2022-12-17 17:42:10 +01:00
|
|
|
{ config, ... }:
|
|
|
|
let
|
2022-12-02 14:25:55 +01:00
|
|
|
# temporary url, zum testen auf laptop zuhause
|
|
|
|
tld = "moe";
|
|
|
|
hostname = "eisvogel";
|
|
|
|
domain = "portunus.${hostname}.${tld}";
|
2022-12-17 13:58:06 +01:00
|
|
|
|
|
|
|
portunusUser = "portunus";
|
|
|
|
portunusGroup = "portunus";
|
|
|
|
|
|
|
|
ldapUser = "openldap";
|
|
|
|
ldapGroup = "openldap";
|
2022-12-17 17:42:10 +01:00
|
|
|
in
|
|
|
|
{
|
2022-12-17 13:58:06 +01:00
|
|
|
users.users."${portunusUser}" = {
|
|
|
|
isSystemUser = true;
|
|
|
|
group = "${portunusGroup}";
|
|
|
|
};
|
|
|
|
|
|
|
|
users.groups."${portunusGroup}" = {
|
|
|
|
name = "${portunusGroup}";
|
2022-12-17 17:42:10 +01:00
|
|
|
members = [ "${portunusUser}" ];
|
2022-12-17 13:58:06 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
users.users."${ldapUser}" = {
|
|
|
|
isSystemUser = true;
|
|
|
|
group = "${ldapGroup}";
|
|
|
|
};
|
|
|
|
|
|
|
|
users.groups."${ldapGroup}" = {
|
|
|
|
name = "${ldapGroup}";
|
2022-12-17 17:42:10 +01:00
|
|
|
members = [ "${ldapUser}" ];
|
2022-12-17 13:58:06 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
# TODO: eigenes secrets.yaml für seedfile?
|
2022-12-17 18:48:30 +01:00
|
|
|
sops.secrets."portunus_admin" = {
|
2022-12-17 13:58:06 +01:00
|
|
|
owner = "${portunusUser}";
|
|
|
|
group = "${portunusGroup}";
|
2022-12-02 14:25:55 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
services.portunus = {
|
|
|
|
enable = true;
|
2022-12-17 13:58:06 +01:00
|
|
|
user = "${portunusUser}";
|
|
|
|
group = "${portunusGroup}";
|
2022-12-02 14:25:55 +01:00
|
|
|
domain = "${domain}";
|
|
|
|
ldap = {
|
2022-12-17 13:58:06 +01:00
|
|
|
user = "${ldapUser}";
|
|
|
|
group = "${ldapGroup}";
|
2022-12-02 14:25:55 +01:00
|
|
|
suffix = "dc=${hostname},dc=${tld}";
|
|
|
|
tls = true;
|
|
|
|
};
|
|
|
|
|
2022-12-17 18:27:16 +01:00
|
|
|
seedPath = "../config/portunus_seeds.json";
|
2022-12-02 14:25:55 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
users.ldap = {
|
|
|
|
enable = true;
|
|
|
|
server = "ldaps://${domain}";
|
|
|
|
base = "dc=${hostname},dc=${tld}";
|
2022-12-17 13:58:06 +01:00
|
|
|
# useTLS = true; # nicht nötig weil ldaps domain festgelegt. würde sonst starttls auf port 389 versuchen
|
|
|
|
};
|
|
|
|
|
|
|
|
services.nginx = {
|
|
|
|
enable = true;
|
|
|
|
virtualHosts."${config.services.portunus.domain}" = {
|
|
|
|
forceSSL = true;
|
|
|
|
enableACME = true;
|
|
|
|
locations = {
|
|
|
|
"/".proxyPass = "http://localhost:${toString config.services.portunus.port}";
|
|
|
|
"/dex".proxyPass = "http://localhost:${toString config.services.portunus.dex.port}";
|
|
|
|
};
|
|
|
|
};
|
2022-12-02 14:25:55 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
networking.firewall.allowedTCPPorts = [
|
|
|
|
80 # http
|
|
|
|
443 # https
|
|
|
|
636 # ldaps
|
|
|
|
];
|
|
|
|
}
|