{"id":120,"date":"2024-03-19T15:28:17","date_gmt":"2024-03-19T07:28:17","guid":{"rendered":"https:\/\/blog.bijiafeng.com\/?p=120"},"modified":"2024-03-20T10:39:45","modified_gmt":"2024-03-20T02:39:45","slug":"openshift-cluster-oauth-ad-ldap","status":"publish","type":"post","link":"https:\/\/blog.bijiafeng.com\/?p=120","title":{"rendered":"Openshift Cluster OAuth &#8211; AD LDAP"},"content":{"rendered":"\n<p>Create user and group in AD.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>ocp-user:<\/strong> Users with OpenShift access<br>Any users who should be able to log-in to OpenShift must be members of this group<br>All of the below mentioned users are in this group<br><strong>ocp-normal-dev: <\/strong>Normal OpenShift users<br>Regular users of OpenShift without special permissions<br>Contains: normaluser1, teamuser1, teamuser2<br><strong>ocp-fancy-dev:<\/strong> Fancy OpenShift users<br>Users of OpenShift that are granted some special privileges<br>Contains: fancyuser1, fancyuser2<br><strong>ocp-teamed-app:<\/strong> Teamed app users<br>A group of users that will have access to the same OpenShift Project<br>Contains: teamuser1, teamuser2<\/p>\n<\/blockquote>\n\n\n\n<p>Create a Secret with the bind password.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>oc create secret generic ldapuser-secret --from-literal=bindPassword=yourPassword -n openshift-config<\/code><\/pre>\n\n\n\n<p>Update the cluster OAuth object with the LDAP identity provider.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>spec:\n  identityProviders:\n  - name: ldap\n    challenge: false\n    login: true\n    mappingMethod: claim\n    type: LDAP\n    ldap:\n      attributes:\n        id:\n        - distinguishedName\n        email:\n        - userPrincipalName\n        name:\n        - givenName\n        preferredUsername:\n        - sAMAccountName\n      bindDN: \"cn=ldapuser,cn=Users,dc=dcloud,dc=demo,dc=com\"\n      bindPassword:\n        name: ldapuser-secret\n      insecure: true\n      url: \"ldap:\/\/ad1.dcloud.demo.com:389\/cn=Users,dc=dcloud,dc=demo,dc=com?sAMAccountName?sub?(memberOf=cn=ocp-user,cn=Users,dc=dcloud,dc=demo,dc=com)\"\n  tokenConfig:\n    accessTokenMaxAgeSeconds: 86400<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/rhthsa.github.io\/openshift-demo\/infrastructure-authentication-providers.html\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Create user and group in AD. ocp-user: Users with OpenShift accessAny users who should be able to log-in to OpenShift must be members of this groupAll of the below mentioned users are in this groupocp-normal-dev: Normal OpenShift usersRegular users of OpenShift without special permissionsContains: normaluser1, teamuser1, teamuser2ocp-fancy-dev: Fancy OpenShift usersUsers of OpenShift that are granted [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[],"class_list":["post-120","post","type-post","status-publish","format-standard","hentry","category-openshift"],"_links":{"self":[{"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=\/wp\/v2\/posts\/120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=120"}],"version-history":[{"count":3,"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=\/wp\/v2\/posts\/120\/revisions"}],"predecessor-version":[{"id":123,"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=\/wp\/v2\/posts\/120\/revisions\/123"}],"wp:attachment":[{"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.bijiafeng.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}