feat(freeradius): add dynamic tenant VLAN assignment via unlang policy

This commit is contained in:
2026-05-12 15:50:18 +02:00
parent 328ff7511c
commit 1a1e37ffdf
4 changed files with 44 additions and 2 deletions
+15
View File
@@ -0,0 +1,15 @@
vlan_test {
if (&User-Name =~ /.+@(.+)/) {
update control {
Tmp-String-0 := "%{1}"
}
update reply {
Tunnel-Type := VLAN
Tunnel-Medium-Type := IEEE-802
Tunnel-Private-Group-Id := "%{sql:SELECT vlan_id FROM tenant_subnets WHERE tenant_id='%{control:Tmp-String-0}'}"
}
}
}
+2
View File
@@ -810,6 +810,8 @@ post-auth {
reject reject
} }
# Query VLAN ID from your DB
vlan_test
# Create the CUI value and add the attribute to Access-Accept. # Create the CUI value and add the attribute to Access-Accept.
# Uncomment the line below if *returning* the CUI. # Uncomment the line below if *returning* the CUI.
+19
View File
@@ -0,0 +1,19 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{ (.Files.Glob "files/policy/vlan").AsConfig | indent 2 }}
+6
View File
@@ -292,6 +292,9 @@ spec:
- name: freeradius-filter - name: freeradius-filter
mountPath: /etc/freeradius/policy.d/filter mountPath: /etc/freeradius/policy.d/filter
subPath: filter subPath: filter
- name: freeradius-vlan
mountPath: /etc/freeradius/policy.d/vlan
subPath: vlan
- name: freeradius-sites - name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/default mountPath: /etc/freeradius/sites-enabled/default
subPath: default subPath: default
@@ -346,6 +349,9 @@ spec:
- name: freeradius-filter - name: freeradius-filter
configMap: configMap:
name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }} name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }}
- name: freeradius-vlan
configMap:
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
- name: temp - name: temp
emptyDir: {} emptyDir: {}
- name: shared-certs - name: shared-certs