diff --git a/docs/CHANGELOG.md b/docs/CHANGELOG.md index e42d1129..5d8bea90 100644 --- a/docs/CHANGELOG.md +++ b/docs/CHANGELOG.md @@ -102,6 +102,11 @@ to bind, the failure took down the entire terminal instead of erroring gracefully. +## 2026-09-06 + +- Configured Grafana OIDC authentication via Pocket ID in `platforms/nixos/modules/nmasur/presets/services/grafana/grafana.nix`. +- Enabled `auth.oauth_allow_insecure_email_lookup = true` in Grafana settings to allow linking an incoming OAuth login to an existing Grafana user account with the same email. + ## 2026-07-25 - Added jjui config generation to `jujutsu.nix` in Home Manager to include custom GitHub ruleset bypass commands (`ctrl+b` and `ctrl+shift+b`). diff --git a/docs/oidc-services.md b/docs/oidc-services.md index a4f17815..44183e28 100644 --- a/docs/oidc-services.md +++ b/docs/oidc-services.md @@ -135,18 +135,21 @@ All client secrets should be encrypted with `agenix` under the respective servic - **Pocket ID Redirect URI:** `https://metrics.masu.rs/login/generic_oauth` - **Setup in `grafana/grafana.nix`:** ```nix - services.grafana.settings."auth.generic_oauth" = { - enabled = true; - name = "Pocket ID"; - allow_sign_up = true; - client_id = "85d879ed-1a86-4984-b33d-43806500ef98"; - client_secret = "$__file{${config.secrets.grafana-oidc-secret.dest}}"; - scopes = "openid profile email"; - auth_url = "https://${hostnames.auth}/authorize"; - token_url = "https://${hostnames.auth}/api/oidc/token"; - api_url = "https://${hostnames.auth}/api/oidc/userinfo"; - login_attribute_path = "preferred_username"; - skip_org_role_sync = true; + services.grafana.settings = { + auth.oauth_allow_insecure_email_lookup = true; + "auth.generic_oauth" = { + enabled = true; + name = "Pocket ID"; + allow_sign_up = true; + client_id = "85d879ed-1a86-4984-b33d-43806500ef98"; + client_secret = "$__file{${config.secrets.grafana-oidc-secret.dest}}"; + scopes = "openid profile email"; + auth_url = "https://${hostnames.auth}/authorize"; + token_url = "https://${hostnames.auth}/api/oidc/token"; + api_url = "https://${hostnames.auth}/api/oidc/userinfo"; + login_attribute_path = "preferred_username"; + skip_org_role_sync = true; + }; }; ``` diff --git a/platforms/nixos/modules/nmasur/presets/services/grafana/grafana.nix b/platforms/nixos/modules/nmasur/presets/services/grafana/grafana.nix index 8a45a7bb..234d60b1 100644 --- a/platforms/nixos/modules/nmasur/presets/services/grafana/grafana.nix +++ b/platforms/nixos/modules/nmasur/presets/services/grafana/grafana.nix @@ -56,6 +56,9 @@ in enable = true; settings = { security.secret_key = "$__file{${config.secrets.grafana-secret-key.dest}}"; + auth = { + oauth_allow_insecure_email_lookup = true; + }; server = { domain = hostnames.metrics; http_addr = "127.0.0.1";