Skip to content

Commit 1ad1ad5

Browse files
committed
chore: move miniflux oidc to rauthy
1 parent 6c3342a commit 1ad1ad5

File tree

2 files changed

+11
-3
lines changed

2 files changed

+11
-3
lines changed

podman/miniflux.container.nix

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,7 @@
11
{config, ...}: {
2+
sops.secrets."miniflux/oidcSecret" = {
3+
mode = "0444";
4+
};
25
sops.secrets."miniflux/db" = {};
36
sops.secrets."miniflux/password" = {};
47
sops.secrets."miniflux/user" = {};
@@ -19,13 +22,17 @@
1922
];
2023
environment = {
2124
OAUTH2_CLIENT_ID = "miniflux";
22-
OAUTH2_OIDC_DISCOVERY_ENDPOINT = "http://mail.lua.one";
25+
OAUTH2_CLIENT_SECRET_FILE = "/run/secrets/oidc";
26+
OAUTH2_OIDC_DISCOVERY_ENDPOINT = "https://auth.lua.one/auth/v1";
2327
OAUTH2_PROVIDER = "oidc";
2428
OAUTH2_REDIRECT_URL = "https://rss.lua.one/oauth2/oidc/callback";
2529
OAUTH2_USER_CREATION = "1";
2630
DISABLE_LOCAL_AUTH = "true";
2731
RUN_MIGRATIONS = "1";
2832
};
33+
volumes = [
34+
"${config.sops.secrets."miniflux/oidcSecret".path}:/run/secrets/oidc"
35+
];
2936
};
3037
miniflux-db = {
3138
image = "docker.io/postgres:17-alpine";

secrets.yaml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@ miniflux:
1717
db: ENC[AES256_GCM,data:6SNEbkyghUc=,iv:/hTHYbZbvlUhfhF264HJc1GiY5ujT9gOtXmX0mJe3IY=,tag:h5P+dv5PffO1I6GoUDV8Jw==,type:str]
1818
user: ENC[AES256_GCM,data:6sPVz68x188=,iv:/SeV5zijlZjaM7uBd8YQpS6MbMN1OGmszUDT5FRrkGU=,tag:PhqL0ZKiLsi36CLrIIKNzA==,type:str]
1919
password: ENC[AES256_GCM,data:a+xkNsNC,iv:kKGKs/Jk8DgKVk6iPRLlVHlR9pOoPsI/GRRYfBJD6Hg=,tag:WyML0LRLwNerF9UAhL8Z0Q==,type:str]
20+
oidcSecret: ENC[AES256_GCM,data:eE2/D0vy0TVY9c8Kf9LWgk0zIStb1l5jy+PjUK9khvIe5H2Iv7z8PnS+5T+0vwwud7+WsZpgt01evl9FzSMXKA==,iv:b2o7meYRW/px30C0pXTJ4YQvs5PJ1o9t3qCO1fkG/bs=,tag:0KT/0k46sVIbTu3q/jp8tA==,type:str]
2021
atuin:
2122
db: ENC[AES256_GCM,data:qj/S2Mc=,iv:eixbOyNWtpFLlSzr/rSLuNDcjkr+12FFOqDHONhBCbA=,tag:dQ44MuPHEvvuGoFrJD14VQ==,type:str]
2223
user: ENC[AES256_GCM,data:HD7bu0I=,iv:N7OJEUuMYoVjFc19aqNHp4FK1PRHYITjCq8b5nrnNsc=,tag:K+GIasyTuRmde1wgBHhrSg==,type:str]
@@ -50,8 +51,8 @@ sops:
5051
ZS9IQjA1dEtvVlFmZnEvaDRtdFhhUTgKXUwrNelmv3fIQYoKwgbPe33Bfg4KnFpU
5152
lHC1u7Dfhg18wEcmVWhWxl1Z5lqud4pmKLZy6VBXJMigiMjEWOcEVg==
5253
-----END AGE ENCRYPTED FILE-----
53-
lastmodified: "2025-02-26T15:29:43Z"
54-
mac: ENC[AES256_GCM,data:3FnoBhBB9dswBeWHm4LZz+BBVqCAe9WDgd1T7r6kE9b6JgxM2RpLHItEEJ+rxrp04/yTXfA3Ct/RoVlPMGBRT7BoLbsCQ09YdfSKFe7G645iQvuh6Ar6Qi/G9VvFKh267Xu6ssFa5IrH8u7f1bc+7O2SxZLmthA9W9TYWuFjpI8=,iv:7w8FjFpEQ+WAsxjGo3eHw6CTVmTX1l8QBdjJPaKqdaU=,tag:bJetDzA1/C+sY5KVVd2pxQ==,type:str]
54+
lastmodified: "2025-02-26T15:44:12Z"
55+
mac: ENC[AES256_GCM,data:5t1YpaIdnPekhXzb3gxdtXxIbiegFvx8oVaf1gw/sUTLmCAC6KoWOvHx3HzD4Hq790PVavfvaTKtBduYGRt9MeABONxOCtQ1XUDVIc+hMer/43fhHM3hmjS5RcomYdUAxGaD1/zP3upTwKJZ2AKsJPFdklwqyh9OQMJiN9JbDpA=,iv:SKzLzi+c+MEe68fvxWI7+vxoE02t0PmeffYU4KS2G+M=,tag:C96z9gNbgpvQvkrxNn2QmQ==,type:str]
5556
pgp: []
5657
unencrypted_suffix: _unencrypted
5758
version: 3.9.4

0 commit comments

Comments
 (0)