feat(vouch): separate local cookie

This commit is contained in:
arcnmx 2024-09-04 16:45:38 -07:00
parent 5cbde2e43f
commit b8e5fda0a7
6 changed files with 88 additions and 33 deletions

View file

@ -26,7 +26,7 @@ in {
nixos.ddclient
nixos.acme
nixos.nginx
nixos.vouch
nixos.vouch.local
nixos.access.nginx
nixos.access.global
nixos.access.mosquitto
@ -77,13 +77,6 @@ in {
};
};
# configure a secondary vouch instance for local clients, but don't use it by default
services.vouch-proxy = {
authUrl = "https://${virtualHosts.keycloak'local.serverName}/realms/${config.networking.domain}";
domain = "login.local.${config.networking.domain}";
settings.cookie.domain = "local.${config.networking.domain}";
};
security.acme.certs = {
hakurei = {
inherit (nginx) group;