1
0
Fork 0
mirror of https://codeberg.org/icewind/haze.git synced 2026-10-01 08:44:09 +02:00

feat(service): Add OIDC service

Signed-off-by: Louis Chmn <louis@chmn.me>
This commit is contained in:
Louis Chmn 2026-09-07 00:09:02 +02:00
commit 188a21342f
6 changed files with 200 additions and 16 deletions

View file

@ -1,5 +1,7 @@
mod oidc;
mod saml;
pub use oidc::AuthentikOidc;
pub use saml::AuthentikSaml;
use crate::Result;
@ -19,6 +21,9 @@ use std::net::{IpAddr, Ipv4Addr};
const AUTHENTIK_IMAGE: &str = "ghcr.io/goauthentik/server:2026.8.0";
const POSTGRES_IMAGE: &str = "docker.io/library/postgres:16-alpine";
pub(super) const SIGNING_CERT: &str = include_str!("../../../certificates/authentik/public.crt");
pub(super) const SIGNING_KEY: &str = include_str!("../../../certificates/authentik/private.key");
pub(super) const AUTHENTIK_PORT: u16 = 9000;
const AUTHENTIK_TOKEN: &str = "haze";
@ -90,6 +95,9 @@ async fn spawn_authentik(
let name = container_name(cloud_id, role);
let haze_directory = config.work_dir.join(cloud_id).join("authentik");
write_file(&haze_directory, "public.crt", SIGNING_CERT)?;
write_file(&haze_directory, "private.key", SIGNING_KEY)?;
let blueprints_directory = haze_directory.join("blueprints");
write_file(&blueprints_directory, "nextcloud.yaml", BLUEPRINT)?;
@ -236,6 +244,31 @@ impl ServiceTrait for Authentik {
])
}
async fn post_setup(
&self,
docker: &Docker,
cloud_id: &str,
config: &HazeConfig,
) -> Result<Vec<Vec<String>>> {
let authentik_container = container_name(cloud_id, "server");
let authentik_url = config.proxy.addr_with_port(
&authentik_container,
container_ip(docker, &authentik_container, None).await?,
AUTHENTIK_PORT,
);
let nextcloud_url = config.proxy.addr(
cloud_id,
container_ip(docker, cloud_id, Some("haze")).await?,
);
let haze_directory = config.work_dir.join(cloud_id).join("authentik");
write_file(&haze_directory, "authentik-url", &authentik_url)?;
write_file(&haze_directory, "nextcloud-url", &nextcloud_url)?;
Ok(vec![])
}
fn container_name(&self, cloud_id: &str) -> Option<String> {
Some(container_name(cloud_id, "server"))
}