mirror of
https://codeberg.org/icewind/haze.git
synced 2026-10-01 08:44:09 +02:00
feat(services): Add Authentik to provide SAML
Signed-off-by: Louis Chmn <louis@chmn.me>
This commit is contained in:
parent
872b2e3bac
commit
c8d6cb170a
11 changed files with 622 additions and 3 deletions
96
blueprints/authentik-saml.yaml
Normal file
96
blueprints/authentik-saml.yaml
Normal file
|
|
@ -0,0 +1,96 @@
|
|||
# yaml-language-server: $schema=https://goauthentik.io/blueprints/schema.json
|
||||
version: 1
|
||||
metadata:
|
||||
name: haze-nextcloud-saml
|
||||
entries:
|
||||
- model: authentik_crypto.certificatekeypair
|
||||
id: haze-saml-cert
|
||||
identifiers:
|
||||
name: haze-saml
|
||||
attrs:
|
||||
certificate_data: !File /haze/authentik/public.crt
|
||||
key_data: !File /haze/authentik/private.key
|
||||
|
||||
# Prefix SAML users with 'saml-' so that they don't collide with local users.
|
||||
- model: authentik_providers_saml.samlpropertymapping
|
||||
id: haze-nextcloud-uid
|
||||
identifiers:
|
||||
name: haze-nextcloud-uid
|
||||
attrs:
|
||||
saml_name: http://haze.test/nextcloud/uid
|
||||
expression: 'return "saml-" + request.user.username'
|
||||
|
||||
- model: authentik_providers_saml.samlprovider
|
||||
id: nextcloud-provider
|
||||
identifiers:
|
||||
name: nextcloud
|
||||
attrs:
|
||||
acs_url:
|
||||
!Format [
|
||||
"%s/index.php/apps/user_saml/saml/acs",
|
||||
!File /haze/authentik/nextcloud-url,
|
||||
]
|
||||
audience:
|
||||
!Format [
|
||||
"%s/index.php/apps/user_saml/saml/metadata",
|
||||
!File /haze/authentik/nextcloud-url,
|
||||
]
|
||||
sls_url:
|
||||
!Format [
|
||||
"%s/index.php/apps/user_saml/saml/sls",
|
||||
!File /haze/authentik/nextcloud-url,
|
||||
]
|
||||
sls_binding: redirect
|
||||
sp_binding: post
|
||||
issuer_override:
|
||||
!Format [
|
||||
"%s/application/saml/nextcloud-saml/metadata/",
|
||||
!File /haze/authentik/authentik-url,
|
||||
]
|
||||
default_name_id_policy: urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
|
||||
assertion_valid_not_before: minutes=-5
|
||||
assertion_valid_not_on_or_after: minutes=5
|
||||
session_valid_not_on_or_after: minutes=86400
|
||||
digest_algorithm: http://www.w3.org/2001/04/xmlenc#sha256
|
||||
signature_algorithm: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
|
||||
sign_assertion: true
|
||||
signing_kp: !KeyOf haze-saml-cert
|
||||
authorization_flow:
|
||||
!Find [
|
||||
authentik_flows.flow,
|
||||
[slug, default-provider-authorization-implicit-consent],
|
||||
]
|
||||
invalidation_flow:
|
||||
!Find [authentik_flows.flow, [slug, default-provider-invalidation-flow]]
|
||||
name_id_mapping: !KeyOf haze-nextcloud-uid
|
||||
property_mappings:
|
||||
- !KeyOf haze-nextcloud-uid
|
||||
- !Find [
|
||||
authentik_providers_saml.samlpropertymapping,
|
||||
[managed, goauthentik.io/providers/saml/username],
|
||||
]
|
||||
- !Find [
|
||||
authentik_providers_saml.samlpropertymapping,
|
||||
[managed, goauthentik.io/providers/saml/email],
|
||||
]
|
||||
- !Find [
|
||||
authentik_providers_saml.samlpropertymapping,
|
||||
[managed, goauthentik.io/providers/saml/name],
|
||||
]
|
||||
- !Find [
|
||||
authentik_providers_saml.samlpropertymapping,
|
||||
[managed, goauthentik.io/providers/saml/uid],
|
||||
]
|
||||
- !Find [
|
||||
authentik_providers_saml.samlpropertymapping,
|
||||
[managed, goauthentik.io/providers/saml/groups],
|
||||
]
|
||||
|
||||
- model: authentik_core.application
|
||||
identifiers:
|
||||
slug: nextcloud-saml
|
||||
attrs:
|
||||
name: Nextcloud with SAML
|
||||
provider: !KeyOf nextcloud-provider
|
||||
meta_launch_url: !File /haze/authentik/nextcloud-url
|
||||
meta_description: Nextcloud instance provisioned by haze
|
||||
51
blueprints/authentik.yaml
Normal file
51
blueprints/authentik.yaml
Normal file
|
|
@ -0,0 +1,51 @@
|
|||
# yaml-language-server: $schema=https://goauthentik.io/blueprints/schema.json
|
||||
version: 1
|
||||
metadata:
|
||||
name: haze-nextcloud
|
||||
entries:
|
||||
- model: authentik_core.group
|
||||
id: authentik-group1
|
||||
identifiers:
|
||||
name: authentik-group1
|
||||
- model: authentik_core.group
|
||||
id: authentik-group2
|
||||
identifiers:
|
||||
name: authentik-group2
|
||||
- model: authentik_core.group
|
||||
id: authentik-group3
|
||||
identifiers:
|
||||
name: authentik-group3
|
||||
|
||||
- model: authentik_core.user
|
||||
id: alice
|
||||
identifiers:
|
||||
username: alice
|
||||
attrs:
|
||||
name: Authentik Alice
|
||||
email: alice@haze.test
|
||||
password: password
|
||||
type: internal
|
||||
groups:
|
||||
- !KeyOf authentik-group1
|
||||
- model: authentik_core.user
|
||||
id: bob
|
||||
identifiers:
|
||||
username: bob
|
||||
attrs:
|
||||
name: Authentik Bob
|
||||
email: bob@haze.test
|
||||
password: password
|
||||
type: internal
|
||||
groups:
|
||||
- !KeyOf authentik-group2
|
||||
- model: authentik_core.user
|
||||
id: charlie
|
||||
identifiers:
|
||||
username: charlie
|
||||
attrs:
|
||||
name: Authentik Charlie
|
||||
email: charlie@haze.test
|
||||
password: password
|
||||
type: internal
|
||||
groups:
|
||||
- !KeyOf authentik-group3
|
||||
Loading…
Add table
Add a link
Reference in a new issue