fix(opencloud): load OpenCloud LDAP schema into OpenLDAP on startup
User creation failed with "openCloudUUID: attribute type undefined" because OpenLDAP was missing the OpenCloud schema (OIDs under 1.3.6.1.4.1.63016). Changes: - Add opencloud-ldap-schema.yaml ConfigMap with the official OpenCloud LDAP schema defining openCloudUUID, openCloudUser, openCloudExternalIdentity, openCloudUserEnabled, openCloudUserType, openCloudLastSignInTimestamp - Mount the ConfigMap into the OpenLDAP pod - Add lifecycle postStart hook to load schema via ldapadd -Y EXTERNAL -H ldapi:/// (idempotent: skips if already loaded) - Re-exclude IDM in OpenCloud deployment (external LDAP handles user storage) Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
parent
51d70b052f
commit
a715c8e532
3 changed files with 87 additions and 3 deletions
|
|
@ -99,10 +99,9 @@ spec:
|
|||
- name: PROXY_TLS
|
||||
value: "false"
|
||||
|
||||
# Exclude broken search service, internal IDP, and auth-basic (OIDC-only auth via Pocket ID)
|
||||
# IDM re-enabled: needed for auto-provisioning user storage when users log in via Pocket ID
|
||||
# Exclude: search (broken), idp (using Pocket ID), idm (using external OpenLDAP), auth-basic (OIDC-only)
|
||||
- name: OC_EXCLUDE_RUN_SERVICES
|
||||
value: "search,idp,auth-basic"
|
||||
value: "search,idp,idm,auth-basic"
|
||||
|
||||
# Data paths
|
||||
- name: OPENCLOUD_BASE_DATA_PATH
|
||||
|
|
|
|||
58
apps/opencloud/opencloud-ldap-schema.yaml
Normal file
58
apps/opencloud/opencloud-ldap-schema.yaml
Normal file
|
|
@ -0,0 +1,58 @@
|
|||
---
|
||||
# OpenCloud LDAP schema ConfigMap
|
||||
# Defines openCloudUser objectClass and related attributes (OIDs under 1.3.6.1.4.1.63016)
|
||||
# Mounted into OpenLDAP pod and loaded via lifecycle postStart hook
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: opencloud-ldap-schema
|
||||
namespace: opencloud
|
||||
data:
|
||||
10_opencloud_schema.ldif: |
|
||||
dn: cn=opencloud,cn=schema,cn=config
|
||||
objectClass: olcSchemaConfig
|
||||
cn: opencloud
|
||||
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.1
|
||||
NAME 'openCloudUUID'
|
||||
DESC 'A non-reassignable and persistent account ID'
|
||||
EQUALITY caseIgnoreMatch
|
||||
SUBSTR caseIgnoreSubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256}
|
||||
SINGLE-VALUE )
|
||||
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.2
|
||||
NAME 'openCloudExternalIdentity'
|
||||
DESC 'Represents the objectIdentity resource type of the Graph API'
|
||||
EQUALITY caseIgnoreMatch
|
||||
SUBSTR caseIgnoreSubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
|
||||
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.3
|
||||
NAME 'openCloudUserEnabled'
|
||||
DESC 'Indicates if the user account is enabled'
|
||||
EQUALITY booleanMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.7
|
||||
SINGLE-VALUE )
|
||||
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.4
|
||||
NAME 'openCloudUserType'
|
||||
DESC 'Specifies the user type (Member or Guest)'
|
||||
EQUALITY caseIgnoreMatch
|
||||
SUBSTR caseIgnoreSubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15
|
||||
SINGLE-VALUE )
|
||||
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.5
|
||||
NAME 'openCloudLastSignInTimestamp'
|
||||
DESC 'Timestamp of the most recent authentication event'
|
||||
EQUALITY generalizedTimeMatch
|
||||
ORDERING generalizedTimeOrderingMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.24
|
||||
SINGLE-VALUE )
|
||||
olcObjectClasses: ( 1.3.6.1.4.1.63016.1.2.1
|
||||
NAME 'openCloudObject'
|
||||
DESC 'Base auxiliary class for OpenCloud objects'
|
||||
AUXILIARY
|
||||
MAY ( openCloudUUID ) )
|
||||
olcObjectClasses: ( 1.3.6.1.4.1.63016.1.2.2
|
||||
NAME 'openCloudUser'
|
||||
DESC 'Auxiliary class for OpenCloud user accounts'
|
||||
AUXILIARY
|
||||
SUP openCloudObject
|
||||
MAY ( openCloudExternalIdentity $ openCloudUserEnabled $ openCloudUserType $ openCloudLastSignInTimestamp ) )
|
||||
|
|
@ -109,6 +109,27 @@ spec:
|
|||
- name: LDAP_REMOVE_CONFIG_AFTER_SETUP
|
||||
value: "false"
|
||||
|
||||
lifecycle:
|
||||
postStart:
|
||||
exec:
|
||||
command:
|
||||
- /bin/bash
|
||||
- -c
|
||||
- |
|
||||
# Wait for slapd to initialize
|
||||
sleep 10
|
||||
# Load OpenCloud schema if not already present
|
||||
if ! ldapsearch -Y EXTERNAL -H ldapi:/// \
|
||||
-b "cn=schema,cn=config" \
|
||||
"(cn={*}opencloud)" dn 2>/dev/null | grep -qi "opencloud"; then
|
||||
ldapadd -Y EXTERNAL -H ldapi:/// \
|
||||
-f /container/service/slapd/assets/config/bootstrap/schema/opencloud.ldif \
|
||||
2>&1 | tee /tmp/schema-load.log || true
|
||||
echo "OpenCloud schema load attempted"
|
||||
else
|
||||
echo "OpenCloud schema already present, skipping"
|
||||
fi
|
||||
|
||||
ports:
|
||||
- containerPort: 389
|
||||
name: ldap
|
||||
|
|
@ -120,6 +141,9 @@ spec:
|
|||
mountPath: /var/lib/ldap
|
||||
- name: openldap-config
|
||||
mountPath: /etc/ldap/slapd.d
|
||||
- name: opencloud-schema
|
||||
mountPath: /container/service/slapd/assets/config/bootstrap/schema/opencloud.ldif
|
||||
subPath: 10_opencloud_schema.ldif
|
||||
|
||||
resources:
|
||||
requests:
|
||||
|
|
@ -150,3 +174,6 @@ spec:
|
|||
- name: openldap-config
|
||||
persistentVolumeClaim:
|
||||
claimName: openldap-config
|
||||
- name: opencloud-schema
|
||||
configMap:
|
||||
name: opencloud-ldap-schema
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue