Headscale
Configure Headscale VPN with Pocket ID OIDC
Create OIDC Client in Pocket ID
- Create a new OIDC Client in Pocket ID (e.g.,
Headscale). - Set the callback URL:
https://<HEADSCALE-DOMAIN>/oidc/callback, or leave blank to autofill on first login. - Enable
PKCE. - Copy the Client ID and Client Secret.
Configure Headscale
[!NOTE] Refer to the example
config.yamlfor full OIDC configuration options.
Add the following to config.yaml:
(Optional) Restrict Access to Certain Groups
To allow only specific groups, add: