Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
Ansible
Manage
Activity
Members
Labels
Plan
Issues
3
Issue boards
Milestones
Code
Merge requests
2
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Deploy
Releases
Model registry
Analyze
Value stream analytics
Contributor analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
Nounous
Ansible
Commits
648a35a3
Verified
Commit
648a35a3
authored
4 years ago
by
me5na7qbjqbrp
Browse files
Options
Downloads
Patches
Plain Diff
Change Grafana LDAP configuration
parent
9899a327
No related branches found
No related tags found
1 merge request
!176
Grafana newinfra
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
plays/monitoring.yml
+1
-3
1 addition, 3 deletions
plays/monitoring.yml
roles/grafana/templates/ldap.toml.j2
+4
-17
4 additions, 17 deletions
roles/grafana/templates/ldap.toml.j2
with
5 additions
and
20 deletions
plays/monitoring.yml
+
1
−
3
View file @
648a35a3
...
...
@@ -25,12 +25,10 @@
grafana
:
root_url
:
https://grafana.crans.org
ldap_bind_dn
:
"
cn=grafana,ou=service-users,{{
ldap_base
}}"
ldap_passwd
:
"
{{
vault_ldap_grafana_passwd
}}"
ldap_base
:
'
dc=crans,dc=org'
ldap_master_ipv4
:
'
172.16.10.1'
ldap_user_tree
:
"
ou=
users
,{{
ldap_base
}}"
ldap_user_tree
:
"
ou=
passwd
,{{
ldap_base
}}"
roles
:
-
prometheus
-
prometheus-alertmanager
...
...
This diff is collapsed.
Click to expand it.
roles/grafana/templates/ldap.toml.j2
+
4
−
17
View file @
648a35a3
...
...
@@ -7,9 +7,9 @@
# Ldap server host (specify multiple hosts space separated)
host = "{{ ldap_master_ipv4 }}"
# Default port is 389 or 636 if use_ssl = true
port =
389
port =
636
# Set to true if ldap server supports TLS
use_ssl =
fals
e
use_ssl =
tru
e
# Set to true if connect ldap server with STARTTLS pattern (create connection in insecure, then upgrade to secure connection with TLS)
start_tls = false
# set to true if you want to skip ssl cert validation
...
...
@@ -46,20 +46,7 @@ username = "cn"
member_of = "dn"
email = "mail"
#
Map ldap groups to grafana org roles
#
All LDAP members can edit
[[servers.group_mappings]]
group_dn = "cn=nounou,ou=posix,ou=groups,dc=crans,dc=org"
org_role = "Admin"
# To make user an instance admin (Grafana Admin) uncomment line below
# grafana_admin = true
# The Grafana organization database id, optional, if left out the default org (id 1) will be used
# org_id = 1
[[servers.group_mappings]]
group_dn = "cn=apprenti,ou=posix,ou=groups,dc=crans,dc=org"
org_role = "Editor"
[[servers.group_mappings]]
# If you want to match all (or no ldap groups) then you can use wildcard
group_dn = "*"
org_role = "
Viewe
r"
org_role = "
Edito
r"
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment