!zghijEASpYQWYFzriI:nixos.org

Hydra

394 Members
110 Servers

Load older messages


SenderMessageTime
21 Jan 2022
@janne.hess:helsinki-systems.dedas_j
In reply to @andreas.schraegle:helsinki-systems.de
It's the same signin menu and same accounts. It just checks LDAP for auth and takes the groups from it and writes them to the database.
To be more precise: You need to be in a group called hydra-user or hydra-admin
14:23:14
@janne.hess:helsinki-systems.dedas_j(or just hydra-admin?)14:23:31
@andreas.schraegle:helsinki-systems.deajs124you do?14:23:35
@andreas.schraegle:helsinki-systems.deajs124I only remember the substring thing, where it removes the first 6 characters (hydra-) from the groups it gets from LDAP 😬14:25:03
@kenran_:matrix.orgkenran_ The manual describes those groups as hydra_admin with underscore instead of dash. Does that make a difference? 15:07:48
@kenran_:matrix.orgkenran_We can't get it to work, even though we've created the groups, but have to stop now. Do you have any tips on how to get actual feedback what went wrong?15:08:27
@janne.hess:helsinki-systems.dedas_jRedacted or Malformed Event15:08:45
@grahamc:nixos.org@grahamc:nixos.orgI would be cautious about making the assumption that it'd work like that forever without it being documented as being a thing15:12:48
@grahamc:nixos.org@grahamc:nixos.orgespecially since I think you just dropped a possibly CVE-worthy bug in chat15:14:10
@kenran_:matrix.orgkenran_I don't think I'll get it to work without any debug output. I can't even tell if my connection to LDAP even works.15:19:13
@grahamc:nixos.org@grahamc:nixos.org kenran_: https://github.com/NixOS/hydra/pull/1129 15:42:00
@grahamc:nixos.org@grahamc:nixos.organd a follow-up: https://github.com/NixOS/hydra/pull/113015:42:43
@kenran_:matrix.orgkenran_ grahamc (he/him): nice, thanks! 15:46:07
@grahamc:nixos.org@grahamc:nixos.orgyep! I'd hit something similar recently but thought I was doing it wrong15:46:20
@kenran_:matrix.orgkenran_I also opened a PR right now, found a nasty typo: https://github.com/NixOS/hydra/pull/113115:46:29
@grahamc:nixos.org@grahamc:nixos.orgoh cool15:46:40
@kenran_:matrix.orgkenran_ You wouldn't happen to know if there's a way to see some debut output for the LDAP access? I've tried setting debugServer = true;, but don't see output about this aspect. 15:47:42
@kenran_:matrix.orgkenran_ * You wouldn't happen to know if there's a way to see some debug output for the LDAP access? I've tried setting debugServer = true;, but don't see output about this aspect. 15:48:03
@grahamc:nixos.org@grahamc:nixos.orglets see ..15:48:52
@grahamc:nixos.org@grahamc:nixos.orgI've only got a few minutes left before I need to move to some paid work but let's see what I can do15:49:14
@kenran_:matrix.orgkenran_Oh, no need to do anything right now, I'd just have asked at some point next week otherwise. I can live just fine with the manually created admin users for now!15:49:59
@kenran_:matrix.orgkenran_Please prefer your paid work over this :D15:50:18
@janne.hess:helsinki-systems.dedas_jyou can pass options to Net::LDAP->new(): https://metacpan.org/pod/Catalyst::Authentication::Store::LDAP#ldap_server_options15:50:42
@janne.hess:helsinki-systems.dedas_j(from the yaml)15:50:46
@janne.hess:helsinki-systems.dedas_jone of these options can be debug15:50:52
@grahamc:nixos.org@grahamc:nixos.orgnice! a PR with that in the docs would be great15:51:02
@kenran_:matrix.orgkenran_Thanks!15:52:49
@grahamc:nixos.org@grahamc:nixos.orgif I could get a review on these doc updates that'd be great: https://github.com/NixOS/hydra/pull/1129 16:14:16
@grahamc:nixos.org@grahamc:nixos.org das_j: do you have an example of passing debug? 17:24:54
@grahamc:nixos.org@grahamc:nixos.org

ah:

                  store:
                    class: LDAP
                    ldap_server: localhost
                    ldap_server_options:
                      timeout: 30
                      debug: 2
17:29:06

Show newer messages


Back to Room ListRoom Version: 6