From 112416454aac46c21dcc1e1ec3864ab2c3a83fd2 Mon Sep 17 00:00:00 2001 From: Adam0 Date: Sun, 7 Jun 2026 00:24:27 +0200 Subject: [PATCH] authentik --- flake.lock | 325 ++++++++++++++---- flake.nix | 8 +- modules/hosts/euclid/default.nix | 1 + modules/nix/determinate.nix | 4 +- modules/nix/home-manager.nix | 8 +- modules/programs/cli/eh.nix | 67 ---- .../tui/opencode/skills/nix/search.md | 3 +- .../programs/tui/television/nix-search.nix | 16 + modules/services/authentik.nix | 59 ++++ modules/services/crowdsec.nix | 11 + modules/services/traefik.nix | 94 +++-- secrets.yaml | 6 +- 12 files changed, 424 insertions(+), 178 deletions(-) delete mode 100644 modules/programs/cli/eh.nix create mode 100644 modules/services/authentik.nix diff --git a/flake.lock b/flake.lock index 4cd70d9..9ad7c0b 100644 --- a/flake.lock +++ b/flake.lock @@ -33,6 +33,52 @@ "type": "github" } }, + "authentik-nix": { + "inputs": { + "authentik-src": "authentik-src", + "flake-compat": "flake-compat", + "flake-parts": [ + "flake-parts" + ], + "flake-utils": "flake-utils", + "napalm": "napalm", + "nixpkgs": "nixpkgs", + "pyproject-build-systems": "pyproject-build-systems", + "pyproject-nix": "pyproject-nix", + "systems": "systems", + "uv2nix": "uv2nix" + }, + "locked": { + "lastModified": 1780582607, + "narHash": "sha256-zAJcOvOHBdaqnmGXxeXPwIgQ3p4VDMt8ecJ2sl4cdjQ=", + "owner": "nix-community", + "repo": "authentik-nix", + "rev": "7611d20f7a0db3e08bd94b3cb3948d8e38958776", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "authentik-nix", + "type": "github" + } + }, + "authentik-src": { + "flake": false, + "locked": { + "lastModified": 1779981174, + "narHash": "sha256-djsdph2E+JIIu9Sy5gJwBG378nunXXK2LPW5z/oneMs=", + "owner": "goauthentik", + "repo": "authentik", + "rev": "2d26ce9b538df68b9d78dccdd5ac5bfb4c1b2983", + "type": "github" + }, + "original": { + "owner": "goauthentik", + "ref": "version/2026.5.2", + "repo": "authentik", + "type": "github" + } + }, "base16": { "inputs": { "fromYaml": "fromYaml" @@ -201,7 +247,7 @@ "determinate-nixd-aarch64-linux": "determinate-nixd-aarch64-linux", "determinate-nixd-x86_64-linux": "determinate-nixd-x86_64-linux", "nix": "nix", - "nixpkgs": "nixpkgs_2" + "nixpkgs": "nixpkgs_3" }, "locked": { "lastModified": 1779475417, @@ -289,26 +335,6 @@ "type": "github" } }, - "eh": { - "inputs": { - "nixpkgs": [ - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1779984401, - "narHash": "sha256-NmHQCjNHSP52KP2bfSb0bQ4Ej8kFqLOmTOX47ukKjGE=", - "owner": "NotAShelf", - "repo": "eh", - "rev": "b0f0ea0c45c0fdf00441374c94f9d5aa0fd1aeb0", - "type": "github" - }, - "original": { - "owner": "NotAShelf", - "repo": "eh", - "type": "github" - } - }, "firefox-gnome-theme": { "flake": false, "locked": { @@ -326,6 +352,22 @@ } }, "flake-compat": { + "flake": false, + "locked": { + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", + "owner": "edolstra", + "repo": "flake-compat", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", + "type": "github" + }, + "original": { + "owner": "edolstra", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-compat_2": { "flake": false, "locked": { "lastModified": 1696426674, @@ -341,7 +383,7 @@ "type": "github" } }, - "flake-compat_2": { + "flake-compat_3": { "flake": false, "locked": { "lastModified": 1767039857, @@ -357,7 +399,7 @@ "type": "github" } }, - "flake-compat_3": { + "flake-compat_4": { "flake": false, "locked": { "lastModified": 1761588595, @@ -373,7 +415,7 @@ "type": "github" } }, - "flake-compat_4": { + "flake-compat_5": { "flake": false, "locked": { "lastModified": 1767039857, @@ -389,7 +431,7 @@ "type": "github" } }, - "flake-compat_5": { + "flake-compat_6": { "locked": { "lastModified": 1733328505, "narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=", @@ -403,7 +445,7 @@ "url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz" } }, - "flake-compat_6": { + "flake-compat_7": { "flake": false, "locked": { "lastModified": 1777699697, @@ -493,6 +535,27 @@ "type": "github" } }, + "flake-utils": { + "inputs": { + "systems": [ + "authentik-nix", + "systems" + ] + }, + "locked": { + "lastModified": 1731533236, + "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "flake-utils", + "type": "github" + } + }, "fromYaml": { "flake": false, "locked": { @@ -511,7 +574,7 @@ }, "git-hooks-nix": { "inputs": { - "flake-compat": "flake-compat", + "flake-compat": "flake-compat_2", "gitignore": [ "determinate", "nix" @@ -627,7 +690,7 @@ "nixpkgs": [ "nixpkgs" ], - "systems": "systems", + "systems": "systems_2", "treefmt-nix": [ "treefmt-nix" ] @@ -715,9 +778,9 @@ "hyprutils": "hyprutils", "hyprwayland-scanner": "hyprwayland-scanner", "hyprwire": "hyprwire", - "nixpkgs": "nixpkgs_3", + "nixpkgs": "nixpkgs_4", "pre-commit-hooks": "pre-commit-hooks", - "systems": "systems_2", + "systems": "systems_3", "xdph": "xdph" }, "locked": { @@ -1051,6 +1114,32 @@ "type": "github" } }, + "napalm": { + "inputs": { + "flake-utils": [ + "authentik-nix", + "flake-utils" + ], + "nixpkgs": [ + "authentik-nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1725806412, + "narHash": "sha256-lGZjkjds0p924QEhm/r0BhAxbHBJE1xMOldB/HmQH04=", + "owner": "willibutz", + "repo": "napalm", + "rev": "b492440d9e64ae20736d3bec5c7715ffcbde83f5", + "type": "github" + }, + "original": { + "owner": "willibutz", + "ref": "avoid-foldl-stack-overflow", + "repo": "napalm", + "type": "github" + } + }, "ndg": { "inputs": { "nixpkgs": [ @@ -1077,7 +1166,7 @@ "inputs": { "flake-parts": "flake-parts", "git-hooks-nix": "git-hooks-nix", - "nixpkgs": "nixpkgs", + "nixpkgs": "nixpkgs_2", "nixpkgs-23-11": "nixpkgs-23-11", "nixpkgs-regression": "nixpkgs-regression" }, @@ -1098,9 +1187,9 @@ "inputs": { "cachyos-kernel": "cachyos-kernel", "cachyos-kernel-patches": "cachyos-kernel-patches", - "flake-compat": "flake-compat_4", + "flake-compat": "flake-compat_5", "flake-parts": "flake-parts_3", - "nixpkgs": "nixpkgs_4" + "nixpkgs": "nixpkgs_5" }, "locked": { "lastModified": 1780253365, @@ -1188,7 +1277,7 @@ "nixpkgs": [ "nixpkgs" ], - "systems": "systems_3", + "systems": "systems_4", "treefmt-nix": [ "treefmt-nix" ] @@ -1209,11 +1298,11 @@ }, "nixcord": { "inputs": { - "flake-compat": "flake-compat_5", + "flake-compat": "flake-compat_6", "flake-parts": [ "flake-parts" ], - "nixpkgs": "nixpkgs_5", + "nixpkgs": "nixpkgs_6", "nixpkgs-nixcord": "nixpkgs-nixcord" }, "locked": { @@ -1232,16 +1321,18 @@ }, "nixpkgs": { "locked": { - "lastModified": 1773222311, - "narHash": "sha256-BHoB/XpbqoZkVYZCfXJXfkR+GXFqwb/4zbWnOr2cRcU=", - "rev": "0590cd39f728e129122770c029970378a79d076a", - "revCount": 909248, - "type": "tarball", - "url": "https://api.flakehub.com/f/pinned/NixOS/nixpkgs/0.2511.909248%2Brev-0590cd39f728e129122770c029970378a79d076a/019ce32b-8ace-7339-b129-cceaa8dd10c6/source.tar.gz" + "lastModified": 1779560665, + "narHash": "sha256-tpyBcxPpcQb8ukyNF7DoCwfSY3VPsxHoYwj00Cayv5o=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "64c08a7ca051951c8eae34e3e3cb1e202fe36786", + "type": "github" }, "original": { - "type": "tarball", - "url": "https://flakehub.com/f/NixOS/nixpkgs/0.2511" + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" } }, "nixpkgs-23-11": { @@ -1324,6 +1415,20 @@ } }, "nixpkgs_2": { + "locked": { + "lastModified": 1773222311, + "narHash": "sha256-BHoB/XpbqoZkVYZCfXJXfkR+GXFqwb/4zbWnOr2cRcU=", + "rev": "0590cd39f728e129122770c029970378a79d076a", + "revCount": 909248, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/NixOS/nixpkgs/0.2511.909248%2Brev-0590cd39f728e129122770c029970378a79d076a/019ce32b-8ace-7339-b129-cceaa8dd10c6/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/NixOS/nixpkgs/0.2511" + } + }, + "nixpkgs_3": { "locked": { "lastModified": 1778869304, "narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=", @@ -1337,7 +1442,7 @@ "url": "https://flakehub.com/f/DeterminateSystems/nixpkgs-weekly/0.1" } }, - "nixpkgs_3": { + "nixpkgs_4": { "locked": { "lastModified": 1778443072, "narHash": "sha256-zi7/fsqM/kFdNuED//4WOCUtezGtKKqRNORjMvfwjnA=", @@ -1353,7 +1458,7 @@ "type": "github" } }, - "nixpkgs_4": { + "nixpkgs_5": { "locked": { "lastModified": 1780206209, "narHash": "sha256-33WNQ5sssy+8+xhUz953aEnjR1Oh828j0DgLU1TfMqE=", @@ -1369,7 +1474,7 @@ "type": "github" } }, - "nixpkgs_5": { + "nixpkgs_6": { "locked": { "lastModified": 1780453794, "narHash": "sha256-bXMRa9VTsHSPXL4Cw8R6JJLQeY3Y/IP4+YJCYVmQ7FY=", @@ -1385,7 +1490,7 @@ "type": "github" } }, - "nixpkgs_6": { + "nixpkgs_7": { "locked": { "lastModified": 1780365719, "narHash": "sha256-JX05Ms/dk0c+UoW9IqQriB53HNZFckX9Qd3EJqmcqEw=", @@ -1427,7 +1532,7 @@ "nixpkgs": [ "nixpkgs" ], - "systems": "systems_4", + "systems": "systems_5", "treefmt-nix": "treefmt-nix" }, "locked": { @@ -1469,7 +1574,7 @@ }, "nvf": { "inputs": { - "flake-compat": "flake-compat_6", + "flake-compat": "flake-compat_7", "flake-parts": [ "flake-parts" ], @@ -1478,7 +1583,7 @@ "nixpkgs": [ "nixpkgs" ], - "systems": "systems_5" + "systems": "systems_6" }, "locked": { "lastModified": 1779458887, @@ -1506,7 +1611,7 @@ "nixpkgs": [ "nixpkgs" ], - "systems": "systems_6", + "systems": "systems_7", "treefmt-nix": [ "treefmt-nix" ] @@ -1527,7 +1632,7 @@ }, "pre-commit": { "inputs": { - "flake-compat": "flake-compat_3", + "flake-compat": "flake-compat_4", "gitignore": "gitignore_2", "nixpkgs": [ "lanzaboote", @@ -1550,7 +1655,7 @@ }, "pre-commit-hooks": { "inputs": { - "flake-compat": "flake-compat_2", + "flake-compat": "flake-compat_3", "gitignore": "gitignore", "nixpkgs": [ "hyprland", @@ -1571,11 +1676,61 @@ "type": "github" } }, + "pyproject-build-systems": { + "inputs": { + "nixpkgs": [ + "authentik-nix", + "nixpkgs" + ], + "pyproject-nix": [ + "authentik-nix", + "pyproject-nix" + ], + "uv2nix": [ + "authentik-nix", + "uv2nix" + ] + }, + "locked": { + "lastModified": 1779676664, + "narHash": "sha256-MbXylBTkWqVm8/VYjoULtMoVRgWBN1gSHbeRKsOsPlU=", + "owner": "pyproject-nix", + "repo": "build-system-pkgs", + "rev": "7bff980f37fc24e09dbc986643719900c139bf12", + "type": "github" + }, + "original": { + "owner": "pyproject-nix", + "repo": "build-system-pkgs", + "type": "github" + } + }, + "pyproject-nix": { + "inputs": { + "nixpkgs": [ + "authentik-nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1778901413, + "narHash": "sha256-GSKXTAnFqRAMlZkJrIPcQMYf+lpMr66K3i60mB9STvc=", + "owner": "pyproject-nix", + "repo": "pyproject.nix", + "rev": "a228447c3e179d477c1b6246ef3efa8cfe3c469a", + "type": "github" + }, + "original": { + "owner": "pyproject-nix", + "repo": "pyproject.nix", + "type": "github" + } + }, "root": { "inputs": { + "authentik-nix": "authentik-nix", "determinate": "determinate", "disko": "disko", - "eh": "eh", "flake-file": "flake-file", "flake-parts": "flake-parts_2", "home-manager": "home-manager", @@ -1589,7 +1744,7 @@ "nix-index-database": "nix-index-database", "nix-userstyles": "nix-userstyles", "nixcord": "nixcord", - "nixpkgs": "nixpkgs_6", + "nixpkgs": "nixpkgs_7", "nixpkgs-crowdsec": "nixpkgs-crowdsec", "noctalia": "noctalia", "noctalia-qs": "noctalia-qs", @@ -1671,7 +1826,7 @@ "nixpkgs": [ "nixpkgs" ], - "systems": "systems_7" + "systems": "systems_8" }, "locked": { "lastModified": 1780422259, @@ -1704,7 +1859,7 @@ "nur": [ "nur" ], - "systems": "systems_8", + "systems": "systems_9", "tinted-kitty": "tinted-kitty", "tinted-schemes": "tinted-schemes", "tinted-tmux": "tinted-tmux", @@ -1725,6 +1880,21 @@ } }, "systems": { + "locked": { + "lastModified": 1689347949, + "narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=", + "owner": "nix-systems", + "repo": "default-linux", + "rev": "31732fcf5e8fea42e59c2488ad31a0e651500f68", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default-linux", + "type": "github" + } + }, + "systems_2": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1739,7 +1909,7 @@ "type": "github" } }, - "systems_2": { + "systems_3": { "locked": { "lastModified": 1689347949, "narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=", @@ -1754,7 +1924,7 @@ "type": "github" } }, - "systems_3": { + "systems_4": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1769,7 +1939,7 @@ "type": "github" } }, - "systems_4": { + "systems_5": { "locked": { "lastModified": 1689347949, "narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=", @@ -1784,7 +1954,7 @@ "type": "github" } }, - "systems_5": { + "systems_6": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1799,7 +1969,7 @@ "type": "github" } }, - "systems_6": { + "systems_7": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1814,7 +1984,7 @@ "type": "github" } }, - "systems_7": { + "systems_8": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1829,7 +1999,7 @@ "type": "github" } }, - "systems_8": { + "systems_9": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1971,6 +2141,31 @@ "type": "github" } }, + "uv2nix": { + "inputs": { + "nixpkgs": [ + "authentik-nix", + "nixpkgs" + ], + "pyproject-nix": [ + "authentik-nix", + "pyproject-nix" + ] + }, + "locked": { + "lastModified": 1779411315, + "narHash": "sha256-IMFlxeyClau51KplhhSRGhdGTvD/knShHdybP1UOTuk=", + "owner": "pyproject-nix", + "repo": "uv2nix", + "rev": "fdf2a76275d7a9c27deb5d2f2ab33526ac9052ff", + "type": "github" + }, + "original": { + "owner": "pyproject-nix", + "repo": "uv2nix", + "type": "github" + } + }, "xdph": { "inputs": { "hyprland-protocols": [ diff --git a/flake.nix b/flake.nix index d81ab9c..4f5db2a 100644 --- a/flake.nix +++ b/flake.nix @@ -4,15 +4,15 @@ outputs = inputs: inputs.flake-parts.lib.mkFlake { inherit inputs; } (inputs.import-tree ./modules); inputs = { + authentik-nix = { + url = "github:nix-community/authentik-nix"; + inputs.flake-parts.follows = "flake-parts"; + }; determinate.url = "https://flakehub.com/f/DeterminateSystems/determinate/3"; disko = { url = "github:nix-community/disko?ref=latest"; inputs.nixpkgs.follows = "nixpkgs"; }; - eh = { - url = "github:NotAShelf/eh"; - inputs.nixpkgs.follows = "nixpkgs"; - }; flake-file.url = "github:vic/flake-file"; flake-parts = { url = "github:hercules-ci/flake-parts"; diff --git a/modules/hosts/euclid/default.nix b/modules/hosts/euclid/default.nix index cdf8a64..01d980e 100644 --- a/modules/hosts/euclid/default.nix +++ b/modules/hosts/euclid/default.nix @@ -6,6 +6,7 @@ # Services # keep-sorted start + authentik crowdsec-server godns mysql diff --git a/modules/nix/determinate.nix b/modules/nix/determinate.nix index 9b612ed..6c2dec1 100644 --- a/modules/nix/determinate.nix +++ b/modules/nix/determinate.nix @@ -1,7 +1,5 @@ {inputs, ...}: { - flake-file.inputs = { - determinate.url = "https://flakehub.com/f/DeterminateSystems/determinate/3"; - }; + flake-file.inputs.determinate.url = "https://flakehub.com/f/DeterminateSystems/determinate/3"; flake.modules.generic.determinate = {pkgs, ...}: let inherit (pkgs.stdenv.hostPlatform) system; diff --git a/modules/nix/home-manager.nix b/modules/nix/home-manager.nix index e5c86e6..ffff1a7 100644 --- a/modules/nix/home-manager.nix +++ b/modules/nix/home-manager.nix @@ -7,11 +7,9 @@ flake.homeModules = self.modules.homeManager; - flake-file.inputs = { - home-manager = { - url = "github:nix-community/home-manager"; - inputs.nixpkgs.follows = "nixpkgs"; - }; + flake-file.inputs.home-manager = { + url = "github:nix-community/home-manager"; + inputs.nixpkgs.follows = "nixpkgs"; }; flake.modules.nixos.home-manager = { diff --git a/modules/programs/cli/eh.nix b/modules/programs/cli/eh.nix deleted file mode 100644 index 9148ad1..0000000 --- a/modules/programs/cli/eh.nix +++ /dev/null @@ -1,67 +0,0 @@ -{ - # keep-sorted start - inputs, - self, - # keep-sorted end - ... -}: { - flake-file.inputs = { - eh = { - url = "github:NotAShelf/eh"; - inputs.nixpkgs.follows = "nixpkgs"; - }; - }; - - flake.modules.homeManager.eh = { - # keep-sorted start - lib, - pkgs, - # keep-sorted end - ... - }: let - inherit - (lib) - # keep-sorted start - getExe - getExe' - # keep-sorted end - ; - inherit (pkgs) writeShellApplication; - - # keep-sorted start - eh = getExe pkgs.eh; - nix = getExe' pkgs.nix "nix"; - # keep-sorted end - - nixWrapper = writeShellApplication { - name = "nix"; - text = '' - case "''${1-}" in - build|develop|run|shell) - exec ${eh} "$@" - ;; - flake) - if [[ $# -ge 2 && "''${2-}" == update ]]; then - shift 2 - exec ${eh} update "$@" - fi - ;; - esac - - exec ${nix} "$@" - ''; - }; - in { - home.packages = [pkgs.eh nixWrapper]; - }; - - flake.modules.nixos.eh = { - nixpkgs.overlays = [self.overlays.eh]; - }; - - flake.overlays.eh = final: _prev: let - inherit (final.stdenv.hostPlatform) system; - in { - inherit (inputs.eh.packages.${system}) eh; - }; -} diff --git a/modules/programs/tui/opencode/skills/nix/search.md b/modules/programs/tui/opencode/skills/nix/search.md index aac8676..c4ad151 100644 --- a/modules/programs/tui/opencode/skills/nix/search.md +++ b/modules/programs/tui/opencode/skills/nix/search.md @@ -5,7 +5,7 @@ description: Use this skill to search NixOS packages and options with `nix-searc # Nix Search -Use `nix-search-tv` for packages/options. Builtin indexes: `nixpkgs`, `home-manager`, `nixos`, `nur`, `noogle`. Custom option indexes: `disko`, `home-manager-nixos`, `lanzaboote`, `nix-flatpak`, `nix-index-database`, `nixcord`, `noctalia`, `nvf`, `overzicht`, `sops-nix`, `sops-nix-home-manager`, `spicetify-nix`, `stylix`, `stylix-home-manager`, `zen-browser`. +Use `nix-search-tv` for packages/options. Builtin indexes: `home-manager`, `nixos`, `nixpkgs`, `noogle`, `nur`. Custom option indexes: `authentik-nix`, `determinate`, `disko`, `home-manager-nixos`, `hylix`, `lanzaboote`, `nix-flatpak`, `nix-index-database`, `nixcord`, `noctalia`, `nvf`, `overzicht`, `sops-nix`, `sops-nix-home-manager`, `spicetify-nix`, `stylix`, `stylix-home-manager`, `zen-browser`. This repo wires builtin indexes through `settings.indexes` and custom option sources through `settings.experimental.options_file`; both use `--indexes `. @@ -19,6 +19,7 @@ nix-search-tv preview --indexes nixpkgs firefox nix-search-tv preview --indexes nixos boot.loader.systemd-boot.enable nix-search-tv preview --indexes zen-browser enable nix-search-tv preview --indexes nixpkgs --json firefox +nix-search-tv source --indexes authentik-nix services.authentik nix-search-tv source --indexes noctalia programs.noctalia-shell.settings.bar nix-search-tv homepage --indexes nixpkgs firefox ``` diff --git a/modules/programs/tui/television/nix-search.nix b/modules/programs/tui/television/nix-search.nix index 8a6a0b7..a9c460b 100644 --- a/modules/programs/tui/television/nix-search.nix +++ b/modules/programs/tui/television/nix-search.nix @@ -168,6 +168,22 @@ # NixOS-backed sources. # keep-sorted start block=yes newline_separated=yes + authentik-nix = { + rawDoc = mkNixosDoc inputs.authentik-nix.nixosModules.default; + prefixes = [ + "services.authentik" + "services.authentik-ldap" + "services.authentik-proxy" + "services.authentik-rac" + "services.authentik-radius" + ]; + }; + + determinate = { + rawDoc = mkNixosDoc inputs.determinate.nixosModules.default; + prefixes = ["determinate"]; + }; + disko = { rawDoc = mkNixosDoc inputs.disko.nixosModules.disko; prefixes = ["disko"]; diff --git a/modules/services/authentik.nix b/modules/services/authentik.nix new file mode 100644 index 0000000..f50ba45 --- /dev/null +++ b/modules/services/authentik.nix @@ -0,0 +1,59 @@ +{inputs, ...}: { + flake-file.inputs.authentik-nix = { + url = "github:nix-community/authentik-nix"; + inputs.flake-parts.follows = "flake-parts"; + }; + + flake.modules.nixos.authentik = { + # keep-sorted start + config, + vars, + # keep-sorted end + ... + }: let + inherit (vars) groundDomain; + in { + imports = [inputs.authentik-nix.nixosModules.default]; + + sops = { + secrets = { + # keep-sorted start + "authentik/proxy_token" = {}; + "authentik/secret_key" = {}; + # keep-sorted end + }; + + templates = { + "authentik.env".content = '' + AUTHENTIK_SECRET_KEY=${config.sops.placeholder."authentik/secret_key"} + ''; + + "authentik-proxy.env".content = '' + AUTHENTIK_HOST=https://authentik.${groundDomain} + AUTHENTIK_TOKEN=${config.sops.placeholder."authentik/proxy_token"} + ''; + }; + }; + + services = { + authentik = { + enable = true; + environmentFile = config.sops.templates."authentik.env".path; + + settings = { + avatars = "gravatar"; + + # Disable unrequired features. + disable_startup_analytics = true; + disable_update_check = true; + error_reporting.enabled = false; + }; + }; + + authentik-proxy = { + enable = true; + environmentFile = config.sops.templates."authentik-proxy.env".path; + }; + }; + }; +} diff --git a/modules/services/crowdsec.nix b/modules/services/crowdsec.nix index 629170b..124c788 100644 --- a/modules/services/crowdsec.nix +++ b/modules/services/crowdsec.nix @@ -49,6 +49,7 @@ "crowdsecurity/linux" "crowdsecurity/sshd" "crowdsecurity/traefik" + "firix/authentik" # keep-sorted end ]; }; @@ -69,6 +70,15 @@ source = "file"; } + { + journalctl_filter = [ + "_SYSTEMD_UNIT=authentik.service" + "_SYSTEMD_UNIT=authentik-worker.service" + ]; + labels.type = "authentik"; + source = "journalctl"; + } + { journalctl_filter = ["_SYSTEMD_UNIT=sshd.service"]; labels.type = "syslog"; @@ -197,6 +207,7 @@ User = config.services.crowdsec.user; }; }; + # keep-sorted end }; }; diff --git a/modules/services/traefik.nix b/modules/services/traefik.nix index 0930929..de919c4 100644 --- a/modules/services/traefik.nix +++ b/modules/services/traefik.nix @@ -20,11 +20,6 @@ }; "traefik/mail" = {}; - - "traefik/redis_crowdsec_password" = { - owner = "traefik"; - mode = "0400"; - }; # keep-sorted end }; @@ -35,16 +30,6 @@ services = { # keep-sorted start block=yes newline_separated=yes - redis.servers.traefik-crowdsec = { - enable = true; - bind = "127.0.0.1"; - port = 6379; - databases = 1; - maxclients = 64; - save = []; - requirePassFile = secrets."traefik/redis_crowdsec_password".path; - }; - traefik = { enable = true; group = "podman"; @@ -118,26 +103,73 @@ }; dynamicConfigOptions = { - http.middlewares = { - redirect-to-https.redirectscheme = { - scheme = "https"; - permanent = true; + http = { + middlewares = { + authentik.forwardAuth = { + address = "http://[::1]:9005/outpost.goauthentik.io/auth/traefik"; + trustForwardHeader = true; + authResponseHeaders = [ + # keep-sorted start + "X-authentik-email" + "X-authentik-entitlements" + "X-authentik-groups" + "X-authentik-jwt" + "X-authentik-meta-app" + "X-authentik-meta-jwks" + "X-authentik-meta-outpost" + "X-authentik-meta-provider" + "X-authentik-meta-version" + "X-authentik-name" + "X-authentik-uid" + "X-authentik-username" + # keep-sorted end + ]; + }; + + crowdsec.plugin.bouncer = { + enabled = true; + crowdsecMode = "appsec"; + crowdsecAppsecEnabled = true; + crowdsecAppsecHost = "127.0.0.1:7424"; + crowdsecAppsecKeyFile = secrets."traefik/crowdsec_bouncer_key".path; + }; + + redirect-to-https.redirectscheme = { + scheme = "https"; + permanent = true; + }; }; - crowdsec.plugin.bouncer = { - enabled = true; - crowdsecMode = "stream"; - crowdsecLapiHost = "127.0.0.1:8080"; - crowdsecLapiKeyFile = secrets."traefik/crowdsec_bouncer_key".path; + routers = { + authentik = { + entryPoints = ["websecure"]; + rule = "Host(`authentik.${groundDomain}`)"; + service = "authentik"; + }; + + authentik-outpost = { + entryPoints = ["websecure"]; + priority = 15; + rule = "PathPrefix(`/outpost.goauthentik.io/`)"; + service = "authentik-outpost"; + }; + + traefik-dashboard = { + entryPoints = ["websecure"]; + middlewares = ["authentik@file"]; + rule = "Host(`traefik.${groundDomain}`)"; + service = "api@internal"; + }; + }; - crowdsecAppsecEnabled = true; - crowdsecAppsecHost = "127.0.0.1:7424"; - crowdsecAppsecKeyFile = secrets."traefik/crowdsec_bouncer_key".path; + services = { + authentik.loadBalancer.servers = [ + {url = "http://[::1]:9000";} + ]; - redisCacheEnabled = true; - redisCacheHost = "127.0.0.1:6379"; - redisCachePasswordFile = secrets."traefik/redis_crowdsec_password".path; - redisCacheDatabase = "0"; + authentik-outpost.loadBalancer.servers = [ + {url = "http://[::1]:9005/outpost.goauthentik.io";} + ]; }; }; diff --git a/secrets.yaml b/secrets.yaml index 7094d7f..f62ef67 100644 --- a/secrets.yaml +++ b/secrets.yaml @@ -48,6 +48,8 @@ traefik: mail: ENC[AES256_GCM,data:kU+b4zXyyVmT85TYvV3yaOwsy+DEbw==,iv:aE96ngF6yC+ayp/X0jPcDyr9wHPL0ItJjq4x/9IVhnA=,tag:UqeJHyHVwCMgltCzxFfAaQ==,type:str] redis_crowdsec_password: ENC[AES256_GCM,data:bdsMoMhwYv6oZBz1cChD03wSRQwwWNNbKd9hIcM0Ls2lM5kAj2iEMRfDzoA=,iv:uFRAZvN2hH3XKmzY0EAH66rlRbKVipHd3VVQc38FpeQ=,tag:qV7YbHTizliEFcAuWweZ4A==,type:str] crowdsec_bouncer_key: ENC[AES256_GCM,data:NogMDioHUe+mKwtpCwF5xhABv9asVg0bbTx5yIVucb5g5OHWD2BO2dykWsg=,iv:cmnFSJXvNStbARyBKNeUdoV/OG04wqQBLYRfn/zXiFA=,tag:nk9+Fr69pl6ciROtBe/Vvg==,type:str] +authentik: + secret_key: ENC[AES256_GCM,data:YxLwQVyVSA3bh6UsYRc8jkI/Ff0Jjqt2cfVyVovTfiyR8vgivpppR2sKq8Q6J1E4rDSL83N3iqU8/wTZKrHhnjyebpcl4oqo6RYIiEx80fU=,iv:RIb84Gic36jzBgOuu55nwBr54AoSO8690VuW0mYHvY4=,tag:iKFjHaz3SVgSNkKQrcM7uQ==,type:str] sops: age: - enc: | @@ -86,8 +88,8 @@ sops: w2ToACYVigKMSlqPNG9bKcK75XI/iAONG48DQm1Nse3yB9/q3jwd+Q== -----END AGE ENCRYPTED FILE----- recipient: age1yl52c6aemw9anmfuqayamvsnkvlu6fmy0kk3gzvrraexxd9pr90qvs8pe5 - lastmodified: "2026-06-06T17:11:29Z" - mac: ENC[AES256_GCM,data:WN34D+bJIPg7ztOQIQ0tK0aBHeoO2XUAW3u3SbocSZCU3IiKPfEmB4NnXjqtF34ce1a1NBrrCCnMa3m037XNYXtmyyzXXCMy00OLZHMVKUooDiAHCq0mFMFWk5CncK1dXEtReM3g19KW8mPqN+snS2ZHfWXo8/CCLyUcw+Sm0Vs=,iv:sHtY3/6/0Rwti/E3j6amxRz371vlEVVAOIK+2A4+bnM=,tag:0GF/m2GmSSw4KpWFajXOKw==,type:str] + lastmodified: "2026-06-06T20:51:26Z" + mac: ENC[AES256_GCM,data:bD/W1n0gGHtzn+mX+Hz8mv61uTvcH3SXGnPWHk5AWMqKLhrNM5cmEiGxVp8idb8OBerB60TvFsrULLJ3IATsHJPep/gtrDeC/O2R8DDOxgfYZu+I2Io8IrgIiFaaFh7yZsKrO2vbrlqBj1WzEfKjQ0oUvUwgJoBvwZFvSrlPi+w=,iv:6146XWaPlxzcYUidSfyjAHaqJEpxyAHfREVnlUonsbM=,tag:Rnb01bq6crQXJOgQTz9kLA==,type:str] pgp: - created_at: "2026-06-02T01:50:38Z" enc: |- -- 2.51.2