From 006bcb47ce574d0b0d1aa69abfdebff181801269 Mon Sep 17 00:00:00 2001 From: imnyang Date: Mon, 7 Sep 2026 11:16:13 +0900 Subject: [PATCH] wow --- flake.lock | 1 + hosts/server/hikari/hako/services/caddy.nix | 8 +++--- .../hako/services/quadlet/authentik.nix | 25 ++++++++++++++++--- 3 files changed, 27 insertions(+), 7 deletions(-) diff --git a/flake.lock b/flake.lock index ae4b8a8..d42ee42 100644 --- a/flake.lock +++ b/flake.lock @@ -1104,3 +1104,4 @@ "root": "root", "version": 7 } + diff --git a/hosts/server/hikari/hako/services/caddy.nix b/hosts/server/hikari/hako/services/caddy.nix index 1e21210..628947e 100644 --- a/hosts/server/hikari/hako/services/caddy.nix +++ b/hosts/server/hikari/hako/services/caddy.nix @@ -151,7 +151,7 @@ in openFirewall = true; package = pkgs.caddy.withPlugins { plugins = [ - "github.com/caddy-dns/cloudflare@v0.2.2" + "github.com/caddy-dns/cloudflare@v0.2.4" "github.com/aksdb/caddy-cgi/v2@v2.2.6" "github.com/shift72/caddy-geo-ip@v0.6.0" "github.com/lolPants/caddy-requestid@v1.1.2" @@ -161,7 +161,7 @@ in "github.com/RussellLuo/caddy-ext/ratelimit@v0.3.0" "github.com/neodyme-labs/user_agent_parse@v0.0.1" ]; - hash = "sha256-z9/LF2gws+H0pKL6F62QfklD0W8DKWCccnXLOOs3+jY="; + hash = "sha256-r4MgRk8HpKYx7f8FmA3PKgD/5ZNTIHpQvlE+zRbP0lw="; }; globalConfig = '' @@ -394,7 +394,9 @@ in requires = [ "mnt-static.mount" ]; after = [ "mnt-static.mount" "systemd-tmpfiles-setup.service" ]; serviceConfig = { - EnvironmentFile = "-/etc/caddy/cloudflare.env"; + # Keep the manually provisioned token outside NixOS-managed /etc. + # /var/lib/caddy is persistent across system generations. + EnvironmentFile = "/var/lib/caddy/cloudflare.env"; RuntimeDirectory = "caddy"; RuntimeDirectoryMode = "0755"; }; diff --git a/hosts/server/hikari/hako/services/quadlet/authentik.nix b/hosts/server/hikari/hako/services/quadlet/authentik.nix index 05f623c..15500ed 100644 --- a/hosts/server/hikari/hako/services/quadlet/authentik.nix +++ b/hosts/server/hikari/hako/services/quadlet/authentik.nix @@ -2,6 +2,7 @@ let inherit (config.virtualisation.quadlet) containers networks; + authentikVersion = "2026.5.6"; authentikEnv = config.sops.secrets."containers/authentik.env".path; outpostEnv = config.sops.secrets."containers/authentik-outpost.env".path; in @@ -53,7 +54,7 @@ in authentik-server = { containerConfig = { - image = "ghcr.io/goauthentik/server:2026.5.0"; + image = "ghcr.io/goauthentik/server:${authentikVersion}"; exec = "server"; networks = [ networks.authentik.ref ]; publishPorts = [ @@ -65,6 +66,11 @@ in "/home/imnyang/Docker/authentik/custom-templates:/templates:Z" ]; environmentFiles = [ authentikEnv ]; + environments = { + # Authentik 2026.5 defaults to [::], but hako is reached over IPv4. + AUTHENTIK_LISTEN__HTTP = "0.0.0.0:9000"; + AUTHENTIK_LISTEN__HTTPS = "0.0.0.0:9443"; + }; }; unitConfig = { @@ -77,7 +83,7 @@ in authentik-worker = { containerConfig = { - image = "ghcr.io/goauthentik/server:2026.5.0"; + image = "ghcr.io/goauthentik/server:${authentikVersion}"; exec = "worker"; user = "root"; networks = [ networks.authentik.ref ]; @@ -85,9 +91,11 @@ in "/home/imnyang/Docker/authentik/certs:/certs:Z" "/home/imnyang/Docker/authentik/media:/media:Z" "/home/imnyang/Docker/authentik/custom-templates:/templates:Z" - "/var/run/docker.sock:/var/run/docker.sock" ]; environmentFiles = [ authentikEnv ]; + environments = { + AUTHENTIK_LISTEN__HTTP = "0.0.0.0:9000"; + }; }; unitConfig = { @@ -100,7 +108,7 @@ in authentik-outpost-ldap = { containerConfig = { - image = "ghcr.io/goauthentik/ldap:2026.5.0"; + image = "ghcr.io/goauthentik/ldap:${authentikVersion}"; entrypoint = [ "/ldap" ]; user = "1000"; networks = [ networks.authentik.ref ]; @@ -109,6 +117,15 @@ in "636:6636" ]; environmentFiles = [ outpostEnv ]; + environments = { + # Keep the outpost-to-core API traffic on the private Podman network. + # The public hostname resolves through Cloudflare and hairpins back + # through the reverse proxy, which currently returns 502 from hako. + AUTHENTIK_HOST = "http://authentik-server:9000"; + AUTHENTIK_INSECURE = "true"; + AUTHENTIK_LISTEN__LDAP = "0.0.0.0:3389"; + AUTHENTIK_LISTEN__LDAPS = "0.0.0.0:6636"; + }; }; unitConfig = {