From d8afb2ec87151df2fa97469e023bf9f64cbf358f Mon Sep 17 00:00:00 2001 From: Kevin Veen-Birkenbach Date: Wed, 22 Jan 2025 11:08:33 +0100 Subject: [PATCH] Optimized ldap configuration --- group_vars/all | 9 ++--- .../templates/docker-compose.yml.j2 | 35 ++++++++++++------- 2 files changed, 28 insertions(+), 16 deletions(-) diff --git a/group_vars/all b/group_vars/all index 6ffd2da3..2534d19c 100644 --- a/group_vars/all +++ b/group_vars/all @@ -245,10 +245,11 @@ keycloak_version: "latest" keycloak_administrator_username: "{{administrator_username}}" #### LDAP -ldap_version: "latest" -ldap_admin_version: "2.0.0-dev" # @todo Attention: Change this as fast as released to latest -ldap_administrator_username: "{{administrator_username}}" -ldap_administrator_password: "{{user_administrator_initial_password}}" #CHANGE for security reasons +ldap_version: "latest" +ldap_admin_version: "2.0.0-dev" # @todo Attention: Change this as fast as released to latest +ldap_administrator_username: "{{administrator_username}}" +ldap_administrator_password: "{{user_administrator_initial_password}}" #CHANGE for security reasons +ldap_administrator_database_password: "{{user_administrator_initial_password}}" #CHANGE for security reasons #### Listmonk listmonk_admin_username: "{{administrator_username}}" diff --git a/roles/docker-ldap/templates/docker-compose.yml.j2 b/roles/docker-ldap/templates/docker-compose.yml.j2 index 44fc483e..35987551 100644 --- a/roles/docker-ldap/templates/docker-compose.yml.j2 +++ b/roles/docker-ldap/templates/docker-compose.yml.j2 @@ -22,22 +22,33 @@ services: # @See https://hub.docker.com/r/bitnami/openldap # GENERAL - LDAP_ADMIN_USERNAME: {{ldap_administrator_username}} # LDAP database admin user. - LDAP_ADMIN_PASSWORD: {{ldap_administrator_password}} # LDAP database admin password. - #LDAP_USERS: user01,user02 # Comma separated list of LDAP users to create in the default LDAP tree. Default: user01,user02 - #LDAP_PASSWORDS: password1,password2 # Comma separated list of passwords to use for LDAP users. Default: bitnami1,bitnami - LDAP_ROOT: {{ldap_root}} # LDAP baseDN (or suffix) of the LDAP tree. Default: dc=example,dc=org - LDAP_ADMIN_DN: {{ldap_admin_dn}} - LDAP_PORT_NUMBER: {{ldap_localhost_port}} # Route to default port - - # TLS - LDAP_ENABLE_TLS: no # Using nginx proxy - LDAP_LDAPS_PORT_NUMBER: {{ldap_secure_localhost_port}} # Port used for TLS secure traffic. Priviledged port is supported (e.g. 636). Default: 1636 (non privileged port). + ## Database + LDAP_ADMIN_USERNAME: {{ldap_administrator_username}} # LDAP database admin user. + LDAP_ADMIN_PASSWORD: {{ldap_administrator_database_password}} # LDAP database admin password. + + ## Users + #LDAP_USERS: ' ' # Comma separated list of LDAP users to create in the default LDAP tree. Default: user01,user02 + #LDAP_PASSWORDS: ' ' # Comma separated list of passwords to use for LDAP users. Default: bitnami1,bitnami2 + LDAP_ROOT: {{ldap_root}} # LDAP baseDN (or suffix) of the LDAP tree. Default: dc=example,dc=org + + ## Admin + LDAP_ADMIN_DN: {{ldap_admin_dn}} # Not well documented. Don't know if this has an effect + LDAP_CONFIG_ADMIN_ENABLED: yes + LDAP_CONFIG_ADMIN_USERNAME: {{ldap_administrator_username}} + LDAP_CONFIG_ADMIN_PASSWORD: {{ldap_administrator_password}} + + # Network + LDAP_PORT_NUMBER: {{ldap_localhost_port}} # Route to default port + LDAP_ENABLE_TLS: no # Using nginx proxy for tls + LDAP_LDAPS_PORT_NUMBER: {{ldap_secure_localhost_port}} # Port used for TLS secure traffic. Priviledged port is supported (e.g. 636). Default: 1636 (non privileged port). + + # Security + LDAP_ALLOW_ANON_BINDING: yes # Allow anonymous bindings to the LDAP server. Default: yes. volumes: - 'data:/bitnami/openldap' healthcheck: test: > - ldapsearch -x -H ldap://localhost:389 -b "{{ldap_root}}" -D "{{ldap_admin_dn}}" -w "{{ldap_administrator_password}}" + ldapsearch -x -H ldap://localhost:389 -b "{{ldap_root}}" -D "{{ldap_admin_dn}}" -w "{{ldap_administrator_database_password}}" interval: 30s timeout: 10s retries: 3