Skip to content

Repository files navigation

LDAP Alpine

The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

This image is based on Alpine Linux and OpenLDAP.

Customisation

Override the following environment variables when running the docker container to customise LDAP:

VARIABLEDESCRIPTIONDEFAULT
ORGANISATION_NAMEOrganisation nameExample Ltd
SUFFIXOrganisation distinguished namedc=example,dc=com
ROOT_USERRoot usernameadmin
ROOT_PWRoot passwordpassword
USER_UIDInitial user's uidpgarrett
USER_GIVEN_NAMEInitial user's given namePhill
USER_SURNAMEInitial user's surnameGarrett
USER_EMAILInitial user's emailpgarrett@example.com
USER_PWInitial user's passwordpassword
ACCESS_CONTROLGlobal access controlaccess to * by * read
LOG_LEVELLDAP logging level, see below for valid values.stats

For example:

docker run -t -p 389:389 \
-e ORGANISATION_NAME="Beispiel gmbh" \
-e SUFFIX="dc=beispiel,dc=de" \
-e ROOT_PW="geheimnis" \
pgarrett/ldap-alpine

Search for user:

ldapsearch -x -b "dc=beispiel,dc=de" "uid=pgarrett"

Logging Levels

NAMEDESCRIPTION
anyenable all debugging (warning! lots of messages will be output)
tracetrace function calls
packetsdebug packet handling
argsheavy trace debugging
connsconnection management
BERprint out packets sent and received
filtersearch filter processing
configconfiguration processing
ACLaccess control list processing
statsstats log connections/operations/results
stats2stats log entries sent
shellprint communication with shell backends
parseprint entry parsing debugging
syncsyncrepl consumer processing
noneonly messages that get logged whatever log level is set

Custom ldif files

*.ldif files can be used to add lots of people to the organisation on startup.

Copy ldif files to /ldif and the container will execute them. This can be done either by extending this Dockerfile with your own:

FROM pgarrett/ldap-alpine
COPY my-users.ldif /ldif/

Or by mounting your scripts directory into the container:

docker run -t -p 389:389 -v /my-ldif:/ldif pgarrett/ldap-alpine

Persist data

The container uses a standard mdb backend. To persist this database outside the container mount /var/lib/openldap/openldap-data. For example:

docker run -t -p 389:389 -v /my-backup:/var/lib/openldap/openldap-data pgarrett/ldap-alpine

Transport Layer Security

The container can be started using the encrypted LDAPS protocol. You must provide all three TLS environment variables.

VARIABLEDESCRIPTIONEXAMPLE
CA_FILEPEM-format file containing certificates for the CA's that slapd will trust/etc/ssl/certs/ca.pem
KEY_FILEThe slapd server private key/etc/ssl/certs/public.key
CERT_FILEThe slapd server certificate/etc/ssl/certs/public.crt
TLS_VERIFY_CLIENTSlapd option for client certificate verificationtry, never, demand

Note these variables inform the entrypoint script (executed on startup) where to find the SSL certificates inside the container. So the certificates must also be mounted at runtime too, for example:

docker run -t -p 389:389 \
-v /my-certs:/etc/ssl/certs \
-e CA_FILE /etc/ssl/certs/ca.pem \
-e KEY_FILE /etc/ssl/certs/public.key \
-e CERT_FILE /etc/ssl/certs/public.crt \
pgarrett/ldap-alpine

Where /my-certs on the host contains the three certificate files ca.pem, public.key and public.crt.

To disable client certificates set TLS_VERIFY_CLIENT to never or try.

Access Control

Global access to your directory can be configured via the ACCESS_CONTROL environment variable.

The default policy allows anyone and everyone to read anything but restricts updates to rootdn.

access to * by * read

Note rootdn can always read and write everything!

You can find detailed documentation on access control here https://www.openldap.org/doc/admin24/access-control.html

This following access control allows the user to modify their entry, allows anonymous to authenticate against these entries, and allows all others to read these entries:

docker run -t -p 389:389 \
-e ACCESS_CONTROL="access to * by self write by anonymous auth by users read" \
pgarrett/ldap-alpine

Now ldapsearch -x -b "dc=example,dc=com" "uid=pgarret" will return no results.

In order to search you will need to authenticate (bind) first:

ldapsearch -D "uid=pgarrett,ou=Users,dc=example,dc=com" -w password -b "dc=example,dc=com" "uid=pgarrett"

About

OpenLDAP based on Alpine Linux

Topics

Resources

Contributing

Stars

41 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - gitphill/ldap-alpine: OpenLDAP based on Alpine Linux · GitHub
Skip to content

Repository files navigation

LDAP Alpine

The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

This image is based on Alpine Linux and OpenLDAP.

Customisation

Override the following environment variables when running the docker container to customise LDAP:

VARIABLEDESCRIPTIONDEFAULT
ORGANISATION_NAMEOrganisation nameExample Ltd
SUFFIXOrganisation distinguished namedc=example,dc=com
ROOT_USERRoot usernameadmin
ROOT_PWRoot passwordpassword
USER_UIDInitial user's uidpgarrett
USER_GIVEN_NAMEInitial user's given namePhill
USER_SURNAMEInitial user's surnameGarrett
USER_EMAILInitial user's emailpgarrett@example.com
USER_PWInitial user's passwordpassword
ACCESS_CONTROLGlobal access controlaccess to * by * read
LOG_LEVELLDAP logging level, see below for valid values.stats

For example:

docker run -t -p 389:389 \
-e ORGANISATION_NAME="Beispiel gmbh" \
-e SUFFIX="dc=beispiel,dc=de" \
-e ROOT_PW="geheimnis" \
pgarrett/ldap-alpine

Search for user:

ldapsearch -x -b "dc=beispiel,dc=de" "uid=pgarrett"

Logging Levels

NAMEDESCRIPTION
anyenable all debugging (warning! lots of messages will be output)
tracetrace function calls
packetsdebug packet handling
argsheavy trace debugging
connsconnection management
BERprint out packets sent and received
filtersearch filter processing
configconfiguration processing
ACLaccess control list processing
statsstats log connections/operations/results
stats2stats log entries sent
shellprint communication with shell backends
parseprint entry parsing debugging
syncsyncrepl consumer processing
noneonly messages that get logged whatever log level is set

Custom ldif files

*.ldif files can be used to add lots of people to the organisation on startup.

Copy ldif files to /ldif and the container will execute them. This can be done either by extending this Dockerfile with your own:

FROM pgarrett/ldap-alpine
COPY my-users.ldif /ldif/

Or by mounting your scripts directory into the container:

docker run -t -p 389:389 -v /my-ldif:/ldif pgarrett/ldap-alpine

Persist data

The container uses a standard mdb backend. To persist this database outside the container mount /var/lib/openldap/openldap-data. For example:

docker run -t -p 389:389 -v /my-backup:/var/lib/openldap/openldap-data pgarrett/ldap-alpine

Transport Layer Security

The container can be started using the encrypted LDAPS protocol. You must provide all three TLS environment variables.

VARIABLEDESCRIPTIONEXAMPLE
CA_FILEPEM-format file containing certificates for the CA's that slapd will trust/etc/ssl/certs/ca.pem
KEY_FILEThe slapd server private key/etc/ssl/certs/public.key
CERT_FILEThe slapd server certificate/etc/ssl/certs/public.crt
TLS_VERIFY_CLIENTSlapd option for client certificate verificationtry, never, demand

Note these variables inform the entrypoint script (executed on startup) where to find the SSL certificates inside the container. So the certificates must also be mounted at runtime too, for example:

docker run -t -p 389:389 \
-v /my-certs:/etc/ssl/certs \
-e CA_FILE /etc/ssl/certs/ca.pem \
-e KEY_FILE /etc/ssl/certs/public.key \
-e CERT_FILE /etc/ssl/certs/public.crt \
pgarrett/ldap-alpine

Where /my-certs on the host contains the three certificate files ca.pem, public.key and public.crt.

To disable client certificates set TLS_VERIFY_CLIENT to never or try.

Access Control

Global access to your directory can be configured via the ACCESS_CONTROL environment variable.

The default policy allows anyone and everyone to read anything but restricts updates to rootdn.

access to * by * read

Note rootdn can always read and write everything!

You can find detailed documentation on access control here https://www.openldap.org/doc/admin24/access-control.html

This following access control allows the user to modify their entry, allows anonymous to authenticate against these entries, and allows all others to read these entries:

docker run -t -p 389:389 \
-e ACCESS_CONTROL="access to * by self write by anonymous auth by users read" \
pgarrett/ldap-alpine

Now ldapsearch -x -b "dc=example,dc=com" "uid=pgarret" will return no results.

In order to search you will need to authenticate (bind) first:

ldapsearch -D "uid=pgarrett,ou=Users,dc=example,dc=com" -w password -b "dc=example,dc=com" "uid=pgarrett"

About

OpenLDAP based on Alpine Linux

Topics

Resources

Contributing

Stars

41 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - gitphill/ldap-alpine: OpenLDAP based on Alpine Linux · GitHub
Skip to content

Repository files navigation

LDAP Alpine

The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

This image is based on Alpine Linux and OpenLDAP.

Customisation

Override the following environment variables when running the docker container to customise LDAP:

VARIABLEDESCRIPTIONDEFAULT
ORGANISATION_NAMEOrganisation nameExample Ltd
SUFFIXOrganisation distinguished namedc=example,dc=com
ROOT_USERRoot usernameadmin
ROOT_PWRoot passwordpassword
USER_UIDInitial user's uidpgarrett
USER_GIVEN_NAMEInitial user's given namePhill
USER_SURNAMEInitial user's surnameGarrett
USER_EMAILInitial user's emailpgarrett@example.com
USER_PWInitial user's passwordpassword
ACCESS_CONTROLGlobal access controlaccess to * by * read
LOG_LEVELLDAP logging level, see below for valid values.stats

For example:

docker run -t -p 389:389 \
-e ORGANISATION_NAME="Beispiel gmbh" \
-e SUFFIX="dc=beispiel,dc=de" \
-e ROOT_PW="geheimnis" \
pgarrett/ldap-alpine

Search for user:

ldapsearch -x -b "dc=beispiel,dc=de" "uid=pgarrett"

Logging Levels

NAMEDESCRIPTION
anyenable all debugging (warning! lots of messages will be output)
tracetrace function calls
packetsdebug packet handling
argsheavy trace debugging
connsconnection management
BERprint out packets sent and received
filtersearch filter processing
configconfiguration processing
ACLaccess control list processing
statsstats log connections/operations/results
stats2stats log entries sent
shellprint communication with shell backends
parseprint entry parsing debugging
syncsyncrepl consumer processing
noneonly messages that get logged whatever log level is set

Custom ldif files

*.ldif files can be used to add lots of people to the organisation on startup.

Copy ldif files to /ldif and the container will execute them. This can be done either by extending this Dockerfile with your own:

FROM pgarrett/ldap-alpine
COPY my-users.ldif /ldif/

Or by mounting your scripts directory into the container:

docker run -t -p 389:389 -v /my-ldif:/ldif pgarrett/ldap-alpine

Persist data

The container uses a standard mdb backend. To persist this database outside the container mount /var/lib/openldap/openldap-data. For example:

docker run -t -p 389:389 -v /my-backup:/var/lib/openldap/openldap-data pgarrett/ldap-alpine

Transport Layer Security

The container can be started using the encrypted LDAPS protocol. You must provide all three TLS environment variables.

VARIABLEDESCRIPTIONEXAMPLE
CA_FILEPEM-format file containing certificates for the CA's that slapd will trust/etc/ssl/certs/ca.pem
KEY_FILEThe slapd server private key/etc/ssl/certs/public.key
CERT_FILEThe slapd server certificate/etc/ssl/certs/public.crt
TLS_VERIFY_CLIENTSlapd option for client certificate verificationtry, never, demand

Note these variables inform the entrypoint script (executed on startup) where to find the SSL certificates inside the container. So the certificates must also be mounted at runtime too, for example:

docker run -t -p 389:389 \
-v /my-certs:/etc/ssl/certs \
-e CA_FILE /etc/ssl/certs/ca.pem \
-e KEY_FILE /etc/ssl/certs/public.key \
-e CERT_FILE /etc/ssl/certs/public.crt \
pgarrett/ldap-alpine

Where /my-certs on the host contains the three certificate files ca.pem, public.key and public.crt.

To disable client certificates set TLS_VERIFY_CLIENT to never or try.

Access Control

Global access to your directory can be configured via the ACCESS_CONTROL environment variable.

The default policy allows anyone and everyone to read anything but restricts updates to rootdn.

access to * by * read

Note rootdn can always read and write everything!

You can find detailed documentation on access control here https://www.openldap.org/doc/admin24/access-control.html

This following access control allows the user to modify their entry, allows anonymous to authenticate against these entries, and allows all others to read these entries:

docker run -t -p 389:389 \
-e ACCESS_CONTROL="access to * by self write by anonymous auth by users read" \
pgarrett/ldap-alpine

Now ldapsearch -x -b "dc=example,dc=com" "uid=pgarret" will return no results.

In order to search you will need to authenticate (bind) first:

ldapsearch -D "uid=pgarrett,ou=Users,dc=example,dc=com" -w password -b "dc=example,dc=com" "uid=pgarrett"

About

OpenLDAP based on Alpine Linux

Topics

Resources

Contributing

Stars

41 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - gitphill/ldap-alpine: OpenLDAP based on Alpine Linux · GitHub
Skip to content

Repository files navigation

LDAP Alpine

The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

This image is based on Alpine Linux and OpenLDAP.

Customisation

Override the following environment variables when running the docker container to customise LDAP:

VARIABLEDESCRIPTIONDEFAULT
ORGANISATION_NAMEOrganisation nameExample Ltd
SUFFIXOrganisation distinguished namedc=example,dc=com
ROOT_USERRoot usernameadmin
ROOT_PWRoot passwordpassword
USER_UIDInitial user's uidpgarrett
USER_GIVEN_NAMEInitial user's given namePhill
USER_SURNAMEInitial user's surnameGarrett
USER_EMAILInitial user's emailpgarrett@example.com
USER_PWInitial user's passwordpassword
ACCESS_CONTROLGlobal access controlaccess to * by * read
LOG_LEVELLDAP logging level, see below for valid values.stats

For example:

docker run -t -p 389:389 \
-e ORGANISATION_NAME="Beispiel gmbh" \
-e SUFFIX="dc=beispiel,dc=de" \
-e ROOT_PW="geheimnis" \
pgarrett/ldap-alpine

Search for user:

ldapsearch -x -b "dc=beispiel,dc=de" "uid=pgarrett"

Logging Levels

NAMEDESCRIPTION
anyenable all debugging (warning! lots of messages will be output)
tracetrace function calls
packetsdebug packet handling
argsheavy trace debugging
connsconnection management
BERprint out packets sent and received
filtersearch filter processing
configconfiguration processing
ACLaccess control list processing
statsstats log connections/operations/results
stats2stats log entries sent
shellprint communication with shell backends
parseprint entry parsing debugging
syncsyncrepl consumer processing
noneonly messages that get logged whatever log level is set

Custom ldif files

*.ldif files can be used to add lots of people to the organisation on startup.

Copy ldif files to /ldif and the container will execute them. This can be done either by extending this Dockerfile with your own:

FROM pgarrett/ldap-alpine
COPY my-users.ldif /ldif/

Or by mounting your scripts directory into the container:

docker run -t -p 389:389 -v /my-ldif:/ldif pgarrett/ldap-alpine

Persist data

The container uses a standard mdb backend. To persist this database outside the container mount /var/lib/openldap/openldap-data. For example:

docker run -t -p 389:389 -v /my-backup:/var/lib/openldap/openldap-data pgarrett/ldap-alpine

Transport Layer Security

The container can be started using the encrypted LDAPS protocol. You must provide all three TLS environment variables.

VARIABLEDESCRIPTIONEXAMPLE
CA_FILEPEM-format file containing certificates for the CA's that slapd will trust/etc/ssl/certs/ca.pem
KEY_FILEThe slapd server private key/etc/ssl/certs/public.key
CERT_FILEThe slapd server certificate/etc/ssl/certs/public.crt
TLS_VERIFY_CLIENTSlapd option for client certificate verificationtry, never, demand

Note these variables inform the entrypoint script (executed on startup) where to find the SSL certificates inside the container. So the certificates must also be mounted at runtime too, for example:

docker run -t -p 389:389 \
-v /my-certs:/etc/ssl/certs \
-e CA_FILE /etc/ssl/certs/ca.pem \
-e KEY_FILE /etc/ssl/certs/public.key \
-e CERT_FILE /etc/ssl/certs/public.crt \
pgarrett/ldap-alpine

Where /my-certs on the host contains the three certificate files ca.pem, public.key and public.crt.

To disable client certificates set TLS_VERIFY_CLIENT to never or try.

Access Control

Global access to your directory can be configured via the ACCESS_CONTROL environment variable.

The default policy allows anyone and everyone to read anything but restricts updates to rootdn.

access to * by * read

Note rootdn can always read and write everything!

You can find detailed documentation on access control here https://www.openldap.org/doc/admin24/access-control.html

This following access control allows the user to modify their entry, allows anonymous to authenticate against these entries, and allows all others to read these entries:

docker run -t -p 389:389 \
-e ACCESS_CONTROL="access to * by self write by anonymous auth by users read" \
pgarrett/ldap-alpine

Now ldapsearch -x -b "dc=example,dc=com" "uid=pgarret" will return no results.

In order to search you will need to authenticate (bind) first:

ldapsearch -D "uid=pgarrett,ou=Users,dc=example,dc=com" -w password -b "dc=example,dc=com" "uid=pgarrett"

About

OpenLDAP based on Alpine Linux

Topics

Resources

Contributing

Stars

41 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - gitphill/ldap-alpine: OpenLDAP based on Alpine Linux · GitHub
Skip to content

Repository files navigation

LDAP Alpine

The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

This image is based on Alpine Linux and OpenLDAP.

Customisation

Override the following environment variables when running the docker container to customise LDAP:

VARIABLEDESCRIPTIONDEFAULT
ORGANISATION_NAMEOrganisation nameExample Ltd
SUFFIXOrganisation distinguished namedc=example,dc=com
ROOT_USERRoot usernameadmin
ROOT_PWRoot passwordpassword
USER_UIDInitial user's uidpgarrett
USER_GIVEN_NAMEInitial user's given namePhill
USER_SURNAMEInitial user's surnameGarrett
USER_EMAILInitial user's emailpgarrett@example.com
USER_PWInitial user's passwordpassword
ACCESS_CONTROLGlobal access controlaccess to * by * read
LOG_LEVELLDAP logging level, see below for valid values.stats

For example:

docker run -t -p 389:389 \
-e ORGANISATION_NAME="Beispiel gmbh" \
-e SUFFIX="dc=beispiel,dc=de" \
-e ROOT_PW="geheimnis" \
pgarrett/ldap-alpine

Search for user:

ldapsearch -x -b "dc=beispiel,dc=de" "uid=pgarrett"

Logging Levels

NAMEDESCRIPTION
anyenable all debugging (warning! lots of messages will be output)
tracetrace function calls
packetsdebug packet handling
argsheavy trace debugging
connsconnection management
BERprint out packets sent and received
filtersearch filter processing
configconfiguration processing
ACLaccess control list processing
statsstats log connections/operations/results
stats2stats log entries sent
shellprint communication with shell backends
parseprint entry parsing debugging
syncsyncrepl consumer processing
noneonly messages that get logged whatever log level is set

Custom ldif files

*.ldif files can be used to add lots of people to the organisation on startup.

Copy ldif files to /ldif and the container will execute them. This can be done either by extending this Dockerfile with your own:

FROM pgarrett/ldap-alpine
COPY my-users.ldif /ldif/

Or by mounting your scripts directory into the container:

docker run -t -p 389:389 -v /my-ldif:/ldif pgarrett/ldap-alpine

Persist data

The container uses a standard mdb backend. To persist this database outside the container mount /var/lib/openldap/openldap-data. For example:

docker run -t -p 389:389 -v /my-backup:/var/lib/openldap/openldap-data pgarrett/ldap-alpine

Transport Layer Security

The container can be started using the encrypted LDAPS protocol. You must provide all three TLS environment variables.

VARIABLEDESCRIPTIONEXAMPLE
CA_FILEPEM-format file containing certificates for the CA's that slapd will trust/etc/ssl/certs/ca.pem
KEY_FILEThe slapd server private key/etc/ssl/certs/public.key
CERT_FILEThe slapd server certificate/etc/ssl/certs/public.crt
TLS_VERIFY_CLIENTSlapd option for client certificate verificationtry, never, demand

Note these variables inform the entrypoint script (executed on startup) where to find the SSL certificates inside the container. So the certificates must also be mounted at runtime too, for example:

docker run -t -p 389:389 \
-v /my-certs:/etc/ssl/certs \
-e CA_FILE /etc/ssl/certs/ca.pem \
-e KEY_FILE /etc/ssl/certs/public.key \
-e CERT_FILE /etc/ssl/certs/public.crt \
pgarrett/ldap-alpine

Where /my-certs on the host contains the three certificate files ca.pem, public.key and public.crt.

To disable client certificates set TLS_VERIFY_CLIENT to never or try.

Access Control

Global access to your directory can be configured via the ACCESS_CONTROL environment variable.

The default policy allows anyone and everyone to read anything but restricts updates to rootdn.

access to * by * read

Note rootdn can always read and write everything!

You can find detailed documentation on access control here https://www.openldap.org/doc/admin24/access-control.html

This following access control allows the user to modify their entry, allows anonymous to authenticate against these entries, and allows all others to read these entries:

docker run -t -p 389:389 \
-e ACCESS_CONTROL="access to * by self write by anonymous auth by users read" \
pgarrett/ldap-alpine

Now ldapsearch -x -b "dc=example,dc=com" "uid=pgarret" will return no results.

In order to search you will need to authenticate (bind) first:

ldapsearch -D "uid=pgarrett,ou=Users,dc=example,dc=com" -w password -b "dc=example,dc=com" "uid=pgarrett"

About

OpenLDAP based on Alpine Linux

Topics

Resources

Contributing

Stars

41 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - gitphill/ldap-alpine: OpenLDAP based on Alpine Linux · GitHub
Skip to content

Repository files navigation

LDAP Alpine

The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

This image is based on Alpine Linux and OpenLDAP.

Customisation

Override the following environment variables when running the docker container to customise LDAP:

VARIABLEDESCRIPTIONDEFAULT
ORGANISATION_NAMEOrganisation nameExample Ltd
SUFFIXOrganisation distinguished namedc=example,dc=com
ROOT_USERRoot usernameadmin
ROOT_PWRoot passwordpassword
USER_UIDInitial user's uidpgarrett
USER_GIVEN_NAMEInitial user's given namePhill
USER_SURNAMEInitial user's surnameGarrett
USER_EMAILInitial user's emailpgarrett@example.com
USER_PWInitial user's passwordpassword
ACCESS_CONTROLGlobal access controlaccess to * by * read
LOG_LEVELLDAP logging level, see below for valid values.stats

For example:

docker run -t -p 389:389 \
-e ORGANISATION_NAME="Beispiel gmbh" \
-e SUFFIX="dc=beispiel,dc=de" \
-e ROOT_PW="geheimnis" \
pgarrett/ldap-alpine

Search for user:

ldapsearch -x -b "dc=beispiel,dc=de" "uid=pgarrett"

Logging Levels

NAMEDESCRIPTION
anyenable all debugging (warning! lots of messages will be output)
tracetrace function calls
packetsdebug packet handling
argsheavy trace debugging
connsconnection management
BERprint out packets sent and received
filtersearch filter processing
configconfiguration processing
ACLaccess control list processing
statsstats log connections/operations/results
stats2stats log entries sent
shellprint communication with shell backends
parseprint entry parsing debugging
syncsyncrepl consumer processing
noneonly messages that get logged whatever log level is set

Custom ldif files

*.ldif files can be used to add lots of people to the organisation on startup.

Copy ldif files to /ldif and the container will execute them. This can be done either by extending this Dockerfile with your own:

FROM pgarrett/ldap-alpine
COPY my-users.ldif /ldif/

Or by mounting your scripts directory into the container:

docker run -t -p 389:389 -v /my-ldif:/ldif pgarrett/ldap-alpine

Persist data

The container uses a standard mdb backend. To persist this database outside the container mount /var/lib/openldap/openldap-data. For example:

docker run -t -p 389:389 -v /my-backup:/var/lib/openldap/openldap-data pgarrett/ldap-alpine

Transport Layer Security

The container can be started using the encrypted LDAPS protocol. You must provide all three TLS environment variables.

VARIABLEDESCRIPTIONEXAMPLE
CA_FILEPEM-format file containing certificates for the CA's that slapd will trust/etc/ssl/certs/ca.pem
KEY_FILEThe slapd server private key/etc/ssl/certs/public.key
CERT_FILEThe slapd server certificate/etc/ssl/certs/public.crt
TLS_VERIFY_CLIENTSlapd option for client certificate verificationtry, never, demand

Note these variables inform the entrypoint script (executed on startup) where to find the SSL certificates inside the container. So the certificates must also be mounted at runtime too, for example:

docker run -t -p 389:389 \
-v /my-certs:/etc/ssl/certs \
-e CA_FILE /etc/ssl/certs/ca.pem \
-e KEY_FILE /etc/ssl/certs/public.key \
-e CERT_FILE /etc/ssl/certs/public.crt \
pgarrett/ldap-alpine

Where /my-certs on the host contains the three certificate files ca.pem, public.key and public.crt.

To disable client certificates set TLS_VERIFY_CLIENT to never or try.

Access Control

Global access to your directory can be configured via the ACCESS_CONTROL environment variable.

The default policy allows anyone and everyone to read anything but restricts updates to rootdn.

access to * by * read

Note rootdn can always read and write everything!

You can find detailed documentation on access control here https://www.openldap.org/doc/admin24/access-control.html

This following access control allows the user to modify their entry, allows anonymous to authenticate against these entries, and allows all others to read these entries:

docker run -t -p 389:389 \
-e ACCESS_CONTROL="access to * by self write by anonymous auth by users read" \
pgarrett/ldap-alpine

Now ldapsearch -x -b "dc=example,dc=com" "uid=pgarret" will return no results.

In order to search you will need to authenticate (bind) first:

ldapsearch -D "uid=pgarrett,ou=Users,dc=example,dc=com" -w password -b "dc=example,dc=com" "uid=pgarrett"

About

OpenLDAP based on Alpine Linux

Topics

Resources

Contributing

Stars

41 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - gitphill/ldap-alpine: OpenLDAP based on Alpine Linux · GitHub
Skip to content

Repository files navigation

LDAP Alpine

The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

This image is based on Alpine Linux and OpenLDAP.

Customisation

Override the following environment variables when running the docker container to customise LDAP:

VARIABLEDESCRIPTIONDEFAULT
ORGANISATION_NAMEOrganisation nameExample Ltd
SUFFIXOrganisation distinguished namedc=example,dc=com
ROOT_USERRoot usernameadmin
ROOT_PWRoot passwordpassword
USER_UIDInitial user's uidpgarrett
USER_GIVEN_NAMEInitial user's given namePhill
USER_SURNAMEInitial user's surnameGarrett
USER_EMAILInitial user's emailpgarrett@example.com
USER_PWInitial user's passwordpassword
ACCESS_CONTROLGlobal access controlaccess to * by * read
LOG_LEVELLDAP logging level, see below for valid values.stats

For example:

docker run -t -p 389:389 \
-e ORGANISATION_NAME="Beispiel gmbh" \
-e SUFFIX="dc=beispiel,dc=de" \
-e ROOT_PW="geheimnis" \
pgarrett/ldap-alpine

Search for user:

ldapsearch -x -b "dc=beispiel,dc=de" "uid=pgarrett"

Logging Levels

NAMEDESCRIPTION
anyenable all debugging (warning! lots of messages will be output)
tracetrace function calls
packetsdebug packet handling
argsheavy trace debugging
connsconnection management
BERprint out packets sent and received
filtersearch filter processing
configconfiguration processing
ACLaccess control list processing
statsstats log connections/operations/results
stats2stats log entries sent
shellprint communication with shell backends
parseprint entry parsing debugging
syncsyncrepl consumer processing
noneonly messages that get logged whatever log level is set

Custom ldif files

*.ldif files can be used to add lots of people to the organisation on startup.

Copy ldif files to /ldif and the container will execute them. This can be done either by extending this Dockerfile with your own:

FROM pgarrett/ldap-alpine
COPY my-users.ldif /ldif/

Or by mounting your scripts directory into the container:

docker run -t -p 389:389 -v /my-ldif:/ldif pgarrett/ldap-alpine

Persist data

The container uses a standard mdb backend. To persist this database outside the container mount /var/lib/openldap/openldap-data. For example:

docker run -t -p 389:389 -v /my-backup:/var/lib/openldap/openldap-data pgarrett/ldap-alpine

Transport Layer Security

The container can be started using the encrypted LDAPS protocol. You must provide all three TLS environment variables.

VARIABLEDESCRIPTIONEXAMPLE
CA_FILEPEM-format file containing certificates for the CA's that slapd will trust/etc/ssl/certs/ca.pem
KEY_FILEThe slapd server private key/etc/ssl/certs/public.key
CERT_FILEThe slapd server certificate/etc/ssl/certs/public.crt
TLS_VERIFY_CLIENTSlapd option for client certificate verificationtry, never, demand

Note these variables inform the entrypoint script (executed on startup) where to find the SSL certificates inside the container. So the certificates must also be mounted at runtime too, for example:

docker run -t -p 389:389 \
-v /my-certs:/etc/ssl/certs \
-e CA_FILE /etc/ssl/certs/ca.pem \
-e KEY_FILE /etc/ssl/certs/public.key \
-e CERT_FILE /etc/ssl/certs/public.crt \
pgarrett/ldap-alpine

Where /my-certs on the host contains the three certificate files ca.pem, public.key and public.crt.

To disable client certificates set TLS_VERIFY_CLIENT to never or try.

Access Control

Global access to your directory can be configured via the ACCESS_CONTROL environment variable.

The default policy allows anyone and everyone to read anything but restricts updates to rootdn.

access to * by * read

Note rootdn can always read and write everything!

You can find detailed documentation on access control here https://www.openldap.org/doc/admin24/access-control.html

This following access control allows the user to modify their entry, allows anonymous to authenticate against these entries, and allows all others to read these entries:

docker run -t -p 389:389 \
-e ACCESS_CONTROL="access to * by self write by anonymous auth by users read" \
pgarrett/ldap-alpine

Now ldapsearch -x -b "dc=example,dc=com" "uid=pgarret" will return no results.

In order to search you will need to authenticate (bind) first:

ldapsearch -D "uid=pgarrett,ou=Users,dc=example,dc=com" -w password -b "dc=example,dc=com" "uid=pgarrett"

About

OpenLDAP based on Alpine Linux

Topics

Resources

Contributing

Stars

41 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - gitphill/ldap-alpine: OpenLDAP based on Alpine Linux · GitHub
Skip to content

Repository files navigation

LDAP Alpine

The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

This image is based on Alpine Linux and OpenLDAP.

Customisation

Override the following environment variables when running the docker container to customise LDAP:

VARIABLEDESCRIPTIONDEFAULT
ORGANISATION_NAMEOrganisation nameExample Ltd
SUFFIXOrganisation distinguished namedc=example,dc=com
ROOT_USERRoot usernameadmin
ROOT_PWRoot passwordpassword
USER_UIDInitial user's uidpgarrett
USER_GIVEN_NAMEInitial user's given namePhill
USER_SURNAMEInitial user's surnameGarrett
USER_EMAILInitial user's emailpgarrett@example.com
USER_PWInitial user's passwordpassword
ACCESS_CONTROLGlobal access controlaccess to * by * read
LOG_LEVELLDAP logging level, see below for valid values.stats

For example:

docker run -t -p 389:389 \
-e ORGANISATION_NAME="Beispiel gmbh" \
-e SUFFIX="dc=beispiel,dc=de" \
-e ROOT_PW="geheimnis" \
pgarrett/ldap-alpine

Search for user:

ldapsearch -x -b "dc=beispiel,dc=de" "uid=pgarrett"

Logging Levels

NAMEDESCRIPTION
anyenable all debugging (warning! lots of messages will be output)
tracetrace function calls
packetsdebug packet handling
argsheavy trace debugging
connsconnection management
BERprint out packets sent and received
filtersearch filter processing
configconfiguration processing
ACLaccess control list processing
statsstats log connections/operations/results
stats2stats log entries sent
shellprint communication with shell backends
parseprint entry parsing debugging
syncsyncrepl consumer processing
noneonly messages that get logged whatever log level is set

Custom ldif files

*.ldif files can be used to add lots of people to the organisation on startup.

Copy ldif files to /ldif and the container will execute them. This can be done either by extending this Dockerfile with your own:

FROM pgarrett/ldap-alpine
COPY my-users.ldif /ldif/

Or by mounting your scripts directory into the container:

docker run -t -p 389:389 -v /my-ldif:/ldif pgarrett/ldap-alpine

Persist data

The container uses a standard mdb backend. To persist this database outside the container mount /var/lib/openldap/openldap-data. For example:

docker run -t -p 389:389 -v /my-backup:/var/lib/openldap/openldap-data pgarrett/ldap-alpine

Transport Layer Security

The container can be started using the encrypted LDAPS protocol. You must provide all three TLS environment variables.

VARIABLEDESCRIPTIONEXAMPLE
CA_FILEPEM-format file containing certificates for the CA's that slapd will trust/etc/ssl/certs/ca.pem
KEY_FILEThe slapd server private key/etc/ssl/certs/public.key
CERT_FILEThe slapd server certificate/etc/ssl/certs/public.crt
TLS_VERIFY_CLIENTSlapd option for client certificate verificationtry, never, demand

Note these variables inform the entrypoint script (executed on startup) where to find the SSL certificates inside the container. So the certificates must also be mounted at runtime too, for example:

docker run -t -p 389:389 \
-v /my-certs:/etc/ssl/certs \
-e CA_FILE /etc/ssl/certs/ca.pem \
-e KEY_FILE /etc/ssl/certs/public.key \
-e CERT_FILE /etc/ssl/certs/public.crt \
pgarrett/ldap-alpine

Where /my-certs on the host contains the three certificate files ca.pem, public.key and public.crt.

To disable client certificates set TLS_VERIFY_CLIENT to never or try.

Access Control

Global access to your directory can be configured via the ACCESS_CONTROL environment variable.

The default policy allows anyone and everyone to read anything but restricts updates to rootdn.

access to * by * read

Note rootdn can always read and write everything!

You can find detailed documentation on access control here https://www.openldap.org/doc/admin24/access-control.html

This following access control allows the user to modify their entry, allows anonymous to authenticate against these entries, and allows all others to read these entries:

docker run -t -p 389:389 \
-e ACCESS_CONTROL="access to * by self write by anonymous auth by users read" \
pgarrett/ldap-alpine

Now ldapsearch -x -b "dc=example,dc=com" "uid=pgarret" will return no results.

In order to search you will need to authenticate (bind) first:

ldapsearch -D "uid=pgarrett,ou=Users,dc=example,dc=com" -w password -b "dc=example,dc=com" "uid=pgarrett"

About

OpenLDAP based on Alpine Linux

Topics

Resources

Contributing

Stars

41 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages