Files
ThothII/deploy/nginx-authenticated-proxy.conf.example

48 lines
2.3 KiB
Plaintext

# Host nginx example. The auth service MUST authenticate every request and return only the
# normalized X-Thoth-* identity/admin claims below. ThothII remains on 127.0.0.1:8080.
server {
listen 443 ssl;
server_name thoth.example.test;
ssl_certificate /etc/nginx/tls/fullchain.pem;
ssl_certificate_key /etc/nginx/tls/privkey.pem;
location = /_authenticate {
internal;
proxy_pass http://authentication-gateway/verify;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Original-URI $request_uri;
proxy_set_header X-Authenticated-User "";
proxy_set_header X-Thoth-Principal-Issuer "";
proxy_set_header X-Thoth-Principal-Subject "";
proxy_set_header X-Thoth-Principal-Display-Name "";
proxy_set_header X-Thoth-Is-Admin "";
proxy_set_header X-Thoth-Trusted-Principal-Issuer "";
proxy_set_header X-Thoth-Trusted-Principal-Subject "";
proxy_set_header X-Thoth-Trusted-Principal-Display-Name "";
proxy_set_header X-Thoth-Trusted-Is-Admin "";
}
location / {
auth_request /_authenticate;
auth_request_set $thoth_principal_issuer $upstream_http_x_thoth_principal_issuer;
auth_request_set $thoth_principal_subject $upstream_http_x_thoth_principal_subject;
auth_request_set $thoth_principal_display_name $upstream_http_x_thoth_principal_display_name;
auth_request_set $thoth_is_admin $upstream_http_x_thoth_is_admin;
# Clear public normalized claims and carry auth_request results over the private hop.
proxy_set_header X-Authenticated-User "";
proxy_set_header X-Thoth-Principal-Issuer "";
proxy_set_header X-Thoth-Principal-Subject "";
proxy_set_header X-Thoth-Principal-Display-Name "";
proxy_set_header X-Thoth-Is-Admin "";
proxy_set_header X-Thoth-Trusted-Principal-Issuer $thoth_principal_issuer;
proxy_set_header X-Thoth-Trusted-Principal-Subject $thoth_principal_subject;
proxy_set_header X-Thoth-Trusted-Principal-Display-Name $thoth_principal_display_name;
proxy_set_header X-Thoth-Trusted-Is-Admin $thoth_is_admin;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header Host $host;
proxy_pass http://127.0.0.1:8080;
}
}