mirror of
https://codeberg.org/icewind/haze.git
synced 2026-10-01 08:44:09 +02:00
feat(service): Add OIDC service
Signed-off-by: Louis Chmn <louis@chmn.me>
This commit is contained in:
parent
6242ca41fe
commit
188a21342f
6 changed files with 200 additions and 16 deletions
|
|
@ -1,5 +1,7 @@
|
|||
mod oidc;
|
||||
mod saml;
|
||||
|
||||
pub use oidc::AuthentikOidc;
|
||||
pub use saml::AuthentikSaml;
|
||||
|
||||
use crate::Result;
|
||||
|
|
@ -19,6 +21,9 @@ use std::net::{IpAddr, Ipv4Addr};
|
|||
const AUTHENTIK_IMAGE: &str = "ghcr.io/goauthentik/server:2026.8.0";
|
||||
const POSTGRES_IMAGE: &str = "docker.io/library/postgres:16-alpine";
|
||||
|
||||
pub(super) const SIGNING_CERT: &str = include_str!("../../../certificates/authentik/public.crt");
|
||||
pub(super) const SIGNING_KEY: &str = include_str!("../../../certificates/authentik/private.key");
|
||||
|
||||
pub(super) const AUTHENTIK_PORT: u16 = 9000;
|
||||
|
||||
const AUTHENTIK_TOKEN: &str = "haze";
|
||||
|
|
@ -90,6 +95,9 @@ async fn spawn_authentik(
|
|||
let name = container_name(cloud_id, role);
|
||||
|
||||
let haze_directory = config.work_dir.join(cloud_id).join("authentik");
|
||||
write_file(&haze_directory, "public.crt", SIGNING_CERT)?;
|
||||
write_file(&haze_directory, "private.key", SIGNING_KEY)?;
|
||||
|
||||
let blueprints_directory = haze_directory.join("blueprints");
|
||||
write_file(&blueprints_directory, "nextcloud.yaml", BLUEPRINT)?;
|
||||
|
||||
|
|
@ -236,6 +244,31 @@ impl ServiceTrait for Authentik {
|
|||
])
|
||||
}
|
||||
|
||||
async fn post_setup(
|
||||
&self,
|
||||
docker: &Docker,
|
||||
cloud_id: &str,
|
||||
config: &HazeConfig,
|
||||
) -> Result<Vec<Vec<String>>> {
|
||||
let authentik_container = container_name(cloud_id, "server");
|
||||
|
||||
let authentik_url = config.proxy.addr_with_port(
|
||||
&authentik_container,
|
||||
container_ip(docker, &authentik_container, None).await?,
|
||||
AUTHENTIK_PORT,
|
||||
);
|
||||
let nextcloud_url = config.proxy.addr(
|
||||
cloud_id,
|
||||
container_ip(docker, cloud_id, Some("haze")).await?,
|
||||
);
|
||||
|
||||
let haze_directory = config.work_dir.join(cloud_id).join("authentik");
|
||||
write_file(&haze_directory, "authentik-url", &authentik_url)?;
|
||||
write_file(&haze_directory, "nextcloud-url", &nextcloud_url)?;
|
||||
|
||||
Ok(vec![])
|
||||
}
|
||||
|
||||
fn container_name(&self, cloud_id: &str) -> Option<String> {
|
||||
Some(container_name(cloud_id, "server"))
|
||||
}
|
||||
|
|
|
|||
86
src/service/authentik/oidc.rs
Normal file
86
src/service/authentik/oidc.rs
Normal file
|
|
@ -0,0 +1,86 @@
|
|||
use super::{AUTHENTIK_PORT, container_ip, container_name, write_file};
|
||||
use crate::Result;
|
||||
use crate::cloud::CloudOptions;
|
||||
use crate::config::HazeConfig;
|
||||
use crate::service::{ServiceTrait, split_cmnd};
|
||||
use bollard::Docker;
|
||||
|
||||
const BLUEPRINT: &str = include_str!("../../../blueprints/authentik-oidc.yaml");
|
||||
|
||||
#[derive(Debug, Clone, Eq, PartialEq)]
|
||||
pub struct AuthentikOidc;
|
||||
|
||||
#[async_trait::async_trait]
|
||||
impl ServiceTrait for AuthentikOidc {
|
||||
fn name(&self) -> &str {
|
||||
"oidc"
|
||||
}
|
||||
|
||||
async fn spawn(
|
||||
&self,
|
||||
_docker: &Docker,
|
||||
cloud_id: &str,
|
||||
_network: &str,
|
||||
config: &HazeConfig,
|
||||
_options: &CloudOptions,
|
||||
) -> Result<Vec<String>> {
|
||||
let blueprints_directory = config
|
||||
.work_dir
|
||||
.join(cloud_id)
|
||||
.join("authentik")
|
||||
.join("blueprints");
|
||||
write_file(&blueprints_directory, "oidc.yaml", BLUEPRINT)?;
|
||||
|
||||
Ok(Vec::new())
|
||||
}
|
||||
|
||||
fn apps(&self) -> &'static [&'static str] {
|
||||
&["user_oidc"]
|
||||
}
|
||||
|
||||
async fn post_setup(
|
||||
&self,
|
||||
docker: &Docker,
|
||||
cloud_id: &str,
|
||||
config: &HazeConfig,
|
||||
) -> Result<Vec<Vec<String>>> {
|
||||
let authentik_container = container_name(cloud_id, "server");
|
||||
let authentik_url = config.proxy.addr_with_port(
|
||||
&authentik_container,
|
||||
container_ip(docker, &authentik_container, None).await?,
|
||||
AUTHENTIK_PORT,
|
||||
);
|
||||
|
||||
let allow_insecure = if config.proxy.https { "0" } else { "1" };
|
||||
|
||||
Ok(vec![
|
||||
split_cmnd(&format!(
|
||||
"occ config:app:set --silent user_oidc allow_insecure_http --value {allow_insecure}"
|
||||
)),
|
||||
split_cmnd(
|
||||
"occ config:app:set --silent user_oidc allow_multiple_user_backends --value 1",
|
||||
),
|
||||
vec![
|
||||
"occ".into(),
|
||||
"user_oidc:provider".into(),
|
||||
"Authentik OIDC".into(),
|
||||
"--clientid=nextcloud".into(),
|
||||
"--clientsecret=haze-oidc-secret".into(),
|
||||
format!(
|
||||
"--discoveryuri={authentik_url}/application/o/nextcloud-oidc/.well-known/openid-configuration"
|
||||
),
|
||||
format!(
|
||||
"--endsessionendpointuri={authentik_url}/application/o/nextcloud-oidc/end-session/"
|
||||
),
|
||||
"--scope".into(),
|
||||
"openid email profile nextcloud".into(),
|
||||
"--mapping-uid=nextcloud_uid".into(),
|
||||
"--mapping-display-name=name".into(),
|
||||
"--mapping-email=email".into(),
|
||||
"--mapping-groups=groups".into(),
|
||||
"--group-provisioning=1".into(),
|
||||
"--unique-uid=0".into(),
|
||||
],
|
||||
])
|
||||
}
|
||||
}
|
||||
|
|
@ -2,11 +2,10 @@ use super::{AUTHENTIK_PORT, container_ip, container_name, write_file};
|
|||
use crate::Result;
|
||||
use crate::cloud::CloudOptions;
|
||||
use crate::config::{HazeConfig, ProxyConfig};
|
||||
use crate::service::authentik::SIGNING_CERT;
|
||||
use crate::service::{ServiceTrait, split_cmnd};
|
||||
use bollard::Docker;
|
||||
|
||||
const SIGNING_CERT: &str = include_str!("../../../certificates/authentik/public.crt");
|
||||
const SIGNING_KEY: &str = include_str!("../../../certificates/authentik/private.key");
|
||||
const BLUEPRINT: &str = include_str!("../../../blueprints/authentik-saml.yaml");
|
||||
|
||||
#[derive(Debug, Clone, Eq, PartialEq)]
|
||||
|
|
@ -26,10 +25,6 @@ impl ServiceTrait for AuthentikSaml {
|
|||
config: &HazeConfig,
|
||||
_options: &CloudOptions,
|
||||
) -> Result<Vec<String>> {
|
||||
let haze_directory = config.work_dir.join(cloud_id).join("authentik");
|
||||
write_file(&haze_directory, "public.crt", SIGNING_CERT)?;
|
||||
write_file(&haze_directory, "private.key", SIGNING_KEY)?;
|
||||
|
||||
let blueprints_directory = config
|
||||
.work_dir
|
||||
.join(cloud_id)
|
||||
|
|
@ -51,20 +46,11 @@ impl ServiceTrait for AuthentikSaml {
|
|||
config: &HazeConfig,
|
||||
) -> Result<Vec<Vec<String>>> {
|
||||
let authentik_container = container_name(cloud_id, "server");
|
||||
|
||||
let authentik_url = config.proxy.addr_with_port(
|
||||
&authentik_container,
|
||||
container_ip(docker, &authentik_container, None).await?,
|
||||
AUTHENTIK_PORT,
|
||||
);
|
||||
let nextcloud_url = config.proxy.addr(
|
||||
cloud_id,
|
||||
container_ip(docker, cloud_id, Some("haze")).await?,
|
||||
);
|
||||
|
||||
let haze_directory = config.work_dir.join(cloud_id).join("authentik");
|
||||
write_file(&haze_directory, "authentik-url", &authentik_url)?;
|
||||
write_file(&haze_directory, "nextcloud-url", &nextcloud_url)?;
|
||||
|
||||
Ok(vec![
|
||||
split_cmnd("occ config:app:set --silent user_saml type --value saml"),
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue