about summary refs log tree commit diff
path: root/nixos
diff options
context:
space:
mode:
authorJonathan Zielinski <jozi@dbc.dk>2024-04-10 23:33:39 +0200
committerJonathan Zielinski <jozi@dbc.dk>2024-04-18 15:20:53 +0000
commit87bbc5fbbed9265649c90c2567cc9df6df5266bc (patch)
tree813b579e92a2095095719e515f2936c89c667313 /nixos
parent0057749884f87a7c095cf2ed1bfa0a407a3d602f (diff)
nixos/oauth2_proxy: add oidc-issuer-url flag
Diffstat (limited to 'nixos')
-rw-r--r--nixos/modules/services/security/oauth2_proxy.nix10
1 files changed, 10 insertions, 0 deletions
diff --git a/nixos/modules/services/security/oauth2_proxy.nix b/nixos/modules/services/security/oauth2_proxy.nix
index d1dc37d549d2d..d3e1a70d7c204 100644
--- a/nixos/modules/services/security/oauth2_proxy.nix
+++ b/nixos/modules/services/security/oauth2_proxy.nix
@@ -47,6 +47,7 @@ let
     reverse-proxy = reverseProxy;
     proxy-prefix = proxyPrefix;
     profile-url = profileURL;
+    oidc-issuer-url = oidcIssuerUrl;
     redeem-url = redeemURL;
     redirect-url = redirectURL;
     request-logging = requestLogging;
@@ -131,6 +132,15 @@ in
       example = "123456.apps.googleusercontent.com";
     };
 
+    oidcIssuerUrl = mkOption {
+      type = types.nullOr types.str;
+      default = null;
+      description = ''
+        The OAuth issuer URL.
+      '';
+      example = "https://login.microsoftonline.com/{TENANT_ID}/v2.0";
+    };
+
     clientSecret = mkOption {
       type = types.nullOr types.str;
       description = lib.mdDoc ''