This project provides a Dockerfile and scripts used to build a docker image from official openldap sources This work is partially based on the Bitnami OpenLDAP image, except the build from source part, and therefore uses the same environment variable names
OpenLDAP is the open-source solution for LDAP (Lightweight Directory Access Protocol). It is a protocol used to store and retrieve data from a hierarchical directory structure such as in databases.
This project was made with the goal of building OpenLDAP from source. No pre-built images are available on Docker Repositories.
- Clone this repository and cd into it
- Change the first line of the Dockerfile
ARG OPENLDAP_VERSION=<version>and replace version using the one you want to build (This dockerfile has been tested only on 2.6.9) - Change the second line of the Dockerfile
ARG DOWNLOAD_MIRROR="<mirror_url>"and replace mirror_url using the one you want. You can find some of them directly on OpenLDAP Website
- To build directly using docker compose, please see this example
- To build from command line :
docker build -t openldap-docker:<version> ./Using Docker container networking, a different server running inside a container can easily be accessed by your application containers and vice-versa.
Containers attached to the same network can communicate with each other using the container name as the hostname.
When not specified, Docker Compose automatically sets up a new network and attaches all deployed services to that network. However, we will explicitly define a new bridge network named my-network. In this example we assume that you want to connect to the OpenLDAP server from your own custom application image which is identified in the following snippet by the service name myapp.
networks:
my-network:
driver: bridge
services:
openldap:
build: /PATH/TO/THIS/REPOSITORY
image: openldap-docker:<version>
ports:
- '1389:1389'
- '1636:1636'
environment:
- LDAP_ADMIN_USERNAME=admin
- LDAP_ADMIN_PASSWORD=adminpassword
- LDAP_USERS=user01,user02
- LDAP_PASSWORDS=password1,password2
networks:
- my-network
volumes:
- 'openldap_data:/openldap'
myapp:
image: 'YOUR_APPLICATION_IMAGE'
networks:
- my-network
volumes:
openldap_data:
driver: localIMPORTANT:
- Please update the /PATH/TO/THIS/REPOSITORY placeholder in the above snippet with the path to this repository
- Please update the placeholder in the above snippet with the path to this repository
- Please update the YOUR_APPLICATION_IMAGE placeholder in the above snippet with your application image
- In your application container, use the hostname
openldapto connect to the OpenLDAP server- If you're willing to map a directory instead of using a docker volume, your folder on the host needs to be owned by user 1001:1001
Launch the containers using:
docker-compose up -dDocker OpenLDAP can be easily setup with the following environment variables:
LDAP_PORT_NUMBER: The port OpenLDAP is listening for requests. Priviledged port is supported (e.g.389). Default: 1389 (non privileged port).LDAP_ROOT: LDAP baseDN (or suffix) of the LDAP tree. Default: dc=example,dc=orgLDAP_ADMIN_USERNAME: LDAP database admin user. Default: adminLDAP_ADMIN_PASSWORD: LDAP database admin password. Default: adminpasswordLDAP_ADMIN_PASSWORD_FILE: Path to a file that contains the LDAP database admin user password. This will override the value specified inLDAP_ADMIN_PASSWORD. No defaults.LDAP_CONFIG_ADMIN_ENABLED: Whether to create a configuration admin user. Default: no.LDAP_CONFIG_ADMIN_USERNAME: LDAP configuration admin user. This is separate fromLDAP_ADMIN_USERNAME. Default: admin.LDAP_CONFIG_ADMIN_PASSWORD: LDAP configuration admin password. Default: configpassword.LDAP_CONFIG_ADMIN_PASSWORD_FILE: Path to a file that contains the LDAP configuration admin user password. This will override the value specified inLDAP_CONFIG_ADMIN_PASSWORD. No defaults.LDAP_USERS: Comma separated list of LDAP users to create in the default LDAP tree. Default: user01,user02LDAP_PASSWORDS: Comma separated list of passwords to use for LDAP users. Default: user01,user02LDAP_USER_OU: Name for the user's organizational unit. Default: usersLDAP_GROUP_OU: Name for the group's organizational unit. Default: groupsLDAP_USER_DC: DC for the users' organizational unit. DEPRECATED Please useLDAP_USER_OUandLDAP_GROUP_OUinstead.LDAP_GROUP: Group used to group created users. Default: readersLDAP_ADD_SCHEMAS: Whether to add the schemas specified inLDAP_EXTRA_SCHEMAS. Default: yesLDAP_EXTRA_SCHEMAS: Extra schemas to add, among OpenLDAP's distributed schemas. Default: cosine, inetorgperson, nisLDAP_SKIP_DEFAULT_TREE: Whether to skip creating the default LDAP tree based onLDAP_USERS,LDAP_PASSWORDS,LDAP_USER_OU,LDAP_GROUP_OUandLDAP_GROUP. Please note that this will not skip the addition of schemas or importing of LDIF files. Default: noLDAP_CUSTOM_LDIF_DIR: Location of a directory that contains LDIF files that should be used to bootstrap the database. Only files ending in.ldifwill be used. Default LDAP tree based on theLDAP_USERS,LDAP_PASSWORDS,LDAP_USER_OU,LDAP_GROUP_OUandLDAP_GROUPwill be skipped whenLDAP_CUSTOM_LDIF_DIRis used. When using this it will override the usage ofLDAP_USERS,LDAP_PASSWORDS,LDAP_USER_OU,LDAP_GROUP_OUandLDAP_GROUP. You should setLDAP_ROOTto your base to make sure theolcSuffixconfigured on the database matches the contents imported from the LDIF files. Default: /ldifsLDAP_CUSTOM_SCHEMA_FILE: Location of a custom internal schema file that could not be added as custom ldif file (i.e. containing somestructuralObjectClass). Default is /schema/custom.ldif"LDAP_CUSTOM_SCHEMA_DIR: Location of a directory containing custom internal schema files that could not be added as custom ldif files (i.e. containing somestructuralObjectClass). This can be used in addition to or instead ofLDAP_CUSTOM_SCHEMA_FILE(above) to add multiple schema files. Default: /schemasLDAP_ULIMIT_NOFILES: Maximum number of open file descriptors. Default: 1024.LDAP_ALLOW_ANON_BINDING: Allow anonymous bindings to the LDAP server. Default: yes.LDAP_LOGLEVEL: Set the loglevel for the OpenLDAP server (see https://www.openldap.org/doc/admin26/slapdconfig.html for possible values). Default: 256.LDAP_PASSWORD_HASH: Hash to be used in generation of user passwords. Must be one of {SSHA}, {SHA}, {SMD5}, {MD5}, {CRYPT}, and {CLEARTEXT}. Default: {SSHA}.LDAP_CONFIGURE_PPOLICY: Enables the ppolicy module and creates an empty configuration. Default: no.LDAP_PPOLICY_USE_LOCKOUT: Whether bind attempts to locked accounts will always return an error. Will only be applied withLDAP_CONFIGURE_PPOLICYactive. Default: no.LDAP_PPOLICY_HASH_CLEARTEXT: Whether plaintext passwords should be hashed automatically. Will only be applied withLDAP_CONFIGURE_PPOLICYactive. Default: no.
Other special variables can be found in the script entrypoint.sh
You can bootstrap the contents of your database by putting LDIF files in the directory /ldifs (or the one you define in LDAP_CUSTOM_LDIF_DIR). Those may only contain content underneath your base DN (set by LDAP_ROOT). You can not set configuration for e.g. cn=config in those files.
Check the official OpenLDAP Configuration Reference for more information about how to configure OpenLDAP.
To ensure that the OpenLDAP state is retained across container restarts and updates, it is recommended to mount a volume at /openldap.
Overlays are dynamic modules that can be added to an OpenLDAP server to extend or modify its functionality.
This overlay can record accesses to a given backend database on another database.
LDAP_ENABLE_ACCESSLOG: Enables the accesslog module with the following configuration defaults unless specified otherwise. Default: no.LDAP_ACCESSLOG_ADMIN_USERNAME: Admin user for accesslog database. Default: admin.LDAP_ACCESSLOG_ADMIN_PASSWORD: Admin password for accesslog database. Default: accesspassword.LDAP_ACCESSLOG_DB: The DN (Distinguished Name) of the database where the access log entries will be stored. Will only be applied withLDAP_ENABLE_ACCESSLOGactive. Default: cn=accesslog.LDAP_ACCESSLOG_LOGOPS: Specify which types of operations to log. Valid aliases for common sets of operations are: writes, reads, session or all. Will only be applied withLDAP_ENABLE_ACCESSLOGactive. Default: writes.LDAP_ACCESSLOG_LOGSUCCESS: Whether successful operations should be logged. Will only be applied withLDAP_ENABLE_ACCESSLOGactive. Default: TRUE.LDAP_ACCESSLOG_LOGPURGE: When and how often old access log entries should be purged. Format"dd+hh:mm". Will only be applied withLDAP_ENABLE_ACCESSLOGactive. Default: 07+00:00 01+00:00.LDAP_ACCESSLOG_LOGOLD: An LDAP filter that determines which entries should be logged. Will only be applied withLDAP_ENABLE_ACCESSLOGactive. Default: (objectClass=*).LDAP_ACCESSLOG_LOGOLDATTR: Specifies an attribute that should be logged. Will only be applied withLDAP_ENABLE_ACCESSLOGactive. Default: objectClass.
Check the official page OpenLDAP, Overlays, Access Logging for detailed configuration information.
LDAP_ENABLE_SYNCPROV: Enables the syncrepl module with the following configuration defaults unless specified otherwise. Default: no.LDAP_SYNCPROV_CHECKPPOINT: For every 100 operations or 10 minutes, which ever is sooner, the contextCSN will be checkpointed. Will only be applied withLDAP_ENABLE_SYNCPROVactive. Default: 100 10.LDAP_SYNCPROV_SESSIONLOG: The maximum number of session log entries the session log can record. Will only be applied withLDAP_ENABLE_SYNCPROVactive. Default: 100.
Check the official page OpenLDAP, Overlays, Sync Provider for detailed configuration information.
OpenLDAP clients and servers are capable of using the Transport Layer Security (TLS) framework to provide integrity and confidentiality protections and to support LDAP authentication using the SASL EXTERNAL mechanism. Should you desire to enable this optional feature, you may use the following environment variables to configure the application:
LDAP_ENABLE_TLS: Whether to enable TLS for traffic or not. Defaults tono.LDAP_REQUIRE_TLS: Whether connections must use TLS. Will only be applied withLDAP_ENABLE_TLSactive. Defaults tono.LDAP_LDAPS_PORT_NUMBER: Port used for TLS secure traffic. Priviledged port is supported (e.g.636). Default: 1636 (non privileged port).LDAP_TLS_CERT_FILE: File containing the certificate file for the TLS traffic. No defaults.LDAP_TLS_KEY_FILE: File containing the key for certificate. No defaults.LDAP_TLS_CA_FILE: File containing the CA of the certificate. No defaults.LDAP_TLS_DH_PARAMS_FILE: File containing the DH parameters. No defaults.
This new feature is not mutually exclusive, which means it is possible to listen to both TLS and non-TLS connection simultaneously. To use TLS you can use the URI ldaps://openldap:1636 or use the non-TLS URI forcing ldap to use TLS ldap://openldap:1389 -ZZ.
Modifying the docker-compose.yml file present in this repository:
```yaml
services:
openldap:
...
environment:
...
- LDAP_ENABLE_TLS=yes
- LDAP_TLS_CERT_FILE=/opt/openldap/certs/openldap.crt
- LDAP_TLS_KEY_FILE=/opt/openldap/certs/openldap.key
- LDAP_TLS_CA_FILE=/opt/openldap/certs/openldapCA.crt
...
volumes:
- /path/to/certs:/opt/openldap/certs
- /path/to/openldap-data-persistence:/openldap/
...
```
OpenLDAP supports the HAProxy proxy protocol version 2 to detect real client IP that is masked when server runs behind load balancer. You can enable and configure this feature with the following environment variables:
LDAP_ENABLE_PROXYPROTO: Whether to enable proxy protocol support for traffic or not. Defaults tono.LDAP_PROXYPROTO_PORT_NUMBER: The port OpenLDAP is listening for requests that is wrapped in proxy protocol. Default: the LDAP_PORT_NUMBER value.LDAP_PROXYPROTO_LDAPS_PORT_NUMBER: Port used for TLS secure traffic that is wrapped in proxy protocol. Default: the LDAP_LDAPS_PORT_NUMBER value.
Enabling this feature will replace regular and TLS ports with proxy protocol capable analogs. To use both port types, set LDAP_PROXYPROTO_PORT_NUMBER to some different value than LDAP_PORT_NUMBER. The same statement applied to LDAP_PROXYPROTO_LDAPS_PORT_NUMBER and LDAP_LDAPS_PORT_NUMBER pair.
Security warning: To prevent client IP spoofing, it is highly advised to secure the proxy protocol capable ports by firewall that allow traffic only from load balancer hosts.
Check the official page OpenLDAP, Running slapd, Command-Line Options for additional information.
This image allows you to use your custom scripts to initialize a fresh instance.
The allowed script extension is .sh, all scripts are executed in alphabetical order.
- You can include them in image by placing scripts in the scripts/entrypoint folder before executing docker build
- You can mount your scripts directly into the folder
/docker-entrypoint-initdb.d/of the container
Scripts are executed are after the initilization and before the startup of the OpenLDAP service.
The image sends the container logs to stdout. To view the logs:
docker logs openldapYou can configure the containers logging driver using the --log-driver option if you wish to consume the container logs differently. In the default configuration docker uses the json-file driver.