chore: improvements to keycloak local development (#26518)
* update keycloak docker image * update realm file with a compatible realm * import realm on start-docker command Since bitnami's image does not support importing directly, the import of the test realm is done in the make file start-docker action * Use official image from quay * updated realm keycloak config * final note about nickname attrib for saml * add admin user * update realm * Updated from master * Updated docs * local typo * use jq for ldap and saml * updated readme
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
db45c0132e
Коммит
4e32da62fa
@@ -1,12 +1,39 @@
|
||||
Overwrite your SamlSettings section in your config.json file by running `make config-saml` and restarting your server. You will need to set the following `SamlSettings` in order to complete the setup:
|
||||
- Enable: true
|
||||
- FirstNameAttribute: "givenName"
|
||||
- LastNameAttribute: "surname"
|
||||
# Keycloak development environment
|
||||
|
||||
Admin Login:
|
||||
- admin/admin
|
||||
## Setting up
|
||||
|
||||
Users:
|
||||
- homer/password
|
||||
- marge/password
|
||||
- lisa/password
|
||||
### OpenID
|
||||
|
||||
Overwrite your `OpenIdSettings` section in your config.json file by running `make config-openid` and restarting your server.
|
||||
|
||||
- [Official OpenID with Keycloak documentation](https://docs.mattermost.com/onboard/sso-openidconnect.html)
|
||||
|
||||
### SAML
|
||||
|
||||
Overwrite your `SamlSettings` section in your config.json file by running `make config-saml` and restarting your server.
|
||||
|
||||
- [Official SAML with Keycloak documentation](https://docs.mattermost.com/onboard/sso-saml-keycloak.html)
|
||||
|
||||
### LDAP
|
||||
|
||||
Overwrite your `LdapSettings` section in your config.json file by running `make config-ldap` and restarting your server.
|
||||
|
||||
- [Official LDAP with Keycloak documentation](https://docs.mattermost.com/onboard/ad-ldap.html)
|
||||
|
||||
## Credentials to log in
|
||||
|
||||
- **Admin account**, used to log in to the Keycloak Admin UI:
|
||||
- `admin`/`admin`
|
||||
|
||||
- **User accounts**, used to log in to Mattermost:
|
||||
- `homer`/`password`
|
||||
- `marge`/`password`
|
||||
- `lisa`/`password`
|
||||
|
||||
## Updating the `realm-export.json`
|
||||
|
||||
The `realm-export.json` file is automatically imported by the keycloak development container. If you make any modifications to this file or to the base configuration, export it by running a terminal in the container and running:
|
||||
|
||||
```bash
|
||||
/opt/keycloak/bin/kc.sh export --realm mattermost --users realm_file --file /opt/keycloak/data/import/realm-export.json
|
||||
```
|
||||
|
||||
39
server/build/docker/keycloak/ldap.mmsettings.json
Обычный файл
39
server/build/docker/keycloak/ldap.mmsettings.json
Обычный файл
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"LdapSettings": {
|
||||
"Enable": true,
|
||||
"EnableSync": false,
|
||||
"LdapServer": "localhost",
|
||||
"LdapPort": 389,
|
||||
"ConnectionSecurity": "",
|
||||
"BaseDN": "dc=mm,dc=test,dc=com",
|
||||
"BindUsername": "cn=admin,dc=mm,dc=test,dc=com",
|
||||
"BindPassword": "mostest",
|
||||
"UserFilter": "",
|
||||
"GroupFilter": "",
|
||||
"GuestFilter": "",
|
||||
"EnableAdminFilter": false,
|
||||
"AdminFilter": "",
|
||||
"GroupDisplayNameAttribute": "cn",
|
||||
"GroupIdAttribute": "entryUUID",
|
||||
"FirstNameAttribute": "cn",
|
||||
"LastNameAttribute": "sn",
|
||||
"EmailAttribute": "mail",
|
||||
"UsernameAttribute": "uid",
|
||||
"NicknameAttribute": "cn",
|
||||
"IdAttribute": "uid",
|
||||
"PositionAttribute": "title",
|
||||
"LoginIdAttribute": "uid",
|
||||
"PictureAttribute": "",
|
||||
"SyncIntervalMinutes": 60,
|
||||
"SkipCertificateVerification": false,
|
||||
"PublicCertificateFile": "",
|
||||
"PrivateKeyFile": "",
|
||||
"QueryTimeout": 60,
|
||||
"MaxPageSize": 0,
|
||||
"LoginFieldName": "",
|
||||
"LoginButtonColor": "#0000",
|
||||
"LoginButtonBorderColor": "#2389D7",
|
||||
"LoginButtonTextColor": "#2389D7",
|
||||
"Trace": false
|
||||
}
|
||||
}
|
||||
14
server/build/docker/keycloak/openid.mmsettings.json
Обычный файл
14
server/build/docker/keycloak/openid.mmsettings.json
Обычный файл
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"OpenIdSettings": {
|
||||
"Enable": true,
|
||||
"Secret": "9Y7dykcoA9luTC77XtXxOu9UbNx3rhj6",
|
||||
"Id": "mattermost-openid",
|
||||
"Scope": "profile openid email",
|
||||
"AuthEndpoint": "",
|
||||
"TokenEndpoint": "",
|
||||
"UserAPIEndpoint": "",
|
||||
"DiscoveryEndpoint": "http://localhost:8484/realms/mattermost/.well-known/openid-configuration",
|
||||
"ButtonText": "Login using OpenID",
|
||||
"ButtonColor": "#ffaa4c"
|
||||
}
|
||||
}
|
||||
Разница между файлами не показана из-за своего большого размера
Загрузить разницу
38
server/build/docker/keycloak/saml.mmsettings.json
Обычный файл
38
server/build/docker/keycloak/saml.mmsettings.json
Обычный файл
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"SamlSettings": {
|
||||
"Enable": true,
|
||||
"EnableSyncWithLdap": false,
|
||||
"EnableSyncWithLdapIncludeAuth": false,
|
||||
"IgnoreGuestsLdapSync": false,
|
||||
"Verify": false,
|
||||
"Encrypt": false,
|
||||
"SignRequest": false,
|
||||
"IdpURL": "http://localhost:8484/realms/mattermost/protocol/saml",
|
||||
"IdpDescriptorURL": "http://localhost:8484/realms/mattermost",
|
||||
"IdpMetadataURL": "http://localhost:8484/realms/mattermost/protocol/saml/descriptor",
|
||||
"ServiceProviderIdentifier": "mattermost",
|
||||
"AssertionConsumerServiceURL": "http://localhost:8065/login/sso/saml",
|
||||
"SignatureAlgorithm": "RSAwithSHA1",
|
||||
"CanonicalAlgorithm": "Canonical1.0",
|
||||
"ScopingIDPProviderId": "",
|
||||
"ScopingIDPName": "",
|
||||
"IdpCertificateFile": "saml-idp.crt",
|
||||
"PublicCertificateFile": "",
|
||||
"PrivateKeyFile": "",
|
||||
"IdAttribute": "uid",
|
||||
"GuestAttribute": "",
|
||||
"EnableAdminAttribute": false,
|
||||
"AdminAttribute": "",
|
||||
"FirstNameAttribute": "givenName",
|
||||
"LastNameAttribute": "surname",
|
||||
"EmailAttribute": "mail",
|
||||
"UsernameAttribute": "uid",
|
||||
"NicknameAttribute": "cn",
|
||||
"LocaleAttribute": "",
|
||||
"PositionAttribute": "title",
|
||||
"LoginButtonText": "SAML",
|
||||
"LoginButtonColor": "#34a28b",
|
||||
"LoginButtonBorderColor": "#2389D7",
|
||||
"LoginButtonTextColor": "#ffffff"
|
||||
}
|
||||
}
|
||||
Ссылка в новой задаче
Block a user