feat(freeradius): add dynamic tenant VLAN assignment via unlang policy
This commit is contained in:
@@ -0,0 +1,15 @@
|
|||||||
|
vlan_test {
|
||||||
|
|
||||||
|
if (&User-Name =~ /.+@(.+)/) {
|
||||||
|
|
||||||
|
update control {
|
||||||
|
Tmp-String-0 := "%{1}"
|
||||||
|
}
|
||||||
|
|
||||||
|
update reply {
|
||||||
|
Tunnel-Type := VLAN
|
||||||
|
Tunnel-Medium-Type := IEEE-802
|
||||||
|
Tunnel-Private-Group-Id := "%{sql:SELECT vlan_id FROM tenant_subnets WHERE tenant_id='%{control:Tmp-String-0}'}"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -810,6 +810,8 @@ post-auth {
|
|||||||
reject
|
reject
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Query VLAN ID from your DB
|
||||||
|
vlan_test
|
||||||
|
|
||||||
# Create the CUI value and add the attribute to Access-Accept.
|
# Create the CUI value and add the attribute to Access-Accept.
|
||||||
# Uncomment the line below if *returning* the CUI.
|
# Uncomment the line below if *returning* the CUI.
|
||||||
|
|||||||
@@ -0,0 +1,19 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
|
||||||
|
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||||
|
{{- if .Values.commonLabels }}
|
||||||
|
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
data:
|
||||||
|
{{ (.Files.Glob "files/policy/vlan").AsConfig | indent 2 }}
|
||||||
@@ -292,6 +292,9 @@ spec:
|
|||||||
- name: freeradius-filter
|
- name: freeradius-filter
|
||||||
mountPath: /etc/freeradius/policy.d/filter
|
mountPath: /etc/freeradius/policy.d/filter
|
||||||
subPath: filter
|
subPath: filter
|
||||||
|
- name: freeradius-vlan
|
||||||
|
mountPath: /etc/freeradius/policy.d/vlan
|
||||||
|
subPath: vlan
|
||||||
- name: freeradius-sites
|
- name: freeradius-sites
|
||||||
mountPath: /etc/freeradius/sites-enabled/default
|
mountPath: /etc/freeradius/sites-enabled/default
|
||||||
subPath: default
|
subPath: default
|
||||||
@@ -346,6 +349,9 @@ spec:
|
|||||||
- name: freeradius-filter
|
- name: freeradius-filter
|
||||||
configMap:
|
configMap:
|
||||||
name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }}
|
name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }}
|
||||||
|
- name: freeradius-vlan
|
||||||
|
configMap:
|
||||||
|
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
|
||||||
- name: temp
|
- name: temp
|
||||||
emptyDir: {}
|
emptyDir: {}
|
||||||
- name: shared-certs
|
- name: shared-certs
|
||||||
|
|||||||
Reference in New Issue
Block a user