summaryrefslogtreecommitdiff
path: root/hosts/auth
diff options
context:
space:
mode:
Diffstat (limited to 'hosts/auth')
-rw-r--r--hosts/auth/default.nix78
-rw-r--r--hosts/auth/keycloak.nix18
2 files changed, 96 insertions, 0 deletions
diff --git a/hosts/auth/default.nix b/hosts/auth/default.nix
new file mode 100644
index 0000000..b4c23f1
--- /dev/null
+++ b/hosts/auth/default.nix
@@ -0,0 +1,78 @@
+{ config, lib, ... }:
+let
+ mac = "02:00:00:00:00:01";
+in
+{
+ imports = [
+ ./keycloak.nix
+ ];
+ sops.defaultSopsFile = ../../secrets/auth/secrets.yaml;
+ sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
+
+ sops.secrets = {
+ "wg/0xa-proxy" = {
+ owner = config.users.users.systemd-network.name;
+ };
+ "keycloak/db_pass" = { };
+ };
+
+ microvm = {
+ hypervisor = "qemu";
+ mem = 2 * 1024;
+ vcpu = 2;
+ interfaces = [
+ {
+ type = "tap";
+ id = "uvm-auth";
+ mac = mac;
+ }
+ ];
+ shares =
+ [
+ {
+ source = "/nix/store";
+ mountPoint = "/nix/.ro-store";
+ tag = "store";
+ proto = "virtiofs";
+ socket = "store.socket";
+ }
+ ]
+ ++ map
+ (dir: {
+ source = dir;
+ mountPoint = "/${dir}";
+ tag = dir;
+ proto = "virtiofs";
+ socket = "${dir}.socket";
+ })
+ [
+ "etc"
+ "var"
+ "home"
+ ];
+ };
+
+ networking.useNetworkd = true;
+ networking.firewall.enable = lib.mkForce false; # firewalling done by the host
+
+ systemd.network = {
+ enable = true;
+ networks."11-host" = {
+ matchConfig.MACAddress = mac;
+ networkConfig = {
+ Address = "10.99.99.11/24";
+ DHCP = "no";
+ };
+ routes = [
+ {
+ Gateway = "10.99.99.1";
+ Destination = "0.0.0.0/0";
+ Metric = 1024;
+ }
+ ];
+ };
+ };
+
+ networking.hostName = "auth";
+ system.stateVersion = "24.11";
+}
diff --git a/hosts/auth/keycloak.nix b/hosts/auth/keycloak.nix
new file mode 100644
index 0000000..de537ef
--- /dev/null
+++ b/hosts/auth/keycloak.nix
@@ -0,0 +1,18 @@
+{ config, ... }:
+{
+ services.keycloak = {
+ enable = true;
+ database = {
+ type = "postgresql";
+ createLocally = true;
+ passwordFile = config.sops.secrets."keycloak/db_pass".path;
+ };
+ settings = {
+ hostname = "https://auth.oxapentane.com";
+ http-port = 38080;
+ http-enabled = true;
+ proxy-headers = "xforwarded";
+ proxy-trusted-addresses = "10.89.88.0/24,fd31:185d:722f::/48";
+ };
+ };
+}