You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Verdaccio 5.19.0(Docker部署)LDAP认证配置求助

Verdaccio 5.19.0 LDAP认证配置修复方案

一、核心问题定位

配置失败主要源于插件版本不兼容和Docker插件安装方式错误,Verdaccio 5.x需要匹配特定版本的LDAP插件,且插件安装路径需符合容器加载规则。

二、修正Dockerfile(适配插件版本与安装路径)

替换原有Dockerfile为以下内容,确保安装兼容Verdaccio 5.19.0的LDAP插件:

FROM verdaccio/verdaccio:5.19.0

WORKDIR /verdaccio

# 安装与Verdaccio 5.x兼容的LDAP插件(指定5.x版本分支)
RUN npm install verdaccio-ldap@5.0.0 --save

注:不要用-g全局安装插件,Verdaccio不会加载全局路径下的插件,必须安装在容器工作目录的node_modules中。

三、修改config.yaml配置文件

更新auth段内容,替换原有htpasswd配置为LDAP认证配置(可保留htpasswd作为 fallback,先测试单一LDAP认证):

storage: /verdaccio/storage
plugins: /verdaccio/plugins
web:
  title: Verdaccio
auth:
  # 临时注释htpasswd,优先测试LDAP
  # htpasswd:
  #   file: ./htpasswd
  ldap:
    type: ldap
    client_options:
      # 替换为你的LDAP服务器地址与端口
      url: "ldap://your-ldap-host:389"
      # LDAPS协议请用 ldaps://your-ldap-host:636
      # 绑定LDAP的管理员账号DN
      bindDN: "cn=admin,dc=your-domain,dc=com"
      # 绑定账号的密码
      bindCredentials: "your-admin-password"
      # 用户搜索的基础DN
      searchBase: "dc=your-domain,dc=com"
      # 用户匹配规则:OpenLDAP用uid,Active Directory用sAMAccountName
      searchFilter: "(uid={{username}})"
      # 返回的用户属性(可选,用于同步用户信息)
      searchAttributes:
        - uid
        - mail
        - cn
      # 若使用LDAPS,需配置TLS选项(测试阶段可关闭证书校验)
      # tlsOptions:
      #   rejectUnauthorized: false
uplinks:
  npmjs:
    url: https://registry.npmjs.org/                                
packages:
  '@*/*':
    access: $all
    publish: $authenticated
    unpublish: $authenticated
    proxy: npmjs
  '**':
    access: $all
    publish: $authenticated
    unpublish: $authenticated
    proxy: npmjs
middlewares:
  audit:
    enabled: true
logs:
  - {type: stdout, format: pretty, level: http}

四、部署与测试步骤

  1. 重新构建Docker镜像:
    docker build -t verdaccio-ldap .
    
  2. 启动容器(挂载配置与存储目录):
    docker run -d -p 4873:4873 -v ./your-config-dir:/verdaccio/conf -v ./your-storage-dir:/verdaccio/storage verdaccio-ldap
    
  3. 查看容器日志排查错误:
    docker logs <container-id>
    
    重点关注LDAP连接、绑定、搜索相关日志,比如LDAP client connected或Invalid credentials等提示。
  4. 使用npm登录测试:
    npm login --registry http://localhost:4873
    
    输入LDAP服务器中的用户名与密码,若提示Logged in as <username> on http://localhost:4873.则配置成功。

五、常见问题排查

  • 版本不兼容:确保verdaccio-ldap版本为5.x,6.x版本仅适配Verdaccio 6.x,切勿混用。
  • LDAP连接失败:检查容器网络能否访问LDAP服务器(可在容器内执行ping your-ldap-host验证),确认端口未被防火墙拦截。
  • 绑定权限不足:确保bindDN对应的账号拥有LDAP用户搜索权限。
  • 用户匹配失败:根据LDAP服务器类型调整searchFilter,Active Directory需改为(sAMAccountName={{username}})。

内容的提问来源于stack exchange,提问作者Abbey

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 08:15:52