Agent skill

Configuration Identity Stores

by greenpau in greenpau/caddy-security

Configure local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration Identity Stores

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-identity-stores -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-identity-stores --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-identity-stores .claude/skills/configuration-identity-stores && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-identity-stores
GitHub stars
2.3k
Token cost
~2.3k tokens
SKILL.md length
956 words
Files
3 (incl. references)
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings.

  • Works in 4 steps: Identification opens a fresh… → Identification fails unless exactly one… → It maps LDAP group DNs to roles from… → …
  • Backend & APIs work in your project
  • SKILL.md covers Purpose, Local Stores, LDAP Stores and Store Options, plus 2 more sections
  • Calls openssl; needs LDAP_USER_SECRET and ALICE_PASSWORD

What it does

Configuration Identity Stores is an agent skill from greenpau/caddy-security. Configure local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings. Delegates static account entries to configuration-users.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/local-identity.md`).

It sits in Backend & APIs. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/configuration-identity-stores”

Requirements

  • A credential in AUTHP_ADMIN_SECRET
  • A credential in LDAP_USER_SECRET

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identification opens a fresh service-bound connection, escapes the submitted
  2. Identification fails unless exactly one user object is found.
  3. It maps LDAP group DNs to roles from explicit or automatic group mapping.
  4. Password authentication opens another fresh service-bound connection,

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • LDAP_USER_SECRET
    • ALICE_PASSWORD
    • AUTHP_ADMIN_SECRET
    • LDAP_BIND_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration Identity Stores loads about 2.3k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 49 tokens; SKILL.md has 956 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 956 words, ~2,331 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-identity-stores/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
configuration-identity-stores
description
Configure local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings. Delegates static account entries to configuration-users.

Configuration Identity Stores

Purpose

Use this skill to configure local identity store <name> and ldap identity store <name> blocks. The dispatcher is caddyfile_identity.go; the store parser is caddyfile_identity_store.go.

Use configuration-users to configure static user <username> entries, password imports, API keys, and stored challenge rules. For password verification, credential versions, management/profile mutations, reload invalidation, and Caddy qualification, read local identity compatibility. Check github.com/greenpau/go-authcrunch/pkg/ids when changing this skill: ids.Config.Validate admits only local and ldap stores and validates the authcrunch parameter names produced by the Caddyfile parser.

Local Stores

Local stores require realm and path in the authcrunch config. The full Caddyfile form is:

caddyfile
{
	security {
		local identity store localdb {
			realm local
			path assets/config/users.json
		}
	}
}

The local shortcut is valid and sets realm local plus the user file path. Only local stores support this shortcut:

caddyfile
local identity store localdb assets/config/users.json

Add users inline only when the Caddyfile should own the local account data:

caddyfile
user alice {
	name "Alice Example"
	email alice@example.com
	password {env.ALICE_PASSWORD} overwrite
	roles authp/user authp/admin
}

Local store-level options supported by authcrunch are login_icon, username_recovery_enabled, password_recovery_enabled, contact_support_enabled, support_link, and support_email. In Caddyfile, set those with icon, enable username recovery, enable password recovery, enable contact support, support link, and support email.

Authcrunch creates a missing local database and bootstraps an administrative user whenever the loaded database has no administrator, including an existing database. Configure the bootstrap password explicitly before first startup: the selected library logs the created username, email and roles, but does not log the generated password. These environment variables set the account:

text
AUTHP_ADMIN_USER
AUTHP_ADMIN_EMAIL
AUTHP_ADMIN_SECRET

The local database stores password and username policy fields. The default password policy requires length 8-128, and the default username policy requires length 3-50. Users with non-guest portal access can change their password from the portal profile/settings UI; administrators can reset passwords and manage users through security local or authdbctl. These commands use the running portal's admin API.

LDAP Stores

LDAP stores require realm and servers at config-validation time. At provisioning time authcrunch also needs bind credentials, search_base_dn, and either explicit groups or automatic group mapping. Use this practical shape:

caddyfile
ldap identity store corp {
	realm corp.example.com
	servers {
		ldaps://ldap.example.com
	}
	trusted_authority /etc/caddy/ldap/corp-ca.pem
	username "CN=authsvc,OU=Service Accounts,DC=example,DC=com"
	password {env.LDAP_BIND_PASSWORD}
	search_base_dn "DC=example,DC=com"
	search_user_filter "(&(|(sAMAccountName=%s)(mail=%s))(objectclass=user))"
	attributes {
		name givenName
		surname sn
		username sAMAccountName
		member_of memberOf
		email mail
	}
	groups {
		"CN=Admins,OU=Groups,DC=example,DC=com" authp/admin
		"CN=Users,OU=Groups,DC=example,DC=com" authp/user
	}
}

Use these Caddyfile-to-authcrunch aliases deliberately:

  • username becomes bind_username; do not write bind_username in Caddyfile.
  • password becomes bind_password; if omitted, authcrunch falls back to LDAP_USER_SECRET during provisioning.
  • search_filter is a legacy alias for search_user_filter; prefer search_user_filter for clarity when adding new examples.
  • trusted_authority <path> appends to authcrunch trusted_authorities.
  • icon becomes login_icon.

LDAP server addresses must start with ldap:// or ldaps://. Authcrunch uses default ports 389 and 636, or a port in the URL, and defaults timeout to 5 seconds; the Caddyfile parser currently exposes only ignore_cert_errors and posix_groups server flags.

Prefer trusted_authority <path> for LDAPS trust over ignore_cert_errors. When collecting a server certificate chain for trust configuration, use openssl s_client -showcerts against the LDAPS endpoint, split the PEM certificates, verify the intended CA against the directory operator's trust material, and point trusted_authority at those CA files. A certificate retrieved from the endpoint alone does not establish trust in that endpoint.

If search_user_filter, search_group_filter, or attributes are omitted, authcrunch defaults to Active Directory-style values: sAMAccountName/mail, memberOf, givenName, sn, and (&(uniqueMember=%s)(objectClass=groupOfUniqueNames)). Override them for POSIX or non-AD directories.

Group mapping rules:

  • Use groups { <group_dn> <role> [<role>...] } for explicit LDAP DN to role mappings.
  • Use enable short automatic group mapping to map group DNs to the lower-case first RDN value, such as ou=mathematicians,... to mathematicians.
  • Use enable full automatic group mapping to map group DNs to lower-case full DN roles.
  • Add posix_groups on a server when group membership must be found through search_group_filter instead of the user's member_of attribute.
  • Authcrunch supports fallback_roles for roles assigned when the user authenticates but no LDAP group mapping produced roles. It does not replace the requirement for explicit or automatic group mapping to configure LDAP.
  • Use fallback role authp/user or fallback roles authp/user directory/member inside an LDAP store. All supplied roles survive adaptation; repeating the directive replaces the list. Local stores reject this LDAP-only setting. TestIdentityStoreFallbackRoles checks typed mapping; the LDAP journey in TestCaddyAuthenticationChallengesE2E verifies a real service bind, user bind, signed role claims and protected route over disposable verified LDAPS/TLS.
Show full SKILL.md (312 more words)Show less

Runtime LDAP authentication flow:

  1. Identification opens a fresh service-bound connection, escapes the submitted username/email for search_user_filter, and searches under search_base_dn.
  2. Identification fails unless exactly one user object is found.
  3. It maps LDAP group DNs to roles from explicit or automatic group mapping. If no role is produced and no supported fallback applies, authentication fails before token issuance.
  4. Password authentication opens another fresh service-bound connection, repeats the user search, then binds as the found user DN with the submitted password. Completing the required challenges allows token issuance.

Connections are closed after each operation; identification and password verification do not share a long-lived connection.

This flow means a correct-looking Caddyfile can still fail because the search filter is too broad, group membership does not map to any role, LDAPS trust is missing, or service bind credentials are wrong.

Store Options

Supported store-level options include:

  • disabled
  • realm, path, search_base_dn, search_group_filter, search_user_filter, search_filter, username, and password
  • trusted_authority <path>
  • attributes { <local_name> <remote_name> }
  • servers { <ldap_url> [ignore_cert_errors] [posix_groups] }
  • groups { <group_dn> <role> [<role>...] }
  • enable username recovery, enable password recovery, enable contact support
  • enable full automatic group mapping and enable short automatic group mapping
  • support link <url> and support email <address>
  • icon <text> ...

Do not invent raw authcrunch JSON field names as Caddyfile directives unless the parser accepts them. In particular, Caddyfile uses username, password, trusted_authority, and search_filter/search_user_filter, while the adapted authcrunch config stores bind_username, bind_password, trusted_authorities, and search_user_filter.

Portal Wiring

After defining a store, enable it from an authentication portal:

caddyfile
authentication portal myportal {
	enable identity store localdb corp
}

Fixtures

Use these examples:

  • caddyfile_identity_test.go.
  • caddyfile_identity_store_test.go.
  • testdata/caddyfile_adapt/testcase_security_authentication_portal.Caddyfile.

The LDAP journey in ldap_fallback_e2e_test.go, invoked by TestCaddyAuthenticationChallengesE2E, checks verified LDAPS, fallback role claims and a protected route. It does not qualify every directory schema, POSIX group lookup, or production CA configuration. For those changes, verify exactly-one-user selection, explicit and automatic mapping, unmapped-user rejection or fallback, wrong-password rejection and trust failures against a disposable directory before claiming login compatibility.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .codex/skills/configuration-identity-stores of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml
  • references/local-identity.md

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration Identity Stores next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration Identity Stores compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration Identity Stores this skillgreenpau/caddy-security2.3k—~2.3kAutomated safety check: PassApache-2.0
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 5 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about Configuration Identity Stores

What does Configuration Identity Stores do?

Configure local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings. Configuration Identity Stores is an agent skill from greenpau/caddy-security. Configure local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings.

When should I use Configuration Identity Stores?

Configuration Identity Stores fits situations like: backend & APIs work in your project.

How do I install Configuration Identity Stores in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-identity-stores -a claude-code`. Or copy the skill folder (.codex/skills/configuration-identity-stores in greenpau/caddy-security) into .claude/skills/configuration-identity-stores in your project. Claude Code loads it when a task matches its description.

How do I install Configuration Identity Stores in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-identity-stores -a codex`. Or copy the skill folder (.codex/skills/configuration-identity-stores in greenpau/caddy-security) into .agents/skills/configuration-identity-stores in your project. Codex loads it when a task matches its description.

Can I use Configuration Identity Stores in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-identity-stores -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-identity-stores, .gemini/skills/configuration-identity-stores, .github/skills/configuration-identity-stores and .opencode/skills/configuration-identity-stores in your project.

What does Configuration Identity Stores need to run?

Going by SKILL.md and its folder, Configuration Identity Stores needs the command-line tools its instructions call (openssl) and credentials named LDAP_USER_SECRET, ALICE_PASSWORD, AUTHP_ADMIN_SECRET and LDAP_BIND_PASSWORD. Our summary lists: A credential in AUTHP_ADMIN_SECRET; A credential in LDAP_USER_SECRET.

Does Configuration Identity Stores access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration Identity Stores safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration Identity Stores use?

Configuration Identity Stores is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration Identity Stores use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Configuration Identity Stores?

Skills that share tags, products or a category with Configuration Identity Stores: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration Identity Stores?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.