Commit Graph

69 Commits

Author SHA1 Message Date
c2fc2f
feb3f31915 nixos/kanidm: add entry management
See https://kanidm.github.io/kanidm/stable/entry_management.html
2026-10-02 16:06:22 +02:00
git@71rd.net
71de89537d services.kanidm: fix broken link in description 2026-07-29 19:06:04 +00:00
Adam C. Stephens
e76403f0ff nixos/kanidm: remove TemporaryFileSystem masking /
This has caused problems before, and again recently https://github.com/kanidm/kanidm/issues/4209.
Instead of continuing to fix edge cases from this non-standard hardening, remove it.
2026-04-07 09:23:52 -04:00
oddlama
77ac8592ef nixos/kanidm: only eliminate directory prefixes when merging BindPaths 2026-04-01 20:41:20 +02:00
oddlama
4828be9bb5 kanidm_1_9: update provision patches 2026-02-14 17:47:57 +01:00
Yureka
0877c3b5d8 nixos/kanidm: Automatically rename server domain (#478222) 2026-02-12 08:56:13 +00:00
rkuklik
7ae6c9bf88 kanidm: refactor option organization and integrate ssh
Change option names to be consistent with other NixOS modules and
option to integrate with Kanidm SSH keys when using the unix module.
2026-01-29 21:15:05 +01:00
Adam C. Stephens
4e4dd876a9 kanidm: add adamcstephens as module/test maintainer 2026-01-29 09:51:48 -05:00
Adam C. Stephens
741dd145a1 nixos/kanidm: require explicit version from all users 2026-01-29 09:48:20 -05:00
NAHO
a2ed7e8d88 nixos: remove optional builtins prefixes from prelude functions
Remove optional builtins prefixes from prelude functions by running:

    builtins=(
      abort
      baseNameOf
      break
      derivation
      derivationStrict
      dirOf
      false
      fetchGit
      fetchMercurial
      fetchTarball
      fetchTree
      fromTOML
      import
      isNull
      map
      null
      placeholder
      removeAttrs
      scopedImport
      throw
      toString
      true
    )

    fd \
      --exclude doc/manual/release-notes \
      --type file \
      . \
      nixos \
      --exec-batch sed --in-place --regexp-extended "
        s/\<builtins\.($(
          printf '%s\n' "${builtins[@]}" |
            paste --delimiter '|' --serial -
        ))\>/\1/g
      "

    nix fmt
2026-01-15 16:07:55 +01:00
Marcus Ramberg
05f7778bc2 nixos/kanidm: add support for kanidm unixd config v2 (#432765) 2026-01-11 16:23:13 +00:00
Patrick
e00fd16309 nixos/kanidm: fix order of nssDatabase entries 2026-01-11 14:43:13 +01:00
provokateurin
7b2ff2f909 nixos/kanidm: Automatically rename server domain 2026-01-09 00:00:06 +01:00
Robert Schütz
29ee69dc27 nixos/kanidm: fix instanceUrl defaultText 2026-01-02 10:13:40 -08:00
Patrick
5af86e8cba nixos/kanidm: add support for kanidm unixd config v2
Co-authored-by: Sammy Etur <sammyetur11@gmail.com>
2025-12-03 19:38:42 +01:00
Shelvacu
505a382b55 nixos/kanidm: fix trying to create backup dir when server is not enabled 2025-11-07 23:12:28 -08:00
Marcus Ramberg
3a8dc6fe7a nixos/kanidm: allow unixd-tasks to read /etc/{passwd/group/shadow}
This seems needed to allow map_group to work

fixes
 process_etc_passwd_group [ 107µs | 100.00% ]
┕━ 🚨 [error]:  | err: Os { code: 2, kind: NotFound, message: "No such file or directory" }
2025-09-20 19:04:04 +02:00
isabel
f587787ba6 kanidm: Fix timeout from endless loop when provisioning (#381954) 2025-08-14 12:57:11 +01:00
Adam C. Stephens
da4f70e2ad kanidm_1_7: init at 1.7.1 (#430205) 2025-08-06 14:54:56 -04:00
Sandro
02e4fa0530 nixos/kanidm: bind ca-bundle to validate url on provisioning (#409184) 2025-08-03 23:32:08 +02:00
Adam C. Stephens
8dca13f414 kanidm: add EOL notice and set for 1.6 2025-08-03 15:27:30 -04:00
Marc Plano-Lesay
0d25584641 nixos/kanidm: accept originUrls following rfc8252 (#428204) 2025-07-25 20:41:26 +08:00
Wolfgang Walther
5a0711127c treewide: run nixfmt 1.0.0 2025-07-24 13:55:40 +02:00
Bert Proesmans
a73ba5c93a nixos/kanidm: bind ca-bundle to validate url on provisioning
The provisioning script can be configured to validate the server certificate,
but the unit lockdown prevents access to the trusted certificate authority
(ca) bundle.
The system trusted ca store path is added to the bind paths as solution.
2025-06-08 18:48:38 +00:00
oddlama
5f833b1008 nixos/kanidm: add option and tests for imperative group management 2025-06-08 11:38:33 +02:00
Adam C. Stephens
a4ff0e3c64 nixos/kanidm: Fix bind paths (#409310) 2025-06-06 08:35:49 -04:00
isabel
5829277e3c nixos/kandim: Fix pkg name withSecretProvisioning (#405263) 2025-06-03 16:34:16 +02:00
Ilan Joselevich
3b6b50dfad nixos/kanidm: merge recursively with extraJsonFile
Previously, if you set group memberships in both locations, they will
get replaced by the ones in extraJsonFile, which is unexpected as it
kicks users from the group. Now the state files get merged recursively,
including the arrays.
2025-05-27 23:44:44 +03:00
Flakebi
c4f052c08a nixos/kanidm: Fix bind paths
1. We bound the directory of certificates, this lead to forced read-only
   binds of these directories, even if they should have been bound
   read-write for other files in there. Looking at the history, there
   seems to be no compelling reason for this, so switch to binding
   the files directly.
2. `/run/kanidmd` is configured as `RuntimeDirectory` so bound
   automatically and we don’t need to specify it explicitly.
2025-05-21 08:49:52 +02:00
provokateurin
89187a62b4 nixos/kandim: Fix pkg name withSecretProvisioning
b22909a5fe/pkgs/by-name/ka/kanidm/generic.nix (L156-L156)
2025-05-08 16:20:45 +02:00
Defelo
32dd44ab11 kanidm-provision: 1.1.2 -> 1.2.0 2025-04-08 17:39:43 +02:00
jopejoe1
daf56b64ff nixos/kanidm: don't set RUST_LOG in systemd service (#394964) 2025-04-03 10:57:36 +02:00
Jappie3
b40d9c82c1 nixos/kanidm: don't set RUST_LOG in systemd service
setting RUST_LOG in the systemd service means that the
serverSettings.log_level option is pretty much useless, as RUST_LOG
takes precedence
2025-03-31 19:34:06 +02:00
oddlama
f15f20aad7 nixos/kanidm: add extraJsonFile to BindReadOnlyPaths if set 2025-03-18 19:42:43 +01:00
Sophie Taylor
4582e7ed83 nixos/kanidm: fix build error from typo (#389686) 2025-03-14 12:16:31 +01:00
h7x4
2c3adc5fc6 nixos/kanidm: add extraJsonFile option (#376490) 2025-03-12 13:15:36 +01:00
Jappie3
16cdde8008 nixos/kanidm: add extraJsonFile option to allow provisioning from a json file 2025-03-01 23:12:29 +01:00
oddlama
2f45486c6c nixos/kanidm: add home_mount_prefix to BindPaths if set 2025-02-17 21:14:45 +01:00
Sophie Taylor
ad55bb9688 kanidm: Fix timeout from endless loop when provisioning 2025-02-14 14:30:19 +10:00
Adam C. Stephens
90840cdb05 nixos/kanidm: set default package version based on stateVersion 2024-12-04 13:35:00 +00:00
oddlama
91cbd96ffe kanidm: allow hydra to cache alternative build with secret provisioning 2024-11-24 19:24:43 +01:00
Sefa Eyeoglu
baa412f46d nixos/kanidm: allow origin url ending without slash (#355216) 2024-11-22 13:44:09 +01:00
oddlama
3e29e0560d nixos/kanidm: add provisioning secret directories to BindReadOnlyPaths 2024-11-20 01:41:31 +01:00
Patrick
6728211ec8 nixos/kanidm: allow origin url ending without slash 2024-11-17 23:21:07 +01:00
Patrick
abeafd2a72 nixos/kanidm: allow not setting bindaddress 2024-11-05 13:53:58 +01:00
Kerstin Humm
b12bcabd24 maintainers: remove erictapen from packages that I don't really maintain anymore 2024-10-22 12:32:29 +02:00
TheRealGramdalf
5a1e877394 nixos/kanidm: fix systemd service type 2024-08-26 18:05:32 +00:00
TheRealGramdalf
8f18393d38 nixos/kanidm: inherit lib, nixfmt 2024-08-26 18:01:58 +00:00
oddlama
aa6cbcbf09 nixos/kanidm: run nixfmt-rfc-style 2024-08-23 20:55:03 +02:00
oddlama
391d05ce95 nixos/kanidm: update provisioning to allow multiple origin urls 2024-08-23 20:46:53 +02:00