1.3 KiB
1.3 KiB
Obin AD User Creator
Small FastAPI app for creating Wheelytho Active Directory accounts from a web form.
Current scope:
- Collect username, password, and email.
- Create an AD user in one configured OU.
- Set the initial password over LDAPS.
- Enable the account.
- Add the user to configured default Authelia groups, currently intended as
Authelia-Friends. - Redirect to a created/instructions page with links to Authelia and the future welcome page.
Security notes:
- Use a dedicated AD creator service account, not the existing Authelia read/bind account.
- Delegate the service account only to the target OU and required default group membership.
- Password setting requires LDAPS/SSL to AD. Do not run AD password creation over plain LDAP.
- Keep real AD creator credentials and invite codes in Portainer runtime env or
/home/wheelz/.hermes/runtime-secrets/obin-ad-user-creator.env, not in Gitea or Obsidian. - The first deployment should be internal-only until the OU, group, and rollback behavior are verified.
- If exposed externally later, keep
APP_REQUIRE_INVITE_CODE=trueunless the page is protected by a separate approval/admin workflow.
Validation already available:
pytest -qdocker compose --env-file <runtime.env> -f obin-ad-user-creator-compose.yml configGET /health