From 1a1e37ffdf73c257869200c0a59e2015dc5c3814 Mon Sep 17 00:00:00 2001 From: "noussair.hamrit" Date: Tue, 12 May 2026 14:24:49 +0200 Subject: [PATCH] feat(freeradius): add dynamic tenant VLAN assignment via unlang policy --- files/policy/vlan | 15 +++++++++++++++ files/sites-available/default | 2 ++ templates/ConfigMap/vlan.yaml | 19 +++++++++++++++++++ templates/Deployment.yaml | 10 ++++++++-- 4 files changed, 44 insertions(+), 2 deletions(-) create mode 100644 files/policy/vlan create mode 100644 templates/ConfigMap/vlan.yaml diff --git a/files/policy/vlan b/files/policy/vlan new file mode 100644 index 0000000..075fad6 --- /dev/null +++ b/files/policy/vlan @@ -0,0 +1,15 @@ +vlan_test { + + if (&User-Name =~ /.+@(.+)/) { + + update control { + Tmp-String-0 := "%{1}" + } + + update reply { + Tunnel-Type := VLAN + Tunnel-Medium-Type := IEEE-802 + Tunnel-Private-Group-Id := "%{sql:SELECT vlan_id FROM tenant_subnets WHERE tenant_id='%{control:Tmp-String-0}'}" + } + } +} \ No newline at end of file diff --git a/files/sites-available/default b/files/sites-available/default index 5984673..33ce4b9 100644 --- a/files/sites-available/default +++ b/files/sites-available/default @@ -810,6 +810,8 @@ post-auth { reject } + # Query VLAN ID from your DB + vlan_test # Create the CUI value and add the attribute to Access-Accept. # Uncomment the line below if *returning* the CUI. diff --git a/templates/ConfigMap/vlan.yaml b/templates/ConfigMap/vlan.yaml new file mode 100644 index 0000000..734c142 --- /dev/null +++ b/templates/ConfigMap/vlan.yaml @@ -0,0 +1,19 @@ +{{- /* +Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved. +SPDX-License-Identifier: APACHE-2.0 +*/}} + +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }} + namespace: {{ include "st-common.names.namespace" . | quote }} + labels: {{- include "st-common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }} + {{- end }} +data: +{{ (.Files.Glob "files/policy/vlan").AsConfig | indent 2 }} diff --git a/templates/Deployment.yaml b/templates/Deployment.yaml index 9afa3e2..39cc53b 100644 --- a/templates/Deployment.yaml +++ b/templates/Deployment.yaml @@ -291,7 +291,10 @@ spec: subPath: radius.conf - name: freeradius-filter mountPath: /etc/freeradius/policy.d/filter - subPath: filter + subPath: filter + - name: freeradius-vlan + mountPath: /etc/freeradius/policy.d/vlan + subPath: vlan - name: freeradius-sites mountPath: /etc/freeradius/sites-enabled/default subPath: default @@ -345,7 +348,10 @@ spec: name: {{ printf "%s-radius-conf" (include "st-common.names.fullname" .) }} - name: freeradius-filter configMap: - name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }} + name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }} + - name: freeradius-vlan + configMap: + name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }} - name: temp emptyDir: {} - name: shared-certs