Skip to content

Commit 581e1cf

Browse files
authored
add userSearchBase and groupSearchBase to security/RBAC config (#118)
LGTM
1 parent f251ca8 commit 581e1cf

16 files changed

+32
-0
lines changed

hybrid/multi-region-clusters/confluent-platform/kafka/kafka-central.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -73,10 +73,12 @@ spec:
7373
groupNameAttribute: cn
7474
groupObjectClass: group
7575
groupSearchBase: dc=test,dc=com
76+
groupSearchScope: 1
7677
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
7778
userNameAttribute: cn
7879
userObjectClass: organizationalRole
7980
userSearchBase: dc=test,dc=com
81+
userSearchScope: 1
8082
type: ldap
8183
tls:
8284
enabled: true

hybrid/multi-region-clusters/confluent-platform/kafka/kafka-east.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -75,10 +75,12 @@ spec:
7575
groupNameAttribute: cn
7676
groupObjectClass: group
7777
groupSearchBase: dc=test,dc=com
78+
groupSearchScope: 1
7879
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
7980
userNameAttribute: cn
8081
userObjectClass: organizationalRole
8182
userSearchBase: dc=test,dc=com
83+
userSearchScope: 1
8284
type: ldap
8385
tls:
8486
enabled: true

hybrid/multi-region-clusters/confluent-platform/kafka/kafka-west.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -75,10 +75,12 @@ spec:
7575
groupNameAttribute: cn
7676
groupObjectClass: group
7777
groupSearchBase: dc=test,dc=com
78+
groupSearchScope: 1
7879
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
7980
userNameAttribute: cn
8081
userObjectClass: organizationalRole
8182
userSearchBase: dc=test,dc=com
83+
userSearchScope: 1
8284
type: ldap
8385
tls:
8486
enabled: true

security/configure-with-vault/rbac/confluent-platform-withrbac-vault.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -83,10 +83,12 @@ spec:
8383
groupMemberAttribute: member
8484
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8585
groupSearchBase: dc=test,dc=com
86+
groupSearchScope: 1
8687
userNameAttribute: cn
8788
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8889
userObjectClass: organizationalRole
8990
userSearchBase: dc=test,dc=com
91+
userSearchScope: 1
9092
podTemplate:
9193
serviceAccountName: confluent-sa
9294
annotations:

security/configure-with-vault/rbac/zk_kafka.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -83,10 +83,12 @@ spec:
8383
groupMemberAttribute: member
8484
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8585
groupSearchBase: dc=test,dc=com
86+
groupSearchScope: 1
8687
userNameAttribute: cn
8788
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8889
userObjectClass: organizationalRole
8990
userSearchBase: dc=test,dc=com
91+
userSearchScope: 1
9092
podTemplate:
9193
serviceAccountName: confluent-sa
9294
annotations:

security/internal_external-tls_mtls_confluent-rbac/confluent-platform-mtls-rbac.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -80,10 +80,12 @@ spec:
8080
groupMemberAttribute: member
8181
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8282
groupSearchBase: dc=test,dc=com
83+
groupSearchScope: 1
8384
userNameAttribute: cn
8485
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8586
userObjectClass: organizationalRole
8687
userSearchBase: dc=test,dc=com
88+
userSearchScope: 1
8789
dependencies:
8890
kafkaRest:
8991
authentication:

security/production-secure-deploy-auto-gen-certs/confluent-platform-production-autogeneratedcerts.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -80,10 +80,12 @@ spec:
8080
groupMemberAttribute: member
8181
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8282
groupSearchBase: dc=test,dc=com
83+
groupSearchScope: 1
8384
userNameAttribute: cn
8485
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8586
userObjectClass: organizationalRole
8687
userSearchBase: dc=test,dc=com
88+
userSearchScope: 1
8789
dependencies:
8890
kafkaRest:
8991
authentication:

security/production-secure-deploy-auto-gen-certs/confluent-platform-production-mtls.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -82,10 +82,12 @@ spec:
8282
groupMemberAttribute: member
8383
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8484
groupSearchBase: dc=test,dc=com
85+
groupSearchScope: 1
8586
userNameAttribute: cn
8687
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8788
userObjectClass: organizationalRole
8889
userSearchBase: dc=test,dc=com
90+
userSearchScope: 1
8991
dependencies:
9092
kafkaRest:
9193
authentication:

security/production-secure-deploy-auto-gen-certs/confluent-platform-production.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -80,10 +80,12 @@ spec:
8080
groupMemberAttribute: member
8181
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8282
groupSearchBase: dc=test,dc=com
83+
groupSearchScope: 1
8384
userNameAttribute: cn
8485
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8586
userObjectClass: organizationalRole
8687
userSearchBase: dc=test,dc=com
88+
userSearchScope: 1
8789
dependencies:
8890
kafkaRest:
8991
authentication:

security/production-secure-deploy/confluent-platform-production-autogeneratedcerts.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -80,10 +80,12 @@ spec:
8080
groupMemberAttribute: member
8181
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8282
groupSearchBase: dc=test,dc=com
83+
groupSearchScope: 1
8384
userNameAttribute: cn
8485
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8586
userObjectClass: organizationalRole
8687
userSearchBase: dc=test,dc=com
88+
userSearchScope: 1
8789
dependencies:
8890
kafkaRest:
8991
authentication:

security/production-secure-deploy/confluent-platform-production-mtls.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -82,10 +82,12 @@ spec:
8282
groupMemberAttribute: member
8383
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8484
groupSearchBase: dc=test,dc=com
85+
groupSearchScope: 1
8586
userNameAttribute: cn
8687
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8788
userObjectClass: organizationalRole
8889
userSearchBase: dc=test,dc=com
90+
userSearchScope: 1
8991
dependencies:
9092
kafkaRest:
9193
authentication:

security/production-secure-deploy/confluent-platform-production.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -80,10 +80,12 @@ spec:
8080
groupMemberAttribute: member
8181
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8282
groupSearchBase: dc=test,dc=com
83+
groupSearchScope: 1
8384
userNameAttribute: cn
8485
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8586
userObjectClass: organizationalRole
8687
userSearchBase: dc=test,dc=com
88+
userSearchScope: 1
8789
dependencies:
8890
kafkaRest:
8991
authentication:

security/userprovided-tls_mtls-sasl_confluent-rbac/confluent-platform-mtls-sasl-rbac.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -77,10 +77,12 @@ spec:
7777
groupMemberAttribute: member
7878
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
7979
groupSearchBase: dc=test,dc=com
80+
groupSearchScope: 1
8081
userNameAttribute: cn
8182
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8283
userObjectClass: organizationalRole
8384
userSearchBase: dc=test,dc=com
85+
userSearchScope: 1
8486
dependencies:
8587
kafkaRest:
8688
authentication:

security/userprovided-tls_mtls_confluent-rbac/confluent-platform-mtls-rbac-hostbased-ingress.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -82,10 +82,12 @@ spec:
8282
groupMemberAttribute: member
8383
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8484
groupSearchBase: dc=test,dc=com
85+
groupSearchScope: 1
8586
userNameAttribute: cn
8687
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8788
userObjectClass: organizationalRole
8889
userSearchBase: dc=test,dc=com
90+
userSearchScope: 1
8991
dependencies:
9092
kafkaRest:
9193
authentication:

security/userprovided-tls_mtls_confluent-rbac/confluent-platform-mtls-rbac.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -82,10 +82,12 @@ spec:
8282
groupMemberAttribute: member
8383
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
8484
groupSearchBase: dc=test,dc=com
85+
groupSearchScope: 1
8586
userNameAttribute: cn
8687
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
8788
userObjectClass: organizationalRole
8889
userSearchBase: dc=test,dc=com
90+
userSearchScope: 1
8991
dependencies:
9092
kafkaRest:
9193
authentication:

security/userprovided-tls_mtls_confluent-rbac/kafka.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -63,10 +63,12 @@ spec:
6363
groupMemberAttribute: member
6464
groupMemberAttributePattern: CN=(.*),DC=test,DC=com
6565
groupSearchBase: dc=test,dc=com
66+
groupSearchScope: 1
6667
userNameAttribute: cn
6768
userMemberOfAttributePattern: CN=(.*),DC=test,DC=com
6869
userObjectClass: organizationalRole
6970
userSearchBase: dc=test,dc=com
71+
userSearchScope: 1
7072
dependencies:
7173
kafkaRest:
7274
authentication:

0 commit comments

Comments
 (0)