skip to Main Content

My Rundeck detail Rundeck version: 4.10.0
install type: DEB
OS Name/version: Debian 11
DB Type/version: h2

A LDAP user without a Role membership can properly login but can not see any Projects – so far fine.
How can i block such a user to Login at all?
We have one "userBaseDn" Group (userBaseDn="cn=Users,ou=PROD,dc=company,dc=com") in which all users are stored. But of course, only users in following roleBaseDn (roleBaseDn="cn=Rundeck_Admins,cn=Applications,ou=PROD,dc=company,dc=com") Group should have access to Rundeck Web UI.

I expect, only users in Group "Rundeck_Admins" can Login to Rundeck at all

2

Answers


  1. Chosen as BEST ANSWER

    Currently, means there will be a change on this behavior?

    As far a i understand LDAP right, for a specific LADP branch in which a place users, i have to manage users twice. 1st, in user directory and 2nd in the specific Rundeck Group. For me quite unhandy...


  2. Currently, you can only restrict that using an ACL policy (the user can log in but cannot view/edit/run any project/job, as you say), please take a look at this.

    Alternatively, you can create a specific branch in your LDAP server only for Rundeck users.

    Login or Signup to reply.
Please signup or login to give your own answer.
Back To Top
Search