diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index a34ea48..31efc0a 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -8,7 +8,7 @@ stages: variables: CHART_NAME: "freeradius" - CHART_VERSION: "1.0.11" + CHART_VERSION: "1.0.12" PACKAGE_PATH: "packages" ST_COMMON_PROJECT_ID: "270" COMMON_PROJECT_URL: "${CI_API_V4_URL}/projects/${ST_COMMON_PROJECT_ID}/packages/helm/stable" diff --git a/Chart.yaml b/Chart.yaml index 12465d9..ff4f688 100644 --- a/Chart.yaml +++ b/Chart.yaml @@ -27,4 +27,4 @@ sources: - https://freeradius.org/ - https://github.com/FreeRADIUS/freeradius-server type: application -version: 1.0.11 +version: 1.0.12 diff --git a/files/mods-available/sqlippool b/files/mods-available/sqlippool new file mode 100644 index 0000000..4ec3d78 --- /dev/null +++ b/files/mods-available/sqlippool @@ -0,0 +1,110 @@ +# Configuration for the SQL based IP Pool module (rlm_sqlippool) +# +# The database schemas are available at: +# +# raddb/mods-config/sql/ippool//schema.sql +# +# $Id: f17a9898e906d3db0ad5871d8683f731f7a6baab $ + +sqlippool { + # SQL instance to use (from mods-available/sql) + # + # If you have multiple sql instances, such as "sql sql1 {...}", + # use the *instance* name here: sql1. + sql_module_instance = "sql" + + # This is duplicative of info available in the SQL module, but + # we have to list it here as we do not yet support nested + # reference expansions. + dialect = $ENV{FREERADIUS_MODS_SQL_DIALECT} + + # Name of the check item attribute to be used as a key in the SQL queries + pool_name = "Pool-Name" + + # SQL table to use for ippool range and lease info + ippool_table = $ENV{FREERADIUS_MODS_SQL_TABLE_RADIPPOOL} + + # IP lease duration. (Leases expire even if Acct Stop packet is lost) + # + # Note that you SHOULD also set Session-Timeout to this value! + # That way the NAS will automatically kick the user offline when the + # lease expires. + # + lease_duration = 86400 + + # + # Timeout between each consecutive 'allocate_clear' queries (default: 1s) + # This will avoid having too many deadlock issues, especially on MySQL backend. + # + allocate_clear_timeout = 1 + + # + # The attribute to use for IP address assignment. The + # default is Framed-IP-Address. You can change this to any + # attribute which is IPv4 or IPv6. + # + # e.g. Framed-IPv6-Prefix, or Delegated-IPv6-Prefix. + # + # All of the default queries use this attribute_name. So you + # can do IPv6 address assignment simply by putting IPv6 + # addresses into the pool, and changing the following line to + # "Framed-IPv6-Prefix" + # + # Note that you MUST use separate pools for each attribute. i.e. one pool + # for Framed-IP-Address, a different one for Framed-IPv6-prefix, etc. + # + # This means configuring separate "sqlippool" instances, and different + # "ippool_table" in SQL. Then, populate the pool with addresses and + # it will all just work. + # + attribute_name = Framed-IP-Address + + # + # Assign the IP address, even if the above attribute already exists + # in the reply. + # +# allow_duplicates = no + + # The attribute in which an IP address hint may be supplied + req_attribute_name = Framed-IP-Address + + # Attribute which should be considered unique per NAS + # + # Using NAS-Port gives behaviour similar to rlm_ippool. (And ACS) + # Using Calling-Station-Id works for NAS that send fixed NAS-Port + # ONLY change this if you know what you are doing! + # pool_key = "%{NAS-Port}" + # pool_key = "%{Calling-Station-Id}" + pool_key = "%{User-Name}" + + ################################################################ + # + # WARNING: MySQL (MyISAM) has certain limitations that means it can + # hand out the same IP address to 2 different users. + # + # We suggest using an SQL DB with proper transaction + # support, such as PostgreSQL, or using MySQL + # with InnoDB. + # + ################################################################ + + # These messages are added to the "control" items, as + # Module-Success-Message. They are not logged anywhere else, + # unlike previous versions. If you want to have them logged + # to a file, see the "linelog" module, and create an entry + # which writes Module-Success-Message message. + # + messages { + exists = "Existing IP: %{reply:${..attribute_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})" + + success = "Allocated IP: %{reply:${..attribute_name}} from %{control:${..pool_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})" + + clear = "Released IP %{request:${..attribute_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} user %{User-Name})" + + failed = "IP Allocation FAILED from %{control:${..pool_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})" + + nopool = "No ${..pool_name} defined (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})" + } + + $INCLUDE ${modconfdir}/sql/ippool/${dialect}/queries.conf +} \ No newline at end of file diff --git a/files/schema/mysql.sql b/files/schema/mysql.sql index ef78b2b..fd28aa5 100644 --- a/files/schema/mysql.sql +++ b/files/schema/mysql.sql @@ -163,3 +163,22 @@ CREATE TABLE IF NOT EXISTS nas ( PRIMARY KEY (id), KEY nasname (nasname) ) ENGINE = INNODB; + +# +# Table structure for table 'radippool' +# +CREATE TABLE IF NOT EXISTS radippool ( + id int(11) unsigned NOT NULL auto_increment, + pool_name varchar(30) NOT NULL, + framedipaddress varchar(15) NOT NULL default '', + nasipaddress varchar(15) NOT NULL default '', + calledstationid VARCHAR(30) NOT NULL default '', + callingstationid VARCHAR(30) NOT NULL default '', + expiry_time DATETIME NOT NULL default NOW(), + username varchar(64) NOT NULL default '', + pool_key varchar(64) NOT NULL default '', + PRIMARY KEY (id), + KEY radippool_poolname_expire (pool_name, expiry_time), + UNIQUE KEY framedipaddress_unique (framedipaddress), + KEY radippool_nasip_poolkey_ipaddress (nasipaddress, pool_key, framedipaddress) +) ENGINE=InnoDB; \ No newline at end of file diff --git a/files/sites-available/default b/files/sites-available/default index f287d0a..b77ca8f 100644 --- a/files/sites-available/default +++ b/files/sites-available/default @@ -619,7 +619,7 @@ accounting { # Return an address to the IP Pool when we see a stop record. # Ensure that &control:Pool-Name is set to determine which pool of IPs are used. -# sqlippool + sqlippool # Log traffic to an SQL database. # See "Accounting queries" in mods-available/sql @@ -752,7 +752,7 @@ post-auth { # # Ensure that &control:Pool-Name is set to determine which # pool of IPs are used. -# sqlippool + sqlippool # Create the CUI value and add the attribute to Access-Accept. diff --git a/templates/ConfigMap/envvars.yaml b/templates/ConfigMap/envvars.yaml index 2b6b3a1..2194e23 100644 --- a/templates/ConfigMap/envvars.yaml +++ b/templates/ConfigMap/envvars.yaml @@ -38,6 +38,7 @@ data: FREERADIUS_MODS_SQL_TABLE_GROUPREPLY: {{ .Values.modsEnabled.sql.table.groupreply }} FREERADIUS_MODS_SQL_TABLE_POSTAUTH: {{ .Values.modsEnabled.sql.table.postauth }} FREERADIUS_MODS_SQL_TABLE_USERGROUP: {{ .Values.modsEnabled.sql.table.usergroup }} + FREERADIUS_MODS_SQL_TABLE_RADIPPOOL: {{ .Values.modsEnabled.sql.table.sqlippool }} FREERADIUS_MODS_SQL_TLS_ENABLE: {{ ternary "yes" "no" .Values.modsEnabled.sql.tls.enabled | quote }} FREERADIUS_MODS_SQL_READ_CLIENTS: {{ ternary "yes" "no" .Values.modsEnabled.sql.readClients | quote }} diff --git a/templates/ConfigMap/mods-enabled.yaml b/templates/ConfigMap/mods-enabled.yaml index 3302c81..4393ecd 100644 --- a/templates/ConfigMap/mods-enabled.yaml +++ b/templates/ConfigMap/mods-enabled.yaml @@ -18,6 +18,7 @@ metadata: data: {{ (.Files.Glob "files/mods-available/eap").AsConfig | indent 2 }} {{ (.Files.Glob "files/mods-available/dynamic_clients").AsConfig | indent 2 }} +{{ (.Files.Glob "files/mods-available/sqlippool").AsConfig | indent 2 }} {{- if .Values.modsEnabled.sql.enabled }} {{ (.Files.Glob "files/mods-available/sql").AsConfig | indent 2 }} {{- end }} diff --git a/templates/Deployment.yaml b/templates/Deployment.yaml index 3a60f6a..4af19a5 100644 --- a/templates/Deployment.yaml +++ b/templates/Deployment.yaml @@ -280,6 +280,9 @@ spec: - name: freeradius-mods mountPath: /etc/freeradius/mods-enabled/dynamic_clients subPath: dynamic_clients + - name: freeradius-mods + mountPath: /etc/freeradius/mods-enabled/sqlippool + subPath: sqlippool - name: freeradius-mods-config mountPath: /etc/freeradius/mods-config/sql/main/mysql/queries.conf subPath: queries.conf diff --git a/values.yaml b/values.yaml index c45687a..3c19d04 100644 --- a/values.yaml +++ b/values.yaml @@ -825,6 +825,7 @@ modsEnabled: groupreply: radgroupreply postauth: radpostauth usergroup: radusergroup + sqlippool: radippool ## @param modsEnabled.sql.groupAttribute The group attribute specific to this instance of rlm_sql ## groupAttribute: SQL-Group