Sign inSign up

kubed/openldap

By kubed

•Updated 5 days ago

Image
0

886

kubed/openldap repository overview

⁠Open LDAP

Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network. LDAP is commonly used for storing user credentials and other information in a centralized location.

⁠Cheetsheet

The following sections cover useful tid bits and commands that can be quickly references for common tasks.

Commands below run inside the pod, where ldapi:/// is root:

kubectl exec -it -n auth openldap-0 -c openldap -- sh
⁠Backup and restore

A CronJob dumps the database weekly to gs://backups.kellyferrone.com/openldap/. Restore into an empty database:

kubectl delete pvc -n auth data-openldap-0   # only when restoring over a live server
kubectl up overlays/restore                   # fetch + slapadd, then
kubectl up .                                  # back to the base case
⁠Make a Password
slappasswd -s "yourpassword"

⁠Destroy

kubectl down .
kubectl delete pvc -n auth data-openldap-0
⁠One Shot Commands
echo 'dn: uid=,ou=users,dc=burbs
objectClass: inetOrgPerson
objectClass: posixAccount
uid: 
cn: 
sn: 
mail: 
userPassword: 
uidNumber: 1003
gidNumber: 2003
homeDirectory: /home/
loginShell: /bin/bash' | ldapadd -x -D "cn=admin,dc=burbs" -w "$LDAP_ADMIN_PASSWORD"

adds member to group

echo -e 'dn: cn=services,ou=groups,dc=burbs\nchangetype: modify\nadd: memberUid\nmemberUid: synology-csi' | ldapmodify -x -D "cn=admin,dc=burbs" -w "$LDAP_ADMIN_PASSWORD"

See all of the classes

ldapsearch -x -b "cn=subschema" -s base "(objectClass=*)" objectClasses | grep -oP 'NAME \K[^ ]+' | sort | uniq

View the current ACLs

ldapsearch -Y EXTERNAL -H ldapi:/// -b "olcDatabase={1}mdb,cn=config" olcAccess

check root dn

ldapsearch -Y EXTERNAL -H ldapi:/// -b "olcDatabase={1}mdb,cn=config" "(objectClass=*)" olcRootDN olcRootPW

simple check

ldapsearch -x -D "cn=admin,dc=burbs" -w "$LDAP_ADMIN_PASSWORD" -H ldap://localhost:3389 -b "dc=burbs" "(objectClass=*)"

change password

ldappasswd -H ldap:/// -x -D "cn=admin,dc=burbs" -w "$LDAP_ADMIN_PASSWORD" -S "uid=<userid>,ou=users,dc=burbs"

update a mail proeprty

cat <<'EOF' | ldapmodify -Y EXTERNAL -H ldapi:///
dn: uid=bob,ou=users,dc=burbs
changetype: modify
replace: mail
mail: [email protected]
EOF

Add an alternate mail address:

cat <<'EOF' | ldapmodify -Y EXTERNAL -H ldapi:///
dn: uid=bob,ou=users,dc=burbs
changetype: add
add: mailAlternateAddress
mailAlternateAddress: [email protected]
EOF

⁠Access Control Lists (ACLs)

The ACLs live in components/instance/slapd.ldif⁠, which is the whole cn=config, rebuilt on every start. Access is granted by membership of the ldap Client roles:

RoleGets
cn=admin,cn=ldap,ou=clientsmanage the whole tree, write passwords
cn=consumer,cn=ldap,ou=clientsread the tree, bind users

To change them, edit slapd.ldif, kubectl up ., and prove the change with the access matrix:

scripts/acl-matrix.sh auth openldap-0 /etc/openldap/slapd.d > before.txt   # then again after, and diff

⁠Upgrading

WhatPinLatest from
Alpine / OpenLDAPFROM in Dockerfile⁠alpine tags⁠, openldap package⁠
Published imagenewTag in kustomization.yaml⁠ and overlays/restore⁠kubed/openldap tags⁠

CI builds the image on main and bumps both newTags. Every app authenticates here, so check binds after an upgrade before moving on.

⁠Who Uses LDAP

AppUses LDAP forLDAP config
codeserver⁠drupal's SA credsenv⁠
Drupal⁠service accountservice-account⁠
Emby⁠login (plugin UI), SAldap⁠
Grafana⁠login, client, SAldap⁠
Keycloak⁠federation (writable), SArealm⁠
Mailserver⁠mailboxes, SMTP authldap.yaml⁠
mcp-kb⁠service accountldap.yaml⁠
n8n⁠SA: postgres + nextcloud loginldap⁠
Nextcloud⁠users (user_ldap), client, SAldap⁠
Penpot⁠login, client, SAldap⁠
PostgreSQL⁠pg_hba auth, client, SAs (+ grafana-postgresql)ldap⁠
Prometheus⁠alertmanager SMTP SAldap.yaml⁠
qBittorrent⁠service accountldap⁠
Selenium⁠service accountsservice-accounts⁠
SSP⁠password self-servicessp⁠
synology-csi⁠SMB user (legacy Entry, inactive)auth⁠
UPS rmcard⁠login (on the card), SAk8s/ldap.yaml⁠
ProjectRole
terraform-ldap-components⁠ldap.kubed.io CRDs: ServiceAccount, Client, Team, Group, Role
providers/opentofu⁠the ProviderConfig those CRDs write through
terraform-keycloak-components⁠LdapFederation CRD behind the realm
cluster/components/realm⁠the realm: federation, teams, roles

⁠References

Tag summary

Content type

Image

Digest

sha256:d5ec2c759…

Size

5 MB

Last updated

5 days ago

docker pull kubed/openldap