Active Directory: Support load-balanced LDAP servers
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 20/100
- Issue type
- Bug
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- kubernetes
- Domain
- authentication
Research direction
No files, tests, or entry points are named. Start by tracing krb5.conf generation and the user-info-fetcher LDAP/Kerberos connection behavior, then reproduce DNS load balancing with the affected Stackable 25.3 setup. Done means load-balanced LDAP authentication works without reintroducing Kubernetes PTR-related failures.
Written by the indexing model from the issue text.
Description
Affected Stackable version
25.3
Affected OpenPolicyAgent version
irrelevant, user-info-fetcher
Current and expected behavior
Currently, we don't support connecting to LDAP servers that are behind DNS-based load balancing, instead just returning a kind-of-useless "not found in Kerberos database" error.
This is because we disable krb5's DNS canonicalization. Normally, it does a "canonicalization dance" for each request. Let's say we try to connect to ldap-lb. That would then be resolved to 1.2.3.4, which is what we do a TCP connection to. Then it would do a reverse DNS (PTR) query for the IP address (1.2.3.4), which returns the hostname for that specific replica (ldap-1). Then it'd use that hostname to build the Kerberos principal that we validate against (ldap/ldap-1@CORP.COM).
We disable DNS canonicalization, because it causes other problems in K8s (K8s pods have inconsistent PTR results, which would cause other similar issues depending on the order returned...). That makes krb5 use the specified hostname for the principal instead (ldap/ldap-lb@CORP.COM). The LDAP server doesn't have that principal, so we fail to authenticate. (The actual "Kerberos database" error is because the Kerberos KDC doesn't have any registered principal with that name.)
Possible solution
I honestly don't know.
We can't just blanket-enable canonicalization, because of the aforementioned K8s issues. But we also need to handle this in some way. Maybe we'll need some flag on which krb5.conf to generate, but that feels like a slippery road to start walking.
Additional context
No response
Environment
No response
Would you like to work on fixing this bug?
None
- Dominant language
- Rust
- Stars
- 21
- Forks
- 5
- Avg merge
- 12h 44m
- Merged PRs (30d)
- 11
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from stackabletech/opa-operator
-
type/bug
Difficulty 4/5 3-5 days Newbie friendliness 52/100
stackabletech/opa-operator#823 ·
-
Difficulty 5/5 Over a week Newbie friendliness 30/100
stackabletech/opa-operator#766 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
stackabletech/opa-operator#733 ·
-
Difficulty 2/5 Half a day Newbie friendliness 50/100
stackabletech/opa-operator#724 ·
-
type/bug
Difficulty 3/5 1-2 days Newbie friendliness 35/100
stackabletech/opa-operator#690 ·
All issues in stackabletech/opa-operator
Similar issues
-
todo:perf
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
ACP agents get no MCP servers when the thread is created before the project's first worktree loads Openstate:needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
zed-industries/zed#64611 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
ontola/atomic-server#1625 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
objectionary/phie#154 ·