headscale/docker-dev/headscale-config-oidc.yaml

60 lines
1.2 KiB
YAML
Raw Permalink Normal View History

---
# Headscale configuration with OIDC enabled for testing
server_url: http://localhost:8180
listen_addr: 0.0.0.0:8080
metrics_listen_addr: 0.0.0.0:9090
grpc_listen_addr: 0.0.0.0:50443
grpc_allow_insecure: true
# IP prefixes for the tailnet
prefixes:
v4: 100.64.0.0/10
v6: fd7a:115c:a1e0::/48
ip_allocation: sequential
# Database configuration
database:
type: sqlite
sqlite:
path: /var/lib/headscale/db.sqlite
# OIDC Configuration for testing with Keycloak
oidc:
issuer: "http://keycloak:8080/realms/headscale"
client_id: "headscale-client"
client_secret: "your-client-secret"
scope: ["openid", "profile", "email", "groups"]
extra_params: {}
allowed_domains: []
allowed_groups: []
allowed_users: []
expiry: 180d
use_expiry_from_token: false
pkce:
enabled: true
method: "S256"
# DNS Configuration
dns:
override_local_dns: true
nameservers:
global: ["1.1.1.1", "1.0.0.1", "8.8.8.8"]
domains: []
extra_records: []
magic_dns: true
base_domain: headscale.net
# TLS disabled for local testing
disable_check_updates: true
ephemeral_node_inactivity_timeout: 30m
# Policy configuration
policy:
mode: file
path: "/etc/headscale/acl.hujson"
# Log configuration
log:
format: text
level: info