Making nix the user provisioner for my own self-hosted services

Hello, I a building towards making all my authenticated services auto-provision my accounts using a combination of kanidm, rauthy, agenix, and nix.

You can track my flake work here: https://codeberg.org/caniko/nix-provenance

Currently focused on:

Special thanks to oddlama for opening my eyes to this idea with his project: GitHub - oddlama/kanidm-provision: A small utility to help with kanidm provisioning · GitHub , I use it

I love nix! Automating my IT life has started to pay dividends already, join me! :slight_smile:

2 Likes

at least for rauthy, it already supports bootstrapping. see Bootstrapping - Rauthy Documentation, especially close to the bottom with the schemas. The rest of these like immich you could solve with OIDC or some other form of SSO, no?

1 Like

Yes, OIDC is great for user self onboarding (roles like admin, user, guest are controlled via ldap backend group management)

my nix stack:

  • lldap authoritative usr mgnt with self services like avatar, phone change, password reset mail
  • authelia issues oidc passkeys (otp/smartcard)
  • oidc auto subscriber:
    • nextcloud
    • immich
    • matrix / element (chat)
    • vaultwarden
    • paperless-ngx
    • paperless-ai
    • vikunja (project/tickets/todo)
    • openweb-ui (ai-chat)
    • miniflux (rss)
    • readeck (bookmark/webarchive)
    • jellyfin
    • vaultls
    • caddy reverse proxy

yeah, nix-provenance uses OIDC under the hood