Initial commit

- update else condition on the line 239 in templates/Deployment
- update  st-common version from 0.1.10 to 0.1.12 on Chart.yaml file
- add gitlab ci/cd pipeline to  package the Helm chart into a .tgz. and Publish it to GitLab’s Helm package registry
This commit is contained in:
2025-06-24 11:20:34 +02:00
commit 98c2fa6240
44 changed files with 6338 additions and 0 deletions
+54
View File
@@ -0,0 +1,54 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and (include "freeradius.createTlsSecret" .) .Values.tls.autoGenerator.certmanager.enabled }}
{{- if not (eq (include "st-common.capabilities.certManager.apiVersion" .) "false") }}
{{- $releaseNamespace := include "st-common.names.namespace" . }}
{{- $clusterDomain := .Values.clusterDomain }}
{{- $fullname := include "st-common.names.fullname" . }}
{{- $serviceName := include "st-common.names.fullname" . }}
{{- $altNames := list (printf "%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $serviceName $releaseNamespace) (printf "%s.%s" $serviceName $releaseNamespace) $fullname }}
{{/*
{{- $altNames := list (printf "*.%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $serviceName $releaseNamespace) (printf "%s.%s" $serviceName $releaseNamespace) $fullname }}
*/}}
apiVersion: {{ include "st-common.capabilities.certManager.apiVersion" . }}
kind: Certificate
metadata:
name: {{ include "st-common.names.fullname" . }}-tls
namespace: {{ include "st-common.names.namespace" . | quote }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
spec:
secretName: {{ include "freeradius.tlsSecretName" . }}
issuerRef:
group: cert-manager.io
kind: {{ .Values.tls.autoGenerator.certmanager.issuerKind }}
name: {{ .Values.tls.autoGenerator.certmanager.issuerName }}
#name: letsencrypt-prd
privateKey:
algorithm: ECDSA
rotationPolicy: Always
size: 256
subject:
organizations:
- {{ .Release.Name | quote }}
organizationalUnits:
- {{ include "st-common.names.fullname" . }}
dnsNames:
- {{ .Values.ingress.hostname | quote }}
{{- range .Values.ingress.extraHosts }}
- {{ .name | quote }}
{{- end }}
{{- with $altNames }}
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
{{- end }}
---
+23
View File
@@ -0,0 +1,23 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if not .Values.clients.existingConfigMapName }}
{{- $client := index .Values "clients" "localhost" }}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-clients" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
clients.conf: |-
client
{{- end }}
+75
View File
@@ -0,0 +1,75 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ include "freeradius.names.envvars" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
FREERADIUS_ENABLE_TLS: {{ ternary "true" "false" .Values.tls.enabled | quote }}
FREERADIUS_CLIENTS_SHORTNAME: ""
FREERADIUS_CLIENTS_IPV4ADDR: ""
FREERADIUS_CLIENTS_IPV6ADDR: ""
FREERADIUS_CLIENTS_SECRET: ""
{{- if .Values.modsEnabled.sql.enabled }}
FREERADIUS_MODS_SQL_DIALECT: {{ .Values.modsEnabled.sql.dialect }}
FREERADIUS_MODS_SQL_SERVER: {{ include "freeradius.database.host" . | quote }}
FREERADIUS_MODS_SQL_PORT: {{ include "freeradius.database.port" . }}
FREERADIUS_MODS_SQL_LOGIN: {{ include "freeradius.database.user" . | quote }}
FREERADIUS_MODS_SQL_DB: {{ include "freeradius.database.name" . | quote }}
FREERADIUS_MODS_SQL_TABLE_ACCT1: {{ .Values.modsEnabled.sql.table.acct1 }}
FREERADIUS_MODS_SQL_TABLE_ACCT2: {{ .Values.modsEnabled.sql.table.acct2 }}
FREERADIUS_MODS_SQL_TABLE_AUTHCHECK: {{ .Values.modsEnabled.sql.table.authcheck }}
FREERADIUS_MODS_SQL_TABLE_AUTHREPLY: {{ .Values.modsEnabled.sql.table.authreply }}
FREERADIUS_MODS_SQL_TABLE_CLIENT: {{ .Values.modsEnabled.sql.table.client }}
FREERADIUS_MODS_SQL_TABLE_GROUPCHECK: {{ .Values.modsEnabled.sql.table.groupcheck }}
FREERADIUS_MODS_SQL_TABLE_GROUPREPLY: {{ .Values.modsEnabled.sql.table.groupreply }}
FREERADIUS_MODS_SQL_TABLE_POSTAUTH: {{ .Values.modsEnabled.sql.table.postauth }}
FREERADIUS_MODS_SQL_TABLE_USERGROUP: {{ .Values.modsEnabled.sql.table.usergroup }}
FREERADIUS_MODS_SQL_TLS_ENABLE: {{ ternary "yes" "no" .Values.modsEnabled.sql.tls.enabled | quote }}
FREERADIUS_MODS_SQL_READ_CLIENTS: {{ ternary "yes" "no" .Values.modsEnabled.sql.readClients | quote }}
FREERADIUS_MODS_SQL_GROUP_ATTRIBUTE: {{ .Values.modsEnabled.sql.groupAttribute | quote }}
FREERADIUS_MODS_SQL_SQLITE_FILENAME: {{ .Values.modsEnabled.sql.sqlite.filename | quote }}
FREERADIUS_MODS_SQL_SQLITE_BUSY_TIMEOUT: {{ .Values.modsEnabled.sql.sqlite.busyTimeout | quote }}
{{- if .Values.modsEnabled.sql.tls.enabled }}
FREERADIUS_MODS_SQL_TLS_CACERT: {{ include "freeradius.sqlTlsCACert" . | quote }}
FREERADIUS_MODS_SQL_TLS_CIPHER: {{ .Values.modsEnabled.sql.tls.ciphers | quote }}
FREERADIUS_MODS_SQL_TLS_CERTIFICATE: {{ include "freeradius.sqlTlsCert" . | quote }}
FREERADIUS_MODS_SQL_TLS_PRIVATEKEY: {{ include "freeradius.sqlTlsCertKey" . | quote }}
FREERADIUS_MODS_SQL_TLS_PRIVATEKEY_PASSWORD: {{ .Values.modsEnabled.sql.tls.privateKeyPassword | quote }}
{{- end }}
{{- end }}
FREERADIUS_SITES_NAMESPACE: radius
FREERADIUS_SITES_DEFAULT_AUTH_PORT: {{ .Values.containerPorts.auth | quote }}
FREERADIUS_SITES_DEFAULT_ACCT_PORT: {{ .Values.containerPorts.acct | quote }}
{{- if .Values.sitesEnabled.coa.enabled }}
FREERADIUS_SITES_COA_PORT: {{ .Values.containerPorts.coa | quote }}
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
FREERADIUS_SITES_STATUS_LISTEN: {{ .Values.sitesEnabled.status.listen | quote }}
FREERADIUS_SITES_STATUS_PORT: {{ .Values.containerPorts.status | quote }}
{{- end }}
{{- if .Values.sitesEnabled.tls.enabled }}
FREERADIUS_SITES_TLS_PORT: {{ .Values.containerPorts.radsec | quote }}
FREERADIUS_SITES_TLS_CA_FILE: {{ include "freeradius.tlsCACert" . | quote }}
FREERADIUS_SITES_TLS_CERTIFICATE_FILE: {{ include "freeradius.tlsCert" . | quote }}
FREERADIUS_SITES_TLS_CIPHER: {{ default "DEFAULT" .Values.sitesEnabled.tls.cipher | quote }}
FREERADIUS_SITES_TLS_PRIVKEY_FILE: {{ include "freeradius.tlsCertKey" . | quote }}
{{- end }}
+21
View File
@@ -0,0 +1,21 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-mods" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{- if .Values.modsEnabled.sql.enabled }}
{{ (.Files.Glob "files/mods-available/sql").AsConfig | indent 2 }}
{{- end }}
+29
View File
@@ -0,0 +1,29 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-sites" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{ (.Files.Glob "files/sites-available/default").AsConfig | indent 2 }}
{{ (.Files.Glob "files/sites-available/inner-tunnel").AsConfig | indent 2 }}
{{- if .Values.sitesEnabled.coa.enabled }}
{{ (.Files.Glob "files/sites-available/coa").AsConfig | indent 2 }}
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
{{ (.Files.Glob "files/sites-available/status").AsConfig | indent 2 }}
{{- end }}
{{- if .Values.sitesEnabled.tls.enabled }}
{{ (.Files.Glob "files/sites-available/tls").AsConfig | indent 2 }}
{{- end }}
+366
View File
@@ -0,0 +1,366 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* vim: set filetype=mustache: */}}
{{- $globalSecretName := printf "%s" (tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecret "context" $)) $) }}
apiVersion: {{ include "st-common.capabilities.deployment.apiVersion" . }}
kind: Deployment
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
spec:
replicas: {{ .Values.replicaCount }}
revisionHistoryLimit: {{ .Values.revisionHistoryLimit }}
selector:
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 6 }}
app.kubernetes.io/component: freeradius
{{- if .Values.updateStrategy }}
strategy: {{- toYaml .Values.updateStrategy | nindent 4 }}
{{- end }}
template:
metadata:
annotations:
checksum/configmap-env: {{ include (print $.Template.BasePath "/ConfigMap/envvars.yaml") . | sha256sum }}
checksum/configmap-mods: {{ include (print $.Template.BasePath "/ConfigMap/mods-enabled.yaml") . | sha256sum }}
checksum/configmap-sites: {{ include (print $.Template.BasePath "/ConfigMap/sites-enabled.yaml") . | sha256sum }}
checksum/secret-credentials: {{ include (print $.Template.BasePath "/Secret/credentials.yaml") . | sha256sum }}
checksum/secret-sql-tls: {{ include (print $.Template.BasePath "/Secret/sql-tls.yaml") . | sha256sum }}
checksum/secret-tls: {{ include (print $.Template.BasePath "/Secret/tls.yaml") . | sha256sum }}
{{- if .Values.podAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.podAnnotations "context" $) | nindent 8 }}
{{- end }}
labels: {{- include "st-common.labels.standard" . | nindent 8 }}
app.kubernetes.io/component: freeradius
{{- if .Values.podLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.podLabels "context" $) | nindent 8 }}
{{- end }}
spec:
{{- if .Values.affinity }}
affinity: {{- include "st-common.tplvalues.render" (dict "value" .Values.affinity "context" $) | nindent 8 }}
{{- else }}
affinity:
podAffinity: {{- include "st-common.affinities.pods" (dict "type" .Values.podAffinityPreset "context" $) | nindent 10 }}
podAntiAffinity: {{- include "st-common.affinities.pods" (dict "type" .Values.podAntiAffinityPreset "context" $) | nindent 10 }}
nodeAffinity: {{- include "st-common.affinities.nodes" (dict "type" .Values.nodeAffinityPreset.type "key" .Values.nodeAffinityPreset.key "values" .Values.nodeAffinityPreset.values) | nindent 10 }}
{{- end }}
{{- include "freeradius.imagePullSecrets" . | nindent 6 }}
{{- if .Values.hostAliases }}
hostAliases: {{- include "st-common.tplvalues.render" (dict "value" .Values.hostAliases "context" $) | nindent 8 }}
{{- end }}
{{- if .Values.nodeSelector }}
nodeSelector: {{- include "st-common.tplvalues.render" (dict "value" .Values.nodeSelector "context" $) | nindent 8 }}
{{- end }}
{{- if .Values.priorityClassName }}
priorityClassName: {{ .Values.priorityClassName | quote }}
{{- end }}
{{- if .Values.schedulerName }}
schedulerName: {{ .Values.schedulerName | quote }}
{{- end }}
{{- if .Values.podSecurityContext.enabled }}
securityContext: {{- omit .Values.podSecurityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
serviceAccountName: {{ include "freeradius.serviceAccountName" . }}
{{- if .Values.tolerations }}
tolerations: {{- include "st-common.tplvalues.render" (dict "value" .Values.tolerations "context" .) | nindent 8 }}
{{- end }}
{{- if .Values.topologySpreadConstraints }}
topologySpreadConstraints: {{- include "st-common.tplvalues.render" (dict "value" .Values.topologySpreadConstraints "context" .) | nindent 8 }}
{{- end }}
{{- if or (and .Values.volumePermissions.enabled .Values.persistence.enabled) .Values.initContainers }}
initContainers:
{{- if .Values.initContainers }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.initContainers "context" $) | nindent 8 }}
{{- end }}
{{- if and .Values.volumePermissions.enabled .Values.persistence.enabled }}
- name: volume-permissions
image: {{ include "freeradius.volumePermissions.image" . }}
imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }}
command:
- /bin/bash
args:
- -ec
- |
printf '%s\n' "[system] Change permission" >&2
chown -R {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }} {{ .Values.persistence.mountPath }}
chmod 0711 {{ .Values.persistence.mountPath }}
{{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }}
securityContext: {{- omit .Values.volumePermissions.securityContext "runAsUser" | toYaml | nindent 12 }}
{{- else }}
securityContext: {{- .Values.volumePermissions.securityContext | toYaml | nindent 12 }}
{{- end }}
{{- if .Values.volumePermissions.resources }}
resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }}
{{- end }}
volumeMounts:
- name: data
mountPath: {{ .Values.persistence.mountPath }}
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- end }}
{{- end }}
{{- end }}
containers:
- name: freeradius
image: {{ include "freeradius.image" . }}
imagePullPolicy: {{ .Values.image.pullPolicy | quote }}
{{- if .Values.diagnosticMode.enabled }}
command: {{- include "st-common.tplvalues.render" (dict "value" .Values.diagnosticMode.command "context" $) | nindent 12 }}
{{- else if .Values.command }}
command: {{- include "st-common.tplvalues.render" (dict "value" .Values.command "context" $) | nindent 12 }}
{{- end }}
{{- if .Values.diagnosticMode.enabled }}
args: {{- include "st-common.tplvalues.render" (dict "value" .Values.diagnosticMode.args "context" $) | nindent 12 }}
{{- else if .Values.args }}
args: {{- include "st-common.tplvalues.render" (dict "value" .Values.args "context" $) | nindent 12 }}
{{- else }}
args:
- -fxx
- -l
- stdout
{{- end }}
env:
{{- if .Values.modsEnabled.sql.enabled }}
- name: FREERADIUS_MODS_SQL_PASSWORD
valueFrom:
secretKeyRef:
{{- if .Values.auth.existingSecretPerPassword }}
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.databasePassword "context" $)) $ }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "databasePassword") }}
{{- else }}
name: {{ include "freeradius.database.secretName" . }}
key: {{ include "freeradius.database.secretKey" . }}
{{- end }}
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
- name: FREERADIUS_SITES_STATUS_SECRET
valueFrom:
secretKeyRef:
{{- if .Values.auth.existingSecretPerPassword }}
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.sitesStatusSecret "context" $)) $ }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "sitesStatusSecret") }}
{{- else }}
name: {{ $globalSecretName }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecret "key" "sites-status-secret") }}
{{- end }}
{{- end }}
{{- if .Values.sitesEnabled.tls.enabled }}
- name: FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD
valueFrom:
secretKeyRef:
{{- if .Values.auth.existingSecretPerPassword }}
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.sitesTlsPrivKeyPassword "context" $)) $ }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "sitesTlsPrivKeyPassword") }}
{{- else }}
name: {{ $globalSecretName }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecret "key" "sites-tls-privkey-password") }}
{{- end }}
{{- end }}
{{- if .Values.extraEnvVars }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }}
{{- end }}
envFrom:
- configMapRef:
name: {{ include "freeradius.names.envvars" . }}
{{- if .Values.extraEnvVarsCM }}
- configMapRef:
name: {{ .Values.extraEnvVarsCM }}
{{- end }}
{{- if .Values.extraEnvVarsSecret }}
- secretRef:
name: {{ .Values.extraEnvVarsSecret }}
{{- end }}
{{- if .Values.lifecycleHooks }}
lifecycle: {{- include "st-common.tplvalues.render" (dict "value" .Values.lifecycleHooks "context" $) | nindent 12 }}
{{- end }}
ports:
- name: auth
containerPort: {{ .Values.containerPorts.auth }}
protocol: UDP
- name: acct
containerPort: {{ .Values.containerPorts.acct }}
protocol: UDP
{{- if .Values.sitesEnabled.coa.enabled }}
- name: coa
containerPort: {{ .Values.containerPorts.coa }}
protocol: UDP
{{- end }}
{{- if .Values.tls.enabled }}
- name: radsec
containerPort: {{ .Values.containerPorts.radsec }}
protocol: TCP
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
- name: status
containerPort: {{ .Values.containerPorts.status }}
protocol: UDP
{{- end }}
{{- if not .Values.diagnosticMode.enabled }}
{{- if .Values.customStartupProbe }}
startupProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customStartupProbe "context" $) | nindent 12 }}
{{- else if .Values.startupProbe.enabled }}
startupProbe: {{- include "st-common.tplvalues.render" (dict "value" (omit .Values.startupProbe "enabled") "context" $) | nindent 12 }}
exec:
command:
- sh
- -c
- |
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
if [[ ! -f "{{ .Values.persistence.mountPath }}/.user_scripts_initialized" ]]; then
echo "Init scripts still not executed. Skipping check"
exit 1
fi
{{- end }}
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
{{- end }}
{{- if .Values.customLivenessProbe }}
livenessProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customLivenessProbe "context" $) | nindent 12 }}
{{- else if .Values.livenessProbe.enabled }}
livenessProbe: {{- omit .Values.livenessProbe "enabled" | toYaml | nindent 12 }}
exec:
command:
- sh
- -c
- >-
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
{{- end }}
{{- if .Values.customReadinessProbe }}
readinessProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customReadinessProbe "context" $) | nindent 12 }}
{{- else if .Values.readinessProbe.enabled }}
readinessProbe: {{- omit .Values.readinessProbe "enabled" | toYaml | nindent 12 }}
exec:
command:
- sh
- -c
- >-
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
{{- end }}
{{- end }}
{{- if .resources }}
resources: {{- include "st-common.tplvalues.render" (dict "value" .resources "context" $) | nindent 12 }}
{{- else if and .resourcesPreset (ne .resourcesPreset "none") }}
resources: {{- include "st-common.resources.preset" (dict "type" .resourcesPreset) | nindent 12 }}
{{- end }}
{{- if .Values.containerSecurityContext.enabled }}
securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }}
{{- end }}
volumeMounts:
- name: data
mountPath: {{ default "/startechnica/freeradius" .Values.persistence.mountPath }}
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- end }}
{{- if or (.Files.Glob "files/radiusd.conf") .Values.configuration .Values.configurationConfigMap }}
- name: freeradius-config
mountPath: /etc/freeradius/radiusd.conf
subPath: radiusd.conf
{{- end }}
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
- name: custom-init-scripts
mountPath: /docker-entrypoint-initdb.d
{{- end }}
{{- if .Values.modsEnabled.sql.enabled }}
- name: freeradius-mods
mountPath: /etc/freeradius/mods-enabled/sql
subPath: sql
{{- end }}
- name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/default
subPath: default
- name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/status
subPath: status
{{- if .Values.sitesEnabled.coa.enabled }}
- name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/coa
subPath: coa
{{- end }}
{{- if .Values.tls.enabled }}
- name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/tls
subPath: tls
- name: freeradius-tls
mountPath: /opt/startechnica/freeradius/certs
readOnly: true
{{- end }}
{{- if and .Values.modsEnabled.sql.enabled (eq .Values.modsEnabled.sql.dialect "sqlite") }}
- name: freeradius-sqlite
mountPath: {{ .Values.modsEnabled.sql.sqlite.filename | quote }}
{{- end }}
{{- if .Values.modsEnabled.sql.tls.enabled }}
- name: freeradius-sql-tls
mountPath: /opt/startechnica/freeradius/certs
{{- end }}
- name: shared-certs
mountPath: /opt/startechnica/freeradius/shared-certs
readOnly: true
- name: temp
mountPath: /startechnica/freeradius/tmp
{{- if .Values.extraVolumeMounts }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraVolumeMounts "context" $) | nindent 12 }}
{{- end }}
{{- if .Values.sidecars }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.sidecars "context" $) | nindent 8 }}
{{- end }}
volumes:
- name: freeradius-mods
configMap:
name: {{ printf "%s-mods" (include "st-common.names.fullname" .) }}
- name: freeradius-sites
configMap:
name: {{ printf "%s-sites" (include "st-common.names.fullname" .) }}
- name: temp
emptyDir: {}
- name: shared-certs
emptyDir: {}
- name: data
{{- if .Values.persistence.enabled }}
persistentVolumeClaim:
claimName: {{ include "freeradius.claimName" . }}
{{- else }}
emptyDir: {}
{{- end }}
{{- if and .Values.modsEnabled.sql.enabled (eq .Values.modsEnabled.sql.dialect "sqlite") }}
- name: freeradius-sqlite
emptyDir: {}
{{- end }}
{{- if .Values.tls.enabled }}
- name: freeradius-tls
secret:
secretName: {{ include "freeradius.tlsSecretName" . }}
{{- end }}
{{- if .Values.modsEnabled.sql.tls.enabled }}
- name: freeradius-sql-tls
secret:
secretName: {{ include "freeradius.sqlTlsSecretName" . }}
items:
- key: tls.crt
path: sql-tls.crt
- key: tls.key
path: sql-tls.key
- key: ca.crt
path: sql-ca.crt
{{- end }}
{{- if or (.Files.Glob "files/radiusd.conf") .Values.configuration .Values.configurationConfigMap }}
- name: freeradius-config
configMap:
name: {{ include "freeradius.configurationCM" . }}
{{- end }}
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
- name: custom-init-scripts
configMap:
name: {{ include "freeradius.initdbScriptsCM" . }}
{{- end }}
{{- if .Values.extraVolumes }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraVolumes "context" $) | nindent 8 }}
{{- end }}
+69
View File
@@ -0,0 +1,69 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.gateway.enabled (not .Values.gateway.existingGateway) }}
{{- if not (eq (include "st-common.capabilities.istioGateway.apiVersion" .) "false") }}
apiVersion: {{ include "st-common.capabilities.istioGateway.apiVersion" . }}
kind: Gateway
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
{{- end }}
spec:
selector:
istio.io/gateway-name: {{ default "ingressgateway" .Values.gateway.name }}
servers:
- port:
name: auth
number: {{ .Values.service.ports.auth }}
protocol: UDP
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host.name | quote }}
{{- end }}
- port:
name: acct
number: {{ .Values.service.ports.acct }}
protocol: UDP
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host.name | quote }}
{{- end }}
- port:
name: coa
number: {{ .Values.service.ports.coa }}
protocol: UDP
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host.name | quote }}
{{- end }}
- port:
name: radsec
number: {{ .Values.service.ports.radsec }}
protocol: TLS
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host.name | quote }}
{{- end }}
tls:
mode: PASSTHROUGH
{{- if .Values.sitesEnabled.tls.enabled }}
credentialName: {{ include "freeradius.tlsSecretName" . }}
{{- end }}
{{- end }}
{{- end }}
+47
View File
@@ -0,0 +1,47 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.gateway.enabled (not .Values.gateway.existingVirtualService) }}
{{- if not (eq (include "st-common.capabilities.istioVirtualService.apiVersion" .) "false") }}
apiVersion: {{ include "st-common.capabilities.istioVirtualService.apiVersion" . }}
kind: VirtualService
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
{{- end }}
spec:
gateways:
- {{ printf "%s/%s" (include "st-common.names.namespace" .) (include "st-common.names.fullname" .) }}
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host | quote }}
{{- end }}
tls:
- match:
- port: {{ .Values.service.ports.radsec }}
sniHosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host | quote }}
{{- end }}
route:
- destination:
# host: {{ printf "%s.%s.svc.%s" (include "st-common.names.fullname" .) (include "st-common.names.namespace" .) .Values.clusterDomain }}
host: {{ printf "%s.%s.svc.cluster.local" (include "st-common.names.fullname" .) (include "st-common.names.namespace" .) }}
port:
number: {{ .Values.service.ports.radsec }}
{{- end }}
{{- end }}
+57
View File
@@ -0,0 +1,57 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.networkPolicy.enabled }}
apiVersion: {{ include "st-common.capabilities.networkPolicy.apiVersion" . }}
kind: NetworkPolicy
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
spec:
podSelector:
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 6 }}
ingress:
- ports:
- port: {{ .Values.containerPorts.auth }}
protocol: UDP
- port: {{ .Values.containerPorts.acct }}
protocol: UDP
{{- if .Values.tls.enabled }}
- port: {{ .Values.containerPorts.radsec }}
protocol: TCP
{{- end }}
{{- if .Values.metrics.enabled }}
- port: {{ .Values.containerPorts.metrics }}
protocol: TCP
{{- end }}
{{- if .Values.sitesEnabled.coa.enabled }}
- port: {{ .Values.containerPorts.coa }}
protocol: UDP
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
- port: {{ .Values.containerPorts.status }}
protocol: UDP
{{- end }}
{{- if not .Values.networkPolicy.allowExternal }}
from:
- podSelector:
matchLabels:
{{ include "st-common.names.fullname" . }}-client: "true"
- podSelector:
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 14 }}
app.kubernetes.io/component: freeradius
{{- if .Values.networkPolicy.additionalRules }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.networkPolicy.additionalRules "context" $) | nindent 8 }}
{{- end }}
{{- end }}
{{- end }}
+38
View File
@@ -0,0 +1,38 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) -}}
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
{{- if or .Values.persistence.annotations .Values.commonAnnotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
{{- if .Values.persistence.annotations }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.persistence.annotations "context" $ ) | nindent 4 }}
{{- end }}
{{- end }}
spec:
accessModes:
{{- if not (empty .Values.persistence.accessModes) }}
{{- range .Values.persistence.accessModes }}
- {{ . | quote }}
{{- end }}
{{- else }}
- {{ .Values.persistence.accessMode | quote }}
{{- end }}
resources:
requests:
storage: {{ .Values.persistence.size | quote }}
{{- include "st-common.storage.class" (dict "persistence" .Values.persistence "global" .Values.global) | nindent 2 }}
{{- end -}}
+28
View File
@@ -0,0 +1,28 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.podDisruptionBudget.create }}
apiVersion: {{ include "st-common.capabilities.policy.apiVersion" . }}
kind: PodDisruptionBudget
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
spec:
{{- if .Values.podDisruptionBudget.minAvailable }}
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
{{- end }}
{{- if .Values.podDisruptionBudget.maxUnavailable }}
maxUnavailable: {{ .Values.podDisruptionBudget.maxUnavailable }}
{{- end }}
selector:
matchLabels: {{ include "st-common.labels.matchLabels" . | nindent 6 }}
{{- end }}
+25
View File
@@ -0,0 +1,25 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{ if and .Values.metrics.enabled .Values.metrics.prometheusRules.enabled }}
apiVersion: monitoring.coreos.com/v1
kind: PrometheusRule
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.metrics.prometheusRules.additionalLabels "context" $) | nindent 4 }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
spec:
groups:
- name: {{ include "st-common.names.fullname" . }}
rules:
{{- toYaml .Values.metrics.prometheusRules.rules | nindent 6 }}
{{ end }}
+29
View File
@@ -0,0 +1,29 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.rbac.create }}
apiVersion: {{ include "st-common.capabilities.rbac.apiVersion" . }}
kind: Role
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
rules:
- apiGroups:
- ""
resources:
- secrets
- configmaps
verbs:
- get
- list
- watch
{{- end }}
+26
View File
@@ -0,0 +1,26 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.serviceAccount.create .Values.rbac.create }}
apiVersion: {{ include "st-common.capabilities.rbac.apiVersion" . }}
kind: RoleBinding
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
subjects:
- kind: ServiceAccount
name: {{ include "freeradius.serviceAccountName" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: {{ include "st-common.names.fullname" . }}
{{- end }}
+38
View File
@@ -0,0 +1,38 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and (not .Values.auth.existingSecret) (not .Values.auth.existingSecretPerPassword) }}
{{- $secretName := include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecret "context" $) }}
apiVersion: v1
kind: Secret
metadata:
name: {{ $secretName }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
type: Opaque
data:
{{- if and (not .Values.mariadb.enabled) (not .Values.externalDatabase.existingSecret) }}
database-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "database-password" "length" 10 "providedValues" (list "externalDatabase.password") "context" $) }}
{{- end }}
{{- if and (.Values.mariadb.enabled) (not (empty .Values.mariadb.auth.username)) }}
mariadb-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "mariadb-password" "providedValues" (list "mariadb.auth.password") "context" $) }}
{{- end }}
{{- if (.Values.sitesEnabled.status.enabled) }}
sites-status-secret: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "sites-status-secret" "length" 10 "providedValues" (list "sitesEnabled.status.secret") "context" $) }}
{{- end }}
{{- if (.Values.sitesEnabled.tls.enabled) }}
sites-tls-privkey-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "sites-tls-privkey-password" "length" 10 "providedValues" (list "sitesEnabled.tls.privateKeyPassword") "context" $) }}
{{- end }}
{{- if (.Values.modsEnabled.sql.tls.enabled) }}
mods-sql-tls-privkey-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "mods-sql-tls-privkey-password" "length" 10 "providedValues" (list "modsEnabled.sql.tls.privateKeyPassword") "context" $) }}
{{- end }}
{{- end }}
+30
View File
@@ -0,0 +1,30 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and (include "freeradius.createSqlTlsSecret" .) (not .Values.tls.autoGenerator.certmanager.enabled) }}
{{- $ca := genCA "freeradius-ca" 365 }}
{{- $releaseNamespace := include "st-common.names.namespace" . }}
{{- $clusterDomain := .Values.clusterDomain }}
{{- $fullname := include "st-common.names.fullname" . }}
{{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $fullname $releaseNamespace) (printf "%s.%s" $fullname $releaseNamespace) $fullname }}
{{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
apiVersion: v1
kind: Secret
metadata:
name: {{ include "st-common.names.fullname" . }}-sql-tls
namespace: {{ include "st-common.names.namespace" . | quote }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
type: kubernetes.io/tls
data:
ca.crt: {{ $ca.Cert | b64enc | quote }}
tls.crt: {{ $crt.Cert | b64enc | quote }}
tls.key: {{ $crt.Key | b64enc | quote }}
{{- end }}
+30
View File
@@ -0,0 +1,30 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and (include "freeradius.createTlsSecret" .) (not .Values.tls.autoGenerator.certmanager.enabled) }}
{{- $ca := genCA "freeradius-ca" 365 }}
{{- $releaseNamespace := include "st-common.names.namespace" . }}
{{- $clusterDomain := .Values.clusterDomain }}
{{- $fullname := include "st-common.names.fullname" . }}
{{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $fullname $releaseNamespace) (printf "%s.%s" $fullname $releaseNamespace) $fullname }}
{{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
apiVersion: v1
kind: Secret
metadata:
name: {{ include "st-common.names.fullname" . }}-tls
namespace: {{ include "st-common.names.namespace" . | quote }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
type: kubernetes.io/tls
data:
ca.crt: {{ $ca.Cert | b64enc | quote }}
tls.crt: {{ $crt.Cert | b64enc | quote }}
tls.key: {{ $crt.Key | b64enc | quote }}
{{- end }}
+98
View File
@@ -0,0 +1,98 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: Service
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if or .Values.service.annotations .Values.commonAnnotations .Values.metrics.annotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.service.annotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.service.annotations "context" $) | nindent 4 }}
{{- end }}
{{- if and .Values.metrics.enabled .Values.metrics.annotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.metrics.annotations "context" $) | nindent 4 }}
{{- end }}
{{- end }}
spec:
type: {{ default "ClusterIP" .Values.service.type }}
{{- if eq .Values.service.type "LoadBalancer" }}
allocateLoadBalancerNodePorts: {{ eq .Values.service.allocateLoadBalancerNodePorts "true" }}
{{- end }}
{{- if and .Values.service.clusterIP (eq .Values.service.type "ClusterIP") }}
clusterIP: {{ .Values.service.clusterIP }}
{{- end }}
{{- if and .Values.service.externalTrafficPolicy (or (eq .Values.service.type "LoadBalancer") (eq .Values.service.type "NodePort")) }}
externalTrafficPolicy: {{ .Values.service.externalTrafficPolicy | quote }}
{{- end }}
ipFamilyPolicy: {{ .Values.service.ipFamilyPolicy }}
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerClass)) }}
loadBalancerClass: {{ .Values.service.loadBalancerClass }}
{{- end }}
{{- if (and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerIP))) }}
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
{{- end }}
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerSourceRanges)) }}
loadBalancerSourceRanges: {{ .Values.service.loadBalancerSourceRanges }}
{{- end }}
{{- if .Values.service.sessionAffinity }}
sessionAffinity: {{ .Values.service.sessionAffinity }}
{{- end }}
{{- if .Values.service.sessionAffinityConfig }}
sessionAffinityConfig: {{- include "st-common.tplvalues.render" (dict "value" .Values.service.sessionAffinityConfig "context" $) | nindent 4 }}
{{- end }}
ports:
- name: udp-auth
port: {{ .Values.service.ports.auth }}
protocol: UDP
targetPort: {{ .Values.containerPorts.auth }}
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.auth) }}
nodePort: {{ coalesce .Values.service.nodePorts.auth .Values.service.nodePort }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
- name: udp-acct
port: {{ .Values.service.ports.acct }}
protocol: UDP
targetPort: {{ .Values.containerPorts.acct }}
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.acct) }}
nodePort: {{ .Values.service.nodePorts.acct }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- if .Values.sitesEnabled.coa.enabled }}
- name: udp-coa
port: {{ .Values.service.ports.coa }}
protocol: UDP
targetPort: {{ .Values.containerPorts.coa }}
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.coa) }}
nodePort: {{ .Values.service.nodePorts.coa }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- end }}
{{- if .Values.tls.enabled }}
- name: tcp-radsec
port: {{ .Values.service.ports.radsec }}
protocol: TCP
targetPort: {{ .Values.containerPorts.radsec }}
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.radsec) }}
nodePort: {{ .Values.service.nodePorts.radsec }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- end }}
selector: {{ include "st-common.labels.matchLabels" . | nindent 4 }}
app.kubernetes.io/component: freeradius
---
+27
View File
@@ -0,0 +1,27 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.serviceAccount.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "freeradius.serviceAccountName" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if or .Values.serviceAccount.annotations .Values.commonAnnotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.serviceAccount.annotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.serviceAccount.annotations "context" $) | nindent 4 }}
{{- end }}
{{- end }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
{{- end }}
+95
View File
@@ -0,0 +1,95 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* Create a default fully qualified app name. We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). */}}
{{- define "freeradius.mariadb.fullname" -}}
{{- include "st-common.names.dependency.fullname" (dict "chartName" "mariadb" "chartValues" .Values.mariadb "context" $) -}}
{{- end -}}
{{/* Return the Database hostname */}}
{{- define "freeradius.database.host" -}}
{{- if eq .Values.mariadb.architecture "replication" }}
{{- ternary (include "freeradius.mariadb.fullname" .) .Values.externalDatabase.host .Values.mariadb.enabled -}}-primary
{{- else -}}
{{- ternary (include "freeradius.mariadb.fullname" .) .Values.externalDatabase.host .Values.mariadb.enabled -}}
{{- end -}}
{{- end -}}
{{/* Return the Database port */}}
{{- define "freeradius.database.port" -}}
{{- ternary "3306" .Values.externalDatabase.port .Values.mariadb.enabled | quote -}}
{{- end -}}
{{/* Return the Database database name */}}
{{- define "freeradius.database.name" -}}
{{- if .Values.mariadb.enabled }}
{{- if .Values.global.mariadb }}
{{- if .Values.global.mariadb.auth }}
{{- coalesce .Values.global.mariadb.auth.database .Values.mariadb.auth.database -}}
{{- else -}}
{{- .Values.mariadb.auth.database -}}
{{- end -}}
{{- else -}}
{{- .Values.mariadb.auth.database -}}
{{- end -}}
{{- else -}}
{{- .Values.externalDatabase.database -}}
{{- end -}}
{{- end -}}
{{/* Return the Database user */}}
{{- define "freeradius.database.user" -}}
{{- if .Values.mariadb.enabled }}
{{- if .Values.global.mariadb }}
{{- if .Values.global.mariadb.auth }}
{{- coalesce .Values.global.mariadb.auth.username .Values.mariadb.auth.username -}}
{{- else -}}
{{- .Values.mariadb.auth.username -}}
{{- end -}}
{{- else -}}
{{- .Values.mariadb.auth.username -}}
{{- end -}}
{{- else -}}
{{- .Values.externalDatabase.user -}}
{{- end -}}
{{- end -}}
{{/* Return the Database encrypted password */}}
{{- define "freeradius.database.secretName" -}}
{{- if .Values.mariadb.enabled }}
{{- if .Values.global.mariadb }}
{{- if .Values.global.mariadb.auth }}
{{- if .Values.global.mariadb.auth.existingSecret }}
{{- tpl .Values.global.mariadb.auth.existingSecret $ -}}
{{- else -}}
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
{{- end -}}
{{- else -}}
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
{{- end -}}
{{- else -}}
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
{{- end -}}
{{- else -}}
{{- default (include "st-common.secrets.name" (dict "existingSecret" .Values.mariadb.auth.existingSecret "context" $)) (tpl .Values.externalDatabase.existingSecret $) -}}
{{- end -}}
{{- end -}}
{{/* Add environment variables to configure database values */}}
{{- define "freeradius.database.secretKey" -}}
{{- if .Values.mariadb.enabled -}}
{{- print "mariadb-password" -}}
{{- else -}}
{{- if .Values.externalDatabase.existingSecret -}}
{{- if .Values.externalDatabase.existingSecretPasswordKey -}}
{{- printf "%s" .Values.externalDatabase.existingSecretPasswordKey -}}
{{- else -}}
{{- print "database-password" -}}
{{- end -}}
{{- else -}}
{{- print "database-password" -}}
{{- end -}}
{{- end -}}
{{- end -}}
+140
View File
@@ -0,0 +1,140 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* Create the name of the service account to use */}}
{{- define "freeradius.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "st-common.names.fullname" .) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}
{{/* Return the path to the cert file. */}}
{{- define "freeradius.tlsCert" -}}
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/tls.crt" -}}
{{- else -}}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certFilename -}}
{{- end -}}
{{- end -}}
{{/* Return the path to the cert key file. */}}
{{- define "freeradius.tlsCertKey" -}}
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/tls.key" -}}
{{- else -}}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certKeyFilename -}}
{{- end -}}
{{- end -}}
{{/* Return the path to the CA cert file. */}}
{{- define "freeradius.tlsCACert" -}}
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/ca.crt" -}}
{{- else -}}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certCAFilename -}}
{{- end -}}
{{- end -}}
{{/* Create the name of the SSL certificate to use */}}
{{- define "freeradius.tlsSecretName" -}}
{{- if .Values.tls.certificatesSecret }}
{{ .Values.tls.certificatesSecret }}
{{- else }}
{{- default (printf "%s-tls" (include "st-common.names.fullname" .)) }}
{{- end }}
{{- end -}}
{{/* Return true if a TLS secret object should be created */}}
{{- define "freeradius.createTlsSecret" -}}
{{- if and .Values.tls.enabled .Values.tls.autoGenerated (not .Values.tls.certificatesSecret) }}
{{- true }}
{{- end }}
{{- end -}}
{{/* Validate values of FreeRADIUS - Auth TLS enabled */}}
{{- define "freeradius.validateValues.tls" -}}
{{- if and .Values.tls.enabled (not .Values.tls.autoGenerated) (not .Values.tls.certificatesSecret) }}
freeradius: tls.enabled
In order to enable TLS, you also need to provide
an existing secret containing the Keystore and Truststore or
enable auto-generated certificates.
{{- end }}
{{- end -}}
{{/* Return the path to the SQL cert file. */}}
{{- define "freeradius.sqlTlsCert" -}}
{{- if and .Values.modsEnabled.sql.tls.enabled }}
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/sql-tls.crt" -}}
{{- else if not (empty .Values.modsEnabled.sql.tls.certFilename) }}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certFilename -}}
{{- end }}
{{- else }}
{{- printf "" -}}
{{- end }}
{{- end -}}
{{/* Return the path to the SQL cert key file. */}}
{{- define "freeradius.sqlTlsCertKey" -}}
{{- if and .Values.modsEnabled.sql.tls.enabled }}
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/sql-tls.key" -}}
{{- else if not (empty .Values.modsEnabled.sql.tls.certKeyFilename) }}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certKeyFilename -}}
{{- end }}
{{- else }}
{{- printf "" -}}
{{- end }}
{{- end -}}
{{/* Return the path to the SQL CA cert file. */}}
{{- define "freeradius.sqlTlsCACert" -}}
{{- if and .Values.modsEnabled.sql.tls.enabled }}
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/sql-ca.crt" -}}
{{- else if not (empty .Values.modsEnabled.sql.tls.certCAFilename)}}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certCAFilename -}}
{{- end }}
{{- else }}
{{- printf "" -}}
{{- end }}
{{- end -}}
{{/* Create the name of the secret for SQL SSL certificate to use */}}
{{- define "freeradius.sqlTlsSecretName" -}}
{{- if .Values.modsEnabled.sql.tls.certificatesSecret }}
{{ .Values.modsEnabled.sql.tls.certificatesSecret }}
{{- else }}
{{- default (printf "%s-sql-tls" (include "st-common.names.fullname" .)) }}
{{- end }}
{{- end -}}
{{/* Return true if a TLS secret object should be created */}}
{{- define "freeradius.createSqlTlsSecret" -}}
{{- if and .Values.modsEnabled.sql.tls.enabled .Values.modsEnabled.sql.tls.autoGenerated (not .Values.modsEnabled.sql.tls.certificatesSecret) }}
{{- true }}
{{- end }}
{{- end -}}
{{/* Get the configuration ConfigMap name. */}}
{{- define "freeradius.configurationCM" -}}
{{- if .Values.configurationConfigMap -}}
{{- printf "%s" (tpl .Values.configurationConfigMap $) -}}
{{- else -}}
{{- printf "%s-configuration" (include "st-common.names.fullname" .) -}}
{{- end -}}
{{- end -}}
{{/* Get the initialization scripts ConfigMap name. */}}
{{- define "freeradius.initdbScriptsCM" -}}
{{- if .Values.initdbScriptsConfigMap -}}
{{- printf "%s" .Values.initdbScriptsConfigMap -}}
{{- else -}}
{{- printf "%s-init-scripts" (include "st-common.names.fullname" .) -}}
{{- end -}}
{{- end -}}
+14
View File
@@ -0,0 +1,14 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* Return the proper FreeRADIUS image name */}}
{{- define "freeradius.image" -}}
{{ include "st-common.images.image" (dict "imageRoot" .Values.image "global" .Values.global) }}
{{- end -}}
{{/* Return the proper Docker Image Registry Secret Names */}}
{{- define "freeradius.imagePullSecrets" -}}
{{- include "st-common.images.pullSecrets" (dict "images" (list .Values.image .Values.volumePermissions.image .Values.metrics.image) "global" .Values.global) -}}
{{- end -}}
+10
View File
@@ -0,0 +1,10 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* vim: set filetype=mustache: */}}
{{- define "freeradius.names.envvars" -}}
{{- printf "%s-envvars" (include "st-common.names.fullname" .) -}}
{{- end -}}
+18
View File
@@ -0,0 +1,18 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* Return the FreeRADIUS PVC name. */}}
{{- define "freeradius.claimName" -}}
{{- if .Values.persistence.existingClaim }}
{{- printf "%s" (tpl .Values.persistence.existingClaim $) -}}
{{- else }}
{{- printf "%s" (include "st-common.names.fullname" .) -}}
{{- end }}
{{- end -}}
{{/* Return the proper image name (for the init container volume-permissions image) */}}
{{- define "freeradius.volumePermissions.image" -}}
{{ include "st-common.images.image" (dict "imageRoot" .Values.volumePermissions.image "global" .Values.global) }}
{{- end -}}