feat(tei): update to kanidm-develop

OAuth 2.0 localhost redirects aren't part of a kanidm release yet.
This commit is contained in:
arcnmx 2024-01-21 17:01:06 -08:00
parent c1faa39712
commit 2039c1a9dd
5 changed files with 23 additions and 3 deletions

View file

@ -2,6 +2,7 @@
config,
lib,
meta,
pkgs,
...
}: let
inherit (lib.modules) mkIf mkMerge;
@ -29,6 +30,13 @@ in {
sops.defaultSopsFile = ./secrets.yaml;
services.kanidm = {
package = lib.warnIf
(pkgs.kanidm.version != "1.1.0-rc.15")
"upstream kanidm may have localhost oauth2 support now!"
pkgs.kanidm-develop;
};
networking.firewall = {
interfaces.local.allowedTCPPorts = mkMerge [
(mkIf kanidm.enableServer [