Verdaccio 5.19.0(Docker部署)LDAP认证配置求助
Verdaccio 5.19.0 LDAP认证配置修复方案
一、核心问题定位
配置失败主要源于插件版本不兼容和Docker插件安装方式错误,Verdaccio 5.x需要匹配特定版本的LDAP插件,且插件安装路径需符合容器加载规则。
二、修正Dockerfile(适配插件版本与安装路径)
替换原有Dockerfile为以下内容,确保安装兼容Verdaccio 5.19.0的LDAP插件:
FROM verdaccio/verdaccio:5.19.0 WORKDIR /verdaccio # 安装与Verdaccio 5.x兼容的LDAP插件(指定5.x版本分支) RUN npm install verdaccio-ldap@5.0.0 --save
注:不要用
-g全局安装插件,Verdaccio不会加载全局路径下的插件,必须安装在容器工作目录的node_modules中。
三、修改config.yaml配置文件
更新auth段内容,替换原有htpasswd配置为LDAP认证配置(可保留htpasswd作为 fallback,先测试单一LDAP认证):
storage: /verdaccio/storage plugins: /verdaccio/plugins web: title: Verdaccio auth: # 临时注释htpasswd,优先测试LDAP # htpasswd: # file: ./htpasswd ldap: type: ldap client_options: # 替换为你的LDAP服务器地址与端口 url: "ldap://your-ldap-host:389" # LDAPS协议请用 ldaps://your-ldap-host:636 # 绑定LDAP的管理员账号DN bindDN: "cn=admin,dc=your-domain,dc=com" # 绑定账号的密码 bindCredentials: "your-admin-password" # 用户搜索的基础DN searchBase: "dc=your-domain,dc=com" # 用户匹配规则:OpenLDAP用uid,Active Directory用sAMAccountName searchFilter: "(uid={{username}})" # 返回的用户属性(可选,用于同步用户信息) searchAttributes: - uid - mail - cn # 若使用LDAPS,需配置TLS选项(测试阶段可关闭证书校验) # tlsOptions: # rejectUnauthorized: false uplinks: npmjs: url: https://registry.npmjs.org/ packages: '@*/*': access: $all publish: $authenticated unpublish: $authenticated proxy: npmjs '**': access: $all publish: $authenticated unpublish: $authenticated proxy: npmjs middlewares: audit: enabled: true logs: - {type: stdout, format: pretty, level: http}
四、部署与测试步骤
- 重新构建Docker镜像:
docker build -t verdaccio-ldap . - 启动容器(挂载配置与存储目录):
docker run -d -p 4873:4873 -v ./your-config-dir:/verdaccio/conf -v ./your-storage-dir:/verdaccio/storage verdaccio-ldap - 查看容器日志排查错误:
重点关注LDAP连接、绑定、搜索相关日志,比如docker logs <container-id>LDAP client connected或Invalid credentials等提示。 - 使用npm登录测试:
输入LDAP服务器中的用户名与密码,若提示npm login --registry http://localhost:4873Logged in as <username> on http://localhost:4873.则配置成功。
五、常见问题排查
- 版本不兼容:确保
verdaccio-ldap版本为5.x,6.x版本仅适配Verdaccio 6.x,切勿混用。 - LDAP连接失败:检查容器网络能否访问LDAP服务器(可在容器内执行
ping your-ldap-host验证),确认端口未被防火墙拦截。 - 绑定权限不足:确保
bindDN对应的账号拥有LDAP用户搜索权限。 - 用户匹配失败:根据LDAP服务器类型调整
searchFilter,Active Directory需改为(sAMAccountName={{username}})。
内容的提问来源于stack exchange,提问作者Abbey
相关产品推荐
相关产品推荐

