-
Notifications
You must be signed in to change notification settings - Fork 1
ADR 0005 LDAP Identity
Zlatko Lakisic edited this page Aug 4, 2026
·
1 revision
Status: Accepted
Date: 2026-08-03
Milestone: Phase 2 (directory)
Face recognition returned a free-form CPAI userid that became AO session headers
with no directory binding. FreeIPA is the LAN identity store; biometrics must not
live in LDAP.
- AO/COMSTAR session only — not Kerberos SSO or HA presence in this ADR.
- FreeIPA
uidis the canonical session identity. -
comstarFaceId/comstarVoiceIdbind biometric store IDs to that uid. - Biometrics stay in CPAI / future speaker service.
- Bridge resolves faceId → profile via directory sidecar before
OpenSession. - Fail closed when
directory.require: true. - Planner LDAP MCP deferred (
guest_allowed: falsewhen added).
Full text: docs/adr/0005-ldap-identity.md in the main repo.
COMSTAR AI — Not a mystical AI. A tool you engineered — transparent, hackable, fast.
Home · Architecture · Admin Console · Runbook · Contracts
Apache-2.0 · Pre-alpha · Raspberry Pi 4 terminal + local AI server
COMSTAR AI
Start here
Product
Build & configure
Interfaces
- Contracts Overview
- Bridge ↔ Kiosk
- Bridge ↔ Audio
- CodeProject.AI
- AO Reach
- MCP Tools
- Attention State Machine
Features
- Speech (STT/TTS)
- Vision & Face Enrollment
- Directory Identity
- Wake Word
- MCP Topology
- Terminal Control
- Google Workspace
Decisions (ADRs)
- ADR Index
- 0001 Audio Routing
- 0002 Render Path
- 0003 Speech on Ada
- 0004 Terminal Control
- 0005 LDAP Identity
- 0006 House Presence
- 0007 Full-Duplex AEC
- 0008 TTS Engine
- 0009 Proactivity
- 0010 Text Channel
- 0011 Road VPN
- 0012 Admin Network
- 0013 AO mTLS
- 0014 Fallback Hotspot
Operate
Plan
Meta