Skip to content

Latest commit

 

History

18 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

lldap

Build Status Last Commit

This project is a lightweight authentication server that provides an opinionated, simplified LDAP interface for authentication.

Port 17170
Registry ghcr.io/daemonless/lldap
Source https://github.com/lldap/lldap
Website https://github.com/lldap/lldap

Version Tags

Tag Description Best For
pkg Upstream Binary. Built from official release. Most users — recommended.
latest / pkg-latest FreeBSD Latest. Rolling package updates. Staying current.

Prerequisites

Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions.

Deployment

Podman Compose

services:
  lldap:
    image: "ghcr.io/daemonless/lldap:latest"
    container_name: lldap
    environment:
      - PUID=1000  # User ID for the application process
      - PGID=1000  # Group ID for the application process
      - TZ=UTC  # Timezone for the container
      - LLDAP_LDAP_USER_PASS="path/to/secret"
      - LLDAP_LDAP_USER_EMAIL="path/to/secret"
      - LLDAP_JWT_SECRET_FILE="path/to/secret"
      - LLDAP_KEY_SEED_FILE="path/to/secret"
      - LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret"
    volumes:
      - "/path/to/containers/lldap:/config"
    ports:
      - "17170:17170"
      - "3890:3890"
    # always (not unless-stopped) so FreeBSD's podman rc.d auto-starts it at boot
    restart: always

Save as compose.yaml, then run podman-compose up -d.

AppJail Director

.env:

# .env

DIRECTOR_PROJECT=lldap
PUID=1000
PGID=1000
TZ=UTC
LLDAP_LDAP_USER_PASS="path/to/secret"
LLDAP_LDAP_USER_EMAIL="path/to/secret"
LLDAP_JWT_SECRET_FILE="path/to/secret"
LLDAP_KEY_SEED_FILE="path/to/secret"
LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret"

appjail-director.yml:

# appjail-director.yml

options:
  - virtualnet: ':<random> default'
  - nat:
services:
  lldap:
    name: lldap
    options:
      - container: 'boot args:--pull'
      - expose: '17170:17170 proto:tcp'
      - expose: '3890:3890 proto:tcp'
    oci:
      user: root
      environment:
        - PUID: !ENV '${PUID}'
        - PGID: !ENV '${PGID}'
        - TZ: !ENV '${TZ}'
        - LLDAP_LDAP_USER_PASS: !ENV '${LLDAP_LDAP_USER_PASS}'
        - LLDAP_LDAP_USER_EMAIL: !ENV '${LLDAP_LDAP_USER_EMAIL}'
        - LLDAP_JWT_SECRET_FILE: !ENV '${LLDAP_JWT_SECRET_FILE}'
        - LLDAP_KEY_SEED_FILE: !ENV '${LLDAP_KEY_SEED_FILE}'
        - LLDAP_SMTP_OPTIONS__PASSWORD_FILE: !ENV '${LLDAP_SMTP_OPTIONS__PASSWORD_FILE}'
    volumes:
      - lldap: /config
volumes:
  lldap:
    device: '/path/to/containers/lldap'

Makejail:

# Makejail

ARG tag=pkg

OPTION overwrite=force
OPTION from=ghcr.io/daemonless/lldap:${tag}

Save the files above, then run appjail-director up.

Note: Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the IPv4 address assigned by the virtual network.

Podman CLI

podman run -d --name lldap \
  -p 17170:17170 \
  -p 3890:3890 \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e LLDAP_LDAP_USER_PASS="path/to/secret" \
  -e LLDAP_LDAP_USER_EMAIL="path/to/secret" \
  -e LLDAP_JWT_SECRET_FILE="path/to/secret" \
  -e LLDAP_KEY_SEED_FILE="path/to/secret" \
  -e LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret" \
  -v /path/to/containers/lldap:/config \
  ghcr.io/daemonless/lldap:latest

Save as run.sh, then run sh run.sh.

AppJail

appjail oci run -Pd \
  -o overwrite=force \
  -o container="args:--pull" \
  -o virtualnet=":<random> default" \
  -o nat \
  -o expose="17170:17170 proto:tcp" \
  -o expose="3890:3890 proto:tcp" \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e LLDAP_LDAP_USER_PASS="path/to/secret" \
  -e LLDAP_LDAP_USER_EMAIL="path/to/secret" \
  -e LLDAP_JWT_SECRET_FILE="path/to/secret" \
  -e LLDAP_KEY_SEED_FILE="path/to/secret" \
  -e LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret" \
  -o fstab="/path/to/containers/lldap /config <pseudofs>" \
  ghcr.io/daemonless/lldap:latest lldap

Save as run.sh, then run sh run.sh.

Note: Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the IPv4 address assigned by the virtual network.

Bastille

Warning

Bastille's OCI support is experimental. It requires buildah, shares the host network stack (inherit), and persists image-declared volumes under --data-path.

services:
  lldap:
    image: "ghcr.io/daemonless/lldap:latest"
    container_name: lldap
    network_mode: host  # jail shares host networking
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=UTC
      - LLDAP_LDAP_USER_PASS="path/to/secret"
      - LLDAP_LDAP_USER_EMAIL="path/to/secret"
      - LLDAP_JWT_SECRET_FILE="path/to/secret"
      - LLDAP_KEY_SEED_FILE="path/to/secret"
      - LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret"

Save as podman-compose.yml, then run bastille up. Or via CLI:

bastille create -O \
  --env PUID=1000 \
  --env PGID=1000 \
  --env TZ=UTC \
  --env LLDAP_LDAP_USER_PASS="path/to/secret" \
  --env LLDAP_LDAP_USER_EMAIL="path/to/secret" \
  --env LLDAP_JWT_SECRET_FILE="path/to/secret" \
  --env LLDAP_KEY_SEED_FILE="path/to/secret" \
  --env LLDAP_SMTP_OPTIONS__PASSWORD_FILE="path/to/secret" \
  --data-path /path/to/containers/lldap \
  lldap ghcr.io/daemonless/lldap:latest inherit

Ansible

- name: Deploy lldap
  containers.podman.podman_container:
    name: lldap
    image: "ghcr.io/daemonless/lldap:latest"
    state: started
    restart_policy: always
    env:
      PUID: "1000"
      PGID: "1000"
      TZ: "UTC"
      LLDAP_LDAP_USER_PASS: ""path/to/secret""
      LLDAP_LDAP_USER_EMAIL: ""path/to/secret""
      LLDAP_JWT_SECRET_FILE: ""path/to/secret""
      LLDAP_KEY_SEED_FILE: ""path/to/secret""
      LLDAP_SMTP_OPTIONS__PASSWORD_FILE: ""path/to/secret""
    ports:
      - "17170:17170"
      - "3890:3890"
    volumes:
      - "/path/to/containers/lldap:/config"

Save as lldap-deploy.yaml, then run ansible-playbook lldap-deploy.yaml.

Access at: http://localhost:17170

Parameters

Environment Variables

Variable Default Description
PUID 1000 User ID for the application process
PGID 1000 Group ID for the application process
TZ UTC Timezone for the container
LLDAP_LDAP_USER_PASS "path/to/secret"
LLDAP_LDAP_USER_EMAIL "path/to/secret"
LLDAP_JWT_SECRET_FILE "path/to/secret"
LLDAP_KEY_SEED_FILE "path/to/secret"
LLDAP_SMTP_OPTIONS__PASSWORD_FILE "path/to/secret"

Volumes

Path Description
/config Configuration directory

Ports

Port Protocol Description
17170 TCP Web UI
3890 TCP LDAP

First time setup

To configure the admin user with password and email address during the first startup, you can define some additional environment variables in your container file:

services:
  lldap:
    env:
      - LLDAP_LDAP_USER_EMAIL="admin@example.com"
      - LLDAP_LDAP_USER_PASS="very_secure_password"

Persistent secret values

To set crypto secrets persistently and securely it is best to provide them as secrets to the container.
Define the at the top level of your container file.

Define the secrets

You can either use podman managed secrets like this (assuming your created secrets in podman with the names lldap_jwt_secret, lldap_key_seed and lldap_smtp_password):

secrets:
  lldap_jwt_secret:
    external: true
  lldap_key_seed:
    external: true
  lldap_smtp_password:
    external: true

Or just write the secrets to files next to your container file and define them like shown below.
The files should be owned by $PUID:$PGID and have the appropriate permissions (like 0400).

secrets:
  lldap_jwt_secret:
    file: ./secrets/lldap_jwt_secret
  lldap_key_seed:
    file: ./secrets/lldap_key_seed
  lldap_smtp_password:
    file: ./secrets/lldap_smtp_password

Use the secrets in your service

If you use podman managed secrets, you need to make sure that file ownership and permissions allow the app to access the secrets.

services:
  lldap:
    secrets:
      - source: lldap_jwt_secret
          uid: 1000
          gid: 1000
          mode: "0400"
      - source: lldap_key_seed
          uid: 1000
          gid: 1000
          mode: "0400"
      - source: lldap_smtp_password
          uid: 1000
          gid: 1000
          mode: "0400"

If you provide the secrets directly from files using the second method from above and have set the owner and permissions appropriately, then you can simple do:

services:
  lldap:
    secrets:
      - lldap_jwt_secret
      - lldap_key_seed
      - lldap_smtp_password

Configure lldap to use your secrets

To configure lldap to use the secrets you can define a few environment variables:

service:
  env:
    - LLDAP_JWT_SECRET_FILE="/var/run/secrets/lldap_jwt_secret"
    - LLDAP_KEY_SEED_FILE="/var/run/secrets/lldap_key_seed"
    - LLDAP_SMTP_OPTIONS__PASSWORD_FILE="/var/run/secrets/lldap_smtp_password"

Architectures: amd64 User: bsd (UID/GID via PUID/PGID, defaults to 1000:1000) Base: FreeBSD 15


Need help? Join our Discord community.

About

This project is a lightweight authentication server that provides an opinionated, simplified LDAP interface for authentication.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages