48 lines
2.3 KiB
Plaintext
48 lines
2.3 KiB
Plaintext
# Host nginx example. The auth service MUST authenticate every request and return only the
|
|
# normalized X-Thoth-* identity/admin claims below. ThothII remains on 127.0.0.1:8080.
|
|
server {
|
|
listen 443 ssl;
|
|
server_name thoth.example.test;
|
|
|
|
ssl_certificate /etc/nginx/tls/fullchain.pem;
|
|
ssl_certificate_key /etc/nginx/tls/privkey.pem;
|
|
|
|
location = /_authenticate {
|
|
internal;
|
|
proxy_pass http://authentication-gateway/verify;
|
|
proxy_pass_request_body off;
|
|
proxy_set_header Content-Length "";
|
|
proxy_set_header X-Original-URI $request_uri;
|
|
proxy_set_header X-Authenticated-User "";
|
|
proxy_set_header X-Thoth-Principal-Issuer "";
|
|
proxy_set_header X-Thoth-Principal-Subject "";
|
|
proxy_set_header X-Thoth-Principal-Display-Name "";
|
|
proxy_set_header X-Thoth-Is-Admin "";
|
|
proxy_set_header X-Thoth-Trusted-Principal-Issuer "";
|
|
proxy_set_header X-Thoth-Trusted-Principal-Subject "";
|
|
proxy_set_header X-Thoth-Trusted-Principal-Display-Name "";
|
|
proxy_set_header X-Thoth-Trusted-Is-Admin "";
|
|
}
|
|
|
|
location / {
|
|
auth_request /_authenticate;
|
|
auth_request_set $thoth_principal_issuer $upstream_http_x_thoth_principal_issuer;
|
|
auth_request_set $thoth_principal_subject $upstream_http_x_thoth_principal_subject;
|
|
auth_request_set $thoth_principal_display_name $upstream_http_x_thoth_principal_display_name;
|
|
auth_request_set $thoth_is_admin $upstream_http_x_thoth_is_admin;
|
|
# Clear public normalized claims and carry auth_request results over the private hop.
|
|
proxy_set_header X-Authenticated-User "";
|
|
proxy_set_header X-Thoth-Principal-Issuer "";
|
|
proxy_set_header X-Thoth-Principal-Subject "";
|
|
proxy_set_header X-Thoth-Principal-Display-Name "";
|
|
proxy_set_header X-Thoth-Is-Admin "";
|
|
proxy_set_header X-Thoth-Trusted-Principal-Issuer $thoth_principal_issuer;
|
|
proxy_set_header X-Thoth-Trusted-Principal-Subject $thoth_principal_subject;
|
|
proxy_set_header X-Thoth-Trusted-Principal-Display-Name $thoth_principal_display_name;
|
|
proxy_set_header X-Thoth-Trusted-Is-Admin $thoth_is_admin;
|
|
proxy_set_header X-Forwarded-Proto https;
|
|
proxy_set_header Host $host;
|
|
proxy_pass http://127.0.0.1:8080;
|
|
}
|
|
}
|