From 5c3f0886e592ff2d3e3a8588ab496f36c19e0ce9 Mon Sep 17 00:00:00 2001 From: Grigory Shipunov Date: Tue, 14 Jan 2025 21:24:05 +0000 Subject: yeet authentik, add keycloak and radicale --- microvms/authentik/authentik.nix | 8 ---- microvms/authentik/default.nix | 79 ---------------------------------------- 2 files changed, 87 deletions(-) delete mode 100644 microvms/authentik/authentik.nix delete mode 100644 microvms/authentik/default.nix (limited to 'microvms/authentik') diff --git a/microvms/authentik/authentik.nix b/microvms/authentik/authentik.nix deleted file mode 100644 index 3095944..0000000 --- a/microvms/authentik/authentik.nix +++ /dev/null @@ -1,8 +0,0 @@ -{ config, ... }: -{ - services.authentik = { - enable = true; - environmentFile = config.sops.secrets."authentik/envfile".path; - settings.disable_startup_analytics = true; - }; -} diff --git a/microvms/authentik/default.nix b/microvms/authentik/default.nix deleted file mode 100644 index badb384..0000000 --- a/microvms/authentik/default.nix +++ /dev/null @@ -1,79 +0,0 @@ -{ config, lib, ... }: -let - mac = "02:00:00:00:00:01"; -in -{ - imports = [ - ./authentik.nix - ]; - - sops.defaultSopsFile = ../../secrets/authentik/secrets.yaml; - sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; - - sops.secrets = { - "wg/0xa-proxy" = { - owner = config.users.users.systemd-network.name; - }; - "authentik/envfile" = { }; - }; - - microvm = { - hypervisor = "qemu"; - mem = 2 * 1024; - vcpu = 2; - interfaces = [ - { - type = "tap"; - id = "uvm-authentik"; - mac = mac; - } - ]; - shares = - [ - { - source = "/nix/store"; - mountPoint = "/nix/.ro-store"; - tag = "store"; - proto = "virtiofs"; - socket = "store.socket"; - } - ] - ++ map - (dir: { - source = dir; - mountPoint = "/${dir}"; - tag = dir; - proto = "virtiofs"; - socket = "${dir}.socket"; - }) - [ - "etc" - "var" - "home" - ]; - }; - - networking.useNetworkd = true; - networking.firewall.enable = lib.mkForce false; # firewalling done by the host - - systemd.network = { - enable = true; - networks."11-host" = { - matchConfig.MACAddress = mac; - networkConfig = { - Address = "10.99.99.10/24"; - DHCP = "no"; - }; - routes = [ - { - Gateway = "10.99.99.1"; - Destination = "0.0.0.0/0"; - Metric = 1024; - } - ]; - }; - }; - - networking.hostName = "authentik"; - system.stateVersion = "24.11"; -} -- cgit v1.3.1