Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 3943ed02c5 | |||
| 7f43eee36e | |||
| 19ea7e012a | |||
| 94b357e915 | |||
| f5d8cdd09d |
@@ -60,6 +60,8 @@ It is **both** an OIDC client of the SSO (for login) **and** a direct LDAP
|
|||||||
client (for user lookups). Legacy apps can still bind to LDAPS on the SSO
|
client (for user lookups). Legacy apps can still bind to LDAPS on the SSO
|
||||||
directly.
|
directly.
|
||||||
|
|
||||||
|
- **Multi-Site Support (Geo-Location Scaling):** Built-in support for N-Way Multi-Master LDAP replication, allowing you to deploy the stack across multiple physical locations for HA and low latency.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Before you begin
|
## Before you begin
|
||||||
|
|||||||
@@ -56,6 +56,8 @@ services:
|
|||||||
# reads that are not part of its conf tree.
|
# reads that are not part of its conf tree.
|
||||||
- NODE_ENV=production
|
- NODE_ENV=production
|
||||||
- NODE_PORT=3001
|
- NODE_PORT=3001
|
||||||
|
- LDAP_SERVER_ID=${LDAP_SERVER_ID:-}
|
||||||
|
- LDAP_REPLICATION_HOSTS=${LDAP_REPLICATION_HOSTS:-}
|
||||||
volumes:
|
volumes:
|
||||||
# Operator-edited SSO secrets (sso-secrets.js). Read-WRITE so the bootstrap
|
# Operator-edited SSO secrets (sso-secrets.js). Read-WRITE so the bootstrap
|
||||||
# can write the generated OAuth client creds into proxy-secrets.js. The
|
# can write the generated OAuth client creds into proxy-secrets.js. The
|
||||||
|
|||||||
@@ -44,6 +44,7 @@ snapshots state before every rebuild.
|
|||||||
- **LDAPS** for legacy apps that bind directly.
|
- **LDAPS** for legacy apps that bind directly.
|
||||||
- **Self-service API tokens** in both apps' UIs, for scripting/CI without a
|
- **Self-service API tokens** in both apps' UIs, for scripting/CI without a
|
||||||
browser session.
|
browser session.
|
||||||
|
- **Multi-Site Support (Geo-Location Scaling)** — built-in support for N-Way Multi-Master LDAP replication across physical locations.
|
||||||
|
|
||||||
## Get it
|
## Get it
|
||||||
|
|
||||||
|
|||||||
@@ -59,3 +59,15 @@ CFG_DOMAIN=example.com
|
|||||||
# comment for how to actually change it after the account exists). Do NOT set
|
# comment for how to actually change it after the account exists). Do NOT set
|
||||||
# CFG_LDAP_ADMIN_PASS / CFG_JWT_SECRET / CFG_ADMIN_PASS / CFG_SVC_PASS /
|
# CFG_LDAP_ADMIN_PASS / CFG_JWT_SECRET / CFG_ADMIN_PASS / CFG_SVC_PASS /
|
||||||
# CFG_PROXY_ADMIN_PASS here.
|
# CFG_PROXY_ADMIN_PASS here.
|
||||||
|
|
||||||
|
# ── Geo-Location Scaling (N-Way Multi-Master LDAP) ───────────────────────────
|
||||||
|
# If deploying this stack across multiple physical sites to provide local HA
|
||||||
|
# for directory services, you can enable N-Way Multi-Master OpenLDAP replication.
|
||||||
|
# This requires assigning a unique ID to each site and listing the LDAPS URLs
|
||||||
|
# of all OTHER sites in the cluster.
|
||||||
|
#
|
||||||
|
# Each site MUST have a unique LDAP_SERVER_ID (e.g. 1, 2, 3).
|
||||||
|
# LDAP_REPLICATION_HOSTS is a space-separated list of the other sites' LDAP URLs.
|
||||||
|
# Example for Site 1:
|
||||||
|
#LDAP_SERVER_ID=1
|
||||||
|
#LDAP_REPLICATION_HOSTS="ldaps://sso.site2.com:636 ldaps://sso.site3.com:636"
|
||||||
+1
-1
Submodule sso-manager-node updated: b4fa824609...6ce36b4a14
Reference in New Issue
Block a user