From 448ae8f0bc783a1230ee0f87d01a3a86d7614e10 Mon Sep 17 00:00:00 2001 From: K900 Date: Wed, 21 May 2025 21:55:01 +0300 Subject: [PATCH] nixos/opencloud: slightly better documentation --- nixos/modules/services/web-apps/opencloud.nix | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/nixos/modules/services/web-apps/opencloud.nix b/nixos/modules/services/web-apps/opencloud.nix index 0eded3cc96f9..90820822d64e 100644 --- a/nixos/modules/services/web-apps/opencloud.nix +++ b/nixos/modules/services/web-apps/opencloud.nix @@ -80,6 +80,18 @@ in The possible config options are currently not well documented, see source code: https://github.com/opencloud-eu/opencloud/blob/main/pkg/config/config.go ''; + + example = { + proxy = { + auto_provision_accounts = true; + oidc.rewrite_well_known = true; + role_assignment = { + driver = "oidc"; + oidc_role_mapper.role_claim = "opencloud_roles"; + }; + }; + web.web.config.oidc.scope = "openid profile email opencloud_roles"; + }; }; environmentFile = lib.mkOption { @@ -105,6 +117,8 @@ in Use this to set configuration that may affect multiple microservices. + Set `OC_INSECURE = "false"` if you want OpenCloud to terminate TLS. + Configuration provided here will override `settings`. ''; example = {