Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network. LDAP is commonly used for storing user credentials and other information in a centralized location.
The following sections cover useful tid bits and commands that can be quickly references for common tasks.
Commands below run inside the pod, where ldapi:/// is root:
kubectl exec -it -n auth openldap-0 -c openldap -- sh
A CronJob dumps the database weekly to gs://backups.kellyferrone.com/openldap/. Restore into an empty database:
kubectl delete pvc -n auth data-openldap-0 # only when restoring over a live server
kubectl up overlays/restore # fetch + slapadd, then
kubectl up . # back to the base case
slappasswd -s "yourpassword"
kubectl down .
kubectl delete pvc -n auth data-openldap-0
echo 'dn: uid=,ou=users,dc=burbs
objectClass: inetOrgPerson
objectClass: posixAccount
uid:
cn:
sn:
mail:
userPassword:
uidNumber: 1003
gidNumber: 2003
homeDirectory: /home/
loginShell: /bin/bash' | ldapadd -x -D "cn=admin,dc=burbs" -w "$LDAP_ADMIN_PASSWORD"
adds member to group
echo -e 'dn: cn=services,ou=groups,dc=burbs\nchangetype: modify\nadd: memberUid\nmemberUid: synology-csi' | ldapmodify -x -D "cn=admin,dc=burbs" -w "$LDAP_ADMIN_PASSWORD"
See all of the classes
ldapsearch -x -b "cn=subschema" -s base "(objectClass=*)" objectClasses | grep -oP 'NAME \K[^ ]+' | sort | uniq
View the current ACLs
ldapsearch -Y EXTERNAL -H ldapi:/// -b "olcDatabase={1}mdb,cn=config" olcAccess
check root dn
ldapsearch -Y EXTERNAL -H ldapi:/// -b "olcDatabase={1}mdb,cn=config" "(objectClass=*)" olcRootDN olcRootPW
simple check
ldapsearch -x -D "cn=admin,dc=burbs" -w "$LDAP_ADMIN_PASSWORD" -H ldap://localhost:3389 -b "dc=burbs" "(objectClass=*)"
change password
ldappasswd -H ldap:/// -x -D "cn=admin,dc=burbs" -w "$LDAP_ADMIN_PASSWORD" -S "uid=<userid>,ou=users,dc=burbs"
update a mail proeprty
cat <<'EOF' | ldapmodify -Y EXTERNAL -H ldapi:///
dn: uid=bob,ou=users,dc=burbs
changetype: modify
replace: mail
mail: [email protected]
EOF
Add an alternate mail address:
cat <<'EOF' | ldapmodify -Y EXTERNAL -H ldapi:///
dn: uid=bob,ou=users,dc=burbs
changetype: add
add: mailAlternateAddress
mailAlternateAddress: [email protected]
EOF
The ACLs live in components/instance/slapd.ldif, which is the whole cn=config, rebuilt on every start. Access is granted by membership of the ldap Client roles:
| Role | Gets |
|---|---|
cn=admin,cn=ldap,ou=clients | manage the whole tree, write passwords |
cn=consumer,cn=ldap,ou=clients | read the tree, bind users |
To change them, edit slapd.ldif, kubectl up ., and prove the change with the access matrix:
scripts/acl-matrix.sh auth openldap-0 /etc/openldap/slapd.d > before.txt # then again after, and diff
| What | Pin | Latest from |
|---|---|---|
| Alpine / OpenLDAP | FROM in Dockerfile | alpine tags, openldap package |
| Published image | newTag in kustomization.yaml and overlays/restore | kubed/openldap tags |
CI builds the image on main and bumps both newTags. Every app authenticates here, so check binds after an upgrade before moving on.
| App | Uses LDAP for | LDAP config |
|---|---|---|
| codeserver | drupal's SA creds | env |
| Drupal | service account | service-account |
| Emby | login (plugin UI), SA | ldap |
| Grafana | login, client, SA | ldap |
| Keycloak | federation (writable), SA | realm |
| Mailserver | mailboxes, SMTP auth | ldap.yaml |
| mcp-kb | service account | ldap.yaml |
| n8n | SA: postgres + nextcloud login | ldap |
| Nextcloud | users (user_ldap), client, SA | ldap |
| Penpot | login, client, SA | ldap |
| PostgreSQL | pg_hba auth, client, SAs (+ grafana-postgresql) | ldap |
| Prometheus | alertmanager SMTP SA | ldap.yaml |
| qBittorrent | service account | ldap |
| Selenium | service accounts | service-accounts |
| SSP | password self-service | ssp |
| synology-csi | SMB user (legacy Entry, inactive) | auth |
| UPS rmcard | login (on the card), SA | k8s/ldap.yaml |
| Project | Role |
|---|---|
| terraform-ldap-components | ldap.kubed.io CRDs: ServiceAccount, Client, Team, Group, Role |
| providers/opentofu | the ProviderConfig those CRDs write through |
| terraform-keycloak-components | LdapFederation CRD behind the realm |
| cluster/components/realm | the realm: federation, teams, roles |
Content type
Image
Digest
sha256:d5ec2c759…
Size
5 MB
Last updated
5 days ago
docker pull kubed/openldap