add manager logic

This commit is contained in:
2026-01-24 14:10:58 -07:00
parent 0a4373bb58
commit ec1342f6b3
4 changed files with 26 additions and 0 deletions

View File

@@ -6,3 +6,6 @@ ldap_bind_dn: cn=binduser,{{ ldap_basedn }}
ldap_cert_path: /etc/openldap/certs/ldap.crt
ldap_key_path: /etc/openldap/certs/ldap.key
ldap_directory_manager_dn: "cn=Manager,{{ ldap_basedn }}"
ldap_directory_manager_pw_hash: "{{ ldap_manager_pw_hash }}"

View File

@@ -0,0 +1,10 @@
- name: Find main LDAP database DN
ansible.builtin.command: >
ldapsearch -Y EXTERNAL -H ldapi:/// \
-b cn=config '(olcSuffix={{ ldap_basedn }})' dn
register: ldap_db_dn
changed_when: false
- name: Set fact for main database DN
ansible.builtin.set_fact:
ldap_main_db_dn: "{{ ldap_db_dn.stdout_lines | select('match','^dn:') | first | regex_replace('^dn: ','') }}"

View File

@@ -2,5 +2,7 @@
- import_tasks: disable_ldaps.yaml
#- import_tasks: schemas.yaml
- import_tasks: config.yaml
- import_tasks: find_database.yml
- import_tasks: manager.yml
- import_tasks: tls.yaml
- import_tasks: acls.yaml

View File

@@ -0,0 +1,11 @@
- name: Set directory Manager DN and password
community.general.ldap_attrs:
dn: "{{ ldap_main_db_dn }}"
attributes:
olcRootDN: "{{ ldap_directory_manager_dn }}"
olcRootPW: "{{ ldap_directory_manager_pw_hash }}"
state: exact
args:
server_uri: ldapi:///
bind_dn: cn=admin,cn=config
sasl_class: external