Files
ldap-auth-service/Dockerfile.example
2026-08-21 11:56:14 +05:00

30 lines
1.0 KiB
Docker

# Example Dockerfile for running the service in a Linux container.
# Password setting works via Kerberos (kinit + ldapmodify -Y GSSAPI):
# - openldap-clients provides ldapmodify
# - cyrus-sasl-gssapiv2 provides the SASL GSSAPI plugin used by ldapmodify
# - krb5 provides kinit / kdestroy (there is no krb5-client
# package in Alpine v3.24 — the tools are in krb5)
#
# /etc/krb5.conf is regenerated from .env at every start by
# scripts/generate-krb5-conf.js (the static file below is only a fallback).
# Make sure the container environment does NOT contain
# LDAP_USE_POWERSHELL_PASSWORD=true (remove it from the .env you mount).
FROM node:22-alpine
WORKDIR /app
RUN apk add --no-cache git build-base python3 \
openldap-clients cyrus-sasl-gssapiv2 krb5
COPY config/krb5.conf /etc/krb5.conf
COPY package*.json ./
RUN npm ci --omit=dev
COPY . .
EXPOSE 8080
# Regenerate /etc/krb5.conf from .env at every start, then launch the server
CMD ["sh", "-c", "node scripts/generate-krb5-conf.js && node server.js"]