2021-12-19 01:06:50 +00:00
|
|
|
{ config, options, pkgs, lib, ... }:
|
2020-11-06 00:33:48 +00:00
|
|
|
|
|
|
|
let
|
|
|
|
cfg = config.services.keycloak;
|
2021-12-19 01:06:50 +00:00
|
|
|
opt = options.services.keycloak;
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-04-27 09:35:20 +00:00
|
|
|
inherit (lib)
|
|
|
|
types
|
|
|
|
mkMerge
|
|
|
|
mkOption
|
|
|
|
mkChangedOptionModule
|
|
|
|
mkRenamedOptionModule
|
|
|
|
mkRemovedOptionModule
|
|
|
|
concatStringsSep
|
|
|
|
mapAttrsToList
|
|
|
|
escapeShellArg
|
|
|
|
mkIf
|
|
|
|
optionalString
|
|
|
|
optionals
|
|
|
|
mkDefault
|
|
|
|
literalExpression
|
|
|
|
isAttrs
|
|
|
|
literalDocBook
|
|
|
|
maintainers
|
|
|
|
catAttrs
|
|
|
|
collect
|
|
|
|
splitString
|
|
|
|
;
|
|
|
|
|
|
|
|
inherit (builtins)
|
|
|
|
elem
|
|
|
|
typeOf
|
|
|
|
isInt
|
|
|
|
isString
|
|
|
|
hashString
|
|
|
|
isPath
|
|
|
|
;
|
|
|
|
|
|
|
|
prefixUnlessEmpty = prefix: string: optionalString (string != "") "${prefix}${string}";
|
2022-01-19 23:45:15 +00:00
|
|
|
in
|
|
|
|
{
|
2022-04-27 09:35:20 +00:00
|
|
|
imports =
|
|
|
|
[
|
|
|
|
(mkRenamedOptionModule
|
|
|
|
[ "services" "keycloak" "bindAddress" ]
|
|
|
|
[ "services" "keycloak" "settings" "http-host" ])
|
|
|
|
(mkRenamedOptionModule
|
|
|
|
[ "services" "keycloak" "forceBackendUrlToFrontendUrl"]
|
|
|
|
[ "services" "keycloak" "settings" "hostname-strict-backchannel"])
|
|
|
|
(mkChangedOptionModule
|
|
|
|
[ "services" "keycloak" "httpPort" ]
|
|
|
|
[ "services" "keycloak" "settings" "http-port" ]
|
|
|
|
(config:
|
|
|
|
builtins.fromJSON config.services.keycloak.httpPort))
|
|
|
|
(mkChangedOptionModule
|
|
|
|
[ "services" "keycloak" "httpsPort" ]
|
|
|
|
[ "services" "keycloak" "settings" "https-port" ]
|
|
|
|
(config:
|
|
|
|
builtins.fromJSON config.services.keycloak.httpsPort))
|
|
|
|
(mkRemovedOptionModule
|
|
|
|
[ "services" "keycloak" "frontendUrl" ]
|
|
|
|
''
|
|
|
|
Set `services.keycloak.settings.hostname' and `services.keycloak.settings.http-relative-path' instead.
|
|
|
|
NOTE: You likely want to set 'http-relative-path' to '/auth' to keep compatibility with your clients.
|
|
|
|
See its description for more information.
|
|
|
|
'')
|
|
|
|
(mkRemovedOptionModule
|
|
|
|
[ "services" "keycloak" "extraConfig" ]
|
|
|
|
"Use `services.keycloak.settings' instead.")
|
|
|
|
];
|
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
options.services.keycloak =
|
|
|
|
let
|
2022-04-27 09:35:20 +00:00
|
|
|
inherit (types)
|
|
|
|
bool
|
|
|
|
str
|
|
|
|
int
|
|
|
|
nullOr
|
|
|
|
attrsOf
|
|
|
|
oneOf
|
|
|
|
path
|
|
|
|
enum
|
|
|
|
package
|
|
|
|
port;
|
|
|
|
|
|
|
|
assertStringPath = optionName: value:
|
|
|
|
if isPath value then
|
|
|
|
throw ''
|
|
|
|
services.keycloak.${optionName}:
|
|
|
|
${toString value}
|
|
|
|
is a Nix path, but should be a string, since Nix
|
|
|
|
paths are copied into the world-readable Nix store.
|
|
|
|
''
|
|
|
|
else value;
|
2022-01-19 23:45:15 +00:00
|
|
|
in
|
|
|
|
{
|
|
|
|
enable = mkOption {
|
|
|
|
type = bool;
|
|
|
|
default = false;
|
|
|
|
example = true;
|
|
|
|
description = ''
|
|
|
|
Whether to enable the Keycloak identity and access management
|
|
|
|
server.
|
|
|
|
'';
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
sslCertificate = mkOption {
|
|
|
|
type = nullOr path;
|
|
|
|
default = null;
|
|
|
|
example = "/run/keys/ssl_cert";
|
2022-04-27 09:35:20 +00:00
|
|
|
apply = assertStringPath "sslCertificate";
|
2021-05-28 09:39:13 +00:00
|
|
|
description = ''
|
2022-01-19 23:45:15 +00:00
|
|
|
The path to a PEM formatted certificate to use for TLS/SSL
|
|
|
|
connections.
|
2021-05-28 09:39:13 +00:00
|
|
|
'';
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
sslCertificateKey = mkOption {
|
|
|
|
type = nullOr path;
|
|
|
|
default = null;
|
|
|
|
example = "/run/keys/ssl_key";
|
2022-04-27 09:35:20 +00:00
|
|
|
apply = assertStringPath "sslCertificateKey";
|
2021-05-28 09:39:13 +00:00
|
|
|
description = ''
|
2022-01-19 23:45:15 +00:00
|
|
|
The path to a PEM formatted private key to use for TLS/SSL
|
|
|
|
connections.
|
2021-05-28 09:39:13 +00:00
|
|
|
'';
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-03-30 09:31:56 +00:00
|
|
|
plugins = lib.mkOption {
|
|
|
|
type = lib.types.listOf lib.types.path;
|
2022-04-27 09:35:20 +00:00
|
|
|
default = [ ];
|
2022-03-30 09:31:56 +00:00
|
|
|
description = ''
|
2022-04-27 09:35:20 +00:00
|
|
|
Keycloak plugin jar, ear files or derivations containing
|
|
|
|
them. Packaged plugins are available through
|
|
|
|
<literal>pkgs.keycloak.plugins</literal>.
|
2022-03-30 09:31:56 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
database = {
|
|
|
|
type = mkOption {
|
2022-04-27 09:35:20 +00:00
|
|
|
type = enum [ "mysql" "mariadb" "postgresql" ];
|
2022-01-19 23:45:15 +00:00
|
|
|
default = "postgresql";
|
2022-04-27 09:35:20 +00:00
|
|
|
example = "mariadb";
|
2022-01-19 23:45:15 +00:00
|
|
|
description = ''
|
|
|
|
The type of database Keycloak should connect to.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
host = mkOption {
|
|
|
|
type = str;
|
|
|
|
default = "localhost";
|
|
|
|
description = ''
|
|
|
|
Hostname of the database to connect to.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
port =
|
|
|
|
let
|
|
|
|
dbPorts = {
|
|
|
|
postgresql = 5432;
|
2022-04-27 09:35:20 +00:00
|
|
|
mariadb = 3306;
|
2022-01-19 23:45:15 +00:00
|
|
|
mysql = 3306;
|
|
|
|
};
|
|
|
|
in
|
|
|
|
mkOption {
|
|
|
|
type = port;
|
2021-05-28 09:39:13 +00:00
|
|
|
default = dbPorts.${cfg.database.type};
|
2022-01-19 23:45:15 +00:00
|
|
|
defaultText = literalDocBook "default port of selected database";
|
2021-05-28 09:39:13 +00:00
|
|
|
description = ''
|
|
|
|
Port of the database to connect to.
|
|
|
|
'';
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
useSSL = mkOption {
|
|
|
|
type = bool;
|
|
|
|
default = cfg.database.host != "localhost";
|
|
|
|
defaultText = literalExpression ''config.${opt.database.host} != "localhost"'';
|
|
|
|
description = ''
|
|
|
|
Whether the database connection should be secured by SSL /
|
|
|
|
TLS.
|
|
|
|
'';
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
caCert = mkOption {
|
|
|
|
type = nullOr path;
|
|
|
|
default = null;
|
|
|
|
description = ''
|
|
|
|
The SSL / TLS CA certificate that verifies the identity of the
|
|
|
|
database server.
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
Required when PostgreSQL is used and SSL is turned on.
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
For MySQL, if left at <literal>null</literal>, the default
|
|
|
|
Java keystore is used, which should suffice if the server
|
|
|
|
certificate is issued by an official CA.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
createLocally = mkOption {
|
|
|
|
type = bool;
|
|
|
|
default = true;
|
|
|
|
description = ''
|
|
|
|
Whether a database should be automatically created on the
|
|
|
|
local host. Set this to false if you plan on provisioning a
|
|
|
|
local database yourself. This has no effect if
|
|
|
|
services.keycloak.database.host is customized.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2022-04-27 09:35:20 +00:00
|
|
|
name = mkOption {
|
|
|
|
type = str;
|
|
|
|
default = "keycloak";
|
|
|
|
description = ''
|
|
|
|
Database name to use when connecting to an external or
|
|
|
|
manually provisioned database; has no effect when a local
|
|
|
|
database is automatically provisioned.
|
|
|
|
|
|
|
|
To use this with a local database, set <xref
|
|
|
|
linkend="opt-services.keycloak.database.createLocally" /> to
|
|
|
|
<literal>false</literal> and create the database and user
|
|
|
|
manually.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
username = mkOption {
|
|
|
|
type = str;
|
|
|
|
default = "keycloak";
|
|
|
|
description = ''
|
|
|
|
Username to use when connecting to an external or manually
|
|
|
|
provisioned database; has no effect when a local database is
|
|
|
|
automatically provisioned.
|
|
|
|
|
|
|
|
To use this with a local database, set <xref
|
|
|
|
linkend="opt-services.keycloak.database.createLocally" /> to
|
|
|
|
<literal>false</literal> and create the database and user
|
2022-04-27 09:35:20 +00:00
|
|
|
manually.
|
2022-01-19 23:45:15 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
passwordFile = mkOption {
|
|
|
|
type = path;
|
|
|
|
example = "/run/keys/db_password";
|
2022-04-27 09:35:20 +00:00
|
|
|
apply = assertStringPath "passwordFile";
|
2022-01-19 23:45:15 +00:00
|
|
|
description = ''
|
2022-04-27 09:35:20 +00:00
|
|
|
The path to a file containing the database password.
|
2022-01-19 23:45:15 +00:00
|
|
|
'';
|
|
|
|
};
|
2021-05-28 09:39:13 +00:00
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
package = mkOption {
|
|
|
|
type = package;
|
|
|
|
default = pkgs.keycloak;
|
|
|
|
defaultText = literalExpression "pkgs.keycloak";
|
2021-05-28 09:39:13 +00:00
|
|
|
description = ''
|
2022-01-19 23:45:15 +00:00
|
|
|
Keycloak package to use.
|
2021-05-28 09:39:13 +00:00
|
|
|
'';
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
initialAdminPassword = mkOption {
|
|
|
|
type = str;
|
|
|
|
default = "changeme";
|
2021-05-28 09:39:13 +00:00
|
|
|
description = ''
|
2022-01-19 23:45:15 +00:00
|
|
|
Initial password set for the <literal>admin</literal>
|
|
|
|
user. The password is not stored safely and should be changed
|
|
|
|
immediately in the admin panel.
|
2021-05-28 09:39:13 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
themes = mkOption {
|
|
|
|
type = attrsOf package;
|
|
|
|
default = { };
|
2021-05-28 09:39:13 +00:00
|
|
|
description = ''
|
2022-01-19 23:45:15 +00:00
|
|
|
Additional theme packages for Keycloak. Each theme is linked into
|
|
|
|
subdirectory with a corresponding attribute name.
|
2021-05-28 09:39:13 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
Theme packages consist of several subdirectories which provide
|
|
|
|
different theme types: for example, <literal>account</literal>,
|
|
|
|
<literal>login</literal> etc. After adding a theme to this option you
|
|
|
|
can select it by its name in Keycloak administration console.
|
2021-05-28 09:39:13 +00:00
|
|
|
'';
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-04-27 09:35:20 +00:00
|
|
|
settings = mkOption {
|
|
|
|
type = lib.types.submodule {
|
|
|
|
freeformType = attrsOf (nullOr (oneOf [ str int bool (attrsOf path) ]));
|
|
|
|
|
|
|
|
options = {
|
|
|
|
http-host = mkOption {
|
|
|
|
type = str;
|
|
|
|
default = "0.0.0.0";
|
|
|
|
example = "127.0.0.1";
|
|
|
|
description = ''
|
|
|
|
On which address Keycloak should accept new connections.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
http-port = mkOption {
|
|
|
|
type = port;
|
|
|
|
default = 80;
|
|
|
|
example = 8080;
|
|
|
|
description = ''
|
|
|
|
On which port Keycloak should listen for new HTTP connections.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
https-port = mkOption {
|
|
|
|
type = port;
|
|
|
|
default = 443;
|
|
|
|
example = 8443;
|
|
|
|
description = ''
|
|
|
|
On which port Keycloak should listen for new HTTPS connections.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
http-relative-path = mkOption {
|
|
|
|
type = str;
|
|
|
|
default = "";
|
|
|
|
example = "/auth";
|
|
|
|
description = ''
|
|
|
|
The path relative to <literal>/</literal> for serving
|
|
|
|
resources.
|
|
|
|
|
|
|
|
<note>
|
|
|
|
<para>
|
|
|
|
In versions of Keycloak using Wildfly (<17),
|
|
|
|
this defaulted to <literal>/auth</literal>. If
|
|
|
|
upgrading from the Wildfly version of Keycloak,
|
|
|
|
i.e. a NixOS version before 22.05, you'll likely
|
|
|
|
want to set this to <literal>/auth</literal> to
|
|
|
|
keep compatibility with your clients.
|
|
|
|
|
|
|
|
See <link
|
|
|
|
xlink:href="https://www.keycloak.org/migration/migrating-to-quarkus"
|
|
|
|
/> for more information on migrating from Wildfly
|
|
|
|
to Quarkus.
|
|
|
|
</para>
|
|
|
|
</note>
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
hostname = mkOption {
|
|
|
|
type = str;
|
|
|
|
example = "keycloak.example.com";
|
|
|
|
description = ''
|
|
|
|
The hostname part of the public URL used as base for
|
|
|
|
all frontend requests.
|
|
|
|
|
|
|
|
See <link xlink:href="https://www.keycloak.org/server/hostname" />
|
|
|
|
for more information about hostname configuration.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
hostname-strict-backchannel = mkOption {
|
|
|
|
type = bool;
|
|
|
|
default = false;
|
|
|
|
example = true;
|
|
|
|
description = ''
|
|
|
|
Whether Keycloak should force all requests to go
|
|
|
|
through the frontend URL. By default, Keycloak allows
|
|
|
|
backend requests to instead use its local hostname or
|
|
|
|
IP address and may also advertise it to clients
|
|
|
|
through its OpenID Connect Discovery endpoint.
|
|
|
|
|
|
|
|
See <link xlink:href="https://www.keycloak.org/server/hostname" />
|
|
|
|
for more information about hostname configuration.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
proxy = mkOption {
|
|
|
|
type = enum [ "edge" "reencrypt" "passthrough" "none" ];
|
|
|
|
default = "none";
|
|
|
|
example = "edge";
|
|
|
|
description = ''
|
|
|
|
The proxy address forwarding mode if the server is
|
|
|
|
behind a reverse proxy.
|
|
|
|
|
|
|
|
<variablelist>
|
|
|
|
<varlistentry>
|
|
|
|
<term>edge</term>
|
|
|
|
<listitem>
|
|
|
|
<para>
|
|
|
|
Enables communication through HTTP between the
|
|
|
|
proxy and Keycloak.
|
|
|
|
</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
<varlistentry>
|
|
|
|
<term>reencrypt</term>
|
|
|
|
<listitem>
|
|
|
|
<para>
|
|
|
|
Requires communication through HTTPS between the
|
|
|
|
proxy and Keycloak.
|
|
|
|
</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
<varlistentry>
|
|
|
|
<term>passthrough</term>
|
|
|
|
<listitem>
|
|
|
|
<para>
|
|
|
|
Enables communication through HTTP or HTTPS between
|
|
|
|
the proxy and Keycloak.
|
|
|
|
</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
</variablelist>
|
|
|
|
|
|
|
|
See <link
|
|
|
|
xlink:href="https://www.keycloak.org/server/reverseproxy"
|
|
|
|
/> for more information.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
example = literalExpression ''
|
|
|
|
{
|
2022-04-27 09:35:20 +00:00
|
|
|
hostname = "keycloak.example.com";
|
|
|
|
proxy = "reencrypt";
|
|
|
|
https-key-store-file = "/path/to/file";
|
|
|
|
https-key-store-password = { _secret = "/run/keys/store_password"; };
|
2022-01-19 23:45:15 +00:00
|
|
|
}
|
|
|
|
'';
|
2022-04-27 09:35:20 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
description = ''
|
2022-04-27 09:35:20 +00:00
|
|
|
Configuration options corresponding to parameters set in
|
|
|
|
<filename>conf/keycloak.conf</filename>.
|
|
|
|
|
|
|
|
Most available options are documented at <link
|
|
|
|
xlink:href="https://www.keycloak.org/server/all-config" />.
|
|
|
|
|
|
|
|
Options containing secret data should be set to an attribute
|
|
|
|
set containing the attribute <literal>_secret</literal> - a
|
|
|
|
string pointing to a file containing the value the option
|
|
|
|
should be set to. See the example to get a better picture of
|
|
|
|
this: in the resulting
|
|
|
|
<filename>conf/keycloak.conf</filename> file, the
|
|
|
|
<literal>https-key-store-password</literal> key will be set
|
|
|
|
to the contents of the
|
|
|
|
<filename>/run/keys/store_password</filename> file.
|
2022-01-19 23:45:15 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
|
|
|
config =
|
|
|
|
let
|
2022-04-27 09:35:20 +00:00
|
|
|
# We only want to create a database if we're actually going to
|
|
|
|
# connect to it.
|
2021-05-28 09:39:13 +00:00
|
|
|
databaseActuallyCreateLocally = cfg.database.createLocally && cfg.database.host == "localhost";
|
|
|
|
createLocalPostgreSQL = databaseActuallyCreateLocally && cfg.database.type == "postgresql";
|
2022-04-27 09:35:20 +00:00
|
|
|
createLocalMySQL = databaseActuallyCreateLocally && elem cfg.database.type [ "mysql" "mariadb" ];
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
mySqlCaKeystore = pkgs.runCommand "mysql-ca-keystore" { } ''
|
2021-05-28 09:39:13 +00:00
|
|
|
${pkgs.jre}/bin/keytool -importcert -trustcacerts -alias MySQLCACert -file ${cfg.database.caCert} -keystore $out -storepass notsosecretpassword -noprompt
|
2020-11-06 00:33:48 +00:00
|
|
|
'';
|
|
|
|
|
2022-04-27 09:35:20 +00:00
|
|
|
# Both theme and theme type directories need to be actual
|
|
|
|
# directories in one hierarchy to pass Keycloak checks.
|
2022-01-19 23:45:15 +00:00
|
|
|
themesBundle = pkgs.runCommand "keycloak-themes" { } ''
|
|
|
|
linkTheme() {
|
|
|
|
theme="$1"
|
|
|
|
name="$2"
|
|
|
|
|
|
|
|
mkdir "$out/$name"
|
|
|
|
for typeDir in "$theme"/*; do
|
|
|
|
if [ -d "$typeDir" ]; then
|
|
|
|
type="$(basename "$typeDir")"
|
|
|
|
mkdir "$out/$name/$type"
|
|
|
|
for file in "$typeDir"/*; do
|
|
|
|
ln -sn "$file" "$out/$name/$type/$(basename "$file")"
|
|
|
|
done
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
}
|
|
|
|
|
|
|
|
mkdir -p "$out"
|
2022-04-27 09:35:20 +00:00
|
|
|
for theme in ${keycloakBuild}/themes/*; do
|
2022-01-19 23:45:15 +00:00
|
|
|
if [ -d "$theme" ]; then
|
|
|
|
linkTheme "$theme" "$(basename "$theme")"
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
|
|
|
|
${concatStringsSep "\n" (mapAttrsToList (name: theme: "linkTheme ${theme} ${escapeShellArg name}") cfg.themes)}
|
|
|
|
'';
|
|
|
|
|
2022-04-27 09:35:20 +00:00
|
|
|
keycloakConfig = lib.generators.toKeyValue {
|
|
|
|
mkKeyValue = lib.flip lib.generators.mkKeyValueDefault "=" {
|
|
|
|
mkValueString = v: with builtins;
|
|
|
|
if isInt v then toString v
|
|
|
|
else if isString v then v
|
|
|
|
else if true == v then "true"
|
|
|
|
else if false == v then "false"
|
|
|
|
else if isSecret v then hashString "sha256" v._secret
|
|
|
|
else throw "unsupported type ${typeOf v}: ${(lib.generators.toPretty {}) v}";
|
|
|
|
};
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-04-27 09:35:20 +00:00
|
|
|
isSecret = v: isAttrs v && v ? _secret && isString v._secret;
|
|
|
|
filteredConfig = lib.converge (lib.filterAttrsRecursive (_: v: ! elem v [{ } null])) cfg.settings;
|
|
|
|
confFile = pkgs.writeText "keycloak.conf" (keycloakConfig filteredConfig);
|
|
|
|
keycloakBuild = cfg.package.override {
|
|
|
|
inherit confFile;
|
|
|
|
plugins = cfg.package.enabledPlugins ++ cfg.plugins;
|
|
|
|
};
|
2020-11-06 00:33:48 +00:00
|
|
|
in
|
2022-01-19 23:45:15 +00:00
|
|
|
mkIf cfg.enable
|
|
|
|
{
|
2020-11-06 00:33:48 +00:00
|
|
|
assertions = [
|
|
|
|
{
|
2021-05-28 09:39:13 +00:00
|
|
|
assertion = (cfg.database.useSSL && cfg.database.type == "postgresql") -> (cfg.database.caCert != null);
|
|
|
|
message = "A CA certificate must be specified (in 'services.keycloak.database.caCert') when PostgreSQL is used with SSL";
|
2020-11-06 00:33:48 +00:00
|
|
|
}
|
|
|
|
];
|
|
|
|
|
2022-04-27 09:35:20 +00:00
|
|
|
environment.systemPackages = [ keycloakBuild ];
|
|
|
|
|
|
|
|
services.keycloak.settings =
|
|
|
|
let
|
|
|
|
postgresParams = concatStringsSep "&" (
|
|
|
|
optionals cfg.database.useSSL [
|
|
|
|
"ssl=true"
|
|
|
|
] ++ optionals (cfg.database.caCert != null) [
|
|
|
|
"sslrootcert=${cfg.database.caCert}"
|
|
|
|
"sslmode=verify-ca"
|
|
|
|
]
|
|
|
|
);
|
|
|
|
mariadbParams = concatStringsSep "&" ([
|
|
|
|
"characterEncoding=UTF-8"
|
|
|
|
] ++ optionals cfg.database.useSSL [
|
|
|
|
"useSSL=true"
|
|
|
|
"requireSSL=true"
|
|
|
|
"verifyServerCertificate=true"
|
|
|
|
] ++ optionals (cfg.database.caCert != null) [
|
|
|
|
"trustCertificateKeyStoreUrl=file:${mySqlCaKeystore}"
|
|
|
|
"trustCertificateKeyStorePassword=notsosecretpassword"
|
|
|
|
]);
|
|
|
|
dbProps = if cfg.database.type == "postgresql" then postgresParams else mariadbParams;
|
|
|
|
in
|
|
|
|
mkMerge [
|
|
|
|
{
|
|
|
|
db = if cfg.database.type == "postgresql" then "postgres" else cfg.database.type;
|
|
|
|
db-username = if databaseActuallyCreateLocally then "keycloak" else cfg.database.username;
|
|
|
|
db-password._secret = cfg.database.passwordFile;
|
|
|
|
db-url-host = cfg.database.host;
|
|
|
|
db-url-port = toString cfg.database.port;
|
|
|
|
db-url-database = if databaseActuallyCreateLocally then "keycloak" else cfg.database.name;
|
|
|
|
db-url-properties = prefixUnlessEmpty "?" dbProps;
|
|
|
|
db-url = null;
|
|
|
|
}
|
|
|
|
(mkIf (cfg.sslCertificate != null && cfg.sslCertificateKey != null) {
|
|
|
|
https-certificate-file = "/run/keycloak/ssl/ssl_cert";
|
|
|
|
https-certificate-key-file = "/run/keycloak/ssl/ssl_key";
|
|
|
|
})
|
|
|
|
];
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
systemd.services.keycloakPostgreSQLInit = mkIf createLocalPostgreSQL {
|
2020-11-06 00:33:48 +00:00
|
|
|
after = [ "postgresql.service" ];
|
|
|
|
before = [ "keycloak.service" ];
|
|
|
|
bindsTo = [ "postgresql.service" ];
|
2021-05-28 09:39:13 +00:00
|
|
|
path = [ config.services.postgresql.package ];
|
2020-11-06 00:33:48 +00:00
|
|
|
serviceConfig = {
|
|
|
|
Type = "oneshot";
|
|
|
|
RemainAfterExit = true;
|
|
|
|
User = "postgres";
|
|
|
|
Group = "postgres";
|
2022-03-10 19:12:11 +00:00
|
|
|
LoadCredential = [ "db_password:${cfg.database.passwordFile}" ];
|
2020-11-06 00:33:48 +00:00
|
|
|
};
|
|
|
|
script = ''
|
2021-05-28 09:39:13 +00:00
|
|
|
set -o errexit -o pipefail -o nounset -o errtrace
|
|
|
|
shopt -s inherit_errexit
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2021-05-28 09:39:13 +00:00
|
|
|
create_role="$(mktemp)"
|
|
|
|
trap 'rm -f "$create_role"' ERR EXIT
|
2020-11-06 00:33:48 +00:00
|
|
|
|
2022-03-10 19:12:11 +00:00
|
|
|
db_password="$(<"$CREDENTIALS_DIRECTORY/db_password")"
|
|
|
|
echo "CREATE ROLE keycloak WITH LOGIN PASSWORD '$db_password' CREATEDB" > "$create_role"
|
2021-05-28 09:39:13 +00:00
|
|
|
psql -tAc "SELECT 1 FROM pg_roles WHERE rolname='keycloak'" | grep -q 1 || psql -tA --file="$create_role"
|
|
|
|
psql -tAc "SELECT 1 FROM pg_database WHERE datname = 'keycloak'" | grep -q 1 || psql -tAc 'CREATE DATABASE "keycloak" OWNER "keycloak"'
|
2020-11-06 00:33:48 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
systemd.services.keycloakMySQLInit = mkIf createLocalMySQL {
|
2020-11-06 00:33:48 +00:00
|
|
|
after = [ "mysql.service" ];
|
|
|
|
before = [ "keycloak.service" ];
|
|
|
|
bindsTo = [ "mysql.service" ];
|
2021-05-28 09:39:13 +00:00
|
|
|
path = [ config.services.mysql.package ];
|
2020-11-06 00:33:48 +00:00
|
|
|
serviceConfig = {
|
|
|
|
Type = "oneshot";
|
|
|
|
RemainAfterExit = true;
|
|
|
|
User = config.services.mysql.user;
|
|
|
|
Group = config.services.mysql.group;
|
2022-03-10 19:12:11 +00:00
|
|
|
LoadCredential = [ "db_password:${cfg.database.passwordFile}" ];
|
2020-11-06 00:33:48 +00:00
|
|
|
};
|
|
|
|
script = ''
|
2021-05-28 09:39:13 +00:00
|
|
|
set -o errexit -o pipefail -o nounset -o errtrace
|
|
|
|
shopt -s inherit_errexit
|
2022-03-10 19:12:11 +00:00
|
|
|
db_password="$(<"$CREDENTIALS_DIRECTORY/db_password")"
|
2021-05-04 21:07:42 +00:00
|
|
|
( echo "CREATE USER IF NOT EXISTS 'keycloak'@'localhost' IDENTIFIED BY '$db_password';"
|
2022-03-10 19:12:11 +00:00
|
|
|
echo "CREATE DATABASE IF NOT EXISTS keycloak CHARACTER SET utf8 COLLATE utf8_unicode_ci;"
|
2021-05-04 21:07:42 +00:00
|
|
|
echo "GRANT ALL PRIVILEGES ON keycloak.* TO 'keycloak'@'localhost';"
|
2021-05-28 09:39:13 +00:00
|
|
|
) | mysql -N
|
2020-11-06 00:33:48 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
systemd.services.keycloak =
|
|
|
|
let
|
|
|
|
databaseServices =
|
|
|
|
if createLocalPostgreSQL then [
|
2022-01-19 23:45:15 +00:00
|
|
|
"keycloakPostgreSQLInit.service"
|
|
|
|
"postgresql.service"
|
2020-11-06 00:33:48 +00:00
|
|
|
]
|
|
|
|
else if createLocalMySQL then [
|
2022-01-19 23:45:15 +00:00
|
|
|
"keycloakMySQLInit.service"
|
|
|
|
"mysql.service"
|
2020-11-06 00:33:48 +00:00
|
|
|
]
|
|
|
|
else [ ];
|
2022-04-27 09:35:20 +00:00
|
|
|
secretPaths = catAttrs "_secret" (collect isSecret cfg.settings);
|
|
|
|
mkSecretReplacement = file: ''
|
|
|
|
replace-secret ${hashString "sha256" file} $CREDENTIALS_DIRECTORY/${baseNameOf file} /run/keycloak/conf/keycloak.conf
|
|
|
|
'';
|
|
|
|
secretReplacements = lib.concatMapStrings mkSecretReplacement secretPaths;
|
2022-01-19 23:45:15 +00:00
|
|
|
in
|
|
|
|
{
|
2020-11-06 00:33:48 +00:00
|
|
|
after = databaseServices;
|
|
|
|
bindsTo = databaseServices;
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
2021-05-20 23:08:51 +00:00
|
|
|
path = with pkgs; [
|
2022-04-27 09:35:20 +00:00
|
|
|
keycloakBuild
|
2021-05-28 09:39:13 +00:00
|
|
|
openssl
|
2021-05-20 23:08:51 +00:00
|
|
|
replace-secret
|
|
|
|
];
|
2020-11-06 00:33:48 +00:00
|
|
|
environment = {
|
2022-04-27 09:35:20 +00:00
|
|
|
KC_HOME_DIR = "/run/keycloak";
|
|
|
|
KC_CONF_DIR = "/run/keycloak/conf";
|
2020-11-06 00:33:48 +00:00
|
|
|
};
|
|
|
|
serviceConfig = {
|
2022-04-27 09:35:20 +00:00
|
|
|
LoadCredential =
|
|
|
|
map (p: "${baseNameOf p}:${p}") secretPaths
|
|
|
|
++ optionals (cfg.sslCertificate != null && cfg.sslCertificateKey != null) [
|
|
|
|
"ssl_cert:${cfg.sslCertificate}"
|
|
|
|
"ssl_key:${cfg.sslCertificateKey}"
|
|
|
|
];
|
2020-11-06 00:33:48 +00:00
|
|
|
User = "keycloak";
|
|
|
|
Group = "keycloak";
|
|
|
|
DynamicUser = true;
|
2022-04-27 09:35:20 +00:00
|
|
|
RuntimeDirectory = "keycloak";
|
2020-11-06 00:33:48 +00:00
|
|
|
RuntimeDirectoryMode = 0700;
|
|
|
|
AmbientCapabilities = "CAP_NET_BIND_SERVICE";
|
|
|
|
};
|
2022-01-19 23:45:15 +00:00
|
|
|
script = ''
|
|
|
|
set -o errexit -o pipefail -o nounset -o errtrace
|
|
|
|
shopt -s inherit_errexit
|
|
|
|
|
|
|
|
umask u=rwx,g=,o=
|
|
|
|
|
2022-04-27 09:35:20 +00:00
|
|
|
ln -s ${themesBundle} /run/keycloak/themes
|
|
|
|
ln -s ${keycloakBuild}/providers /run/keycloak/
|
|
|
|
|
|
|
|
install -D -m 0600 ${confFile} /run/keycloak/conf/keycloak.conf
|
|
|
|
|
|
|
|
${secretReplacements}
|
|
|
|
|
|
|
|
'' + optionalString (cfg.sslCertificate != null && cfg.sslCertificateKey != null) ''
|
|
|
|
mkdir -p /run/keycloak/ssl
|
|
|
|
cp $CREDENTIALS_DIRECTORY/ssl_{cert,key} /run/keycloak/ssl/
|
2022-01-19 23:45:15 +00:00
|
|
|
'' + ''
|
2022-04-27 09:35:20 +00:00
|
|
|
export KEYCLOAK_ADMIN=admin
|
|
|
|
export KEYCLOAK_ADMIN_PASSWORD=${cfg.initialAdminPassword}
|
|
|
|
kc.sh start
|
2022-01-19 23:45:15 +00:00
|
|
|
'';
|
2020-11-06 00:33:48 +00:00
|
|
|
};
|
|
|
|
|
2022-01-19 23:45:15 +00:00
|
|
|
services.postgresql.enable = mkDefault createLocalPostgreSQL;
|
|
|
|
services.mysql.enable = mkDefault createLocalMySQL;
|
2022-04-27 09:35:20 +00:00
|
|
|
services.mysql.package =
|
|
|
|
let
|
|
|
|
dbPkg = if cfg.database.type == "mariadb" then pkgs.mariadb else pkgs.mysql80;
|
|
|
|
in
|
|
|
|
mkIf createLocalMySQL (mkDefault dbPkg);
|
2020-11-06 00:33:48 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
meta.doc = ./keycloak.xml;
|
2022-01-19 23:45:15 +00:00
|
|
|
meta.maintainers = [ maintainers.talyz ];
|
2020-11-06 00:33:48 +00:00
|
|
|
}
|