{ lib, pkgs, ... }: { systemd.tmpfiles.rules = [ "d /run/pocket-id 750 pocket-id nginx" ]; # - Create user joe # - Create OIDC Client: oauth2-proxy # - Callback URLs: https://op.mou.fo/oauth2/callback # - PKCE services.pocket-id = { enable = true; credentials.ENCRYPTION_KEY = "/var/secrets/pocket-id.key"; settings = { APP_URL = "https://pi.mou.fo"; TRUST_PROXY = true; UNIX_SOCKET = "/run/pocket-id/socket"; UNIX_SOCKET_MODE = "0777"; # https://pocket-id.org/docs/configuration/environment-variables#overriding-the-ui-configuration UI_CONFIG_DISABLED = true; EMAILS_VERIFIED = true; # needed by oauth2-proxy SMTP_HOST = "localhost"; SMTP_PORT = 25; SMTP_FROM = "noreply@pi.mou.fo"; EMAIL_LOGIN_NOTIFICATION_ENABLED = true; EMAIL_API_KEY_EXPIRATION_ENABLED = true; EMAIL_ONE_TIME_ACCESS_AS_UNAUTHENTICATED_ENABLED = true; }; }; services.nginx.virtualHosts."pi.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://unix:/run/pocket-id/socket"; }; # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites # nginx configs. It can be heavy handed, but we use it for brevity. In # particular, it configures Traefik-like ForwardAuth authentication with # auth_request. Note if this resource is missing for whatever reason, the # module magic will fail open (auth_request unset). services.oauth2-proxy = { enable = true; cookie.domain = "mou.fo"; nginx.domain = "op.mou.fo"; setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email reverseProxy = true; trustedProxyIP = [ "127.0.0.1" ]; provider = "oidc"; clientID = "39edd929-8983-4cb6-b1cd-dc08e2e3358f"; oidcIssuerUrl = "https://pi.mou.fo"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/secrets/oauth2-proxy.env"; # Ignore e-mail address. email.domains = [ "*" ]; extraConfig = { code-challenge-method = "S256"; whitelist-domain = ".mou.fo"; # allowed redirects after authentication insecure-oidc-allow-unverified-email = true; }; }; systemd.services.oauth2-proxy.after = [ "pocket-id.service" ]; # It's somewhat overkill to assign oauth2-proxy its own domain. We can't use # Kanidm's though, because it uses the /oauth2 path which the oauth2-proxy # nginx module is hardcoded for (proxyPrefix is ignored); this module magic is # also why we do not need to explicitly specify proxyPass. services.nginx.virtualHosts."op.mou.fo" = { enableACME = true; forceSSL = true; }; }