mirror of
https://git.sr.ht/~rouven/nixos-config
synced 2024-11-15 05:13:10 +01:00
auth updates
This commit is contained in:
parent
3d76e6ecab
commit
bff20285d2
|
@ -12,7 +12,15 @@ in
|
|||
services.authentik = {
|
||||
enable = true;
|
||||
environmentFile = config.age.secrets.authentik-core.path;
|
||||
settings = {
|
||||
cert_discovery_dir = "env://CREDENTIALS_DIRECTORY";
|
||||
};
|
||||
};
|
||||
systemd.services.authentik-worker.serviceConfig.LoadCredential = [
|
||||
"${domain}.pem:/var/lib/caddy/certificates/acme-v02.api.letsencrypt.org-directory/${domain}/${domain}.crt"
|
||||
"${domain}.key:/var/lib/caddy/certificates/acme-v02.api.letsencrypt.org-directory/${domain}/${domain}.key"
|
||||
];
|
||||
|
||||
services.authentik-ldap = {
|
||||
enable = true;
|
||||
environmentFile = config.age.secrets.authentik-ldap.path;
|
||||
|
|
|
@ -72,6 +72,9 @@ in
|
|||
reverse_proxy /client/* unix//run/matrix-sliding-sync/server.sock
|
||||
reverse_proxy /_matrix/client/unstable/org.matrix.msc3575/sync* unix//run/matrix-sliding-sync/server.sock
|
||||
reverse_proxy 127.0.0.1:8008
|
||||
handle /_synapse/metrics* {
|
||||
respond 404
|
||||
}
|
||||
'';
|
||||
|
||||
# element
|
||||
|
|
Loading…
Reference in a new issue