summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
blob: 7648e8ca570c8a084d9983fc080ffdad1a07ed86 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
{ ... }:

{
  services.keycloak = {
    enable = true;
    database.passwordFile = "/var/lib/secrets/keycloak.dbpass";
    settings = {
      hostname = "kc.elmo.mou.fo";
      http-host = "127.0.0.1";
      http-port = 7567;
      proxy = "edge";
    };
  };

  services.nginx.virtualHosts."kc.elmo.mou.fo" = {
    enableACME = true;
    forceSSL = true;
    locations."/".proxyPass = "http://127.0.0.1:7567";
    # We can handle oauth2-proxy callbacks on any subdomain, but the Keycloak
    # subdomain is the least arbitrary.
    locations."/oauth2/".proxyPass = "http://127.0.0.1:4180";
  };

  # Work around "upstream sent too big header" because of large tokens.
  services.nginx.appendHttpConfig = ''
    proxy_buffers 8 16k;
    proxy_buffer_size 16k;
  '';

  # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites
  # nginx configs. It's mostly unhelpful, but we use it for brevity. In
  # particular, it configures Traefik-like ForwardAuth authentication with
  # auth_request. Note if this resource is missing for whatever reason, the
  # module magic will fail open (auth_request unset).
  services.oauth2_proxy = {
    enable = true;
    cookie.domain = "elmo.mou.fo";
    setXauthrequest = true;  # include claims
    email.domains = [ "*" ];  # allow any authenticated user
    # https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc
    provider = "keycloak-oidc";
    clientID = "oauth2-proxy";
    # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
    keyFile = "/var/lib/secrets/oauth2-proxy.env";
    redirectURL = "https://kc.elmo.mou.fo/oauth2/callback";
    extraConfig = {
      "oidc-issuer-url" = "https://kc.elmo.mou.fo/realms/prod";
      "whitelist-domain" = ".elmo.mou.fo";
      # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
      "insecure-oidc-allow-unverified-email" = true;
      "oidc-email-claim" = "sub";
    };
  };

  # Kludge to bring up after KeyCloak (otherwise OIDC discovery fails). A simple
  # ordering dependency isn't enough because keycloak.service is active before
  # KeyCloak responds to requests.
  systemd.services.oauth2_proxy.serviceConfig.RestartSec = 5;
}