feat(freeradius): add dynamic tenant VLAN assignment via unlang policy
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
vlan_test {
|
||||
|
||||
if (&User-Name =~ /.+@(.+)/) {
|
||||
|
||||
update control {
|
||||
Tmp-String-0 := "%{1}"
|
||||
}
|
||||
|
||||
update reply {
|
||||
Tunnel-Type := VLAN
|
||||
Tunnel-Medium-Type := IEEE-802
|
||||
Tunnel-Private-Group-Id := "%{sql:SELECT vlan_id FROM tenant_subnets WHERE tenant_id='%{control:Tmp-String-0}'}"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -810,6 +810,8 @@ post-auth {
|
||||
reject
|
||||
}
|
||||
|
||||
# Query VLAN ID from your DB
|
||||
vlan_test
|
||||
|
||||
# Create the CUI value and add the attribute to Access-Accept.
|
||||
# Uncomment the line below if *returning* the CUI.
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
data:
|
||||
{{ (.Files.Glob "files/policy/vlan").AsConfig | indent 2 }}
|
||||
@@ -292,6 +292,9 @@ spec:
|
||||
- name: freeradius-filter
|
||||
mountPath: /etc/freeradius/policy.d/filter
|
||||
subPath: filter
|
||||
- name: freeradius-vlan
|
||||
mountPath: /etc/freeradius/policy.d/vlan
|
||||
subPath: vlan
|
||||
- name: freeradius-sites
|
||||
mountPath: /etc/freeradius/sites-enabled/default
|
||||
subPath: default
|
||||
@@ -346,6 +349,9 @@ spec:
|
||||
- name: freeradius-filter
|
||||
configMap:
|
||||
name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }}
|
||||
- name: freeradius-vlan
|
||||
configMap:
|
||||
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
|
||||
- name: temp
|
||||
emptyDir: {}
|
||||
- name: shared-certs
|
||||
|
||||
Reference in New Issue
Block a user