LemonLDAP::NG Manager
50K+
Lemonldap::NG portal based on yadd/lemonldap-ng-base
Note that you should share sessions and configuration to use. See docker-compose example to see how to do this using redis and PostgreSQL.
stable: alias of lts-2.21, the current LTS releasestable-no-s6: the same without S6-overlay2.x.x: versioned lemonldap-ng* packages from Debian backports2.x.x-no-s6: the same without S6-overlaySSODOMAIN)PORTAL)LOGLEVEL)REDIS_SERVER is set, change globalStorage to Apache::Session::Browseable::Redis and configure it (indexes given by REDIS_INDEXES, default: "uid mail")PG_SERVER is given ANDDEFAULT_WEBSITE = no, if set to yes the default Nginx website is
deletedPROTECTION = manager, set it to none if you don't want to protect
the manager by LemonLDAP-NG itselfAUTHBASIC, if you use PROTECTION=none, you can add a basic authentication
using AUTHBASIC=<login>:<password>MANAGER_API = no, set it to yes to enable the
Manager API on
manager-api.$SSODOMAIN (see Manager API below)MANAGER_API_OAUTH2_CLIENTS = (space or comma separated list of OIDC
client IDs allowed to use the API with an access token obtained by client
credentials grant)MANAGER_API_OAUTH2_SCOPE = manager-api, scope required in these access
tokens (empty value: no scope check)MANAGER_API_ALLOW = (space or comma separated list of IP addresses or
networks allowed to access the API, all others are rejected)MANAGER_API_AUTHBASIC = (<login>:<password> to add an Nginx basic
authentication on the API)MANAGER_API_READONLY = no, set it to yes to allow only GET and
HEAD requestsMANAGER_API_PORT = (serve the API on this dedicated port, whatever the
Host header, instead of the manager-api.$SSODOMAIN virtual host)The Manager API allows to modify LemonLDAP::NG configuration (OIDC RPs,
SAML SPs, CAS applications, menu) and users second factors. It performs no
authentication by itself, so it's disabled by default. When enabled with
MANAGER_API=yes, it's served on manager-api.$SSODOMAIN and at least one of
MANAGER_API_OAUTH2_CLIENTS, MANAGER_API_ALLOW or MANAGER_API_AUTHBASIC
is required. If the given variables would leave the API unprotected (or are
invalid), an error is logged and the API stays disabled.
Available protections (they can be combined, except OAuth2 and basic
authentication which both use the Authorization header):
OAuth2 client credentials (recommended): API clients are
applications, not users. Declare each of them as an OIDC Relying Party
allowed to use the client credentials grant, then list their client IDs
in MANAGER_API_OAUTH2_CLIENTS. The API then requires an access token
(Authorization: Bearer ...) that:
MANAGER_API_OAUTH2_SCOPE scope (default: manager-api)Tokens are short-lived, each client has its own secret and the client ID appears in LemonLDAP::NG logs. Example:
TOKEN=$(curl -s -u myclient:mysecret -d grant_type=client_credentials \
-d scope=manager-api https://auth.example.com/oauth2/token | jq -r .access_token)
curl -H "Authorization: Bearer $TOKEN" https://manager-api.example.com/api/v1/status
IP filtering: MANAGER_API_ALLOW="10.1.2.0/24 192.168.0.12". Don't
forget FORWARDED_BY if you're behind a reverse proxy, else the proxy
address is checked. But FORWARDED_BY must contain only your proxy
addresses: if it trusts any client (0.0.0.0/0 or ::/0), the client
address can be spoofed, so the allow list is refused if no other protection
is set. 0.0.0.0/0 and ::/0 are also refused in MANAGER_API_ALLOW if
no other protection is set
Nginx basic authentication: MANAGER_API_AUTHBASIC=<login>:<password>
Read-only mode: MANAGER_API_READONLY=yes rejects all modification
requests (useful for monitoring or inventory). Note that read requests
return secrets (OIDC client secrets for example), so this doesn't replace
a strong protection
By default, the API is a virtual host on the main port. With
MANAGER_API_PORT=8081 for example, it's served instead on port 8081 whatever
the Host header, so a reverse proxy can route /api/ of the manager site to
this port (https://manager.example.com/api/v1/...) or it can be kept
unexposed outside of your internal network. With TLS_CERT_FILE, this port
uses TLS too.
Example: API usable only from the internal network by the ci-deploy OIDC
client:
manager:
image: yadd/lemonldap-ng-manager
environment:
- MANAGER_API=yes
- MANAGER_API_OAUTH2_CLIENTS=ci-deploy
- MANAGER_API_ALLOW=10.0.0.0/8
Example with Crowdsec enabled, Postgres database and Redis to share sessions.
version: "3.4"
services:
db:
image: yadd/lemonldap-ng-pg-database
environment:
- POSTGRES_PASSWORD=zz
healthcheck:
test: ["CMD-SHELL", "pg_isready"]
interval: 10s
timeout: 5s
retries: 5
redis:
image: redis
portal:
image: yadd/lemonldap-ng-portal
environment:
- PG_SERVER=db
- REDIS_SERVER=redis:6379
- LOGGER=stderr
- USERLOGGER=stderr
- CROWDSEC_SERVER=http://crowdsec:8080
- CROWDSEC_KEY=myrandomstring
- CROWDSEC_ACTION=reject
depends_on:
db:
condition: service_healthy
redis:
condition: service_started
manager:
image: yadd/lemonldap-ng-manager
environment:
- PG_SERVER=db
- REDIS_SERVER=redis:6379
- LOGGER=stderr
- USERLOGGER=stderr
depends_on:
db:
condition: service_healthy
redis:
condition: service_started
portal:
condition: service_started
crowdsec:
image: crowdsecurity/crowdsec
environment:
- BOUNCER_KEY_llng=myrandomstring
haproxy:
image: haproxy:2.6-bullseye
ports:
- 80:80
volumes:
- ./haproxy:/usr/local/etc/haproxy:ro
sysctls:
- net.ipv4.ip_unprivileged_port_start=0
depends_on:
- portal
- manager
Copyright:
License: GNU General Public License v2.0
Content type
Image
Digest
sha256:e447a88ff…
Size
147.8 MB
Last updated
4 days ago
docker pull yadd/lemonldap-ng-manager