- Add Groups field to User struct with JSON storage - Include GetGroups() and SetGroups() helper methods - Extract groups from OIDC claims in FromClaim() - Add database migration 202509161200 for groups column - Update config-example.yaml with groups scope - Add comprehensive documentation and testing
60 lines
1.2 KiB
YAML
60 lines
1.2 KiB
YAML
---
|
|
# Headscale configuration with OIDC enabled for testing
|
|
server_url: http://localhost:8180
|
|
listen_addr: 0.0.0.0:8080
|
|
metrics_listen_addr: 0.0.0.0:9090
|
|
grpc_listen_addr: 0.0.0.0:50443
|
|
grpc_allow_insecure: true
|
|
|
|
# IP prefixes for the tailnet
|
|
prefixes:
|
|
v4: 100.64.0.0/10
|
|
v6: fd7a:115c:a1e0::/48
|
|
|
|
ip_allocation: sequential
|
|
|
|
# Database configuration
|
|
database:
|
|
type: sqlite
|
|
sqlite:
|
|
path: /var/lib/headscale/db.sqlite
|
|
|
|
# OIDC Configuration for testing with Keycloak
|
|
oidc:
|
|
issuer: "http://keycloak:8080/realms/headscale"
|
|
client_id: "headscale-client"
|
|
client_secret: "your-client-secret"
|
|
scope: ["openid", "profile", "email", "groups"]
|
|
extra_params: {}
|
|
allowed_domains: []
|
|
allowed_groups: []
|
|
allowed_users: []
|
|
expiry: 180d
|
|
use_expiry_from_token: false
|
|
pkce:
|
|
enabled: true
|
|
method: "S256"
|
|
|
|
# DNS Configuration
|
|
dns:
|
|
override_local_dns: true
|
|
nameservers:
|
|
global: ["1.1.1.1", "1.0.0.1", "8.8.8.8"]
|
|
domains: []
|
|
extra_records: []
|
|
magic_dns: true
|
|
base_domain: headscale.net
|
|
|
|
# TLS disabled for local testing
|
|
disable_check_updates: true
|
|
ephemeral_node_inactivity_timeout: 30m
|
|
|
|
# Policy configuration
|
|
policy:
|
|
mode: file
|
|
path: "/etc/headscale/acl.hujson"
|
|
|
|
# Log configuration
|
|
log:
|
|
format: text
|
|
level: info |