blob: bf7088253708bddceff2536fae145147ea267ca2 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
|
{ ... }:
{
services.keycloak = {
enable = true;
database.passwordFile = "/var/lib/secrets/keycloak.dbpass";
settings = {
hostname = "kc.weebnix.mou.fo";
http-host = "127.0.0.1";
http-port = 7567;
proxy = "edge";
};
};
services.nginx.virtualHosts."kc.weebnix.mou.fo" = {
enableACME = true;
forceSSL = true;
locations."/".proxyPass = "http://127.0.0.1:7567";
# We can handle oauth2-proxy callbacks on any subdomain, but the Keycloak
# subdomain is the least arbitrary.
locations."/oauth2/".proxyPass = "http://127.0.0.1:4180";
};
# Work around "upstream sent too big header" because of large tokens.
services.nginx.appendHttpConfig = ''
proxy_buffers 8 16k;
proxy_buffer_size 16k;
'';
# The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites
# nginx configs. It's mostly unhelpful, but we use it for brevity. In
# particular, it configures Traefik-like ForwardAuth authentication with
# auth_request. Note if this resource is missing for whatever reason, the
# module magic will fail open (auth_request unset).
services.oauth2_proxy = {
enable = true;
cookie.domain = "weebnix.mou.fo";
setXauthrequest = true; # include claims
email.domains = [ "*" ]; # allow any authenticated user
# https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#keycloak-oidc-auth-provider
provider = "keycloak-oidc";
clientID = "weebnix.mou.fo";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/lib/secrets/oauth2-proxy.env";
redirectURL = "https://kc.weebnix.mou.fo/oauth2/callback";
extraConfig = {
"oidc-issuer-url" = "https://kc.weebnix.mou.fo/realms/staging";
"whitelist-domain" = ".weebnix.mou.fo";
};
};
}
|