From 6df61a4e4c661eeae557ebb11aba3129e35ebb91 Mon Sep 17 00:00:00 2001 From: phil Date: Sat, 14 Dec 2024 20:05:26 +0100 Subject: [PATCH] ajout lldap2 pour proxmox --- README.md | 3 +- lldap2/Vagrantfile | 100 +++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 102 insertions(+), 1 deletion(-) create mode 100644 lldap2/Vagrantfile diff --git a/README.md b/README.md index 2a60c80..2481c36 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # vagrant -le 2024-11-29 00h30 - ps +le 2024-12-14 21h30 - ps Ce dépôt héberge des **Vagrantfile** dont : * **dns** : Vagrantfile pour 2 serveurs **Bind9** (1 maitre et un esclave), tests **goss** chainés @@ -21,6 +21,7 @@ Ce dépôt héberge des **Vagrantfile** dont : * **k3s-awx** : Vagrantfile + script **inst-awx** pour installation **Ansible AWX** sur **k3s** avec **awx-on-k3s** * **kea-dhcp-ha** : Vagrantfile pour serveur DHCP kea - HA - tests non finalisés * **lldap** : Vagrantfile pour serveur LDAP en mode service **lldap** + * **lldap2** : Vagrantfile pour serveur LDAP en mode service **lldap** - integration pour Proxmox * **minione** * **netbox** : Vagrantfile pour Netbox dockerisée * **rundeck** : Vagrantfile + playbook pour installation avec Mariadb diff --git a/lldap2/Vagrantfile b/lldap2/Vagrantfile new file mode 100644 index 0000000..803767f --- /dev/null +++ b/lldap2/Vagrantfile @@ -0,0 +1,100 @@ +# -*- mode: ruby -*- +# vi: set ft=ruby : + +# All Vagrant configuration is done below. The "2" in Vagrant.configure +# configures the configuration version (we support older styles for +# backwards compatibility). Please don't change it unless you know what +# you're doing. +Vagrant.configure("2") do |config| + # The most common configuration options are documented and commented below. + # For a complete reference, please see the online documentation at + # https://docs.vagrantup.com. + + # Every Vagrant development environment requires a box. You can search for + # boxes at https://vagrantcloud.com/search. + config.vm.box = "debian/bookworm64" + config.vm.hostname = "ldap" + + # Disable automatic box update checking. If you disable this, then + # boxes will only be checked for updates when the user runs + # `vagrant box outdated`. This is not recommended. + # config.vm.box_check_update = false + + # Create a forwarded port mapping which allows access to a specific port + # within the machine from a port on the host machine. In the example below, + # accessing "localhost:8080" will access port 80 on the guest machine. + # NOTE: This will enable public access to the opened port + # config.vm.network "forwarded_port", guest: 80, host: 8080 + + # Create a forwarded port mapping which allows access to a specific port + # within the machine from a port on the host machine and only allow access + # via 127.0.0.1 to disable public access + # config.vm.network "forwarded_port", guest: 80, host: 8080, host_ip: "127.0.0.1" + + # Create a private network, which allows host-only access to the machine + # using a specific IP. + # config.vm.network "private_network", ip: "192.168.33.10" + #config.vm.network "private_network", ip: "192.168.56.10" + + # Create a public network, which generally matched to bridged network. + # Bridged networks make the machine appear as another physical device on + # your network. + config.vm.network "public_network" + + # Share an additional folder to the guest VM. The first argument is + # the path on the host to the actual folder. The second argument is + # the path on the guest to mount the folder. And the optional third + # argument is a set of non-required options. + # config.vm.synced_folder "../data", "/vagrant_data" + + # Disable the default share of the current code directory. Doing this + # provides improved isolation between the vagrant box and your host + # by making sure your Vagrantfile isn't accessible to the vagrant box. + # If you use this you may want to enable additional shared subfolders as + # shown above. + # config.vm.synced_folder ".", "/vagrant", disabled: true + + # Provider-specific configuration so you can fine-tune various + # backing providers for Vagrant. These expose provider-specific options. + # Example for VirtualBox: + # + # config.vm.provider "virtualbox" do |vb| + # # Display the VirtualBox GUI when booting the machine + # vb.gui = true + # + # # Customize the amount of memory on the VM: + # vb.memory = "1024" + # end + # + # View the documentation for the provider you are using for more + # information on available options. + + # Enable provisioning with a shell script. Additional provisioners such as + # Ansible, Chef, Docker, Puppet and Salt are also available. Please see the + # documentation for more information about their specific syntax and use. + config.vm.provision "shell", inline: <<-SHELL + timedatectl set-timezone Europe/Paris + apt-get update + apt-get install -y vim wget curl git gpg + echo 'deb http://download.opensuse.org/repositories/home:/Masgalor:/LLDAP/Debian_12/ /' | sudo tee /etc/apt/sources.list.d/home:Masgalor:LLDAP.list + curl -fsSL https://download.opensuse.org/repositories/home:Masgalor:LLDAP/Debian_12/Release.key | gpg --dearmor | sudo tee /etc/apt/trusted.gpg.d/home_Masgalor_LLDAP.gpg > /dev/null + apt-get update + apt-get install -y lldap lldap-set-password jq + sed -i 's/^#ldap_base_dn =.*/ldap_base_dn = "dc=labo,dc=lan"/' /etc/lldap/lldap_config.toml + sed -i 's/^#ldap_user_pass =.*/ldap_user_pass= "Azerty1+"/' /etc/lldap/lldap_config.toml + systemctl enable --now lldap + [[ -d lldap-cli ]] || git clone https://github.com/Zepmann/lldap-cli.git + sed -i 's:.*lldapConfig=.*:lldapConfig="/etc/lldap/lldap_config.toml":' lldap-cli/lldap-cli + bash lldap-cli/lldap-cli group add sio2025 + bash lldap-cli/lldap-cli user add pdubois pdubois@jetable.org -p Azerty1+ + bash lldap-cli/lldap-cli user group add pdubois sio2025 + bash lldap-cli/lldap-cli group add sio2026 + bash lldap-cli/lldap-cli user add jleroy jleroy@jetable.org -p Azerty1+ + bash lldap-cli/lldap-cli user group add jleroy sio2026 + bash lldap-cli/lldap-cli user add ldupont ldupont@jetable.org -p Azerty1+ + bash lldap-cli/lldap-cli user group add ldupont sio2026 + bash lldap-cli/lldap-cli user add bind_user bind_user@jetable.org -p Azerty1+ + bash lldap-cli/lldap-cli user group add bind_user illdap_strict_readonly + ip -br a + SHELL +end