Sign inSign up

openemail/fusion-openldap

By openemail

Updated over 5 years ago

Image
0

555

openemail/fusion-openldap repository overview

Table of Contents

Introduction

Dockerfile to build a OpenLDAP Server with Fusion Directory Schema's Included. It includes all the functions in the OpenLDAP Image such as Multi-Master Replication, TLS, and other features.

This Container uses tiredofit/openldap as a base.

Changelog

Authors

Dependencies

To build this image you must have the OpenLDAP Image built and available. To utilize, you must also have the Fusion Directory Image image built and available.

Installation

Automated builds of the image are available on Registry and is the recommended method of installation.

docker pull tiredofit/openldap-fusiondirectory

Quick Start

Start openldap-fusiondirectory using:

docker-compose up

NOTE: Please allow up to 1 minutes for the application to start.

Data-Volumes

There is an additional data volume exposed:

DirectoryDescription
/assets/fusiondirectory-custom/Place Schema files here to be imported into FusionDirectory

Environment Variables

  • Please see OpenLDAP Image for Environment Variables Configuration
  • There are specific environment variables to this image:
VariableDescription
FUSIONDIRECTORY_ADMIN_USERDefault FD Admin User - Default fd-admin
FUSIONDIRECTORY_ADMIN_PASSDefault FD Admin Password - Default admin
ORGANIZATIONOrganization Name Default: Example Organization

Alpine Base Image

Below is the complete list of available options that can be used to customize your installation. These are inherited from Tiredofit Alpine Base Image

ParameterDescription
DEBUG_MODEEnable Debug Mode - Default: FALSE
DEBUG_SMTPSetup Mail Catch all on port 1025 (SMTP) and 8025 (HTTP) - Default: FALSE
ENABLE_CRONEnable Cron - Default: TRUE
ENABLE_SMTPEnable SMTP services - Default: TRUE
ENABLE_ZABBIXEnable Zabbix Agent - Default: TRUE
TIMEZONESet Timezone - Default: Asia/Colombo

If you wish to have this send mail, set ENABLE_SMTP=TRUE and configure the following environment variables. See the MSMTP Configuration Options for further information on options to configure MSMTP

ParameterDescription
ENABLE_SMTP_GMAILAdd setting to supoprt sending through Gmail SMTP - Default: FALSE
SMTP_HOSTHostname of SMTP Server - Default: postfix-openemail
SMTP_PORTPort of SMTP Server - Default: 25
SMTP_DOMAINHELO Domain - Default: docker
SMTP_MAILDOMAINMail Domain From - Default: openemail.io
SMTP_AUTHENTICATIONSMTP Authentication - Default: none
SMTP_USEREnable SMTP services - Default: user
SMTP_PASSEnable SMTP services - Default: password
SMTP_TLSUse TLS - Default: off
SMTP_STARTTLSStart TLS from within Dession - Default: off
SMTP_TLSCERTCHECKCheck remote certificate - Default: off

See The Official Zabbix Agent Documentation for information about the following Zabbix values

Zabbix ParametersDescription
ZABBIX_LOGFILELogfile Location - Default: /var/log/zabbix/zabbix_agentd.log
ZABBIX_LOGFILESIZELogfile Size - Default: 1
ZABBIX_DEBUGLEVELDebug Level - Default: 1
ZABBIX_REMOTECOMMANDSEnable Remote Commands (0/1) - Default: 1
ZABBIX_REMOTECOMMANDS_LOGEnable Remote Commands Log (0/1)
ZABBIX_SERVERAllow connections from Zabbix Server IP - Default: 0.0.0.0/0
ZABBIX_LISTEN_PORTZabbix Agent Listening Port - Default: 10050
ZABBIX_LISTEN_IPZabbix Agent Listening IP - Default: 0.0.0.0
ZABBIX_START_AGENTSHow many Zabbix Agents to Start - Default: `3
ZABBIX_SERVER_ACTIVEServer for Active Checks - Default: zabbix-openemail
ZABBIX_HOSTNAMEContainer hostname to report to server - Default: docker
ZABBIX_REFRESH_ACTIVE_CHECKSSeconds to refresh Active Checks - Default: 120
ZABBIX_BUFFER_SENDBuffer Send - Default: 5
ZABBIX_BUFFER_SIZEBuffer Size - Default: 100
ZABBIX_MAXLINES_SECONDMax Lines Per Second - Default: 20
ZABBIX_ALLOW_ROOTAllow running as root - Default: 1
ZABBIX_USERZabbix user to start as - Default: zabbix

If you enable DEBUG_PERMISSIONS=TRUE all the users and groups have been modified in accordance with Environmental Variables will be displayed in output. e.g. If you add USER_NGINX=1000 it will reset the containers nginx user id from 82 to 1000 - Hint, also change the Group ID to your local development users UID & GID and avoid Docker permission issues when developing.

ParameterDescription
USER_<USERNAME>The user's UID in /etc/passwd will be modified with new UID - Default N/A
GROUP_<GROUPNAME>The group's GID in /etc/group and /etc/passwd will be modified with new GID - Default N/A
GROUP_ADD_<USERNAME>The username will be added in /etc/group after the group name defined - Default N/A
Networking

The following ports are exposed.

PortDescription
1025DEBUG_MODE & DEBUG_SMTP SMTP Catcher
8025DEBUG_MODE & DEBUG_SMTP SMTP HTTP Viewer
10050Zabbix Agent

Schema Installation

Depending on your choices, the following schemas are available for installation. You must have these also enabled on the FusionDirectory application image to make use of it. If you would like to reapply the schemas set REAPPLY_PLUGIN_SCHEMAS to TRUE.

VariableDescription
REAPPLY_PLUGIN_SCHEMASReapply Plugin Schemas TRUE or FALSE - Default: FALSE
PLUGIN_ALIASMail Aliases - Default: FALSE
PLUGIN_APPLICATIONSApplications - Default: FALSE
PLUGIN_ARGONAUTArgonaut - Default: FALSE
PLUGIN_AUDITAudit Trail - Default: TRUE
PLUGIN_AUTOFSAutoFS - Default: FALSE
PLUGIN_CERTIFICATESManage Certificates - Default: FALSE
PLUGIN_COMMUNITYCommunity Plugin - Default: FALSE
PLUGIN_CYRUSCyrus IMAP - Default: FALSE
PLUGIN_DEBCONFArgonaut Debconf - Default: FALSE
PLUGIN_DEVELOPERSDevelopers Plugin - Default: FALSE
PLUGIN_DHCPManage DHCP - Default: FALSE
PLUGIN_DNSManage DNS - Default: FALSE
PLUGIN_DOVECOTDovecot IMAP - Default: FALSE
PLUGIN_DSASystem Accounts - Default: TRUE
PLUGIN_EJBCAUnknown - Default: FALSE
PLUGIN_FAIUnknown - Default: FALSE
PLUGIN_FREERADIUSFreeRadius Management - Default: FALSE
PLUGIN_FUSIONINVENTORYInventory Plugin - Default: FALSE
PLUGIN_GPGManage GPG Keys - Default: FALSE
PLUGIN_IPMIIPMI Management - Default: FALSE
PLUGIN_MAILMail Attributes - Default: TRUE
PLUGIN_MIXEDGROUPSUnix/LDAP Groups - Default: FALSE
PLUGIN_NAGIOSNagios Monitoring - Default: FALSE
PLUGIN_NETGROUPSNIS - Default: FALSE
PLUGIN_NEWSLETTERManage Newsletters - Default: FALSE
PLUGIN_OPSIInventory - Default: FALSE
PLUGIN_PERSONALPersonal Details - Default: TRUE
PLUGIN_POSIXPosix Groups - Default: FALSE
PLUGIN_POSTFIXPostfix SMTP - Default: FALSE
PLUGIN_PPOLICYPassword Policy - Default: TRUE
PLUGIN_PUPPETPuppet CI - Default: FALSE
PLUGIN_PUREFTPDFTP Server - Default: FALSE
PLUGIN_QUOTAManage Quotas - Default: FALSE
PLUGIN_RENATER_PARTAGEUnknown - Default: FALSE
PLUGIN_REPOSITORYArgonaut Deployment Registry - Default: FALSE
PLUGIN_SAMBAFile Sharing - Default: FALSE
PLUGIN_SOGOGroupware - Default: FALSE
PLUGIN_SPAMASSASSINAnti Spam - Default: FALSE
PLUGIN_SQUIDProxy - Default: FALSE
PLUGIN_SSHManage SSH Keys - Default: TRUE
PLUGIN_SUBCONTRACTINGUnknown - Default: FALSE
PLUGIN_SUDOManage SUDO on Hosts - Default: FALSE
PLUGIN_SUPANNSUPANN - Default: FALSE
PLUGIN_SYMPASympa Mailing List - Default: FALSE
PLUGIN_SYSTEMSSystems Management - Default: TRUE
PLUGIN_USER_REMINDERPassword Expiry - Default: FALSE
PLUGIN_WEBLINKDisplay Weblink - Default: FALSE

Networking

Maintenance

Shell Access

For debugging and maintenance purposes you may want access the containers shell.

docker exec -it openldap-fusiondirectory bash

References

Tag summary

Content type

Image

Digest

Size

51.7 MB

Last updated

over 5 years ago

docker pull openemail/fusion-openldap