From bd44fc6fcb1fe3df7b8a8c81839e34470fed7911 Mon Sep 17 00:00:00 2001 From: Grisha Shipunov Date: Sun, 12 Jan 2025 21:32:36 +0100 Subject: authentik: init --- microvms/authentik/authentik.nix | 8 +++++ microvms/authentik/default.nix | 76 ++++++++++++++++++++++++++++++++++++++++ 2 files changed, 84 insertions(+) create mode 100644 microvms/authentik/authentik.nix (limited to 'microvms') diff --git a/microvms/authentik/authentik.nix b/microvms/authentik/authentik.nix new file mode 100644 index 0000000..3095944 --- /dev/null +++ b/microvms/authentik/authentik.nix @@ -0,0 +1,8 @@ +{ config, ... }: +{ + services.authentik = { + enable = true; + environmentFile = config.sops.secrets."authentik/envfile".path; + settings.disable_startup_analytics = true; + }; +} diff --git a/microvms/authentik/default.nix b/microvms/authentik/default.nix index e69de29..a0b3ac8 100644 --- a/microvms/authentik/default.nix +++ b/microvms/authentik/default.nix @@ -0,0 +1,76 @@ +{ config, lib, ... }: +let + mac = "c0:ff:ee:00:00:00"; +in +{ + imports = [ + ./authentik.nix + ]; + + sops.defaultSopsFile = ../../secrets/authentik/secrets.yaml; + sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; + + sops.secrets = { + "wg/0xa-proxy" = { + owner = config.users.users.systemd-network.name; + }; + "authentik/envfile" = { }; + }; + + microvm = { + hypervisor = "cloud-hypervisor"; + mem = 2 * 1024; + vcpu = 2; + interfaces = [ + { + type = "tap"; + id = "uvm-authentik"; + mac = mac; + } + ]; + shares = + [ + { + source = "/nix/store"; + mountPoint = "/nix/.ro-store"; + tag = "store"; + proto = "virtiofs"; + socket = "store.socket"; + } + ] + ++ map + (dir: { + source = dir; + mountPoint = "/${dir}"; + tag = dir; + proto = "virtiofs"; + socket = "${dir}.socket"; + }) + [ + "etc" + "var" + "home" + ]; + }; + + networking.useNetworkd = true; + networking.firewall.enable = lib.mkForce false; # firewalling done by the host + + systemd.network = { + enable = true; + networks."11-host" = { + matchConfig.MACAddress = mac; + networkConfig.Address = "10.99.99.10/24"; + routes = [ + { + Gateway = "10.99.99.1"; + Destination = "0.0.0.0/0"; + Metric = 1024; + } + ]; + }; + }; + + networking.hostName = "authentik"; + system.stateVersion = "24.11"; +} -- cgit v1.3.1