
LDAP Modify
CertifiedApply LDIF changes to LDAP
LDAP Modify
Apply LDIF changes to LDAP
Executes add/delete/modify/moddn operations described in LDIF change records from provided URIs. Each change is sent independently; server-side ACLs apply and failures are logged while processing continues.
type: io.kestra.plugin.ldap.ModifyExamples
Modify entries in LDAP server.
id: ldap_modify
namespace: company.team
tasks:
- id: modify
type: io.kestra.plugin.ldap.Modify
userDn: cn=admin,dc=orga,dc=en
password: "{{ secret('LDAP_PASSWORD') }}"
inputs:
- "{{ outputs.some_task.uri_of_ldif_change_record_formated_file }}"
hostname: 0.0.0.0
port: 18060
Properties
hostname *string
Hostname
Hostname for connection.
inputs *array
LDIF change URIs
URIs to LDIF files containing changeType records; each record is processed in order and errors on a record do not stop the remaining operations.
password *string
Password
User password for connection.
port *integerstring
Port
A whole number describing the port for connection.
userDn *string
User
Username for connection.
assets
Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.
io.kestra.core.models.assets.AssetsDeclaration
IGNOREFAILWARNAsset failure behavior
Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.
Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.
The assets consumed as inputs.
io.kestra.core.models.assets.AssetIdentifier
1The assets produced as outputs.
io.kestra.plugin.ee.assets.Dataset
1150{}1150io.kestra.plugin.ee.assets.File
1150{}1150io.kestra.plugin.ee.assets.Table
1150{}1150io.kestra.plugin.ee.assets.VM
1150{}1150io.kestra.core.models.assets.External
1150{}1150io.kestra.core.models.assets.Custom
11501Custom asset type
{}1150authMethod string
simplesimplegssapiAuthentication method
Authentication method to use with the LDAP server.
kdc string
Kerberos key distribution center
Needed for GSSAPI authentication method. If this is not provided, an attempt will be made to determine the appropriate value from the system configuration.
realm string
Realm
Needed for GSSAPI authentication method. If this is not provided, an attempt will be made to determine the appropriate value from the system configuration.
saslAllowedQoP array
["AUTH_CONF","AUTH_INT","AUTH"]AUTHAUTH_INTAUTH_CONFsaslAllowedQoP
Used for GSSAPI authentication method only. The list of allowed qualities of protection that may be used for communication after authentication has completed, ordered from most preferred to least preferred.
By default, the full list is allowed, sorted from the most secure to the least secure: - AUTH_CONF # This ensures that third-party observers will not be able to decipher communication between the client and server (i.e., that the communication will be encrypted). - AUTH_INT # This ensure that the communication cannot be altered in an undetectable manner. - AUTH # Only authentication is to be performed, with no integrity or confidentiality protection for subsequent communication.
sslOptions
SSL Configuration
Configure SSL/LDAPS connection parameters.
io.kestra.core.http.client.configurations.SslOptions
Whether to disable checking of the remote SSL certificate.
Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.
Metrics
modifications.done counter
The total number of successful modifications on the LDAP server.
modifications.mean.time timer
The mean duration of LDAP modifications in milliseconds.
modifications.requested counter
The total number of modification requests made.