OpenLDAP Docker packages a production-ready OpenLDAP 2.6 server as a single
container. Instead of hand-editing slapd.conf or assembling cn=config with
ldapmodify, you set environment variables and the entrypoint builds the
configuration on first start.
Replication
Multi-master replication is configured from LDAP_DOMAIN, LDAP_REPLICATION_PASSWORD
and REPLICATION_PEERS. Three or more nodes form a mesh where every node accepts
writes and converges through syncrepl. Replication can run over StartTLS with a
configurable TLS_REQCERT level.
Schemas and overlays
INCLUDE_SCHEMAS loads the schemas you name at boot - cosine, inetorgperson, nis -
so an inetOrgPerson entry works immediately rather than failing until someone
runs ldapadd against cn=schema,cn=config by hand. Optional overlays are toggled
the same way: ENABLE_MEMBEROF for memberOf on user entries, ENABLE_PASSWORD_POLICY
for ppolicy, ENABLE_AUDIT_LOG for the auditlog overlay, and ENABLE_MONITORING for
the monitor backend.
TLS
LDAP_TLS_CERT, LDAP_TLS_KEY and LDAP_TLS_CA enable LDAPS on 636 and StartTLS on
389, with LDAP_TLS_VERIFY_CLIENT and LDAP_TLS_PROTOCOL_MIN controlling client
certificate verification and the minimum protocol version.
Security defaults
The server runs as the non-root ldap user (UID 55). Query limits default to 500
soft and 1000 hard, idle connections close after 600 seconds, and ACLs require
authentication for password attributes. Anonymous bind can be disabled with
LDAP_DISABLE_ANONYMOUS_BIND. Every password variable has a _FILE counterpart, so
credentials can come from Docker or Kubernetes secrets rather than the environment.
Images are scanned with Trivy on every build and expose a Docker health check.
Operations
Startup is idempotent - restarting a container does not reinitialise an existing
database - and SIGTERM triggers a graceful shutdown. The image is published for
linux/amd64 and linux/arm64, alongside a Helm chart for Kubernetes with
values.schema.json and GPG-signed provenance.
Licence: MIT.
No comments or reviews, maybe you want to be first?