mirror of
https://github.com/nmasur/dotfiles
synced 2026-09-08 13:36:09 +00:00
fix(grafana): allow oauth email lookup to match existing user
This commit is contained in:
@@ -102,6 +102,11 @@
|
||||
to bind, the failure took down the entire terminal instead of erroring
|
||||
gracefully.
|
||||
|
||||
## 2026-09-06
|
||||
|
||||
- Configured Grafana OIDC authentication via Pocket ID in `platforms/nixos/modules/nmasur/presets/services/grafana/grafana.nix`.
|
||||
- Enabled `auth.oauth_allow_insecure_email_lookup = true` in Grafana settings to allow linking an incoming OAuth login to an existing Grafana user account with the same email.
|
||||
|
||||
## 2026-07-25
|
||||
|
||||
- Added jjui config generation to `jujutsu.nix` in Home Manager to include custom GitHub ruleset bypass commands (`ctrl+b` and `ctrl+shift+b`).
|
||||
|
||||
@@ -135,7 +135,9 @@ All client secrets should be encrypted with `agenix` under the respective servic
|
||||
- **Pocket ID Redirect URI:** `https://metrics.masu.rs/login/generic_oauth`
|
||||
- **Setup in `grafana/grafana.nix`:**
|
||||
```nix
|
||||
services.grafana.settings."auth.generic_oauth" = {
|
||||
services.grafana.settings = {
|
||||
auth.oauth_allow_insecure_email_lookup = true;
|
||||
"auth.generic_oauth" = {
|
||||
enabled = true;
|
||||
name = "Pocket ID";
|
||||
allow_sign_up = true;
|
||||
@@ -148,6 +150,7 @@ All client secrets should be encrypted with `agenix` under the respective servic
|
||||
login_attribute_path = "preferred_username";
|
||||
skip_org_role_sync = true;
|
||||
};
|
||||
};
|
||||
```
|
||||
|
||||
### 5. Paperless-ngx (`paper.masu.rs`)
|
||||
|
||||
@@ -56,6 +56,9 @@ in
|
||||
enable = true;
|
||||
settings = {
|
||||
security.secret_key = "$__file{${config.secrets.grafana-secret-key.dest}}";
|
||||
auth = {
|
||||
oauth_allow_insecure_email_lookup = true;
|
||||
};
|
||||
server = {
|
||||
domain = hostnames.metrics;
|
||||
http_addr = "127.0.0.1";
|
||||
|
||||
Reference in New Issue
Block a user