mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-09-29 19:21:13 +02:00
@@ -23,7 +23,8 @@ version: "3.0"
|
||||
services:
|
||||
oauth2-proxy:
|
||||
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.1
|
||||
ports: []
|
||||
ports:
|
||||
- 4180:4180/tcp
|
||||
hostname: oauth2-proxy
|
||||
container_name: oauth2-proxy
|
||||
command: --config /oauth2-proxy.cfg
|
||||
@@ -44,7 +45,7 @@ services:
|
||||
image: nginx:1.29
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- 80:80/tcp
|
||||
- 8080:8080/tcp
|
||||
hostname: nginx
|
||||
volumes:
|
||||
- "./nginx.conf:/etc/nginx/conf.d/default.conf"
|
||||
|
||||
@@ -1,11 +1,12 @@
|
||||
# Reverse proxy to oauth2-proxy
|
||||
server {
|
||||
listen 80;
|
||||
server_name oauth2-proxy.oauth2-proxy.localhost;
|
||||
listen 8080;
|
||||
server_name oauth2-proxy.localtest.me;
|
||||
|
||||
location / {
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-Uri $request_uri;
|
||||
|
||||
proxy_pass http://oauth2-proxy:4180/;
|
||||
}
|
||||
@@ -13,8 +14,8 @@ server {
|
||||
|
||||
# Reverse proxy to httpbin
|
||||
server {
|
||||
listen 80;
|
||||
server_name httpbin.oauth2-proxy.localhost;
|
||||
listen 8080;
|
||||
server_name httpbin.localtest.me;
|
||||
|
||||
auth_request /internal-auth/oauth2/auth;
|
||||
|
||||
@@ -29,50 +30,7 @@ server {
|
||||
# Named location for OAuth2 sign-in redirect
|
||||
# Returns a proper 302 that works with --skip-provider-button
|
||||
location @oauth2_signin {
|
||||
return 302 http://oauth2-proxy.oauth2-proxy.localhost/oauth2/sign_in?rd=$scheme://$host$request_uri;
|
||||
}
|
||||
|
||||
# auth_request must be a URI so this allows an internal path to then proxy to
|
||||
# the real auth_request path.
|
||||
# The trailing /'s are required so that nginx strips the prefix before proxying.
|
||||
location /internal-auth/ {
|
||||
internal; # Ensure external users can't access this path
|
||||
|
||||
# Make sure the OAuth2 Proxy knows where the original request came from.
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-Uri $request_uri;
|
||||
|
||||
proxy_pass http://oauth2-proxy:4180/;
|
||||
}
|
||||
}
|
||||
|
||||
# Statically serve the nginx welcome
|
||||
server {
|
||||
listen 80;
|
||||
server_name oauth2-proxy.localhost;
|
||||
|
||||
location / {
|
||||
auth_request /internal-auth/oauth2/auth;
|
||||
|
||||
# On 401, redirect to the sign_in page via a named location
|
||||
# This ensures a proper 302 redirect that browsers will follow
|
||||
error_page 401 = @oauth2_signin;
|
||||
|
||||
root /usr/share/nginx/html;
|
||||
index index.html index.htm;
|
||||
}
|
||||
|
||||
# Named location for OAuth2 sign-in redirect
|
||||
# Returns a proper 302 that works with --skip-provider-button
|
||||
location @oauth2_signin {
|
||||
return 302 http://oauth2-proxy.oauth2-proxy.localhost/oauth2/sign_in?rd=$scheme://$host$request_uri;
|
||||
}
|
||||
|
||||
# redirect server error pages to the static page /50x.html
|
||||
error_page 500 502 503 504 /50x.html;
|
||||
location = /50x.html {
|
||||
root /usr/share/nginx/html;
|
||||
return 302 http://oauth2-proxy.localtest.me:8080/oauth2/sign_in?rd=$scheme://$host$request_uri;
|
||||
}
|
||||
|
||||
# auth_request must be a URI so this allows an internal path to then proxy to
|
||||
|
||||
@@ -1,14 +1,19 @@
|
||||
http_address="0.0.0.0:4180"
|
||||
cookie_secret="OQINaROshtE9TcZkNAm-5Zs2Pv3xaWytBmc5W7sPX7w="
|
||||
provider="oidc"
|
||||
email_domains="example.com"
|
||||
oidc_issuer_url="http://dex.localtest.me:5556/dex"
|
||||
cookie_secure="false"
|
||||
upstreams="static://200"
|
||||
cookie_domains=[".localtest.me"] # Required so cookie can be read on all subdomains.
|
||||
whitelist_domains=[".localtest.me"] # Required to allow redirection back to original requested target.
|
||||
|
||||
# dex provider
|
||||
client_secret="b2F1dGgyLXByb3h5LWNsaWVudC1zZWNyZXQK"
|
||||
client_id="oauth2-proxy"
|
||||
cookie_secure="false"
|
||||
redirect_url="http://oauth2-proxy.localtest.me:4180/oauth2/callback"
|
||||
|
||||
oidc_issuer_url="http://dex.localtest.me:5556/dex"
|
||||
provider="oidc"
|
||||
provider_display_name="Dex"
|
||||
|
||||
redirect_url="http://oauth2-proxy.oauth2-proxy.localhost/oauth2/callback"
|
||||
cookie_domains=".oauth2-proxy.localhost" # Required so cookie can be read on all subdomains.
|
||||
whitelist_domains=".oauth2-proxy.localhost" # Required to allow redirection back to original requested target.
|
||||
# Enables the use of `X-Forwarded-*` headers to determine request correctly
|
||||
reverse_proxy="true"
|
||||
|
||||
Reference in New Issue
Block a user