LLDAP

LLDAP

LLDAP (opens in a new tab) runs on Marmot through its MySQL backend. Tested version: 0.6.3 (lldap/lldap:v0.6.3).

Configuration

Create the database once, on any node:

CREATE DATABASE lldap;

Point LLDAP at a node's MySQL port:

LLDAP_DATABASE_URL=mysql://root@marmot-node-1:3306/lldap

LLDAP's migrations run through Marmot and replicate like any other DDL. Its groups table uses an INT AUTO_INCREMENT key, so group ids fit 32 bits (see Narrow AUTO_INCREMENT Columns in Compatibility):

  • A single node needs cluster.standalone = true.
  • On a cluster, LLDAP can start together with the nodes: while a node still holds its claim votes, the first group insert waits for the release (see Compatibility). Each node issues group ids from its own range, so groups created through different nodes get ids from different ranges.

Verified Scenarios

ScenarioVerified
Single nodeLLDAP boots and runs its migrations; users, groups and memberships created through the GraphQL API; a password set with lldap_set_password; LDAP bind as that user; all ids fit their columns; data and login survive a restart of LLDAP and then of Marmot
Three nodes, LLDAP on two of themLLDAP instances on node 1 and node 2 see each other's users and groups and bind the same users; a node stopped gracefully while both keep writing, then restarted, holds identical rows in every LLDAP table (checked with a 30-second bound); no id collisions
Cold start on a clusterLLDAP started against a new database on one node of three: its migrations reach every node, and the schema is identical on all nodes