# Glue: register the swarm's forge as an OIDC client wherever authelia runs. # # ONE PAIRING PER FILE — forge ← authelia, and nothing else. Deleting this # leaves a swarm whose forge is not a client authelia has ever heard of, so # its "sign in with" button can never complete a login and nothing minted its # secret either. # # ⚠️ Gated on authelia being HERE, and deliberately NOT on this host running # the forge. A client is a row in THIS host's provider config, so it can only be # declared where that config is rendered — and ./hive-forge/default.nix's whole # `config` block hangs off `deploy.forgejo.enable`, so a swarm with the forge # and authelia on different hosts would register the client nowhere at all. # Same shape as ./glue-grafana-oidc-client.nix, for the same reason. # # Unlike Grafana's, this client is never unused: every swarm runs a forge. { lib, config, ... }: let hyperhiveCfg = config.services.hyperhive; deployCfg = hyperhiveCfg.deploy; forgeCfg = hyperhiveCfg.swarm.forge; in { config = lib.mkIf deployCfg.authelia.enable { # One declaration, two readers. The forge knows its own callback URL; # making the operator restate it in authelia's client list would be a # second source of truth for a string whose mismatch is a silent # rejected login. services.hyperhive.swarm.authelia.oidc.clients = [ { id = forgeCfg.sso.clientId; description = "HyperHive forge"; redirectUris = [ forgeCfg.sso.redirectUri ]; } ]; }; }