ansible/roles/docker/tasks/services/openldap.yml

74 lines
2.3 KiB
YAML
Raw Permalink Normal View History

---
2019-03-04 17:21:14 +00:00
- name: create ldap volume folders
2022-11-26 08:52:41 +00:00
ansible.builtin.file:
name: '{{ services.openldap.volume_folder }}/{{ volume }}'
2019-03-04 17:21:14 +00:00
state: directory
loop:
2022-11-26 08:52:41 +00:00
- var/lib/ldap
- etc/slapd
- certs
2019-03-04 17:21:14 +00:00
loop_control:
loop_var: volume
- name: Create a network for ldap
2022-11-26 08:52:41 +00:00
community.docker.docker_network:
name: ldap
- name: openLDAP container
2022-11-26 08:52:41 +00:00
community.docker.docker_container:
name: openldap
image: osixia/openldap:{{ services.openldap.version }}
tty: true
interactive: true
restart_policy: unless-stopped
volumes:
2022-11-26 08:52:41 +00:00
- '{{ services.openldap.volume_folder }}/var/lib/ldap:/var/lib/ldap'
- '{{ services.openldap.volume_folder }}/etc/slapd.d:/etc/ldap/slapd.d'
- '{{ services.openldap.volume_folder }}/certs:/container/service/slapd/assets/certs/'
published_ports:
2022-11-26 08:52:41 +00:00
- 389:389
- 636:636
hostname: '{{ services.openldap.domain }}'
domainname: '{{ services.openldap.domain }}' # important: same as hostname
networks:
- name: ldap
env:
2022-11-26 08:52:41 +00:00
LDAP_LOG_LEVEL: '256'
LDAP_ORGANISATION: '{{ base_domain }}'
LDAP_DOMAIN: '{{ base_domain }}'
LDAP_BASE_DN: ''
LDAP_ADMIN_PASSWORD: '{{ ldap_admin_password }}'
LDAP_CONFIG_PASSWORD: '{{ ldap_config_password }}'
LDAP_READONLY_USER: 'false'
LDAP_RFC2307BIS_SCHEMA: 'false'
LDAP_BACKEND: mdb
LDAP_TLS: 'true'
LDAP_TLS_CRT_FILENAME: ldap.crt
LDAP_TLS_KEY_FILENAME: ldap.key
LDAP_TLS_CA_CRT_FILENAME: ca.crt
LDAP_TLS_ENFORCE: 'false'
LDAP_TLS_CIPHER_SUITE: SECURE256:-VERS-SSL3.0
LDAP_TLS_PROTOCOL_MIN: '3.1'
LDAP_TLS_VERIFY_CLIENT: demand
LDAP_REPLICATION: 'false'
KEEP_EXISTING_CONFIG: 'false'
LDAP_REMOVE_CONFIG_AFTER_SETUP: 'true'
LDAP_SSL_HELPER_PREFIX: ldap
2019-01-19 17:11:50 +00:00
- name: phpLDAPadmin container
2022-11-26 08:52:41 +00:00
community.docker.docker_container:
name: phpldapadmin
image: osixia/phpldapadmin:{{ services.phpldapadmin.version }}
restart_policy: unless-stopped
networks:
- name: external_services
- name: ldap
env:
2022-11-26 08:52:41 +00:00
PHPLDAPADMIN_LDAP_HOSTS: openldap
PHPLDAPADMIN_HTTPS: 'false'
PHPLDAPADMIN_TRUST_PROXY_SSL: 'true'
2019-01-19 17:11:50 +00:00
2022-11-26 08:52:41 +00:00
VIRTUAL_HOST: '{{ services.openldap.domain }}'
LETSENCRYPT_HOST: '{{ services.openldap.domain }}'
LETSENCRYPT_EMAIL: '{{ letsencrypt_email }}'