vi /etc/grafana/grafana.ini (文件不必定是這個噢,看本身啓動服務的配置文件)app
修改配置:server
[auth.ldap]dns
enabled = trueip
config_file = /etc/grafana/ldap.toml (文件路徑不必定是這個噢,看本身的配置文件路徑)ssl
allow_sign_up = true email
vi /etc/grafana/ldap.toml (同上面配置的config_file)配置
修改配置:file
verbose_logging = truemap
[[servers]]配置文件
host = XXXX //公司內部ldaphost
port = XXXX //公司內部ldapport
use_ssl = false
ssl_skip_verify = false
bind_dn = "CN=XXXX,OU=XXXX,OU=XXXX,DC=XXXX,DC=com"
bind_password = XXXX
search_filter = "(sAMAccountName=%s)"
search_base_dns = ["OU=XXXX,OU=XXXX,DC=XXXX,DC=XXXX"]
[servers.attributes]
name = "givenName"
surname = "sn"
username = "sAMAccountName"
member_of = "memberOf"
email = "mail"
[[servers.group_mappings]]
group_dn = "CN=XXXX,OU=User Group,OU=XXXX,DC=XXXX,DC=com"
org_role = "Admin"
[[servers.group_mappings]]
group_dn = "*"
org_role = "Viewer" //根據本身的需求定義角色
注意:XXXX根據本身公司ldap的配置填寫
ldap我也不太懂,你們本身能夠研究下