{"repo":"HopopOps/k8s-ldap-auth","free":true,"listed":false,"github":"https://github.com/HopopOps/k8s-ldap-auth","clone":"git clone https://github.com/HopopOps/k8s-ldap-auth.git","description":"Kubernetes webhook token authentication plugin implementation using ldap.","language":"Go","stars":54,"topics":["kubernetes","authentication","ldap","kubernetes-webhook","k8s"],"license":"MPL-2.0","category":"deployment-docker-iac","readme_excerpt":"k8s-ldap-auth A webhook token authentication plugin implementation backed by LDAP. - What - Usage Server + New cluster + Existing cluster Client RBAC + Example - Build - Distribution Docker Binary Linux + Archlinux Darwin + With brew Kubernetes + Helm Chart - Inspiration What k8s-ldap-auth is released as a binary containing both client and server. The server part provides two routes: - /auth for the actual authentication from the CLI tool - /token for the token validation from the kube-apiserver. The user created from the TokenReview will contain both uid and groups from the LDAP user so you can use both for role binding. The same k8s-ldap-auth server can be used to authenticate with multiple kubernetes cluster since the ExecCredential it provides contains a signed token that will eventually be used by a kube-apiserver in a TokenReview that will be sent back. I actually use this setup on quite a few clusters with a growing userbase. Access rights to clusters and resources will not be implemented in this authentication hook, kubernetes RBAC will do that for you. KUBERNETES EXEC INFO is currently disregarded but might be used in future versions. Usage You can see the commands and their options with: Pretty much all options can be set using environment variables and a few also read their values from files. Server Create the password file for the bind-dn: The server can then be started with: Note that if the server do not know of any key pair it will create one at launch but will","default_branch":null,"files":null,"tree":[],"storefront":"/r/HopopOps","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/HopopOps/k8s-ldap-auth/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}