mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-08 04:57:13 +03:00
authelia added
This commit is contained in:
+47
-21
@@ -123,20 +123,54 @@ in
|
||||
forceSSL = true;
|
||||
enableACME = true;
|
||||
};
|
||||
# vtimeline.zeroq.su — static site behind HTTP basic auth.
|
||||
# vtimeline.zeroq.su — static site behind Authelia forward-auth.
|
||||
# Files live under /home/oqyude/External/Git/VeeamTimelineView/public_html,
|
||||
# which is bind-mounted to /var/lib/vtimeline (see systemd.mounts below)
|
||||
# because /home/oqyude is mode 700 and the nginx user (uid 60) cannot
|
||||
# traverse it. Credentials are pulled from sops; see the sops.secrets
|
||||
# block at the bottom of this file.
|
||||
# traverse it. Authentication is delegated to Authelia via
|
||||
# auth_request: nginx sub-requests /authelia on every hit, Authelia
|
||||
# returns 2xx if the session cookie is valid or 401 (which nginx
|
||||
# converts into a 401 to the client; Authelia's response headers
|
||||
# carry the redirect target). The login UI itself is served by the
|
||||
# authelia.zeroq.su vhost below — same Authelia container, different
|
||||
# vhost.
|
||||
"vtimeline.zeroq.su" = {
|
||||
forceSSL = true;
|
||||
enableACME = true;
|
||||
root = "/var/lib/vtimeline";
|
||||
extraConfig = ''
|
||||
auth_basic "vtimeline";
|
||||
auth_basic_user_file ${config.sops.secrets.vtimeline-htpasswd.path};
|
||||
'';
|
||||
locations = {
|
||||
"/" = {
|
||||
extraConfig = ''
|
||||
auth_request /authelia;
|
||||
auth_request_set $authelia_user $upstream_http_remote_user;
|
||||
'';
|
||||
};
|
||||
"= /authelia" = {
|
||||
extraConfig = ''
|
||||
internal;
|
||||
proxy_pass http://127.0.0.1:9091/api/authz/forward-auth;
|
||||
proxy_set_header X-Original-URL $request_uri;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header X-Forwarded-Host $host;
|
||||
proxy_set_header X-Forwarded-Method $request_method;
|
||||
proxy_set_header X-Forwarded-Uri $request_uri;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
# Authelia login UI — same podman container on 127.0.0.1:9091 as the
|
||||
# forward-auth endpoint above, just exposed on a separate vhost so
|
||||
# Authelia has a stable absolute URL to redirect users to. Authelia
|
||||
# generates internal links against $session.cookies[0].authelia_url,
|
||||
# which is set to https://${autheliaFqdn}/ in modules/server/authelia.nix.
|
||||
"authelia.zeroq.su" = {
|
||||
forceSSL = true;
|
||||
enableACME = true;
|
||||
locations."/" = {
|
||||
proxyPass = "http://127.0.0.1:9091";
|
||||
proxyWebsockets = true;
|
||||
};
|
||||
};
|
||||
"pdf.private" = {
|
||||
forceSSL = false;
|
||||
@@ -281,18 +315,10 @@ in
|
||||
(xlib.helpers.mkTmpfile "d" "/var/lib/vtimeline" "0755" "nginx" "nginx")
|
||||
];
|
||||
|
||||
# htpasswd file for vtimeline.zeroq.su basic auth.
|
||||
# Source layout (per modules/server/secrets/vtimeline-htpasswd.yaml):
|
||||
# passwords: |
|
||||
# <user>:<bcrypt-or-apr1-hash>
|
||||
# sops-nix extracts the `passwords` key as the only decrypted content.
|
||||
# The resulting file is consumed by nginx via auth_basic_user_file.
|
||||
sops.secrets.vtimeline-htpasswd = {
|
||||
format = "yaml";
|
||||
key = "passwords";
|
||||
sopsFile = ./secrets/vtimeline-htpasswd.yaml;
|
||||
owner = "nginx";
|
||||
group = "nginx";
|
||||
mode = "0640";
|
||||
};
|
||||
# Note: the previous vtimeline-htpasswd sops declaration lived here. It
|
||||
# was removed when authelia replaced nginx's auth_basic (see the vtimeline
|
||||
# vhost above). The encrypted file modules/server/secrets/vtimeline-htpasswd.yaml
|
||||
# itself was kept untouched per the repo policy of not modifying secrets
|
||||
# without explicit owner sign-off; delete it with `sops --version` and
|
||||
# `rm` once the cutover is verified.
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user