Skip to content

Allow the configuration of multiple LDAP servers #550

Description

@siegfriedweber

Only one LDAP server can be set in a SecretClass:

---
apiVersion: secrets.stackable.tech/v1alpha1
kind: SecretClass
spec:
  backend:
    kerberosKeytab:
      admin:
        activeDirectory:
          ldapServer: sble-addc.sble.test

It would probably be a good idea if multiple LDAP servers can be specified to support high availability.

Activity

  1. maxgruber19 commented on Sep 16, 2025

    @maxgruber19

    hi @siegfriedweber, do you have any updates on that stream? specification of multiple servers would be a good start but most ldap setups will have one "loadbalancer" that routes to the domain controllers. when using that host we get GSSAPI errors with server not found in kerberos database

  2. lfrancke commented on Sep 16, 2025

    @lfrancke
    Member

    I'm afraid we don't :(
    I have seen that error message plenty of times but never with LDAP servers.

    Can you share more details?

  3. maxgruber19 commented on Sep 25, 2025

    @maxgruber19

    tbh I'm struggling with giving more details because I'm not that deep into kerberos and msad but i'll try my best 😄

    for HA purposes msad setups can have multiple domain controllers which are behind a dns entry that serves the requests to those multiple domaincontrollers below. it seems like secret-operator trys to use that dns as the kerberos server but it's just a dns-entry. that leads to the server not found in kerberos database probably.

    A workaround where you might not have to deal with special dns entries might be an array of server names. customer would have to configure them manually and keep track of changes but at least that would enable some kind of fallbackoptions

    I think that would be a major stability enhancement all over the platform in general

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions