-
Notifications
You must be signed in to change notification settings - Fork 71
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Query #94
Comments
get your point and there should be a tool add/del/edit entries. What are the features you want to see in such tool? That being said, this issue is opened against the wrong repo - this is the repo fro the ansible playbook installer - may I ask you to open an issue here instead. Thank you for the above reply anazmy. To be frank, I thought FreeIPA as a GUI tool for managing the users and hosts but later on, I found its different and will not suit our environment. FreeIPA client is not directly supported on Debian distributions whereas all our servers are based on Debian. |
I get your point about FreeIPA, it's a a whole ecosystem that you need to deploy. |
Yup, its a whole separate system and not easy to use it on the already implemented setup. |
is there any possibility of having CSV import or any other method to add and remove entries ? |
Yes, that's what I've in mind. I'm currently on travel and will try working on this when am back in around a week. |
Hello Anazmy |
Anazmy, |
Apologies for the delay. |
Oops..
I was expecting this.
No issues. Thank you
…On Tue, Oct 29, 2019, 9:46 AM anazmy ***@***.***> wrote:
Apologies for the delay.
Unfortunately am completely occupied with no free time to continue working
on this. I will return to it in a future time.
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
<#94?email_source=notifications&email_token=ALKF2HOXKMY4225MNVZBLETQQ62KXA5CNFSM4IJDNRH2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOECPFWPA#issuecomment-547248956>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ALKF2HKRK72VO3VWMSKCC5TQQ62KXANCNFSM4IJDNRHQ>
.
|
Thanks for understanding. Meanwhile if you have got a PR to add this feature I would test it and get it merged |
Hi, |
Hi @EoleDev do you have the mariadb code some available somewhere to look at? |
Not currently because it is using some proprietary information. |
Hi @anazmy, |
@EoleDev you have tried with Mariadb IDP in your setup and got the server list connecting to gateway server? I have pulled the MariaDB branch from your repo and tried setting up the MariaDB idp but it is not working for me. The error message says as "ERROR - MARIADB: Could not connect to database, error :" though I am able to connect to the database via cli. I am not sure whether the branch you have done is ready to use. I was looking for some change to this IDP, so I tried it once I saw this. Sorry if I tried too early. |
Hi @leosimony, |
Hi @leosimony |
Hey thx @EoleDev for the awesome work! BTW, how big is the environment that you tested that on? |
Hi @anazmy, I didn't test this connector in a production environment. |
@anazmy |
Yes, I got it working @EoleDev. To both, |
Considering the phase defined by @anazmy, I am not planning to help on all the things just because It would be quite complex, and I don't quite see who will use it.
For information, I implemented the support for the sftp protocol in Aker. It is not so user friendly for the connection, and if I remember well, I need to use a patched ssh client (due to the fact that they have an issue, they have not corrected on production and I rely on it). I will need to do a cleanup of the code, and to document its use for my own use. When it will be done, I may propose a PR. Maybe the different phase could be modified, and if there is some other thing which would be important, I may help implement it. |
I forgot to mention, I also have a patch to allow the use of multiple IDP. |
@EoleDev About the features listed, I would like to have the below whenever its possible. That will be a great addition to this aker gateway and will be one of the main reasons for one to consider using this setup.
|
@EoleDev Tables: If I have 200 hosts, I can add it to the hosts table using a csv export and that is a 1 minute job. Hurdle: Managing these in DB tables in an environment like us seems to be hard when there are many servers. May be, the work flow in our environment does not suit the Aker gateway Working method. I am just updating this if incase someone know a way to manage this and not in a way of complaining the application. Thank you |
@leosimony You will delete and/or add many servers quite often. It is not a problem with mariadb. You may do it. Could you explain what you are trying to achieve and was is blocking you ? I am currently using Aker with a pool of 400+ servers managed in a mariadb server. And I have no issue. We deploy at least 1 server per week, and there may be some servers deleted per week. |
@EoleDev Tables: hosts hosts_hostgroups(mapping 3 hosts to Infra and Devops Hostgroup) hosts_usergroups(mapping 3 hosts to Infra and Devops usergroups) usergroups: users: users_usersgroups Say If I have 400 hosts and, -I have to do these mappings in the tables by identifying the host id, userid, hostgroup id. Doing these from time to time looks difficult to me(may be only to me because I am lazy |
You could just develop a little UI to manage the database and do this for you! |
you have replied, just like that :-) |
Sorry, I don't understand your answer :D |
@leosimony
|
@EoleDev Of course and thank you. I would prefer a simple Web UI to manage users/hosts/groups. |
I will take the time to do it. |
This is all everyone need 👍
|
Would this workflow make sense?
|
Thank you so much @EoleDev for all the effort ur putting here. |
Yes @anazmy. I hope @EoleDev will be following the same work flow. |
@anazmy I would be glad to join the project. But I have not so much time so I can't promise to do all the patch quickly. @leosimony and @anazmy |
@EoleDev this also sounds okay. As logs as it serves the purpose then its fine. |
@leosimony I began the development, I will try to finish it as soon as possible. |
@leosimony @anazmy |
This is really great news. I will check it out and update you.
Thank you
…On Sat, Feb 29, 2020, 5:03 PM EoleDev ***@***.***> wrote:
@leosimony <https://github.com/leosimony> @anazmy
<https://github.com/anazmy>
The first version for the Mariadb IDP UI is done!!
you may find it here : https://github.com/EoleDev/aker-ui
Hope it will suit your needs.
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
<#94?email_source=notifications&email_token=ALKF2HJSTDLEMZZIOFOWTOTRFDZBRA5CNFSM4IJDNRH2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOENLXY7A#issuecomment-592936060>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ALKF2HMDQM7Q2ZBCRHRSAJDRFDZBRANCNFSM4IJDNRHQ>
.
|
@anazmy You have any idea to Merge this Aker-UI to be a part of the Aker project. I think that will help users looking for an SSH gateway project like this. |
@leosimony |
@EoleDev Oh okay. yes, if it is mentioned on the Readme, people will know. |
@leosimony Good! |
Thx @leosimony for the wonderful contribution! Pls allow me sometime to go through your additions |
Hi @anazmy, |
I am opening this issue here as you said. Sorry that I opened wrongly here https://github.com/aker-gateway/aker-freeipa-playbook/issues/7
Is this project being used in large numbers?
I am in desperate need of a gateway server for our Infra.
I have configured the Json method Aker and its working as expected. But for 500+ servers and growing and dynamic user config Infra, it's not easy to modify JSON files.
I don't have any idea about FreeIPA. Read like bind packages and IPA server needs DNS configs and all. We already running local DNS with dnsmasq.
Will it be an issue if we choose exeternal DNS for freeIPA.
Hosts and users management can be done in gui?
The text was updated successfully, but these errors were encountered: