diff --git a/modules/nixos/system/default.nix b/modules/nixos/system/default.nix index a587cbd..b983f0b 100644 --- a/modules/nixos/system/default.nix +++ b/modules/nixos/system/default.nix @@ -1,9 +1,9 @@ { ... }: { imports = [ ./dbus ./fonts ./hw ./locale ./network ./nix ./security ./xdg ]; - services.journald.extraConfig = '' - LineMax=64K - SystemMaxUse=256M - SystemMaxFileSize=128M - ''; + # services.journald.extraConfig = '' + # LineMax=128K + # SystemMaxUse=512M + # SystemMaxFileSize=128M + # ''; } diff --git a/modules/server/containers/apps/authentik.nix b/modules/server/containers/apps/authentik.nix index 4ae928b..6f563b9 100644 --- a/modules/server/containers/apps/authentik.nix +++ b/modules/server/containers/apps/authentik.nix @@ -86,9 +86,6 @@ in { AUTHENTIK_HOST = "https://${containerCfg.subdomain}.${serverCfg.hostDomain}"; AUTHENTIK_INSECURE = "false"; }; - overrides = { - ports = [ "636:6636" ]; - }; }; }; diff --git a/modules/server/containers/data/authentik/ldap.yaml b/modules/server/containers/data/authentik/ldap.yaml index e46ba5e..29a540e 100644 --- a/modules/server/containers/data/authentik/ldap.yaml +++ b/modules/server/containers/data/authentik/ldap.yaml @@ -50,6 +50,8 @@ entries: state: present identifiers: name: "LDAP Search Role" + permissions: + - "authentik_providers_ldap.search_full_directory" - model: authentik_core.group state: present @@ -60,13 +62,3 @@ entries: - !Find [authentik_core.user, [username, "ldap-service"]] roles: - !Find [authentik_rbac.role, [name, "LDAP Search Role"]] - - - model: authentik_providers_ldap.ldapprovider - state: present - identifiers: - name: ldap-provider - attrs: - object_permissions: - - role: !Find [authentik_rbac.role, [name, "LDAP Search Role"]] - permissions: - - "authentik_providers_ldap.search_full_directory"