1amends "../../config/Service.pkl"
2
3import "../../config/site.pkl" as site
4import "../../config/OpenID.pkl" as sso
5
6local isPreview = read?("prop:preview") == "true"
7
8meta { name = "Forward Auth" }
9rollout = "overlapped"
10
11requirements {
12 new sso.Client {
13 clientId = module.id
14 name = module.meta.name
15 redirectUris {
16 when (isPreview) { "https://\(module.id).\(site.domain)/snow.oauth2/callback" }
17 when (!isPreview) { for (host in new Listing<String> { "music"; "seedbox"; "ddns"; "redis"; "pg"; "snr"; "rdr"; "logs"; "metrics"; "traces"; "jkt" }) {
18 "https://\(host).\(site.domain)/snow.oauth2/callback"
19 } }
20 }
21 }
22}
23
24secrets {
25 ["cookie"] { bytes = 16 }
26}
27
28container {
29 image = "quay.io/oauth2-proxy/oauth2-proxy@sha256:56e3daedf765c7a1eea6e366fbe684be7d3084830ade14b6174570d3c7960954"
30 cpu = 100
31 memory = 256
32 extraHosts { "\(sso.hostname):host-gateway" }
33
34 http {
35 containerPort = 4180
36 checkPath = "/ping"
37 subdomain = if (isPreview) module.id else null
38 }
39
40 volumes {
41 ["/etc/ssl/certs/ca-certificates.crt"] {
42 src = "/var/lib/studio/ca-bundle.crt"
43 readOnly = true
44 }
45 }
46
47 env {
48 ["OAUTH2_PROXY_CLIENT_ID"] = "${secret.oidc.clientId}"
49 ["OAUTH2_PROXY_CLIENT_SECRET"] = "${secret.oidc.clientSecret}"
50 ["OAUTH2_PROXY_COOKIE_SECRET"] = "${secret.own.cookie}"
51 ["OAUTH2_PROXY_PROVIDER"] = "oidc"
52 ["OAUTH2_PROXY_OIDC_ISSUER_URL"] = sso.issuer
53 ["OAUTH2_PROXY_SCOPE"] = "openid profile email groups"
54 ["OAUTH2_PROXY_OIDC_GROUPS_CLAIM"] = "groups"
55 // Existing accounts may have no email.
56 ["OAUTH2_PROXY_OIDC_EMAIL_CLAIM"] = "preferred_username"
57 ["OAUTH2_PROXY_CODE_CHALLENGE_METHOD"] = "S256"
58 ["OAUTH2_PROXY_EMAIL_DOMAINS"] = "*"
59 ["OAUTH2_PROXY_HTTP_ADDRESS"] = "0.0.0.0:4180"
60 ["OAUTH2_PROXY_PROXY_PREFIX"] = "/snow.oauth2"
61 ["OAUTH2_PROXY_SKIP_PROVIDER_BUTTON"] = "true"
62 ["OAUTH2_PROXY_REVERSE_PROXY"] = "true"
63 ["OAUTH2_PROXY_WHITELIST_DOMAINS"] = "*.\(site.domain)"
64 ["OAUTH2_PROXY_COOKIE_DOMAINS"] = ".\(site.domain)"
65 when (isPreview) { ["OAUTH2_PROXY_COOKIE_NAME"] = "_snow_stage_\(module.id)" }
66 ["OAUTH2_PROXY_SET_XAUTHREQUEST"] = "true"
67 ["OAUTH2_PROXY_PASS_USER_HEADERS"] = "true"
68 ["OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL"] = "true"
69 ["OAUTH2_PROXY_UPSTREAMS"] = "static://202"
70 }
71}