Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Latest commit

 

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

lldap

Build Status Last Commit OCI Pulls

This project is a lightweight authentication server that provides an opinionated, simplified LDAP interface for authentication.

Port 17170
Registry ghcr.io/daemonless/lldap
Source https://github.com/lldap/lldap
Website https://github.com/lldap/lldap

Version Tags

Tag Description Best For
pkg Upstream Binary. Built from official release. Most users — recommended.
latest / pkg-latest FreeBSD Latest. Rolling package updates. Staying current.

Prerequisites

Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions.

Deployment

Podman Compose

services:
  lldap:
    image: "ghcr.io/daemonless/lldap:latest"
    container_name: lldap
    environment:
      - PUID=1000  # User ID for the application process
      - PGID=1000  # Group ID for the application process
      - TZ=UTC  # Timezone for the container
      - LLDAP_LDAP_USER_PASS="path/to/secret"
      - LLDAP_LDAP_USER_EMAIL="path/to/secret"
      - LLDAP_JWT_SECRET_FILE="path/to/secret"
      - LLDAP_KEY_SEED_FILE="path/to/secret"
      - LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret"
    volumes:
      - "/path/to/containers/lldap:/config"
    ports:
      - "17170:17170"
      - "3890:3890"
    # always (not unless-stopped) so FreeBSD's podman rc.d auto-starts it at boot
    restart: always

Save as compose.yaml, then run podman-compose up -d.

AppJail Director

.env:

# .env

DIRECTOR_PROJECT=lldap
PUID=1000
PGID=1000
TZ=UTC
LLDAP_LDAP_USER_PASS="path/to/secret"
LLDAP_LDAP_USER_EMAIL="path/to/secret"
LLDAP_JWT_SECRET_FILE="path/to/secret"
LLDAP_KEY_SEED_FILE="path/to/secret"
LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret"

appjail-director.yml:

# appjail-director.yml

options:
  - virtualnet: ':<random> default'
  - nat:
services:
  lldap:
    name: lldap
    options:
      - container: 'args:--pull'
      - expose: '17170:17170 proto:tcp'
      - expose: '3890:3890 proto:tcp'
    oci:
      user: root
      environment:
        - PUID: !ENV '${PUID}'
        - PGID: !ENV '${PGID}'
        - TZ: !ENV '${TZ}'
        - LLDAP_LDAP_USER_PASS: !ENV '${LLDAP_LDAP_USER_PASS}'
        - LLDAP_LDAP_USER_EMAIL: !ENV '${LLDAP_LDAP_USER_EMAIL}'
        - LLDAP_JWT_SECRET_FILE: !ENV '${LLDAP_JWT_SECRET_FILE}'
        - LLDAP_KEY_SEED_FILE: !ENV '${LLDAP_KEY_SEED_FILE}'
        - LLDAP_SMTP_OPTIONS__PASSWORD_FILE: !ENV '${LLDAP_SMTP_OPTIONS__PASSWORD_FILE}'
    volumes:
      - lldap: /config
volumes:
  lldap:
    device: '/path/to/containers/lldap'

Makejail:

# Makejail

ARG tag=pkg

OPTION container=boot
OPTION overwrite=force
OPTION from=ghcr.io/daemonless/lldap:${tag}

Save the files above, then run appjail-director up.

Warning

Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.

To avoid exposing ports, just remove the expose option in your appjail-director.yml or from your command-line arguments.

Podman CLI

podman run -d --name lldap \
  -p 17170:17170 \
  -p 3890:3890 \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e LLDAP_LDAP_USER_PASS="path/to/secret" \
  -e LLDAP_LDAP_USER_EMAIL="path/to/secret" \
  -e LLDAP_JWT_SECRET_FILE="path/to/secret" \
  -e LLDAP_KEY_SEED_FILE="path/to/secret" \
  -e LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret" \
  -v /path/to/containers/lldap:/config \
  ghcr.io/daemonless/lldap:latest

Save as run.sh, then run sh run.sh.

AppJail

appjail oci run -Pd \
  -o overwrite=force \
  -o container="args:--pull" \
  -o virtualnet=":<random> default" \
  -o nat \
  -o expose="17170:17170 proto:tcp" \
  -o expose="3890:3890 proto:tcp" \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e LLDAP_LDAP_USER_PASS="path/to/secret" \
  -e LLDAP_LDAP_USER_EMAIL="path/to/secret" \
  -e LLDAP_JWT_SECRET_FILE="path/to/secret" \
  -e LLDAP_KEY_SEED_FILE="path/to/secret" \
  -e LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret" \
  -o fstab="/path/to/containers/lldap /config <pseudofs>" \
  ghcr.io/daemonless/lldap:latest lldap

Save the files above, then run sh run.sh.

Warning

Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.

To avoid exposing ports, just remove the expose option in your appjail-director.yml or from your command-line arguments.

Bastille

Warning

Bastille's OCI support is experimental. It requires buildah and shares the host network stack (inherit). Mount volumes with --volume HOST JAIL; without it, image-declared volumes are stored under ${bastille_volumesdir}/${jail}.

services:
  lldap:
    name: lldap
    image: "ghcr.io/daemonless/lldap:latest"
    network:
      - mode: host
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=UTC
      - LLDAP_LDAP_USER_PASS="path/to/secret"
      - LLDAP_LDAP_USER_EMAIL="path/to/secret"
      - LLDAP_JWT_SECRET_FILE="path/to/secret"
      - LLDAP_KEY_SEED_FILE="path/to/secret"
      - LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret"
    volumes:
      - "/path/to/containers/lldap:/config"

Save as bastille-compose.yml, then run bastille up. Or via CLI:

bastille create -O \
  --env PUID=1000 \
  --env PGID=1000 \
  --env TZ=UTC \
  --env LLDAP_LDAP_USER_PASS="path/to/secret" \
  --env LLDAP_LDAP_USER_EMAIL="path/to/secret" \
  --env LLDAP_JWT_SECRET_FILE="path/to/secret" \
  --env LLDAP_KEY_SEED_FILE="path/to/secret" \
  --env LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret" \
  --volume /path/to/containers/lldap /config \
  lldap ghcr.io/daemonless/lldap:latest inherit

Ansible

- name: Deploy lldap
  containers.podman.podman_container:
    name: lldap
    image: "ghcr.io/daemonless/lldap:latest"
    state: started
    restart_policy: always
    env:
      PUID: "1000"
      PGID: "1000"
      TZ: "UTC"
      LLDAP_LDAP_USER_PASS: ""path/to/secret""
      LLDAP_LDAP_USER_EMAIL: ""path/to/secret""
      LLDAP_JWT_SECRET_FILE: ""path/to/secret""
      LLDAP_KEY_SEED_FILE: ""path/to/secret""
      LLDAP_SMTP_OPTIONS__PASSWORD_FILE: ""path/to/secret""
    ports:
      - "17170:17170"
      - "3890:3890"
    volumes:
      - "/path/to/containers/lldap:/config"

Save as lldap-deploy.yaml, then run ansible-playbook lldap-deploy.yaml.

Access at: http://localhost:17170

Parameters

Environment Variables

Variable Default Description
PUID 1000 User ID for the application process
PGID 1000 Group ID for the application process
TZ UTC Timezone for the container
LLDAP_LDAP_USER_PASS "path/to/secret"
LLDAP_LDAP_USER_EMAIL "path/to/secret"
LLDAP_JWT_SECRET_FILE "path/to/secret"
LLDAP_KEY_SEED_FILE "path/to/secret"
LLDAP_SMTP_OPTIONS__PASSWORD_FILE "path/to/secret"

Volumes

Path Description
/config Configuration directory

Ports

Port Protocol Description
17170 TCP Web UI
3890 TCP LDAP

First time setup

To configure the admin user with password and email address during the first startup, you can define some additional environment variables in your container file:

services:
  lldap:
    env:
      - LLDAP_LDAP_USER_EMAIL="[email protected]"
      - LLDAP_LDAP_USER_PASS="very_secure_password"

Persistent secret values

To set crypto secrets persistently and securely it is best to provide them as secrets to the container.
Define the at the top level of your container file.

Define the secrets

You can either use podman managed secrets like this (assuming your created secrets in podman with the names lldap_jwt_secret, lldap_key_seed and lldap_smtp_password):

secrets:
  lldap_jwt_secret:
    external: true
  lldap_key_seed:
    external: true
  lldap_smtp_password:
    external: true

Or just write the secrets to files next to your container file and define them like shown below.
The files should be owned by $PUID:$PGID and have the appropriate permissions (like 0400).

secrets:
  lldap_jwt_secret:
    file: ./secrets/lldap_jwt_secret
  lldap_key_seed:
    file: ./secrets/lldap_key_seed
  lldap_smtp_password:
    file: ./secrets/lldap_smtp_password

Use the secrets in your service

If you use podman managed secrets, you need to make sure that file ownership and permissions allow the app to access the secrets.

services:
  lldap:
    secrets:
      - source: lldap_jwt_secret
          uid: 1000
          gid: 1000
          mode: "0400"
      - source: lldap_key_seed
          uid: 1000
          gid: 1000
          mode: "0400"
      - source: lldap_smtp_password
          uid: 1000
          gid: 1000
          mode: "0400"

If you provide the secrets directly from files using the second method from above and have set the owner and permissions appropriately, then you can simple do:

services:
  lldap:
    secrets:
      - lldap_jwt_secret
      - lldap_key_seed
      - lldap_smtp_password

Configure lldap to use your secrets

To configure lldap to use the secrets you can define a few environment variables:

service:
  env:
    - LLDAP_JWT_SECRET_FILE="/var/run/secrets/lldap_jwt_secret"
    - LLDAP_KEY_SEED_FILE="/var/run/secrets/lldap_key_seed"
    - LLDAP_SMTP_OPTIONS__PASSWORD_FILE="/var/run/secrets/lldap_smtp_password"

Architectures: amd64 User: bsd (UID/GID via PUID/PGID, defaults to 1000:1000) Base: FreeBSD 15


Need help? Join our Discord community.

About

This project is a lightweight authentication server that provides an opinionated, simplified LDAP interface for authentication.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages