_proxy.extraConfig = { - "ssl-insecure-skip-verify" = true; - "ssl-upstream-insecure-skip-verify" = true; - }; - # https://go-acme.github.io/lego/dns/exec/ security.acme.defaults.dnsProvider = "exec"; security.acme.defaults.credentialFiles = { diff --git a/hostnix/elmo/dyndns.nix b/hostnix/elmo/dyndns.nix index 5bfde47..5abe98c 100644 --- a/hostnix/elmo/dyndns.nix +++ b/hostnix/elmo/dyndns.nix @@ -66,9 +66,6 @@ ''${IP6:+update add $RR. 300 AAAA $IP6} update delete $RR. TXT update add $RR. 300 TXT "v=spf1 include:_spf.mou.fo ~all" - ; Wildcard all subdomains. - update delete \\*.$1.$RR. CNAME - update add \\*.$1.$RR. 300 CNAME $RR. send . ''; diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index a392dfc..5b29a10 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -684,7 +684,7 @@ }; }; - services.nginx.virtualHosts."ha.elmo.mou.fo" = { + services.nginx.virtualHosts."ha.mou.fo" = { enableACME = true; forceSSL = true; locations."/" = { @@ -716,5 +716,5 @@ }; }; - services.oauth2_proxy.nginx.virtualHosts = [ "ha.elmo.mou.fo" ]; + services.oauth2_proxy.nginx.virtualHosts = [ "ha.mou.fo" ]; } diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index bff769e..8447aa0 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -5,14 +5,14 @@ enable = true; database.passwordFile = "/var/secrets/keycloak.dbpass"; settings = { - hostname = "kc.elmo.mou.fo"; + hostname = "kc.mou.fo"; http-host = "127.0.0.1"; http-port = 7567; proxy = "edge"; }; }; - services.nginx.virtualHosts."kc.elmo.mou.fo" = { + services.nginx.virtualHosts."kc.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://127.0.0.1:7567"; @@ -34,7 +34,7 @@ # module magic will fail open (auth_request unset). services.oauth2_proxy = { enable = true; - cookie.domain = "elmo.mou.fo"; + cookie.domain = "mou.fo"; setXauthrequest = true; # include claims email.domains = [ "*" ]; # allow any authenticated user # https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc @@ -42,10 +42,10 @@ clientID = "oauth2-proxy"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/secrets/oauth2-proxy.env"; - redirectURL = "https://kc.elmo.mou.fo/oauth2/callback"; + redirectURL = "https://kc.mou.fo/oauth2/callback"; extraConfig = { - "oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod"; - "whitelist-domain" = ".elmo.mou.fo"; + "oidc-issuer-url" = "https://kc.mou.fo/realms/prod"; + "whitelist-domain" = ".mou.fo"; # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 "insecure-oidc-allow-unverified-email" = true; "oidc-email-claim" = "sub"; diff --git a/hostnix/elmo/privacy-frontends.nix b/hostnix/elmo/privacy-frontends.nix index b5fcba0..6030d96 100644 --- a/hostnix/elmo/privacy-frontends.nix +++ b/hostnix/elmo/privacy-frontends.nix @@ -18,7 +18,7 @@ }; }; - services.nginx.virtualHosts."lr.elmo.mou.fo" = { + services.nginx.virtualHosts."lr.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://[::1]:7682"; diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix index 63b540e..3b60027 100644 --- a/hostnix/elmo/syncthing.nix +++ b/hostnix/elmo/syncthing.nix @@ -127,7 +127,7 @@ in }; }; - services.nginx.virtualHosts."st.elmo.mou.fo" = { + services.nginx.virtualHosts."st.mou.fo" = { enableACME = true; forceSSL = true; locations."/" = { @@ -137,5 +137,5 @@ in }; }; - services.oauth2_proxy.nginx.virtualHosts = [ "st.elmo.mou.fo" ]; + services.oauth2_proxy.nginx.virtualHosts = [ "st.mou.fo" ]; } diff --git a/hostnix/elmo/usenet.nix b/hostnix/elmo/usenet.nix index ab381a9..26d7a7b 100644 --- a/hostnix/elmo/usenet.nix +++ b/hostnix/elmo/usenet.nix @@ -42,11 +42,11 @@ in }; }; - services.nginx.virtualHosts."ng.elmo.mou.fo" = { + services.nginx.virtualHosts."ng.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://[::1]:6789"; }; - services.oauth2_proxy.nginx.virtualHosts = [ "ng.elmo.mou.fo" ]; + services.oauth2_proxy.nginx.virtualHosts = [ "ng.mou.fo" ]; } -- cgit v1.3.1