A lightweight Docker image designed for LDAP service debugging and testing.
1.2K
A lightweight Docker image designed for LDAP service debugging and testing within Kubernetes clusters.
docker build -f ldap/Dockerfile.ldap -t ldap-debug:latest ldap/
docker run -it --rm ldap-debug:latest
# Simple search
ldapsearch -x -H ldap://ldap-server:389 -b "dc=example,dc=com"
# Search with filter
ldapsearch -x -H ldap://ldap-server:389 -b "dc=example,dc=com" "(uid=jdoe)"
# Authenticated search
ldapsearch -x -H ldap://ldap-server:389 \
-D "cn=admin,dc=example,dc=com" \
-w password \
-b "dc=example,dc=com" \
"(objectClass=person)"
# Search with specific attributes
ldapsearch -x -H ldap://ldap-server:389 \
-b "dc=example,dc=com" \
"(uid=jdoe)" mail cn sn
# LDAPS on port 636
ldapsearch -x -H ldaps://ldap-server:636 \
-b "dc=example,dc=com"
# Skip certificate verification (testing only)
LDAPTLS_REQCERT=never ldapsearch -x -H ldaps://ldap-server:636 \
-b "dc=example,dc=com"
# With custom CA certificate
ldapsearch -x -H ldaps://ldap-server:636 \
-b "dc=example,dc=com" \
env LDAPTLS_CACERT=/path/to/ca.crt
# Use StartTLS on port 389
ldapsearch -x -H ldap://ldap-server:389 \
-ZZ \
-b "dc=example,dc=com"
# Create LDIF file
cat > user.ldif <<EOF
dn: uid=jdoe,ou=users,dc=example,dc=com
objectClass: inetOrgPerson
uid: jdoe
cn: John Doe
sn: Doe
mail: [email protected]
userPassword: secret123
EOF
# Add entry
ldapadd -x -H ldap://ldap-server:389 \
-D "cn=admin,dc=example,dc=com" \
-w password \
-f user.ldif
# Create modify LDIF
cat > modify.ldif <<EOF
dn: uid=jdoe,ou=users,dc=example,dc=com
changetype: modify
replace: mail
mail: [email protected]
EOF
# Apply modification
ldapmodify -x -H ldap://ldap-server:389 \
-D "cn=admin,dc=example,dc=com" \
-w password \
-f modify.ldif
# Delete single entry
ldapdelete -x -H ldap://ldap-server:389 \
-D "cn=admin,dc=example,dc=com" \
-w password \
"uid=jdoe,ou=users,dc=example,dc=com"
# Delete recursively
ldapdelete -x -H ldap://ldap-server:389 \
-D "cn=admin,dc=example,dc=com" \
-w password \
-r "ou=temp,dc=example,dc=com"
# Test bind
ldapwhoami -x -H ldap://ldap-server:389 \
-D "uid=jdoe,ou=users,dc=example,dc=com" \
-w password
# Anonymous bind
ldapwhoami -x -H ldap://ldap-server:389
# Change password
ldappasswd -x -H ldap://ldap-server:389 \
-D "cn=admin,dc=example,dc=com" \
-w adminpass \
-s newpassword \
"uid=jdoe,ou=users,dc=example,dc=com"
# Edit entries interactively
ldapvi -h ldap-server \
-D "cn=admin,dc=example,dc=com" \
-w password \
-b "ou=users,dc=example,dc=com"
if you want to debug using an ephemeral container in an existing pod:
$ kubectl debug mypod -it --image=j4rj4r/ldap-debug
if you want to spin up a throw away pod for debugging.
$ kubectl run tmp-shell --rm -i --tty --image j4rj4r/ldap-debug
if you want to spin up a container on the host's network namespace.
$ kubectl run tmp-shell --rm -i --tty --overrides='{"spec": {"hostNetwork": true}}' --image j4rj4r/ldap-debug
# Deploy the debug pod
kubectl apply -f ldap-debug-pod.yaml
# Exec into pod
kubectl exec -it ldap-debug -- /bin/sh
# Search LDAP service
ldapsearch -x -H ldap://openldap.default.svc.cluster.local:389 \
-b "dc=example,dc=com"
# Test with authentication
ldapsearch -x -H ldap://openldap.default.svc.cluster.local:389 \
-D "cn=admin,dc=example,dc=com" \
-w password \
-b "dc=example,dc=com"
# From ldap-debug pod, test service in another namespace
ldapsearch -x \
-H ldap://openldap.ldap-namespace.svc.cluster.local:389 \
-b "dc=example,dc=com"
# Check certificate
openssl s_client -connect openldap:636 -showcerts
# Test LDAPS connection
ldapsearch -x -H ldaps://openldap:636 \
-b "dc=example,dc=com"
# Debug TLS handshake
openssl s_client -connect openldap:636 -debug -state
# Set default LDAP URI
export LDAPURI="ldap://ldap-server:389"
# Set default base DN
export LDAPBASE="dc=example,dc=com"
# Set default bind DN
export LDAPBINDDN="cn=admin,dc=example,dc=com"
# Skip certificate verification (testing only)
export LDAPTLS_REQCERT=never
# Create ~/.ldaprc
cat > ~/.ldaprc <<EOF
URI ldap://ldap-server:389
BASE dc=example,dc=com
BINDDN cn=admin,dc=example,dc=com
TLS_REQCERT allow
EOF
Content type
Image
Digest
sha256:da6fc7c0d…
Size
13.7 MB
Last updated
12 months ago
docker pull j4rj4r/ldap-debug