Files
Oxicloud/doc/oidc-config-examples.md
T

216 lines
7.0 KiB
Markdown

# 31 - OIDC Config Examples
Configuration examples for integrating with different OIDC (OpenID Connect) providers. One OIDC provider per instance.
## Table of Contents
1. [General OIDC Configuration](#general-oidc-configuration)
2. [Authentik](#authentik)
3. [Authelia](#authelia)
4. [KeyCloak](#keycloak)
5. [Troubleshooting](#troubleshooting)
## General OIDC Configuration
To enable OIDC, set these environment variables:
```bash
# Enable OIDC
OXICLOUD_OIDC_ENABLED=true
# OIDC provider configuration
OXICLOUD_OIDC_PROVIDER_NAME="Display Name"
OXICLOUD_OIDC_ISSUER_URL="https://provider.example.com/realms/your-realm"
OXICLOUD_OIDC_CLIENT_ID="your-client-id"
OXICLOUD_OIDC_CLIENT_SECRET="your-client-secret"
OXICLOUD_OIDC_REDIRECT_URI="https://your-oxicloud.example.com/api/auth/oidc/callback"
OXICLOUD_OIDC_SCOPES="openid profile email"
OXICLOUD_OIDC_FRONTEND_URL="https://your-oxicloud.example.com"
OXICLOUD_OIDC_AUTO_PROVISION="true"
OXICLOUD_OIDC_ADMIN_GROUPS="admin-group"
OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN="false"
```
## Authentik
[Authentik](https://goauthentik.io/) is an open-source identity platform providing authentication, authorization, and user management.
### 1. Create an Application in Authentik
1. Log into the Authentik admin panel
2. Go to "Applications" -> "Create"
3. Enter a name for the application (e.g. "OxiCloud")
4. Select "OAuth2/OpenID Provider" as the provider type
5. In the OAuth2 configuration:
- **Redirect URI/Callback URL**: `https://your-oxicloud.example.com/api/auth/oidc/callback`
- **Client Type**: Confidential
- **Client ID**: auto-generated (note it down)
- **Client Secret**: auto-generated (note it down)
- **Scopes**: openid, email, profile
6. In the UI configuration:
- **Launch URL**: `https://your-oxicloud.example.com/`
- **Icon**: optional
### 2. Configure for Authentik
```yaml
# docker-compose.yml
version: '3'
services:
oxicloud:
image: oxicloud:latest
environment:
OXICLOUD_OIDC_ENABLED: "true"
OXICLOUD_OIDC_PROVIDER_NAME: "Authentik"
OXICLOUD_OIDC_ISSUER_URL: "https://authentik.example.com/application/o/oxicloud"
OXICLOUD_OIDC_CLIENT_ID: "your-authentik-client-id"
OXICLOUD_OIDC_CLIENT_SECRET: "your-authentik-client-secret"
OXICLOUD_OIDC_REDIRECT_URI: "https://oxicloud.example.com/api/auth/oidc/callback"
OXICLOUD_OIDC_SCOPES: "openid profile email"
OXICLOUD_OIDC_FRONTEND_URL: "https://oxicloud.example.com"
OXICLOUD_OIDC_AUTO_PROVISION: "true"
OXICLOUD_OIDC_ADMIN_GROUPS: ""
OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN: "false"
ports:
- "8086:8086"
volumes:
- ./storage:/app/storage
```
## Authelia
[Authelia](https://www.authelia.com/) is an open-source multi-factor authentication solution.
### 1. Configure Authelia
Edit your Authelia configuration (`configuration.yml`):
```yaml
identity_providers:
oidc:
hmac_secret: your-secure-secret # Change to a secure random value
issuer_private_key: /config/private.pem # Path to your private key
cors:
endpoints: ['authorization', 'token', 'revocation', 'introspection']
allowed_origins:
- https://oxicloud.example.com
clients:
- id: oxicloud
description: OxiCloud
secret: your-secure-client-secret # Change this
public: false
authorization_policy: two_factor
redirect_uris:
- https://oxicloud.example.com/api/auth/oidc/callback
scopes: ['openid', 'profile', 'email', 'groups']
userinfo_signing_algorithm: none
```
### 2. Configure for Authelia
```yaml
# docker-compose.yml
version: '3'
services:
oxicloud:
image: oxicloud:latest
environment:
OXICLOUD_OIDC_ENABLED: "true"
OXICLOUD_OIDC_PROVIDER_NAME: "Authelia"
OXICLOUD_OIDC_ISSUER_URL: "https://authelia.example.com"
OXICLOUD_OIDC_CLIENT_ID: "oxicloud"
OXICLOUD_OIDC_CLIENT_SECRET: "your-secure-client-secret"
OXICLOUD_OIDC_REDIRECT_URI: "https://oxicloud.example.com/api/auth/oidc/callback"
OXICLOUD_OIDC_SCOPES: "openid profile email groups"
OXICLOUD_OIDC_FRONTEND_URL: "https://oxicloud.example.com"
OXICLOUD_OIDC_AUTO_PROVISION: "true"
OXICLOUD_OIDC_ADMIN_GROUPS: ""
OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN: "false"
ports:
- "8086:8086"
volumes:
- ./storage:/app/storage
```
## KeyCloak
[KeyCloak](https://www.keycloak.org/) is an open-source identity and access management solution.
### 1. Create a Client in KeyCloak
1. Log into the KeyCloak admin console
2. Select your Realm
3. Go to "Clients" -> "Create"
4. Fill in the form:
- **Client ID**: `oxicloud`
- **Client Protocol**: `openid-connect`
- **Root URL**: `https://oxicloud.example.com`
5. In the client configuration:
- **Access Type**: `confidential`
- **Valid Redirect URIs**: `https://oxicloud.example.com/api/auth/oidc/callback`
- **Web Origins**: `https://oxicloud.example.com` (or `+` to allow all origins)
6. Save the configuration
7. Go to the "Credentials" tab and copy the generated "Secret"
### 2. Configure for KeyCloak
```yaml
# docker-compose.yml
version: '3'
services:
oxicloud:
image: oxicloud:latest
environment:
OXICLOUD_OIDC_ENABLED: "true"
OXICLOUD_OIDC_PROVIDER_NAME: "KeyCloak"
OXICLOUD_OIDC_ISSUER_URL: "https://keycloak.example.com/realms/your-realm"
OXICLOUD_OIDC_CLIENT_ID: "oxicloud"
OXICLOUD_OIDC_CLIENT_SECRET: "your-keycloak-client-secret"
OXICLOUD_OIDC_REDIRECT_URI: "https://oxicloud.example.com/api/auth/oidc/callback"
OXICLOUD_OIDC_SCOPES: "openid profile email"
OXICLOUD_OIDC_FRONTEND_URL: "https://oxicloud.example.com"
OXICLOUD_OIDC_AUTO_PROVISION: "true"
OXICLOUD_OIDC_ADMIN_GROUPS: "oxicloud-admins"
OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN: "false"
ports:
- "8086:8086"
volumes:
- ./storage:/app/storage
```
## Troubleshooting
### Error: "Failed to discover OIDC provider"
The backend cannot reach the provider's discovery endpoint.
**Fixes:**
1. Verify the discovery URL is correct
2. Check that the backend can reach the URL (firewalls, DNS, etc.)
3. If using a self-signed certificate, configure the appropriate trust
### Error: "Invalid redirect URI"
The OIDC provider is rejecting the redirect URI.
**Fixes:**
1. Make sure the redirect URI configured in the backend matches exactly what is registered in the provider
2. Check for protocol differences (http vs https), port, or path mismatches
### Error: "User does not exist and auto-creation is disabled"
**Fixes:**
1. Enable auto-provisioning: `OXICLOUD_OIDC_AUTO_PROVISION="true"`
2. Or manually create the user before attempting OIDC login
### Error: "Could not extract user ID from claim"
The backend cannot find the user ID attribute in the token claims.
**Fixes:**
1. Verify the provider returns the `sub` claim in tokens
2. Make sure scopes in **OXICLOUD_OIDC_SCOPES** include `openid`
3. Configure the provider to include the required claims in tokens
See `oidc-architecture.md` and `oidc-integration.md` for deeper technical details.