[nidaros] Add Keycloak

This commit is contained in:
2025-10-14 18:35:15 +00:00
parent 0109aeec8a
commit 3eaa836098
2 changed files with 28 additions and 0 deletions

View File

@@ -5,6 +5,7 @@
(relativeToBase "modules")
./boot.nix
./hardware.nix
./keycloak.nix
./postgres.nix
./security
];

View File

@@ -0,0 +1,27 @@
{ config, common, ... }:
let
port = 8081;
domain = "iam.${common.domain}";
dbPassKey = "keycloak/database-pass";
in
{
services = {
keycloak = {
enable = true;
settings = {
hostname = "https://${domain}";
http-port = port;
http-enabled = true;
};
database = {
type = "postgresql";
createLocally = true;
port = config.services.postgresql.settings.port;
passwordFile = config.sops.secrets.${dbPassKey}.path;
};
initialAdminPassword = "changeme";
};
};
sops.secrets.${dbPassKey} = { };
}