Owl is a set of tools to manage realms of units, users and groups.
999
Owl is a platform agnostic set of tools to manage realms of units, users and groups. Thanks to the modular conception, any backend can theorically be used to store and access data (LDAP, MySQL, MongoDB, ...). For now, only LDAP is supported, please open an issue if another one is needed.
The project is composed of 3 tools :
This repo is for Owl CLI.
Owl is opiniated on how to manage user accounts, but it is also highly customizable.
There is only 4 types of object manipulated.
Each object has a unique identifier and a set of prefefined properties that can be multivalued. Additional properties can be configured.
Realms are associated with servers, instance, etc... where the data is persisted. Each realm is in isolation from other realms.
| Property | Description |
|---|---|
| ID | Unique realm identifier |
| URL | Location of the realm |
| Username | Used as login account to the realm backend |
Units are logical grouping of users and groups, used to mimic real-world organization (like OU in LDAP).
| Property | Description |
|---|---|
| ID | Unique unit identifier |
| Description | Description of the unit |
| Property | Description |
|---|---|
| ID | Unique user identifier |
| FirstNames | First names [multivalued property] |
| LastNames | Last names [multivalued property] |
| Emails | E-mails owned by the user [multivalued property] |
| Property | Description |
|---|---|
| ID | Unique group identifier |
| Name | Name of the group |
| Members | Ids of users in the group [multivalued property] |
First principle : Owl CLI respect the UNIX philosophy.
Write programs that do one thing and do it well.
Write programs to work together.
Write programs to handle text streams, because that is a universal interface.-- Douglas McIlroy, inventor of Unix pipelines
How ?
Second principle : Owl is a devops tool.
Why ?
Create or modify realms with owl realm set command.
$ owl realm set dev ldap://dev.my-company.com/dc=example,dc=com cn=admin,dc=example,dc=com
Set realm 'dev' to 'ldap://dev.my-company.com/dc=example,dc=com'.
List created realms with owl realm list command.
$ owl realm list -o table
ID Username URL
dev cn=admin,dc=example,dc=com ldap://dev.my-company.com/dc=example,dc=com
prod cn=admin,dc=example,dc=com ldap://prod.my-company.com/dc=example,dc=com
Login into a realm with owl realm login command. It is also possible to use the --realm flag on a specific command.
$ owl realm login dev
Password :
Connected to realm 'dev' as user 'admin'.
Create a new unit with owl unit create command.
$ owl unit create my-unit Test unit
Created unit 'my-unit' in realm 'dev'.
Every create command also read JSON on stdin, so these are other ways of doing :
$ owl unit create <<< '{"ID": "my-unit", "Description": "Test unit"}'
Created unit 'my-unit' in realm 'dev'.
$ echo '{"ID": "my-unit", "Description": "Test unit"}' | owl unit create
Created unit 'my-unit' in realm 'dev'.
List existing units with owl unit list command.
$ owl unit list
ID Description
my-unit Test unit
To create users and groups, you first need to select a unit with owl unit use command. It is also possible to use the --unit flag on a specific command.
$ owl unit use my-unit
Using unit 'my-unit' for next commands.
To create a user, use owl user create command.
$ owl user create batman firstname=Bruce lastname=Wayne
Created user 'batman' in unit 'my-unit' of realm 'dev'.
$ owl user create <<< '{"ID": "batman", "FirstNames": ["Bruce"], "LastNames": ["Wayne"]}'
Created user 'batman' in unit 'my-unit' of realm 'dev'.
You can also create or replace an existing user with owl user apply command.
$ owl user apply firstname=Bruce lastname=Wayne [email protected]
Modified user 'batman' in unit 'my-unit' of realm 'dev'.
$ owl user apply joker firstname=Arthur lastname=Flake [email protected]
Created user 'joker' in unit 'my-unit' of realm 'dev'.
To only add a single attribute, use owl user append command.
$ owl user append joker firstname="Jack"
Modifier user 'joker' in unit 'my-unit' of realm 'dev'.
List user with owl user list command.
$ owl user list
ID First Names Last Names E-mails
batman Bruce Wayne [email protected]
joker Arthur, Jack Flake [email protected]
Give user a random password with owl user new-password command.
$ owl user new-password joker
Assigned new random password to user 'joker' in unit 'my-unit' of realm 'dev'.
You guessed it, use owl group create command to create a group.
$ owl group create bad-guys member=joker member=batman
Created group 'bad-guys' in unit 'my-unit' of realm 'dev'.
Member list can be modified with owl group member sub-commands.
$ owl group member remove bad-guys batman
Modified group 'bad-guys' in unit 'my-unit' of realm 'dev'.
$ owl group member add good-guys batman
Modified group 'good-guys' in unit 'my-unit' of realm 'dev'.
All commands can output results in JSON or YAML format, thanks to the --output (short -o) flag.
$ owl user list -o json
{"Users": [{"ID": "batman", "FirstNames": ["Bruce"], "LastNames": ["Wayne"], "Emails": ["[email protected]"]}, {"ID": "joker", "FirstNames": ["Arthur", "Jack"], "LastNames": ["Flake"], "Emails": ["[email protected]"]}]}
This universal interface enable the use of other programs, for example jq.
$ owl user list -o json | jq
{
"Users": [
{
"ID": "batman",
"FirstNames": [
"Bruce"
],
"LastNames": [
"Wayne"
],
"Emails": [
"[email protected]"
]
},
{
"ID": "joker",
"FirstNames": [
"Arthur",
"Jack"
],
"LastNames": [
"Flake"
],
"Emails": [
"[email protected]"
]
}
]
}
$ owl user ls -o json | jq ".Users | [.[].ID]"
[
"batman",
"joker"
]
Owl also understand JSON if passed throught stdin, this enables chaining of owl commands.
$ owl user list -o json | owl import --realm=prod --unit=organization
Imported 2 users in unit 'organization' of realm 'prod'.
Content type
Image
Digest
Size
10.4 MB
Last updated
almost 7 years ago
docker pull adrienaury/owl