Skip to content
This repository has been archived by the owner on Feb 6, 2024. It is now read-only.

Commit

Permalink
Add ability to configure external ldap user directory
Browse files Browse the repository at this point in the history
Change-Id: I95f2d5c1cc2b816cd40ecdefd0ceed49b8d4b139
  • Loading branch information
AntonFriberg committed Jan 11, 2022
1 parent dd1421a commit 7f8fd4f
Show file tree
Hide file tree
Showing 2 changed files with 37 additions and 0 deletions.
15 changes: 15 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -192,6 +192,21 @@ clickhouse_ldap_servers:
tls_require_cert: "demand"
```
F: You can manage [LDAP External User Directory](https://clickhouse.com/docs/en/operations/external-authenticators/ldap/#ldap-external-user-directory)
```yaml
# Helpful guide on https://altinity.com/blog/integrating-clickhouse-with-ldap-part-two
clickhouse_ldap_user_directories:
- server: "example_ldap_server"
roles:
- "ldap_user"
role_mapping:
base_dn: "ou=groups,dc=example,dc=com"
attribute: "CN"
scope: "subtree"
search_filter: "(&(objectClass=group)(member={bind_dn}))"
prefix: "clickhouse_
```
F: You can manage Merge Tree config. For the list of available parameters, see [MergeTreeSettings.h](https://github.com/yandex/ClickHouse/blob/master/dbms/src/Storages/MergeTree/MergeTreeSettings.h).
```yaml
clickhouse_merge_tree_config:
Expand Down
22 changes: 22 additions & 0 deletions templates/config.j2
Original file line number Diff line number Diff line change
Expand Up @@ -475,4 +475,26 @@
</ldap_servers>
{% endif %}

{% if clickhouse_ldap_user_directories is defined %}
<user_directories>
{% for ldap_user_directory in clickhouse_ldap_user_directories %}
<ldap>
<server>{{ ldap_user_directory['server'] }}</server>
<roles>
{% for role in ldap_user_directory['roles'] %}
<{{ role }}/>
{% endfor %}
</roles>
{% if ldap_user_directory['role_mapping'] is defined %}
<role_mapping>
{% for key, value in ldap_user_directory['role_mapping'].items() %}
<{{ key }}>{{ value }}</{{ key }}>
{% endfor %}
</role_mapping>
{% endif %}
</ldap>
{% endfor %}
</user_directories>
{% endif %}

</yandex>

0 comments on commit 7f8fd4f

Please sign in to comment.