Files
Docker-Compose-Stacks/obin-ad-user-creator/README.md
T

1.3 KiB

Obin AD User Creator

Small FastAPI app for creating Wheelytho Active Directory accounts from a web form.

Current scope:

  • Collect username, password, and email.
  • Create an AD user in one configured OU.
  • Set the initial password over LDAPS.
  • Enable the account.
  • Add the user to configured default Authelia groups, currently intended as Authelia-Friends.
  • Redirect to a created/instructions page with links to Authelia and the future welcome page.

Security notes:

  • Use a dedicated AD creator service account, not the existing Authelia read/bind account.
  • Delegate the service account only to the target OU and required default group membership.
  • Password setting requires LDAPS/SSL to AD. Do not run AD password creation over plain LDAP.
  • Keep real AD creator credentials and invite codes in Portainer runtime env or /home/wheelz/.hermes/runtime-secrets/obin-ad-user-creator.env, not in Gitea or Obsidian.
  • The first deployment should be internal-only until the OU, group, and rollback behavior are verified.
  • If exposed externally later, keep APP_REQUIRE_INVITE_CODE=true unless the page is protected by a separate approval/admin workflow.

Validation already available:

  • pytest -q
  • docker compose --env-file <runtime.env> -f obin-ad-user-creator-compose.yml config
  • GET /health