Centos7配置Grafana對接OpenLDAP


在grafana的主配置文件grafana.ini中開啟LDAP認證

注意:grafana有兩個地方需要指定(/etc/grafana/grafana.ini和/usr/share/grafana/conf/defaults.ini)

[auth.ldap]
enabled = true
config_file = /etc/grafana/ldap.toml
allow_sign_up = true
  • config_file指定grafana的ldap配置文件ldap.toml的具體位置

 ldap.toml配置文件的內容如下:

[[servers]]
host = "10.2.3.147"
port = 389
use_ssl = true
start_tls = true
ssl_skip_verify = true

bind_dn = "cn=Manager,dc=baidu,dc=com"
bind_password = '123qweasdzxc'
search_filter = "(cn=%s)"
search_base_dns = ["ou=People,dc=baidu,dc=com"]        #這個是LDAP里存放所有用戶的
group_search_filter = "(&(objectClass=posixGroup)(memberUid=%s))"
group_search_base_dns = ["ou=Group,dc=baidu,dc=com"]   #這個是LDAP的組

[servers.attributes]
name = "displayName"
surname = "sn"
username = "cn"
member_of = "cn"
email =  "mail"

[[servers.group_mappings]]   #這個就表示LDAP里為yunwei組,映射到grafana里的權限是Viewer權限
group_dn = "yunwei" 
org_role = "Viewer"
[[servers.group_mappings]]   #這個就表示LDAP里的dev組,映射到grafana里的權限是Admin權限
group_dn = "dev"
org_role = "Admin"

 

 重啟grafana

systemctl restart  grafana-server

 

參考文檔

https://blog.frognew.com/2017/07/config-grafana-with-ldap.html 

 


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM