Compare commits

..

2 commits

Author SHA1 Message Date
CTO Agent
a715c8e532 fix(opencloud): load OpenCloud LDAP schema into OpenLDAP on startup
User creation failed with "openCloudUUID: attribute type undefined" because
OpenLDAP was missing the OpenCloud schema (OIDs under 1.3.6.1.4.1.63016).

Changes:
- Add opencloud-ldap-schema.yaml ConfigMap with the official OpenCloud LDAP
  schema defining openCloudUUID, openCloudUser, openCloudExternalIdentity,
  openCloudUserEnabled, openCloudUserType, openCloudLastSignInTimestamp
- Mount the ConfigMap into the OpenLDAP pod
- Add lifecycle postStart hook to load schema via ldapadd -Y EXTERNAL -H ldapi:///
  (idempotent: skips if already loaded)
- Re-exclude IDM in OpenCloud deployment (external LDAP handles user storage)

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 15:51:15 +00:00
CTO Agent
51d70b052f Revert "fix(opencloud): remove external LDAP config, use IDM for user storage"
This reverts commit 5adc38c4d8.
2026-07-05 15:41:56 +00:00
4 changed files with 129 additions and 6 deletions

View file

@ -6,9 +6,22 @@ metadata:
namespace: opencloud namespace: opencloud
data: data:
opencloud.yaml: | opencloud.yaml: |
# OpenCloud Configuration - Pocket ID OIDC auth, IDM for internal user storage # OpenCloud Minimal Configuration
# Only non-default settings - environment variables override these
# Proxy service - OIDC via Pocket ID # Graph service - external OpenLDAP configuration
graph:
identity:
ldap:
uri: ldap://openldap.opencloud.svc.cluster.local:389
base_dn: dc=basicstack,dc=de
bind_dn: cn=admin,dc=basicstack,dc=de
bind_password: ${OPENLDAP_ADMIN_PASSWORD|}
user_base_dn: ou=users,dc=basicstack,dc=de
group_base_dn: ou=groups,dc=basicstack,dc=de
insecure: true
# Proxy service - OIDC configuration (already in env vars, kept for reference)
proxy: proxy:
oidc: oidc:
issuer: https://auth.basicstack.de issuer: https://auth.basicstack.de
@ -17,7 +30,33 @@ data:
user_oidc_claim: preferred_username user_oidc_claim: preferred_username
enable_basic_auth: false enable_basic_auth: false
# IDM service user passwords (required when /etc/opencloud is read-only - init cannot write here) # Users service - external LDAP
users:
drivers:
ldap:
uri: ldap://openldap.opencloud.svc.cluster.local:389
base_dn: dc=basicstack,dc=de
bind_dn: cn=admin,dc=basicstack,dc=de
bind_password: ${OPENLDAP_ADMIN_PASSWORD|}
user_base_dn: ou=users,dc=basicstack,dc=de
user_filter: (objectClass=inetOrgPerson)
user_object_class: inetOrgPerson
insecure: true
# Groups service - external LDAP
groups:
drivers:
ldap:
uri: ldap://openldap.opencloud.svc.cluster.local:389
base_dn: dc=basicstack,dc=de
bind_dn: cn=admin,dc=basicstack,dc=de
bind_password: ${OPENLDAP_ADMIN_PASSWORD|}
group_base_dn: ou=groups,dc=basicstack,dc=de
group_filter: (objectClass=groupOfNames)
group_object_class: groupOfNames
insecure: true
# IDM service user passwords (required when IDM is enabled and /etc/opencloud is read-only)
idm: idm:
service_user_passwords: service_user_passwords:
admin_password: ${OC_IDM_ADMIN_PASSWORD} admin_password: ${OC_IDM_ADMIN_PASSWORD}

View file

@ -99,10 +99,9 @@ spec:
- name: PROXY_TLS - name: PROXY_TLS
value: "false" value: "false"
# Exclude broken search service, internal IDP, and auth-basic (OIDC-only auth via Pocket ID) # Exclude: search (broken), idp (using Pocket ID), idm (using external OpenLDAP), auth-basic (OIDC-only)
# IDM re-enabled: needed for auto-provisioning user storage when users log in via Pocket ID
- name: OC_EXCLUDE_RUN_SERVICES - name: OC_EXCLUDE_RUN_SERVICES
value: "search,idp,auth-basic" value: "search,idp,idm,auth-basic"
# Data paths # Data paths
- name: OPENCLOUD_BASE_DATA_PATH - name: OPENCLOUD_BASE_DATA_PATH

View file

@ -0,0 +1,58 @@
---
# OpenCloud LDAP schema ConfigMap
# Defines openCloudUser objectClass and related attributes (OIDs under 1.3.6.1.4.1.63016)
# Mounted into OpenLDAP pod and loaded via lifecycle postStart hook
apiVersion: v1
kind: ConfigMap
metadata:
name: opencloud-ldap-schema
namespace: opencloud
data:
10_opencloud_schema.ldif: |
dn: cn=opencloud,cn=schema,cn=config
objectClass: olcSchemaConfig
cn: opencloud
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.1
NAME 'openCloudUUID'
DESC 'A non-reassignable and persistent account ID'
EQUALITY caseIgnoreMatch
SUBSTR caseIgnoreSubstringsMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256}
SINGLE-VALUE )
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.2
NAME 'openCloudExternalIdentity'
DESC 'Represents the objectIdentity resource type of the Graph API'
EQUALITY caseIgnoreMatch
SUBSTR caseIgnoreSubstringsMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.3
NAME 'openCloudUserEnabled'
DESC 'Indicates if the user account is enabled'
EQUALITY booleanMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.7
SINGLE-VALUE )
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.4
NAME 'openCloudUserType'
DESC 'Specifies the user type (Member or Guest)'
EQUALITY caseIgnoreMatch
SUBSTR caseIgnoreSubstringsMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15
SINGLE-VALUE )
olcAttributeTypes: ( 1.3.6.1.4.1.63016.1.1.5
NAME 'openCloudLastSignInTimestamp'
DESC 'Timestamp of the most recent authentication event'
EQUALITY generalizedTimeMatch
ORDERING generalizedTimeOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.24
SINGLE-VALUE )
olcObjectClasses: ( 1.3.6.1.4.1.63016.1.2.1
NAME 'openCloudObject'
DESC 'Base auxiliary class for OpenCloud objects'
AUXILIARY
MAY ( openCloudUUID ) )
olcObjectClasses: ( 1.3.6.1.4.1.63016.1.2.2
NAME 'openCloudUser'
DESC 'Auxiliary class for OpenCloud user accounts'
AUXILIARY
SUP openCloudObject
MAY ( openCloudExternalIdentity $ openCloudUserEnabled $ openCloudUserType $ openCloudLastSignInTimestamp ) )

View file

@ -109,6 +109,27 @@ spec:
- name: LDAP_REMOVE_CONFIG_AFTER_SETUP - name: LDAP_REMOVE_CONFIG_AFTER_SETUP
value: "false" value: "false"
lifecycle:
postStart:
exec:
command:
- /bin/bash
- -c
- |
# Wait for slapd to initialize
sleep 10
# Load OpenCloud schema if not already present
if ! ldapsearch -Y EXTERNAL -H ldapi:/// \
-b "cn=schema,cn=config" \
"(cn={*}opencloud)" dn 2>/dev/null | grep -qi "opencloud"; then
ldapadd -Y EXTERNAL -H ldapi:/// \
-f /container/service/slapd/assets/config/bootstrap/schema/opencloud.ldif \
2>&1 | tee /tmp/schema-load.log || true
echo "OpenCloud schema load attempted"
else
echo "OpenCloud schema already present, skipping"
fi
ports: ports:
- containerPort: 389 - containerPort: 389
name: ldap name: ldap
@ -120,6 +141,9 @@ spec:
mountPath: /var/lib/ldap mountPath: /var/lib/ldap
- name: openldap-config - name: openldap-config
mountPath: /etc/ldap/slapd.d mountPath: /etc/ldap/slapd.d
- name: opencloud-schema
mountPath: /container/service/slapd/assets/config/bootstrap/schema/opencloud.ldif
subPath: 10_opencloud_schema.ldif
resources: resources:
requests: requests:
@ -150,3 +174,6 @@ spec:
- name: openldap-config - name: openldap-config
persistentVolumeClaim: persistentVolumeClaim:
claimName: openldap-config claimName: openldap-config
- name: opencloud-schema
configMap:
name: opencloud-ldap-schema