1
0
Fork 0
mirror of https://codeberg.org/icewind/haze.git synced 2026-10-01 08:44:09 +02:00

feat(services): Add Authentik to provide SAML

Signed-off-by: Louis Chmn <louis@chmn.me>
This commit is contained in:
Louis Chmn 2026-09-06 16:12:44 +02:00
commit c8d6cb170a
11 changed files with 622 additions and 3 deletions

View file

@ -1,3 +1,4 @@
mod authentik;
mod clam;
mod dav;
mod imaginary;
@ -18,6 +19,7 @@ mod webhook;
use crate::cloud::CloudOptions;
use crate::config::{HazeConfig, Preset, ProxyConfig};
pub use crate::service::authentik::{Authentik, AuthentikSaml};
pub use crate::service::clam::{Clam, ClamIcap, ClamIcapTls, ClamSocket};
use crate::service::dav::Dav;
use crate::service::imaginary::Imaginary;
@ -35,8 +37,8 @@ use crate::service::sftp::{Sftp, SftpKey};
use crate::service::sharded::{Sharding, ShardingMigrate, ShardingMigrateUnset, SingleShard};
use crate::service::smb::Smb;
use crate::service::webhook::Webhook;
use bollard::models::ContainerState;
use bollard::Docker;
use bollard::models::ContainerState;
use enum_dispatch::enum_dispatch;
use miette::{IntoDiagnostic, Report, Result, WrapErr};
use serde_json::Value;
@ -314,6 +316,10 @@ pub enum ServiceType {
Webhook,
/// Enable DB partitioning for mariadb
Partitioning,
/// Authentik identity provider
Authentik,
/// Configure Authentik as a SAML IDP for Nextcloud
Saml,
}
#[enum_dispatch]
@ -347,6 +353,8 @@ pub enum Service {
RedisTls(RedisTls),
FrankenPhp(FrankenPhp),
Webhook(Webhook),
Authentik(Authentik),
AuthentikSaml(AuthentikSaml),
Preset(PresetService),
}
@ -393,6 +401,11 @@ impl Service {
ServiceType::RedisTls => Some(vec![Service::RedisTls(RedisTls)]),
ServiceType::FrankenPhp => Some(vec![Service::FrankenPhp(FrankenPhp)]),
ServiceType::Webhook => Some(vec![Service::Webhook(Webhook)]),
ServiceType::Authentik => Some(vec![Service::Authentik(Authentik)]),
ServiceType::Saml => Some(vec![
Service::Authentik(Authentik),
Service::AuthentikSaml(AuthentikSaml),
]),
}
} else {
presets
@ -421,6 +434,18 @@ impl Service {
}
}
// Remove duplicate services.
// Useful for Authentik as it is needed by saml and oidc.
pub fn deduplicate_services(services: impl IntoIterator<Item = Service>) -> Vec<Service> {
let mut collected = Vec::new();
for service in services {
if !collected.contains(&service) {
collected.push(service);
}
}
collected
}
fn get_preset<'a>(presets: &'a [Preset], name: &str) -> Option<&'a Preset> {
presets.iter().find(|preset| preset.name == name)
}