From a08dcf69837c865c534b8e36dded4433463f4627 Mon Sep 17 00:00:00 2001 From: "noussair.hamrit" Date: Tue, 1 Jul 2025 12:13:43 +0200 Subject: [PATCH] feat(radius): enable dynamic client support via SQL `nas` table - Activated `dynamic_clients` module to allow loading RADIUS clients dynamically from the database - Configured SQL query to fetch client secret, shortname, and type based on Packet-Src-IP-Address - Integrated `dynamic_clients` into the `authorize` section for real-time NAS resolution - Eliminated need to restart FreeRADIUS when adding new NAS entries --- .gitlab-ci.yml | 2 +- Chart.yaml | 2 +- files/mods-available/dynamic_clients | 41 +++++++++++++++++++++++++++ files/sites-available/default | 1 + templates/ConfigMap/mods-enabled.yaml | 1 + templates/Deployment.yaml | 5 +++- 6 files changed, 49 insertions(+), 3 deletions(-) create mode 100644 files/mods-available/dynamic_clients diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 91d011f..d0aabe5 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -8,7 +8,7 @@ stages: variables: CHART_NAME: "freeradius" - CHART_VERSION: "1.0.7" + CHART_VERSION: "1.0.8" PACKAGE_PATH: "packages" HELM_EXPERIMENTAL_OCI: "1" diff --git a/Chart.yaml b/Chart.yaml index e5fbee7..c02f274 100644 --- a/Chart.yaml +++ b/Chart.yaml @@ -31,4 +31,4 @@ sources: - https://freeradius.org/ - https://github.com/FreeRADIUS/freeradius-server type: application -version: 1.0.7 +version: 1.0.8 diff --git a/files/mods-available/dynamic_clients b/files/mods-available/dynamic_clients new file mode 100644 index 0000000..894403a --- /dev/null +++ b/files/mods-available/dynamic_clients @@ -0,0 +1,41 @@ +# -*- text -*- +# +# $Id: cc2bd5fd22aa473b98af5dde3fac7a66e39a9e9d $ + +# This module loads RADIUS clients as needed, rather than when the server +# starts. +# +# There are no configuration entries for this module. Instead, it +# relies on the "client" configuration. You must: +# +# 1) link raddb/sites-enabled/dynamic_clients to +# raddb/sites-available/dynamic_clients +# +# 2) Define a client network/mask (see top of the above file) +# +# 3) uncomment the "directory" entry in that client definition +# +# 4) list "dynamic_clients" in the "authorize" section of the +# "dynamic_clients' virtual server. The default example already +# does this. +# +# 5) put files into the above directory, one per IP. +# e.g. file "192.0.2.1" should contain a normal client definition +# for a client with IP address 192.0.2.1. +# +# For more documentation, see the file: +# +# raddb/sites-available/dynamic-clients +# +dynamic_clients { + sql = "SELECT secret, shortname, type FROM nas WHERE nasname = '%{Packet-Src-IP-Address}'" + + key = "%{Packet-Src-IP-Address}" + + client { + ipaddr = "%{Packet-Src-IP-Address}" + secret = "%{reply:secret}" + shortname = "%{reply:shortname}" + nastype = "%{reply:type}" + } +} \ No newline at end of file diff --git a/files/sites-available/default b/files/sites-available/default index 75ff190..e32b45e 100644 --- a/files/sites-available/default +++ b/files/sites-available/default @@ -282,6 +282,7 @@ listen { # Make *sure* that 'preprocess' comes before any realm if you # need to setup hints for the remote radius server authorize { + dynamic_clients # # Take a User-Name, and perform some checks on it, for spaces and other # invalid characters. If the User-Name appears invalid, reject the diff --git a/templates/ConfigMap/mods-enabled.yaml b/templates/ConfigMap/mods-enabled.yaml index dd9a935..3302c81 100644 --- a/templates/ConfigMap/mods-enabled.yaml +++ b/templates/ConfigMap/mods-enabled.yaml @@ -17,6 +17,7 @@ metadata: {{- end }} data: {{ (.Files.Glob "files/mods-available/eap").AsConfig | indent 2 }} +{{ (.Files.Glob "files/mods-available/dynamic_clients").AsConfig | indent 2 }} {{- if .Values.modsEnabled.sql.enabled }} {{ (.Files.Glob "files/mods-available/sql").AsConfig | indent 2 }} {{- end }} diff --git a/templates/Deployment.yaml b/templates/Deployment.yaml index 19efeba..501bb7e 100644 --- a/templates/Deployment.yaml +++ b/templates/Deployment.yaml @@ -276,7 +276,10 @@ spec: {{- end }} - name: freeradius-mods mountPath: /etc/freeradius/mods-enabled/eap - subPath: eap + subPath: eap + - name: freeradius-mods + mountPath: /etc/freeradius/mods-enabled/dynamic_clients + subPath: dynamic_clients - name: freeradius-sites mountPath: /etc/freeradius/sites-enabled/default subPath: default