Restructured Documentation
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s

This commit is contained in:
2026-09-05 14:08:43 -06:00
parent c4bd235eba
commit 289769a601
281 changed files with 5403 additions and 3563 deletions
@@ -0,0 +1,23 @@
---
tags:
- Active Directory
- LDAP
- Authentication
---
## Purpose
LDAP settings are used in various services from privacyIDEA to Nextcloud. This will outline the basic parameters in my homelab that are necessary to make it function.
| **Field** | **Value** | **Description** |
| :--- | :--- | :--- |
| Server Address(s) | `ldap://bunny-dc-01.bunny-lab.io` / `192.168.3.8`, `ldap://bunny-db-02.bunny.lab.io` / `192.168.3.9` | Domain Controllers |
| Port | `389` | Unencrypted LDAP |
| STARTTLS | `Disabled` | |
| Base DN | `CN=Users,DC=bunny-lab,DC=io` | This is where users are pulled from |
| User / Bind DN | `CN=Nicole Rappe,CN=Users,DC=bunny-lab,DC=io` | This is the domain admin used to connect to LDAP |
| User / Bind Password | `<Password for User / Bind DN>` | Domain Credentials for Domain Admin account |
| Login Attribute | ` LDAP Filter: (&(&(|(objectclass=person))(|(|(memberof=CN=Domain Users,CN=Users,DC=bunny-lab,DC=io)(primaryGroupID=513))))(samaccountname=%uid)) ` | Used by Nextcloud |
| Login Attribute | `(sAMAccountName=*)(objectCategory=person)` | Used by PrivacyIDEA |
## Related Documentation
- [Related Identity and Certificates Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,20 @@
---
tags:
- Keycloak
- OAuth2
- Authentication
---
## Purpose
Choose the documented Keycloak integration for an application or reverse proxy after Keycloak is deployed. Application OAuth settings and reverse-proxy authentication serve different integration points.
## Prepare Keycloak
[Deploy Keycloak](<../../deployments/Identity and Certificates/Keycloak/Deploy Keycloak.md>) includes the service and proxy-middleware configuration.
## Configure an Application
- [Gitea OAuth2](<../../workflows/Identity and Certificates/Keycloak/Connect Gitea to Keycloak.md>) — Configure the documented application client.
- [Portainer OAuth2](<../../workflows/Identity and Certificates/Keycloak/Connect Portainer to Keycloak.md>) — Configure the documented Portainer integration.
- [Firefox Proxy Authentication](<../../deployments/Networking and Access/Remote Access/Firefox.md>) — Review the deployment that explains the proxy authentication flow.
## Related Documentation
- [Related Identity and Certificates Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
@@ -0,0 +1,23 @@
---
tags:
- Identity and Certificates
- Reference
- Documentation
---
# Identity and Certificates
## Purpose
Connect directory services, certificate trust, single sign-on, and application authentication. Start with the identity system involved, then follow the integration or maintenance procedure.
## Includes
- Build the documented offline root, online subordinate CA, and publication point.
- Publish and monitor CRLs after the PKI exists.
- Provide the trust material needed by directory clients.
## Find the Right Document
- [Deploy Certificate Services](<../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Build the documented offline root, online subordinate CA, and publication point.
- [Maintain Revocation Lists](<../../workflows/Identity and Certificates/Certificates/Publish and Maintain Certificate Revocation Lists.md>) — Publish and monitor CRLs after the PKI exists.
- [Export LDAPS Certificates](<../../workflows/Identity and Certificates/Certificates/Export Certificates for LDAPS Clients.md>) — Provide the trust material needed by directory clients.
- [LDAP Connection Settings](<Active Directory/LDAP Connection Settings.md>) — Locate the recorded directory connection parameters.
- [Keycloak Application Integrations](<Keycloak Integrations.md>) — Choose reverse-proxy authentication or an application-specific OAuth integration.
- [Windows Remote Management](<../../workflows/Identity and Certificates/Windows/Enable WinRM over HTTPS.md>) — Prepare Windows targets for the AWX or Puppet Bolt workflows that reference WinRM.