Phoebus Olog¶
Phoebus Olog is a service that serves as an online logbook, for experimental and industrial logging.
You can install the Phoebus Olog service by using services.phoebus-olog.enable,
and configure it by using the other options in services.phoebus-olog.
Important
Make sure to follow the NixOS Prerequisites.
Important
The EPNix Phoebus Olog NixOS module configures the service to listen for HTTP connections instead of HTTPS, which is the opposite of default upstream.
That’s because the upstream HTTPS configuration’s private key is publicly available in the Git repository, making it insecure.
If you want an HTTPS service, configure a reverse proxy that forwards connections to the Phoebus Olog service.
Enabling the service¶
To enable the Phoebus Olog service, add this to your configuration.
phoebus-olog.nix¶{
services.phoebus-olog = {
enable = true;
# If you want to expose your service as-is:
openFirewall = true;
# Choose your authentication providers,
# see below for a list of available providers.
settings.authenticationProviders = [ "XXX" ];
};
# Phoebus Olog needs ElasticSearch.
# If not already enabled elsewhere in your configuration,
# Enable it with the code below:
services.elasticsearch = {
enable = true;
package = pkgs.elasticsearch7;
};
# Elasticsearch, needed by Phoebus Olog, is not free software (SSPL | Elastic License).
# To accept the license, add the code below:
nixpkgs.config.allowUnfreePredicate = pkg:
builtins.elem (lib.getName pkg) [
"elasticsearch"
];
}
See also
For a complete list of options related to Phoebus Olog,
see services.phoebus-olog.
Custom port¶
To use a custom HTTP port,
set the services.phoebus-olog.settings."server.port" option:
phoebus-olog.nix — Set custom HTTP port¶{
services.phoebus-olog = {
enable = true;
openFirewall = true;
settings."server.port" = 1234;
};
# ...
}
Authentication¶
Phoebus Olog supports multiple authentication providers, which can be combined:
inMemoryNot recommended for production servers. Hard coded users and passwords. Provides 2 users: an administrator and a user.
embeddedLdapAt the start of the Phoebus Olog service, it starts an embedded LDAP server.
ldapFor a usage with an external LDAP server.
activeDirectoryFor a usage with an external Microsoft Active Directory server.
See also
Upstream’s Authentication documentation.
In memory¶
Caution
This authentication type isn’t recommended for production servers.
This authentication configures 2 users:
an admin
adminwithadminPassas password,and a user
userwithuserPassas password.
To use it, set services.phoebus-olog.settings.authenticationProviders to
[ "inMemory" ]:
phoebus-olog.nix — Default values for in memory authentication¶{
services.phoebus-olog = {
enable = true;
# ...
settings = {
"authenticationProviders" = [ "inMemory" ];
};
};
# ...
}
Embedded LDAP¶
With this authentication backend,
Phoebus Olog starts an embedded LDAP server,
which you can configure
by using the services.phoebus-olog.settings.embedded_ldap_ldif option.
This option must point to an LDIF file, that has the content of the LDAP database.
Start by downloading the olog.ldif file from the Phoebus Olog source code,
put it next to your phoebus-olog.nix file,
and edit it to suit your needs.
Configure Phoebus Olog to use your LDIF file:
phoebus-olog.nix — Configure the embedded LDAP authentication¶{
services.phoebus-olog = {
enable = true;
# ...
settings = {
"authenticationProviders" = [ "embeddedLdap" ];
"spring.ldap.embedded.ldif" = "file://${./olog.ldif}";
};
};
# ...
}
To generate a password, use the mkpasswd command:
bcrypt-encrypted password¶mkpasswd -m bcrypt
External LDAP authentication¶
Note
Configuring an fully featured LDAP server is out of scope for this guide. See the OpenLDAP NixOS Wiki page for how to configure an OpenLDAP server on NixOS.
This section assumes you already have a configured LDAP server. This configured LDAP server can be an embedded LDAP server of another service.
If you want to use your company’s LDAP server, ask your IT team for the LDAP configuration. The configuration must include:
URL,
base DN,
user DN pattern,
group search base,
and group search path.
Here is an example configuration:
phoebus-olog.nix — Configure the external LDAP authentication¶{
services.phoebus-olog = {
enable = true;
# ...
settings = {
"auth.impl" = "ldap";
"ldap.urls" = "ldaps://auth.mycompany.com/dc=mycompany,dc=com";
"ldap.base.dn" = "dc=mycompany,dc=com";
"ldap.user.dn.pattern" = "uid={0},ou=People";
"ldap.groups.search.base" = "ou=Group";
"ldap.groups.search.pattern" = "(memberUid= {1})";
};
};
# ...
}