-
Notifications
You must be signed in to change notification settings - Fork 1.8k
OSDOCS-1856: Adding docs for automatically syncing LDAP groups #36040
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
✔️ Deploy Preview for osdocs ready! 🔨 Explore the source changes: 44cacb7 🔍 Inspect the deploy log: https://app.netlify.com/sites/osdocs/deploys/616706f96aa137000836685e 😎 Browse the preview: https://deploy-preview-36040--osdocs.netlify.app |
d496765
to
855a7ab
Compare
modules/ldap-auto-syncing.adoc
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@stlaz Prior to this, we said that you had to set up the LDAP IDP. If you look at our docs on it [1] the names are ldap-secret
for the secret, and ca-config-map
. Any thoughts on if we should use those names, or are they too generic?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@stlaz Did you have any thoughts on this question here?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think you can refer to the secret used in the IdP configuration, specific names are probably not necessary in the description.
855a7ab
to
47da58c
Compare
47da58c
to
bad7aa1
Compare
b788450
to
2742912
Compare
Note to self: change |
96fd7f0
to
5399203
Compare
95368ac
to
1f34da2
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
A couple of very minor comments but this LGTM!
Note to self again: change batch/v1 to batch/v1beta1 for the 4.6 and 4.7 backports. |
1f34da2
to
4b7aecc
Compare
modules/ldap-auto-syncing.adoc
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
is the ca filed required when insecure is false? Will 'insecure is true' be supported?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
you may want to see the already existing docs: https://docs.openshift.com/container-platform/4.8/authentication/ldap-syncing.html#sync-ldap-v1-ldapsyncconfig
modules/ldap-auto-syncing.adoc
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
should the url be ldaps rather than ldap?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'd prefer this being ldaps:// actually, but ldap:// should still work
@stlaz Can you take a look at @yaoli-redhat's comments? I don't know the answer to them. |
4b7aecc
to
44cacb7
Compare
@yaoli-redhat Per @stlaz's answer and discussion in slack, I updated Can you take another look with that update and let me know how this looks? Thanks! |
@bergerhoffer thanks for the update and lgtm. |
Thanks @yaoli-redhat! |
/cherrypick enterprise-4.9 |
@bergerhoffer: once the present PR merges, I will cherry-pick it on top of enterprise-4.9 in a new PR and assign it to you. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/cherrypick enterprise-4.8 |
@bergerhoffer: once the present PR merges, I will cherry-pick it on top of enterprise-4.8 in a new PR and assign it to you. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
4.6 and 4.7 backports to be done manually so that I can change |
@bergerhoffer: new pull request created: #37520 In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
@bergerhoffer: new pull request created: #37521 In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
https://issues.redhat.com/browse/OSDOCS-1856
This epic is for 4.9, but these docs can be backported to all supported 4.x versions.
Preview: https://deploy-preview-36040--osdocs.netlify.app/openshift-enterprise/latest/authentication/ldap-syncing.html#ldap-auto-syncing_ldap-syncing-groups