{ ... }: { services.keycloak = { enable = true; database.passwordFile = "/var/lib/secrets/keycloak.dbpass"; settings = { hostname = "kc.elmo.mou.fo"; http-host = "127.0.0.1"; http-port = 7567; proxy = "edge"; }; }; services.nginx.virtualHosts."kc.elmo.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://127.0.0.1:7567"; # We can handle oauth2-proxy callbacks on any subdomain, but the Keycloak # subdomain is the least arbitrary. locations."/oauth2/".proxyPass = "http://127.0.0.1:4180"; }; # Work around "upstream sent too big header" because of large tokens. services.nginx.appendHttpConfig = '' proxy_buffers 8 16k; proxy_buffer_size 16k; ''; # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites # nginx configs. It's mostly unhelpful, but we use it for brevity. In # particular, it configures Traefik-like ForwardAuth authentication with # auth_request. Note if this resource is missing for whatever reason, the # module magic will fail open (auth_request unset). services.oauth2_proxy = { enable = true; cookie.domain = "elmo.mou.fo"; setXauthrequest = true; # include claims email.domains = [ "*" ]; # allow any authenticated user # https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc provider = "keycloak-oidc"; clientID = "oauth2-proxy"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/lib/secrets/oauth2-proxy.env"; redirectURL = "https://kc.elmo.mou.fo/oauth2/callback"; extraConfig = { "oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod"; "whitelist-domain" = ".elmo.mou.fo"; # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 "insecure-oidc-allow-unverified-email" = true; "oidc-email-claim" = "sub"; }; }; }