8 Commits
60 changed files with 218 additions and 9793 deletions
-1
View File
@@ -1 +0,0 @@
charts/
-62
View File
@@ -1,62 +0,0 @@
default:
tags:
- docker-test
stages:
- package
- publish
variables:
CHART_NAME: "freeradius"
CHART_VERSION: "1.0.12"
PACKAGE_PATH: "packages"
ST_COMMON_PROJECT_ID: "270"
COMMON_PROJECT_URL: "${CI_API_V4_URL}/projects/${ST_COMMON_PROJECT_ID}/packages/helm/stable"
HELM_EXPERIMENTAL_OCI: "1"
GITEA_URL: "gitea.infrastructure.helmholz.cloud"
GITEA_REPO: "oci://gitea.infrastructure.helmholz.cloud/gitea_admin/helm"
package_chart:
stage: package
image:
name: alpine/helm:3.14.0
entrypoint: [""]
script:
- helm repo add st-common ${COMMON_PROJECT_URL} --username gitlab-ci-token --password $CI_JOB_TOKEN
- helm dependency build .
- mkdir -p $PACKAGE_PATH
- helm package . --destination $PACKAGE_PATH
artifacts:
paths:
- ${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz
publish_chart:
stage: publish
image: alpine/curl:8.14.1
script:
- |
curl --fail-with-body --request POST \
--user gitlab-ci-token:$CI_JOB_TOKEN \
--form "chart=@${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz" \
"${CI_API_V4_URL}/projects/${CI_PROJECT_ID}/packages/helm/api/stable/charts"
only:
- main
push_chart_to_gitea:
stage: publish
image:
name: alpine/helm:3.14.0
entrypoint: [""]
variables:
GITEA_URL: "https://gitea.infrastructure.helmholz.cloud"
GITEA_USERNAME: "gitea_admin"
GITEA_PASSWORD: "$GITEA_PASSWORD"
script:
- echo "$GITEA_PASSWORD" | helm registry login $GITEA_URL --username $GITEA_USERNAME --password-stdin
- helm push ${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz $GITEA_REPO
when: manual
only:
- main
dependencies:
- package_chart
-1
View File
@@ -1 +0,0 @@
.git/
-6
View File
@@ -1,6 +0,0 @@
dependencies:
- name: st-common
repository: https://gitlab/api/v4/projects/270/packages/helm/stable
version: 0.1.12
digest: sha256:effc27041fec14dd47ce67b96daae936455482afe0a2d3d6069ebffd7e33ba2c
generated: "2026-02-03T12:45:51.347388527+01:00"
-30
View File
@@ -1,30 +0,0 @@
annotations:
category: AccessManagement
apiVersion: v2
appVersion: 3.2.7
dependencies:
- name: st-common
repository: https://gitlab/api/v4/projects/270/packages/helm/stable
version: 0.1.12
description: FreeRADIUS is a modular, high performance free RADIUS suite developed
and distributed under the GNU General Public License, version 2, and is free for
download and use.
home: https://github.com/startechnica/apps/tree/main/charts/freeradius
icon: https://freeradius.org/img/wordmark.svg
keywords:
- freeradius
- radius
- mysql
- postgresql
- ldap
kubeVersion: '>=1.24.0-0'
maintainers:
- email: firmansyah@nainggolan.id
name: firmansyahn
url: https://firmansyah.nainggolan.id
name: freeradius
sources:
- https://freeradius.org/
- https://github.com/FreeRADIUS/freeradius-server
type: application
version: 1.0.12
+59 -291
View File
@@ -1,325 +1,93 @@
<!--- app-name: FreeRADIUS -->
# FreeRADIUS
# Helm chart for FreeRADIUS
FreeRADIUS is a modular, high performance free RADIUS suite developed and distributed under the GNU General Public License, version 2, and is free for download and use.
[Overview of FreeRADIUS](https://freeradius.org/)
## Getting started
**This chart is not maintained by the upstream project and any issues with the chart should be raised [here](https://github.com/startechnica/apps/issues/new/choose)**
To make it easy for you to get started with GitLab, here's a list of recommended next steps.
## TL;DR
Already a pro? Just edit this README.md and make it your own. Want to make it easy? [Use the template at the bottom](#editing-this-readme)!
```console
helm repo add startechnica https://startechnica.github.io/apps
helm install my-release startechnica/freeradius
## Add your files
- [ ] [Create](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#create-a-file) or [upload](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#upload-a-file) files
- [ ] [Add files using the command line](https://docs.gitlab.com/topics/git/add_files/#add-files-to-a-git-repository) or push an existing Git repository with the following command:
```
cd existing_repo
git remote add origin https://gitlab/next-gen-portal/argocd-project/freeradius.git
git branch -M main
git push -uf origin main
```
## Prerequisites
## Integrate with your tools
- Kubernetes 1.22+
- Helm 3.10.0+
- [ ] [Set up project integrations](https://gitlab/next-gen-portal/argocd-project/freeradius/-/settings/integrations)
## Installing the Chart
## Collaborate with your team
To install the chart with the release name `my-release` on `my-release` namespace:
- [ ] [Invite team members and collaborators](https://docs.gitlab.com/ee/user/project/members/)
- [ ] [Create a new merge request](https://docs.gitlab.com/ee/user/project/merge_requests/creating_merge_requests.html)
- [ ] [Automatically close issues from merge requests](https://docs.gitlab.com/ee/user/project/issues/managing_issues.html#closing-issues-automatically)
- [ ] [Enable merge request approvals](https://docs.gitlab.com/ee/user/project/merge_requests/approvals/)
- [ ] [Set auto-merge](https://docs.gitlab.com/user/project/merge_requests/auto_merge/)
```console
helm repo add startechnica https://startechnica.github.io/apps
helm install my-release startechnica/freeradius --namespace my-release --create-namespace
```
## Test and Deploy
These commands deploy FreeRADIUS on the Kubernetes cluster in the default configuration.
Use the built-in continuous integration in GitLab.
> **Tip**: List all releases using `helm list -A`
- [ ] [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
- [ ] [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
- [ ] [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
- [ ] [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
- [ ] [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)
## Uninstalling the Chart
***
To uninstall/delete the `my-release` deployment:
# Editing this README
```console
helm delete my-release --namespace my-release
```
When you're ready to make this README your own, just edit this file and use the handy template below (or feel free to structure it however you want - this is just a starting point!). Thanks to [makeareadme.com](https://www.makeareadme.com/) for this template.
The command removes all the Kubernetes components associated with the chart and deletes the release.
## Suggestions for a good README
## Parameters
Every project is different, so consider which of these sections apply to yours. The sections used in the template are suggestions for most open source projects. Also keep in mind that while a README can be too long and detailed, too long is better than too short. If you think your README is too long, consider utilizing another form of documentation rather than cutting out information.
### Global parameters
## Name
Choose a self-explaining name for your project.
| Name | Description | Value |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ----- |
| `global.imageRegistry` | Global Docker image registry | `""` |
| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` |
| `global.storageClass` | Global StorageClass for Persistent Volume(s) | `""` |
| `global.namespaceOverride` | Override the namespace for resource deployed by the chart, but can itself be overridden by the local namespaceOverride | `""` |
## Description
Let people know what your project can do specifically. Provide context and add a link to any reference visitors might be unfamiliar with. A list of Features or a Background subsection can also be added here. If there are alternatives to your project, this is a good place to list differentiating factors.
## Badges
On some READMEs, you may see small images that convey metadata, such as whether or not all the tests are passing for the project. You can use Shields to add some to your README. Many services also have instructions for adding a badge.
### Common parameters
## Visuals
Depending on what you are making, it can be a good idea to include screenshots or even a video (you'll frequently see GIFs rather than actual videos). Tools like ttygif can help, but check out Asciinema for a more sophisticated method.
| Name | Description | Value |
| -------------------------- | ----------------------------------------------------------------------------------------------------------------- | --------------- |
| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `""` |
| `nameOverride` | String to partially override common.names.fullname template with a string (will prepend the release name) | `""` |
| `namespaceOverride` | String to fully override common.names.namespace | `""` |
| `fullnameOverride` | String to fully override common.names.fullname template with a string | `""` |
| `commonAnnotations` | Annotations to add to all deployed objects | `{}` |
| `commonLabels` | Labels to add to all deployed objects | `{}` |
| `schedulerName` | Name of the Kubernetes scheduler (other than default) | `""` |
| `clusterDomain` | Kubernetes DNS Domain name to use | `cluster.local` |
| `extraDeploy` | Array of extra objects to deploy with the release (evaluated as a template) | `[]` |
| `diagnosticMode.enabled` | Enable diagnostic mode (all probes will be disabled and the command will be overridden) | `false` |
| `diagnosticMode.command` | Command to override all containers in the deployment | `[]` |
| `diagnosticMode.args` | Args to override all containers in the deployment | `[]` |
### FreeRADIUS parameters
## Installation
Within a particular ecosystem, there may be a common way of installing things, such as using Yarn, NuGet, or Homebrew. However, consider the possibility that whoever is reading your README is a novice and would like more guidance. Listing specific steps helps remove ambiguity and gets people to using your project as quickly as possible. If it only runs in a specific context like a particular programming language version or operating system or has dependencies that have to be installed manually, also add a Requirements subsection.
| Name | Description | Value |
| ----------------------------------------------| -------------------------------------------------------------------------------------------------------------------------| -------------------------------|
| `image.registry` | FreeRADIUS image registry | `docker.io` |
| `image.repository` | FreeRADIUS image repository | `freeradius/freeradius-server` |
| `image.tag` | FreeRADIUS image tag (immutable tags are recommended) | `3.2.3` |
| `image.pullPolicy` | FreeRADIUS image pull policy | `IfNotPresent` |
| `image.pullSecrets` | Specify docker-registry secret names as an array | `[]` |
| `image.debug` | Set to true if you would like to see extra information on logs | `false` |
| `hostAliases` | Deployment pod host aliases | `[]` |
| `command` | Override default container command (useful when using custom images) | `[]` |
| `args` | Override default container args (useful when using custom images) | `[]` |
| `extraEnvVars` | Extra environment variables to be set on FreeRADIUS containers | `[]` |
| `extraEnvVarsCM` | ConfigMap with extra environment variables | `""` |
| `extraEnvVarsSecret` | Secret with extra environment variables | `""` |
| `service.type` | Kubernetes service type | `ClusterIP` |
| `service.clusterIP` | Specific cluster IP when service type is cluster IP. Use `None` for headless service | `""` |
| `service.ports.auth` | FreeRADIUS Authentication and Authorization service port | `1812` |
| `service.ports.acct` | FreeRADIUS Accounting service port | `1813` |
| `service.ports.coa` | FreeRADIUS CoA service port | `3799` |
| `service.ports.radsec` | FreeRADIUS RadSec service port | `2083` |
| `service.ports.status` | FreeRADIUS Status service port | `18121` |
| `service.nodePorts.auth` | Specify the nodePort value for the LoadBalancer and NodePort for Authentication service types. | `""` |
| `service.nodePorts.acct` | Specify the nodePort value for the LoadBalancer and NodePort for Accounting service types. | `""` |
| `service.nodePorts.coa` | Specify the nodePort value for the LoadBalancer and NodePort for CoA service types. | `""` |
| `service.nodePorts.radsec` | Specify the nodePort value for the LoadBalancer and NodePort for RadSec service types. | `""` |
| `service.nodePorts.status` | Specify the nodePort value for the LoadBalancer and NodePort for Status service types. | `""` |
| `service.extraPorts` | Extra ports to expose (normally used with the `sidecar` value) | `[]` |
| `service.externalIPs` | External IP list to use with ClusterIP service type | `[]` |
| `service.loadBalancerIP` | `loadBalancerIP` if service type is `LoadBalancer` | `""` |
| `service.loadBalancerSourceRanges` | Addresses that are allowed when svc is `LoadBalancer` | `[]` |
| `service.externalTrafficPolicy` | FreeRADIUS service external traffic policy | `Cluster` |
| `service.annotations` | Additional annotations for FreeRADIUS service | `{}` |
| `service.sessionAffinity` | Session Affinity for Kubernetes service, can be `None` or `ClientIP` | `None` |
| `service.sessionAffinityConfig` | Additional settings for the sessionAffinity | `{}` |
| `serviceAccount.create` | Specify whether a ServiceAccount should be created | `false` |
| `serviceAccount.name` | Name of the service account to use. If not set and create is true, a name is generated using the fullname template. | `""` |
| `serviceAccount.automountServiceAccountToken` | Automount service account token for the server service account | `false` |
| `serviceAccount.annotations` | Annotations for service account. Evaluated as a template. Only used if `create` is `true`. | `{}` |
| `command` | Override default container command (useful when using custom images) | `[]` |
| `extraEnvVars` | Array containing extra env vars to configure FreeRADIUS | `[]` |
| `extraEnvVarsCM` | ConfigMap containing extra env vars to configure FreeRADIUS | `""` |
| `extraEnvVarsSecret` | Secret containing extra env vars to configure FreeRADIUS | `""` |
| `rbac.create` | Specify whether RBAC resources should be created and used | `false` |
| `podSecurityContext.enabled` | Enable security context | `true` |
| `podSecurityContext.fsGroup` | Group ID for the container filesystem | `101` |
| `podSecurityContext.runAsUser` | User ID for the container | `101` |
| `containerSecurityContext.enabled` | Enabled FreeRADIUS container Security Context | `true` |
| `containerSecurityContext.runAsUser` | Set FreeRADIUS container Security Context runAsUser | `101` |
| `containerSecurityContext.runAsNonRoot` | Set FreeRADIUS container Security Context runAsNonRoot | `true` |
| `tls.enabled` | Enable TLS support for replication traffic | `false` |
| `tls.autoGenerated` | Generate automatically self-signed TLS certificates | `false` |
| `tls.autoGenerator.certmanager.enabled` | | `false` |
| `tls.certificatesSecret` | Name of the secret that contains the certificates | `"false"` |
| `tls.certFilename` | Certificate filename | `""` |
| `tls.certKeyFilename` | Certificate key filename | `""` |
| `tls.certCAFilename` | CA Certificate filename | `""` |
| `configuration` | Configuration for the FreeRADIUS server (`radiusd.conf`) | `""` |
| `configurationConfigMap` | ConfigMap with the FreeRADIUS configuration files (Note: Overrides `configuration`). The value is evaluated as a template. | `""` |
| `initdbScripts` | Specify dictionary of scripts to be run at first boot | `{}` |
| `initdbScriptsConfigMap` | ConfigMap with the initdb scripts (Note: Overrides `initdbScripts`) | `""` |
| `extraFlags` | FreeRADIUS additional command line flags | `""` |
| `replicaCount` | Desired number of cluster nodes | `3` |
| `podLabels` | Extra labels for FreeRADIUS pods | `{}` |
| `podAnnotations` | Annotations for FreeRADIUS pods | `{}` |
| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` |
| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` |
| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` |
| `nodeAffinityPreset.key` | Node label key to match. Ignored if `affinity` is set. | `""` |
| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` |
| `affinity` | Affinity for pod assignment | `{}` |
| `nodeSelector` | Node labels for pod assignment | `{}` |
| `tolerations` | Tolerations for pod assignment | `[]` |
| `topologySpreadConstraints` | Topology Spread Constraints for pods assignment | `[]` |
| `lifecycleHooks` | for the galera container(s) to automate configuration before or after startup | `{}` |
| `containerPorts.auth` | Auth database container port | `1812` |
| `containerPorts.acct` | Acct cluster container port | `1813` |
| `containerPorts.coa` | CoA container port | `3799` |
| `containerPorts.radsec` | RadSec container port | `2083` |
| `containerPorts.status` | Status container port | `18121` |
| `persistence.enabled` | Enable persistence using PVC | `true` |
| `persistence.existingClaim` | Provide an existing `PersistentVolumeClaim` | `""` |
| `persistence.subPath` | Subdirectory of the volume to mount | `""` |
| `persistence.mountPath` | Path to mount the volume at | `/startechnica/freeradius` |
| `persistence.selector` | Selector to match an existing Persistent Volume (this value is evaluated as a template) | `{}` |
| `persistence.storageClass` | Persistent Volume Storage Class | `""` |
| `persistence.annotations` | Persistent Volume Claim annotations | `{}` |
| `persistence.labels` | Persistent Volume Claim Labels | `{}` |
| `persistence.accessModes` | Persistent Volume Access Modes | `["ReadWriteOnce"]` |
| `persistence.size` | Persistent Volume Size | `8Gi` |
| `priorityClassName` | Priority Class Name for Statefulset | `""` |
| `initContainers` | Additional init containers (this value is evaluated as a template) | `[]` |
| `sidecars` | Add additional sidecar containers (this value is evaluated as a template) | `[]` |
| `extraVolumes` | Extra volumes | `[]` |
| `extraVolumeMounts` | Mount extra volume(s) | `[]` |
| `resources.limits` | The resources limits for the container | `{}` |
| `resources.requests` | The requested resources for the container | `{}` |
| `livenessProbe.enabled` | Turn on and off liveness probe | `true` |
| `livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated | `120` |
| `livenessProbe.periodSeconds` | How often to perform the probe | `10` |
| `livenessProbe.timeoutSeconds` | When the probe times out | `1` |
| `livenessProbe.failureThreshold` | Minimum consecutive failures for the probe | `3` |
| `livenessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` |
| `readinessProbe.enabled` | Turn on and off readiness probe | `true` |
| `readinessProbe.initialDelaySeconds` | Delay before readiness probe is initiated | `30` |
| `readinessProbe.periodSeconds` | How often to perform the probe | `10` |
| `readinessProbe.timeoutSeconds` | When the probe times out | `1` |
| `readinessProbe.failureThreshold` | Minimum consecutive failures for the probe | `3` |
| `readinessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` |
| `startupProbe.enabled` | Turn on and off startup probe | `false` |
| `startupProbe.initialDelaySeconds` | Delay before startup probe is initiated | `120` |
| `startupProbe.periodSeconds` | How often to perform the probe | `10` |
| `startupProbe.timeoutSeconds` | When the probe times out | `1` |
| `startupProbe.failureThreshold` | Minimum consecutive failures for the probe | `48` |
| `startupProbe.successThreshold` | Minimum consecutive successes for the probe | `1` |
| `customStartupProbe` | Custom liveness probe for the Web component | `{}` |
| `customLivenessProbe` | Custom liveness probe for the Web component | `{}` |
| `customReadinessProbe` | Custom rediness probe for the Web component | `{}` |
| `podDisruptionBudget.create` | Specifies whether a Pod disruption budget should be created | `false` |
| `podDisruptionBudget.minAvailable` | Minimum number / percentage of pods that should remain scheduled | `1` |
| `podDisruptionBudget.maxUnavailable` | Maximum number / percentage of pods that may be made unavailable | `""` |
| `metrics.enabled` | Start a side-car prometheus exporter | `false` |
| `metrics.image.registry` | FreeRADIUS Prometheus exporter image registry | `""` |
| `metrics.image.repository` | FreeRADIUS Prometheus exporter image repository | `""` |
| `metrics.image.tag` | FreeRADIUS Prometheus exporter image tag (immutable tags are recommended) | `""` |
| `metrics.image.pullPolicy` | FreeRADIUS Prometheus exporter image pull policy | `IfNotPresent` |
| `metrics.image.pullSecrets` | FreeRADIUS Prometheus exporter image pull secrets | `[]` |
| `metrics.extraFlags` | FreeRADIUS Prometheus exporter additional command line flags | `[]` |
| `metrics.resources.limits` | The resources limits for the container | `{}` |
| `metrics.resources.requests` | The requested resources for the container | `{}` |
| `metrics.service.type` | Prometheus exporter service type | `ClusterIP` |
| `metrics.service.port` | Prometheus exporter service port | `9104` |
| `metrics.service.annotations` | Prometheus exporter service annotations | `{}` |
| `metrics.service.loadBalancerIP` | Load Balancer IP if the Prometheus metrics server type is `LoadBalancer` | `""` |
| `metrics.service.clusterIP` | Prometheus metrics service Cluster IP | `""` |
| `metrics.service.loadBalancerSourceRanges` | Prometheus metrics service Load Balancer sources | `[]` |
| `metrics.service.externalTrafficPolicy` | Prometheus metrics service external traffic policy | `Cluster` |
| `metrics.serviceMonitor.enabled` | if `true`, creates a Prometheus Operator ServiceMonitor (also requires `metrics.enabled` to be `true`) | `false` |
| `metrics.serviceMonitor.namespace` | Optional namespace which Prometheus is running in | `""` |
| `metrics.serviceMonitor.jobLabel` | The name of the label on the target service to use as the job name in prometheus. | `""` |
| `metrics.serviceMonitor.interval` | How frequently to scrape metrics (use by default, falling back to Prometheus' default) | `""` |
| `metrics.serviceMonitor.scrapeTimeout` | Timeout after which the scrape is ended | `""` |
| `metrics.serviceMonitor.selector` | ServiceMonitor selector labels | `{}` |
| `metrics.serviceMonitor.relabelings` | RelabelConfigs to apply to samples before scraping | `[]` |
| `metrics.serviceMonitor.metricRelabelings` | MetricRelabelConfigs to apply to samples before ingestion | `[]` |
| `metrics.serviceMonitor.honorLabels` | honorLabels chooses the metric's labels on collisions with target labels | `false` |
| `metrics.serviceMonitor.labels` | ServiceMonitor extra labels | `{}` |
| `metrics.prometheusRules.enabled` | if `true`, creates a Prometheus Operator PrometheusRule (also requires `metrics.enabled` to be `true`, and makes little sense without ServiceMonitor) | `false` |
| `metrics.prometheusRules.additionalLabels` | Additional labels to add to the PrometheusRule so it is picked up by the operator | `{}` |
| `metrics.prometheusRules.rules` | PrometheusRule rules to configure | `{}` |
## Usage
Use examples liberally, and show the expected output if you can. It's helpful to have inline the smallest example of usage that you can demonstrate, while providing links to more sophisticated examples if they are too long to reasonably include in the README.
## Support
Tell people where they can go to for help. It can be any combination of an issue tracker, a chat room, an email address, etc.
### Custom FreeRADIUS enabled mods parameters
## Roadmap
If you have ideas for releases in the future, it is a good idea to list them in the README.
| Name | Description | Value |
| ------------------------------------------ | --------------------------------------------------- | ----------------- |
| `modsEnabled.sql.enabled` | Enable FreeRADIUS SQL module | `false` |
| `modsEnabled.sql.dialect` | The driver module used to execute the queries. | `mysql` |
| `modsEnabled.sql.table.acct1` | Tables containing 'accounting' items | `radacct` |
| `modsEnabled.sql.table.acct2` | Tables containing 'accounting' items | `radacct` |
| `modsEnabled.sql.table.authcheck` | Tables containing 'check' items | `radcheck` |
| `modsEnabled.sql.table.authreply` | Tables containing 'reply' items | `radreply` |
| `modsEnabled.sql.table.client` | Table to keep radius client info | `nas` |
| `modsEnabled.sql.table.groupcheck` | Tables containing 'check' items | `radgroupcheck` |
| `modsEnabled.sql.table.groupreply` | Tables containing 'reply' items | `radgroupreply` |
| `modsEnabled.sql.table.postauth` | Allow for storing data after authentication | `radpostauth` |
| `modsEnabled.sql.table.usergroup` | Table to keep group info | `radusergroup` |
| `modsEnabled.sql.tls.enabled` | Enable FreeRADIUS SQL TLS module | `false` |
| `modsEnabled.sql.tls.autoGenerated` | | `false` |
| `modsEnabled.sql.tls.certificatesSecret` | | `""` |
| `modsEnabled.sql.tls.certFilename` | | `""` |
| `modsEnabled.sql.tls.certKeyFilename` | | `""` |
| `modsEnabled.sql.tls.certCAFilename` | | `""` |
| `modsEnabled.sql.tls.existingTlsSecret` | | `""` |
| `modsEnabled.sql.tls.privateKeyPassword` | | `""` |
## Contributing
State if you are open to contributions and what your requirements are for accepting them.
For people who want to make changes to your project, it's helpful to have some documentation on how to get started. Perhaps there is a script that they should run or some environment variables that they need to set. Make these steps explicit. These instructions could also be useful to your future self.
### Custom FreeRADIUS enabled sites parameters
You can also document commands to lint the code or run tests. These steps help to ensure high code quality and reduce the likelihood that the changes inadvertently break something. Having instructions for running tests is especially helpful if it requires external setup, such as starting a Selenium server for testing in a browser.
| Name | Description | Value |
| ------------------------------------------ | ------------------------------------------------------------------------------- | ----------------- |
| `sitesEnabled.coa.enabled` | Enable FreeRADIUS coa service | `false` |
| `sitesEnabled.status.enabled` | Enable FreeRADIUS status service | `true` |
| `sitesEnabled.tls.enabled` | Enable FreeRADIUS radsec service | `false` |
| `sitesEnabled.tls.cipher` | | `false` |
| `sitesEnabled.tls.privateKeyPassword` | | `false` |
Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example,
```console
helm install my-release \
--set imagePullPolicy=Always \
startechnica/freeradius
```
The above command sets the `imagePullPolicy` to `Always`.
Alternatively, a YAML file that specifies the values for the parameters can be provided while installing the chart. For example,
```console
helm install my-release startechnica/freeradius -f values.yaml
```
> **Tip**: You can use the default [values.yaml](values.yaml)
## Configuration and installation details
### Adding extra environment variables
In case you want to add extra environment variables (useful for advanced operations like custom init scripts), you can use the `extraEnvVars` property.
```yaml
extraEnvVars:
- name: LOG_LEVEL
value: error
```
Alternatively, you can use a ConfigMap or a Secret with the environment variables. To do so, use the `extraEnvVarsCM` or the `extraEnvVarsSecret` values.
### Setting Pod's affinity
This chart allows you to set your custom affinity using the `affinity` parameter. Find more information about Pod's affinity in the [kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity).
### Deploying extra resources
There are cases where you may want to deploy extra objects, such a ConfigMap containing your app's configuration or some extra deployment with a micro service used by your app. For covering this case, the chart allows adding the full specification of other objects using the `extraDeploy` parameter.
## Troubleshooting
Find more information about how to deal with common errors related to Startechnica's Helm charts in [this troubleshooting guide](https://startechnica.github.io/doc/troubleshoot-helm-chart-issues).
## Upgrading
## Authors and acknowledgment
Show your appreciation to those who have contributed to the project.
## License
For open source projects, say how it is licensed.
Copyright &copy; 2023 Startechnica
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
## Project status
If you have run out of energy or time for your project, put a note at the top of the README saying that development has slowed down or stopped completely. Someone may choose to fork your project or volunteer to step in as a maintainer or owner, allowing your project to keep going. You can also make an explicit request for maintainers.
+38
View File
@@ -0,0 +1,38 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: freeradius
namespace: argocd
spec:
project: default
sources:
# FreeRADIUS OCI Helm chart
- repoURL: oci://gitea.infrastructure.helmholz.cloud/gitea_admin/helm/freeradius
targetRevision: 2.0.0
path: .
helm:
valueFiles:
- $values/values.yaml
# Git repo - Kubernetes manifests
- repoURL: ssh://git@gitea-ssh.gitea.svc.cluster.local:22/gitea_admin/FreeRADIUS.git
targetRevision: main
path: manifests
# Git repo - values
- repoURL: ssh://git@gitea-ssh.gitea.svc.cluster.local:22/gitea_admin/FreeRADIUS.git
targetRevision: main
ref: values
destination:
server: "https://138.199.131.114:6443"
namespace: freeradius
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
-55
View File
@@ -1,55 +0,0 @@
# -*- text -*-
######################################################################
#
# Sample virtual server for receiving a CoA or Disconnect-Request packet.
#
server coa {
namespace = $ENV{FREERADIUS_SITES_NAMESPACE}
# Listen on the CoA port.
#
# This uses the normal set of clients, with the same secret as for
# authentication and accounting.
#
listen {
type = CoA-Request
type = Disconnect-Request
transport = udp
udp {
ipaddr = $ENV{FREERADIUS_SITES_COA_LISTEN}
port = $ENV{FREERADIUS_SITES_COA_PORT}
}
}
# Receive a CoA request
recv CoA-Request {
ok
}
# Send a CoA ACK
send CoA-ACK {
ok
}
# Send a CoA NAK
send CoA-NAK {
ok
}
# Receive a Disconnect request
recv Disconnect-Request {
ok
}
# Send a Disconnect ACK
send Disconnect-ACK {
ok
}
# Send a Disconnect NAK
send Disconnect-NAK {
ok
}
}
-247
View File
@@ -1,247 +0,0 @@
######################################################################
#
# RADIUS over TLS
#
######################################################################
server radsec {
listen {
transport = tls
type = Access-Request
type = Accounting-Request
tls {
ipaddr = $ENV{FREERADIUS_SITES_TLS_LISTEN}
port = $ENV{FREERADIUS_SITES_TLS_PORT}
# Connection limiting for sockets with "proto = tcp".
#
limit {
# Limit the number of simultaneous TCP connections to the socket
#
# The default is 16.
# Setting this to 0 means "no limit"
max_connections = 16
# The per-socket "max_requests" option does not exist.
# The lifetime, in seconds, of a TCP connection. After this lifetime, the connection will be closed.
#
# Setting this to 0 means "forever".
lifetime = 0
# The idle timeout, in seconds, of a TCP connection.
# If no packets have been received over the connection for this time, the connection will be closed.
# Setting this to 0 means "no timeout".
#
# We STRONGLY RECOMMEND that you set an idle timeout.
idle_timeout = 30
}
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
# If Private key & Certificate are located in the same file, then private_key_file &
# certificate_file must contain the same file name.
#
# If ca_file (below) is not used, then the certificate_file below MUST include not only the server certificate, but ALSO all
# of the CA certificates used to sign the server certificate.
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
# Trusted Root CA list
#
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
#
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
# In that case, this CA file should contain *one* CA certificate.
#
# This parameter is used only for EAP-TLS, when you issue client certificates. If you do not use client certificates, and you do not want
# to permit EAP-TLS authentication, then delete this configuration item.
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
#
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
#
# openssl dhparam -out certs/dh 1024
dh_file = ${certdir}/dh
#
# If your system doesn't have /dev/urandom, you will need to create this file, and periodically change its contents.
# For security reasons, FreeRADIUS doesn't write to files in its configuration directory.
# random_file = /dev/urandom
#
# The default fragment size is 1K. However, it's possible to send much more data than that over a TCP connection. The upper limit is 64K.
# Setting the fragment size to more than 1K means that there are fewer round trips when setting up a TLS connection. But only if the certificates are large.
fragment_size = 8192
# include_length is a flag which is by default set to yes If set to yes, Total Length of the message is
# included in EVERY packet we send.
# If set to no, Total Length of the message is included ONLY in the First packet of a fragment series.
# include_length = yes
# Check the Certificate Revocation List
#
# 1) Copy CA certificates and CRLs to same directory.
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
# 'c_rehash' is OpenSSL's command.
# 3) uncomment the line below.
# 5) Restart radiusd
# check_crl = yes
ca_path = ${cadir}
# Accept an expired Certificate Revocation List
#
# allow_expired_crl = no
# Accept a not-yet-valid Certificate Revocation List
#
# allow_not_yet_valid_crl = no
#
# If check_cert_issuer is set, the value will
# be checked against the DN of the issuer in
# the client certificate. If the values do not
# match, the certificate verification will fail,
# rejecting the user.
#
# This check can be done more generally by checking
# the value of the TLS-Client-Cert-Issuer attribute.
# This check can be done via any mechanism you choose.
#
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
#
# If check_cert_cn is set, the value will
# be xlat'ed and checked against the CN
# in the client certificate. If the values
# do not match, the certificate verification
# will fail rejecting the user.
#
# This check is done only if the previous
# "check_cert_issuer" is not set, or if
# the check succeeds.
#
# This check can be done more generally by checking
# the value of the TLS-Client-Cert-Common-Name attribute.
# This check can be done via any mechanism you choose.
#
# check_cert_cn = %{User-Name}
#
# Set this option to specify the allowed
# TLS cipher suites. The format is listed
# in "man 1 ciphers".
cipher_list = "DEFAULT"
# If enabled, OpenSSL will use server cipher list
# (possibly defined by cipher_list option above)
# for choosing right cipher suite rather than
# using client-specified list which is OpenSSl default
# behavior. Having it set to 'yes' is best practice
# for TLS.
cipher_server_preference = yes
#
# Session resumption / fast reauthentication
# cache.
#
# The cache contains the following information:
#
# session Id - unique identifier, managed by SSL
# User-Name - from the Access-Accept
# Stripped-User-Name - from the Access-Request
# Cached-Session-Policy - from the Access-Accept
#
# The "Cached-Session-Policy" is the name of a
# policy which should be applied to the cached
# session. This policy can be used to assign
# VLANs, IP addresses, etc. It serves as a useful
# way to re-apply the policy from the original
# Access-Accept to the subsequent Access-Accept
# for the cached session.
#
# On session resumption, these attributes are
# copied from the cache, and placed into the
# reply list.
#
# You probably also want "use_tunneled_reply = yes"
# when using fast session resumption.
#
cache {
#
# Lifetime of the cached entries, in hours.
# The sessions will be deleted after this
# time.
#
lifetime = 24 # hours
#
# Internal "name" of the session cache.
# Used to distinguish which TLS context
# sessions belong to.
#
# The server will generate a random value
# if unset. This will change across server
# restart so you MUST set the "name" if you
# want to persist sessions (see below).
#
# If you use IPv6, change the "ipaddr" below
# to "ipv6addr"
#
#name = "TLS ${..ipaddr} ${..port} ${..proto}"
#
# Simple directory-based storage of sessions.
# Two files per session will be written, the SSL
# state and the cached VPs. This will persist session
# across server restarts.
#
# The server will need write perms, and the directory
# should be secured from anyone else. You might want
# a script to remove old files from here periodically:
#
# find ${logdir}/tlscache -mtime +2 -exec rm -f {} \;
#
# This feature REQUIRES "name" option be set above.
#
#persist_dir = "${logdir}/tlscache"
}
# Require a client certificate.
#
require_client_cert = no
#
# As of version 2.1.10, client certificates can be validated via an external command. This allows dynamic CRLs or OCSP to be used.
#
# This configuration is commented out in the default configuration. Uncomment it, and configure the correct paths below to enable it.
#
verify {
# A temporary directory where the client certificates are stored. This directory MUST be owned by the UID of the server,
# and MUST not be accessible by any other users. When the server starts, it will do "chmod go-rwx" on the directory, for
# security reasons. The directory MUST exist when the server starts.
#
# You should also delete all of the files in the directory when the server starts.
tmpdir = /startechnica/freeradius/tmp
# The command used to verify the client cert. We recommend using the OpenSSL command-line tool.
#
# The ${..ca_path} text is a reference to the ca_path variable defined above.
#
# The %{TLS-Client-Cert-Filename} is the name of the temporary file containing the cert in PEM format. This file is automatically
# deleted by the server when the command returns.
# client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
}
}
}
recv Access-Request {
ok
}
recv Accounting-Request {
ok
}
}
+8
View File
@@ -0,0 +1,8 @@
-----BEGIN DH PARAMETERS-----
MIIBCAKCAQEAmTz/pyBq/Z/b+3FBsJal4JIoT3jibTQ5NsLgUxVX83YayBMfB8o+
Y/kFAtspKLJtXgZ9uNwAcpqBBw19o6vbxsDcln3Gi6IO24uiZrpaWkTAoLZsuOK0
bbE0cFCruWGWv4IDDfvFffRq7mNrI1LK3IkeROu7CuE53lpwRe1JtTK4OPfeerPk
2vyojQJWzkLUz8th2bubMGYvSZ6I8mTXTzsk3eGzxAIWGwd1GvuUwX9+pHiDVbac
ZYAr6NHkSq2nyU11bb92XjR5+yoDGoKapyAxB+B9ZBRVAQ7RHMkcGNyZT/6eGRCw
kHDGqo+qiJBqB8hmvAEwoAWMRgUYd1mZPwIBAg==
-----END DH PARAMETERS-----
+16
View File
@@ -0,0 +1,16 @@
-----BEGIN CERTIFICATE-----
MIICkjCCAXqgAwIBAgIIF5vfktfGFYwwDQYJKoZIhvcNAQELBQAwADAeFw0yNTA2
MjUxMTIyMDBaFw0yNjA2MjUxMTIyMDBaMAAwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQC196tFi2qulBMEQ/dyJD2Wsbi+Sog7vCOmFk0e9UMwogIMF/lC
WO6NOBtKYi8q+JHVWzgD9FqBkLPjAk87RJkGgi+/zE4gLtU3j5xmm48u5CqVmCDs
bu3Y/WDuip3MPhUb1btqQbQRsDU2UuMvQ8e/sSKGcl0BRxVnTsyeVkFXmY49KZYN
GFyXAjK/Fmj0ymWue+2kGEdsn83tqCAE4D7PkOYTOuaGW2E9qL0i11ALMZ/Wd97j
MyimM05385zcv10cr/SdwbKa83l0vawJCXLA+IyFkPJwTbMCr84HzBg43FOWfuOm
6q7cyDR7jHL+gJQj6NWmeLRWNv5mLvGXE54lAgMBAAGjEDAOMAwGA1UdEwQFMAMB
Af8wDQYJKoZIhvcNAQELBQADggEBAIw1kkJ1sgSkEPTAhxxqz22okRik6gFmx3q1
BAjK0KlAniYp2PdYMzH9QJYOjGRzNzRDpCPSED1fz5dVP8ZSKyLlS1UI9IqlZfoX
uoTRL7XUUrwpxAk5oURWqC8hMfM+bYEE8VV7KPvAU1QZneIWMoaCMR9NB7UytaK2
jFPdgJIPdtT5wBVxZPsdEYC/0u9+uiILxNCT/ghI9BwynVe1SfqN5YCtIc4uURj5
tDYWgoL4gJxihKI9tQdoCETOpGMMU81x8kSDERJy3c7Dh+m+B+mhB3pOVu3iD1F8
FgMfHEIz0iHZeAKJRQGzdDIhH1czCjc6lIavUF61lGNySzBIuUU=
-----END CERTIFICATE-----
+27
View File
@@ -0,0 +1,27 @@
-----BEGIN RSA PRIVATE KEY-----
MIIEoQIBAAKCAQEAvij0IoVdfjj7mLZJWFKj4UO96Hy6JQsHvMG/HybeorGL64Bc
vb3L7v/Nwc5hGkgrxXmFJ0eNAc7QsD9wpCi3mEd2tyZeyspZwFelwuC8XiItzO+f
YNwdXFVtwcqy2ouMhGHPnMOrQByrh8Dislz3QbST16Qhq7Qvytih+7xgP5+qnsYg
OnVFOf9Tw0fuci4Xg7mFLGx64St1K9gpeSGGK+k6HxnCC9N8Jy+ZYA/FZfzAS1s8
dVCzTFhR6pnm4+Cz/pu7UkOoCOS5mDh8UCGv+f1EjlMQ7RHJegNTpAenqPpGt26z
nYKp/wPc3qVPoZ350c1anqdf9wArsPlgvcMJaQIDAQABAoH/ZhgIiSrYQCU7YRdg
u0OjKocXxA+kxHd86NqqwfJxznW9N7MkwkhdGLshoJae4O8z5kOtVfeihB0TtRrM
Jjon5ig/PzIhsoXU/1Ly5ObgOzgee1qdNw5L0ZxE++MQzgweLEpXSUTgyPzUcGNz
/Wt6cQVJd0RSXcDuIMERxN0JCKz8jKpPqnVfhsKZhPdCYNOWM2mZ+LZY34Mxn5ie
T4bc4fIrnPNCiZicyq9HK2z6GzxcESnljr4vBwv3cJnTBAfzKjKo3b53k+qLVeAR
PIJBudhIfo6SzuPGCCIuibKT/97eKW1fkRGxSPWjPFBSvGRJ3wzqYoum3BCHrpAe
XXQRAoGBAN9a3mrFyXOUehXXlY3OYomcr7IJ37rtjZJyTDS40uESYj7Wqc9HQsk5
bmDKH2US35LJnZuWLNXon28IbrCC5WkAXWUBG41qcj8Li5CMZbM4B32ryH6iD0oh
FbjpU2ZUxZ1NdxmXlfzTuJr65NHlb6id+M8Welrdk0s/Gv0hQSv1AoGBANn0DJlQ
eDcU0clMvSMnq7+6IZQghErC1Jpzx++LQ49vWs1VQCwDVTs1bXt+5fZop5ayBU0p
R4dPoezyFP2PZsPm/yE3xwsedSYO5RUncm268P/+KCSMlCSkOZJxQPlAvog9wC0t
dMg9vW6kTt5KD2+MZTATbHxghjodDVMwcpMlAoGAQBGBwWDw012g04kelinAbDbs
0wYwDh+8P2jX4TuvCe7LDblnxlRrnOsDdXIlJUoPpbx9oDaor8dljGT/01QI2GDJ
aYKy05LYKKt4IkOTnKASzgKrpV95QUtSPtN3H+BrOx8Qbd/knzxgNNyJLIhCyjxe
NZD+EfiDGs+EP139os0CgYEAkhbbOwiNC56Q33Tocd/tZx3D1B3XjqT5DG3+3blj
F4l0O52g3d9+CanOMLDmQzvy2TeKBiZdI31k9AVvvGWaZEU5TXKtn+5SZ6gkNQGz
2YkscOpSzezMf6L0VAxFmMyk6X06iw2k8XMwvjC0DJtnrUVVrdvXI6cvUVSX0eLv
aWECgYBS07zV381/YNlmCM+E+WTZSZrngjjIeCgcqMJt1t2SpnaBQoHO6DKjJcDk
8Leg8z7B8Ym5FJfy55ZorkDV7LGI1JGwfc3p3MW2RAVhkkV0LoGHLv8VcD6t3Utq
dIMkugPE/JQQinZsDD8B3lLBi165OFfxFWS7mJDbHaw34i7ADQ==
-----END RSA PRIVATE KEY-----
+17
View File
@@ -0,0 +1,17 @@
-----BEGIN CERTIFICATE-----
MIICwjCCAaqgAwIBAgIIOxDIc7UovJkwDQYJKoZIhvcNAQELBQAwADAeFw0yNTA2
MjUxMTMzMDBaFw0yNjA2MjUxMTIyMDBaMDMxMTAvBgNVBAMTKGZyZWVyYWRpdXMu
aW5mcmFzdHJ1Y3R1cmUuaGVsbWhvbHouY2xvdWQwggEiMA0GCSqGSIb3DQEBAQUA
A4IBDwAwggEKAoIBAQC+KPQihV1+OPuYtklYUqPhQ73ofLolCwe8wb8fJt6isYvr
gFy9vcvu/83BzmEaSCvFeYUnR40BztCwP3CkKLeYR3a3Jl7KylnAV6XC4LxeIi3M
759g3B1cVW3ByrLai4yEYc+cw6tAHKuHwOKyXPdBtJPXpCGrtC/K2KH7vGA/n6qe
xiA6dUU5/1PDR+5yLheDuYUsbHrhK3Ur2Cl5IYYr6TofGcIL03wnL5lgD8Vl/MBL
Wzx1ULNMWFHqmebj4LP+m7tSQ6gI5LmYOHxQIa/5/USOUxDtEcl6A1OkB6eo+ka3
brOdgqn/A9zepU+hnfnRzVqep1/3ACuw+WC9wwlpAgMBAAGjDTALMAkGA1UdEwQC
MAAwDQYJKoZIhvcNAQELBQADggEBAJt80P4oe7aRUC3+Hr1uQlHVtATkS1jDZ8um
GJAy8EKtrPp53OR9ZFMUOTieAEAbRRqyxrqgJQDP83opS8Yc2pyIyC3H8nlm2AmW
FzRVxLFaNoUaxotbrGubJOJ6rolaWjpUTLdCZb43P/vgZ9rJHMG3HTgfDn9cYEPj
JlLVonUJkeM92Bx3ds5QCSEhTteQ0u6xIfq1FOo9lt0PxFelL3QwEc0OyqDzUIo5
n4buhEaVZiNqjXIifIv1Dqci7oZBOhVKr6LpGYjs3K9P2+qXNrsNE4zVbZZOYNpI
X+b+0e8bHb9Du84Cn5px0qeFlJPKGrORcz8MWKuGiUnn/MKokNw=
-----END CERTIFICATE-----
@@ -1,3 +0,0 @@
You can copy here your custom .sh, .sql or .sql.gz file so they are executed during the first boot of the image.
More info in the [freeradius/freeradius-server](https://hub.docker.com/r/freeradius/freeradius-server) repository.
-41
View File
@@ -1,41 +0,0 @@
# -*- text -*-
#
# $Id: cc2bd5fd22aa473b98af5dde3fac7a66e39a9e9d $
# This module loads RADIUS clients as needed, rather than when the server
# starts.
#
# There are no configuration entries for this module. Instead, it
# relies on the "client" configuration. You must:
#
# 1) link raddb/sites-enabled/dynamic_clients to
# raddb/sites-available/dynamic_clients
#
# 2) Define a client network/mask (see top of the above file)
#
# 3) uncomment the "directory" entry in that client definition
#
# 4) list "dynamic_clients" in the "authorize" section of the
# "dynamic_clients' virtual server. The default example already
# does this.
#
# 5) put files into the above directory, one per IP.
# e.g. file "192.0.2.1" should contain a normal client definition
# for a client with IP address 192.0.2.1.
#
# For more documentation, see the file:
#
# raddb/sites-available/dynamic-clients
#
dynamic_clients {
sql = "SELECT secret, shortname, type FROM nas WHERE nasname = '%{Packet-Src-IP-Address}'"
key = "%{Packet-Src-IP-Address}"
client {
ipaddr = "%{Packet-Src-IP-Address}"
secret = "%{reply:secret}"
shortname = "%{reply:shortname}"
nastype = "%{reply:type}"
}
}
File diff suppressed because it is too large Load Diff
-366
View File
@@ -1,366 +0,0 @@
# -*- text -*-
##
## mods-available/sql -- SQL modules
##
## $Id: cfeac63ea87c30fead8457af6d10f5c3a0f48aef $
######################################################################
#
# Configuration for the SQL module
#
# The database schemas and queries are located in subdirectories:
#
# sql/<DB>/main/schema.sql Schema
# sql/<DB>/main/queries.conf Authorisation and Accounting queries
#
# Where "DB" is mysql, mssql, oracle, or postgresql.
#
# The name used to query SQL is sql_user_name, which is set in the file
#
# raddb/mods-config/sql/main/${dialect}/queries.conf
#
# If you are using realms, that configuration should be changed to use
# the Stripped-User-Name attribute. See the comments around sql_user_name
# for more information.
#
sql {
#
# The dialect of SQL being used.
#
# Allowed dialects are:
#
# mssql
# mysql
# oracle
# postgresql
# sqlite
# mongo
#
# dialect = "sqlite"
dialect = $ENV{FREERADIUS_MODS_SQL_DIALECT}
#
# The driver module used to execute the queries. Since we
# don't know which SQL drivers are being used, the default is
# "rlm_sql_null", which just logs the queries to disk via the
# "logfile" directive, below.
#
# In order to talk to a real database, delete the next line,
# and uncomment the one after it.
#
# If the dialect is "mssql", then the driver should be set to
# one of the following values, depending on your system:
#
# rlm_sql_db2
# rlm_sql_firebird
# rlm_sql_freetds
# rlm_sql_iodbc
# rlm_sql_unixodbc
#
# driver = "rlm_sql_null"
driver = "rlm_sql_${dialect}"
#
# Driver-specific subsections. They will only be loaded and
# used if "driver" is something other than "rlm_sql_null".
# When a real driver is used, the relevant driver
# configuration section is loaded, and all other driver
# configuration sections are ignored.
#
sqlite {
# Path to the sqlite database
filename = $ENV{FREERADIUS_MODS_SQL_SQLITE_FILENAME}
# How long to wait for write locks on the database to be released (in ms) before giving up.
busy_timeout = $ENV{FREERADIUS_MODS_SQL_SQLITE_BUSY_TIMEOUT}
# If the file above does not exist and bootstrap is set
# a new database file will be created, and the SQL statements
# contained within the bootstrap file will be executed.
bootstrap = "${modconfdir}/${..:name}/main/sqlite/schema.sql"
}
mysql {
# If any of the files below are set, TLS encryption is enabled
tls {
# ca_file = $ENV{FREERADIUS_MODS_SQL_TLS_CACERT}
# ca_path = "/startechnica/freeradius/certs-sql/"
# certificate_file = $ENV{FREERADIUS_MODS_SQL_TLS_CERTIFICATE}
# private_key_file = $ENV{FREERADIUS_MODS_SQL_TLS_PRIVATEKEY}
# cipher = "DHE-RSA-AES256-SHA:AES128-SHA"
# cipher = $ENV{FREERADIUS_MODS_SQL_TLS_CIPHER}
tls_required = $ENV{FREERADIUS_MODS_SQL_TLS_ENABLE}
tls_check_cert = no
tls_check_cert_cn = no
}
# If yes, (or auto and libmysqlclient reports warnings are
# available), will retrieve and log additional warnings from
# the server if an error has occured. Defaults to 'auto'
warnings = auto
}
postgresql {
# unlike MySQL, which has a tls{} connection configuration, postgresql
# uses its connection parameters - see the radius_db option below in
# this file
# Send application_name to the postgres server
# Only supported in PG 9.0 and greater. Defaults to no.
send_application_name = yes
}
#
# Configuration for Mongo.
#
# Note that the Mongo driver is experimental. The FreeRADIUS developers
# are unable to help with the syntax of the Mongo queries. Please see
# the Mongo documentation for that syntax.
#
# The Mongo driver supports only the following methods:
#
# aggregate
# findAndModify
# findOne
# insert
#
# For examples, see the query files:
#
# raddb/mods-config/sql/main/mongo/queries.conf
# raddb/mods-config/sql/main/ippool/queries.conf
#
# In order to use findAndModify with an aggretation pipleline, make
# sure that you are running MongoDB version 4.2 or greater. FreeRADIUS
# assumes that the paramaters passed to the methods are supported by the
# version of MongoDB which it is connected to.
#
mongo {
#
# The application name to use.
#
appname = "freeradius"
#
# The TLS parameters here map directly to the Mongo TLS configuration
#
tls {
certificate_file = $ENV{FREERADIUS_MODS_SQL_TLS_CERTIFICATE}
certificate_password = $ENV{FREERADIUS_MODS_SQL_TLS_PRIVATEKEY}
ca_file = $ENV{FREERADIUS_MODS_SQL_TLS_CACERT}
ca_dir = /startechnica/freeradius/certs-sql/
# crl_file = /path/to/file
weak_cert_validation = false
allow_invalid_hostname = false
}
}
# Connection info:
#
server = $ENV{FREERADIUS_MODS_SQL_SERVER}
port = $ENV{FREERADIUS_MODS_SQL_PORT}
login = $ENV{FREERADIUS_MODS_SQL_LOGIN}
password = $ENV{FREERADIUS_MODS_SQL_PASSWORD}
# Connection info for Mongo
# Authentication Without SSL
# server = "mongodb://USER:PASSWORD@192.16.0.2:PORT/DATABASE?authSource=admin&ssl=false"
# Authentication With SSL
# server = "mongodb://USER:PASSWORD@192.16.0.2:PORT/DATABASE?authSource=admin&ssl=true"
# Authentication with Certificate
# Use this command for retrieve Derived username:
# openssl x509 -in mycert.pem -inform PEM -subject -nameopt RFC2253
# server = mongodb://<DERIVED USERNAME>@192.168.0.2:PORT/DATABASE?authSource=$external&ssl=true&authMechanism=MONGODB-X509
# Database table configuration for everything except Oracle
radius_db = $ENV{FREERADIUS_MODS_SQL_DB}
# If you are using Oracle then use this instead
# radius_db = "(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=localhost)(PORT=1521))(CONNECT_DATA=(SID=your_sid)))"
# If you're using postgresql this can also be used instead of the connection info parameters
# radius_db = "dbname=$ENV{FREERADIUS_MODS_SQL_DB} host=$ENV{FREERADIUS_MODS_SQL_SERVER} port=$ENV{FREERADIUS_MODS_SQL_PORT} user=$ENV{FREERADIUS_MODS_SQL_LOGIN} password=$ENV{FREERADIUS_MODS_SQL_PASSWORD}"
# Postgreql doesn't take tls{} options in its module config like mysql does - if you want to
# use SSL connections then use this form of connection info parameter
# radius_db = "host=localhost port=5432 dbname=radius user=radius password=raddpass sslmode=verify-full sslcert=/etc/ssl/client.crt sslkey=/etc/ssl/client.key sslrootcert=/etc/ssl/ca.crt"
# If you want both stop and start records logged to the
# same SQL table, leave this as is. If you want them in
# different tables, put the start table in acct_table1
# and stop table in acct_table2
acct_table1 = $ENV{FREERADIUS_MODS_SQL_TABLE_ACCT1}
acct_table2 = $ENV{FREERADIUS_MODS_SQL_TABLE_ACCT2}
# Allow for storing data after authentication
postauth_table = $ENV{FREERADIUS_MODS_SQL_TABLE_POSTAUTH}
# Tables containing 'check' items
authcheck_table = $ENV{FREERADIUS_MODS_SQL_TABLE_AUTHCHECK}
groupcheck_table = $ENV{FREERADIUS_MODS_SQL_TABLE_GROUPCHECK}
# Tables containing 'reply' items
authreply_table = $ENV{FREERADIUS_MODS_SQL_TABLE_AUTHREPLY}
groupreply_table = $ENV{FREERADIUS_MODS_SQL_TABLE_GROUPREPLY}
# Table to keep group info
usergroup_table = $ENV{FREERADIUS_MODS_SQL_TABLE_USERGROUP}
# If set to 'yes' (default) we read the group tables unless Fall-Through = no in the reply table.
# If set to 'no' we do not read the group tables unless Fall-Through = yes in the reply table.
# read_groups = yes
# If set to 'yes' (default) we read profiles unless Fall-Through = no in the groupreply table.
# If set to 'no' we do not read profiles unless Fall-Through = yes in the groupreply table.
# read_profiles = yes
# Remove stale session if checkrad does not see a double login
delete_stale_sessions = yes
# Write SQL queries to a logfile. This is potentially useful for tracing
# issues with authorization queries. See also "logfile" directives in
# mods-config/sql/main/*/queries.conf. You can enable per-section logging
# by enabling "logfile" there, or global logging by enabling "logfile" here.
#
# Per-section logging can be disabled by setting "logfile = ''"
# logfile = ${logdir}/sqllog.sql
# Set the maximum query duration and connection timeout
# for rlm_sql_mysql.
# query_timeout = 5
# As of version 3.0, the "pool" section has replaced the
# following configuration items:
#
# num_sql_socks
# connect_failure_retry_delay
# lifetime
# max_queries
#
# The connection pool is new for 3.0, and will be used in many
# modules, for all kinds of connection-related activity.
#
# When the server is not threaded, the connection pool
# limits are ignored, and only one connection is used.
#
# If you want to have multiple SQL modules re-use the same
# connection pool, use "pool = name" instead of a "pool"
# section. e.g.
#
# sql sql1 {
# ...
# pool {
# ...
# }
# }
#
# # sql2 will use the connection pool from sql1
# sql sql2 {
# ...
# pool = sql1
# }
#
pool {
# Connections to create during module instantiation.
# If the server cannot create specified number of
# connections during instantiation it will exit.
# Set to 0 to allow the server to start without the database being available.
start = ${thread[pool].start_servers}
# Minimum number of connections to keep open
min = ${thread[pool].min_spare_servers}
# Maximum number of connections
#
# If these connections are all in use and a new one
# is requested, the request will NOT get a connection.
#
# Setting 'max' to LESS than the number of threads means
# that some threads may starve, and you will see errors
# like 'No connections available and at max connection limit'
#
# Setting 'max' to MORE than the number of threads means
# that there are more connections than necessary.
max = ${thread[pool].max_servers}
# Spare connections to be left idle
#
# NOTE: Idle connections WILL be closed if "idle_timeout"
# is set. This should be less than or equal to "max" above.
spare = ${thread[pool].max_spare_servers}
# Number of uses before the connection is closed
#
# 0 means "infinite"
uses = 0
# The number of seconds to wait after the server tries
# to open a connection, and fails. During this time,
# no new connections will be opened.
retry_delay = 30
# The lifetime (in seconds) of the connection
lifetime = 0
# idle timeout (in seconds). A connection which is
# unused for this length of time will be closed.
idle_timeout = 60
# NOTE: All configuration settings are enforced. If a
# connection is closed because of "idle_timeout",
# "uses", or "lifetime", then the total number of
# connections MAY fall below "min". When that
# happens, it will open a new connection. It will
# also log a WARNING message.
#
# The solution is to either lower the "min" connections,
# or increase lifetime/idle_timeout.
}
# Set to 'yes' to read radius clients from the database ('nas' table)
# Clients will ONLY be read on server startup.
#
# A client can be link to a virtual server via the SQL
# module. This link is done via the following process:
#
# If there is no listener in a virtual server, SQL clients
# are added to the global list for that virtual server.
#
# If there is a listener, and the first listener does not
# have a "clients=..." configuration item, SQL clients are
# added to the global list.
#
# If there is a listener, and the first one does have a
# "clients=..." configuration item, SQL clients are added to
# that list. The client { ...} ` configured in that list are
# also added for that listener.
#
# The only issue is if you have multiple listeners in a
# virtual server, each with a different client list, then
# the SQL clients are added only to the first listener.
#
read_clients = $ENV{FREERADIUS_MODS_SQL_READ_CLIENTS}
# Table to keep radius client info
client_table = $ENV{FREERADIUS_MODS_SQL_TABLE_CLIENT}
#
# The group attribute specific to this instance of rlm_sql
#
# This entry should be used for additional instances (sql foo {})
# of the SQL module.
# group_attribute = "${.:instance}-SQL-Group"
# This entry should be used for the default instance (sql {})
# of the SQL module.
group_attribute = $ENV{FREERADIUS_MODS_SQL_GROUP_ATTRIBUTE}
# Read database-specific queries
$INCLUDE ${modconfdir}/${.:name}/main/${dialect}/queries.conf
}
-110
View File
@@ -1,110 +0,0 @@
# Configuration for the SQL based IP Pool module (rlm_sqlippool)
#
# The database schemas are available at:
#
# raddb/mods-config/sql/ippool/<DB>/schema.sql
#
# $Id: f17a9898e906d3db0ad5871d8683f731f7a6baab $
sqlippool {
# SQL instance to use (from mods-available/sql)
#
# If you have multiple sql instances, such as "sql sql1 {...}",
# use the *instance* name here: sql1.
sql_module_instance = "sql"
# This is duplicative of info available in the SQL module, but
# we have to list it here as we do not yet support nested
# reference expansions.
dialect = $ENV{FREERADIUS_MODS_SQL_DIALECT}
# Name of the check item attribute to be used as a key in the SQL queries
pool_name = "Pool-Name"
# SQL table to use for ippool range and lease info
ippool_table = $ENV{FREERADIUS_MODS_SQL_TABLE_RADIPPOOL}
# IP lease duration. (Leases expire even if Acct Stop packet is lost)
#
# Note that you SHOULD also set Session-Timeout to this value!
# That way the NAS will automatically kick the user offline when the
# lease expires.
#
lease_duration = 18000
#
# Timeout between each consecutive 'allocate_clear' queries (default: 1s)
# This will avoid having too many deadlock issues, especially on MySQL backend.
#
allocate_clear_timeout = 1
#
# The attribute to use for IP address assignment. The
# default is Framed-IP-Address. You can change this to any
# attribute which is IPv4 or IPv6.
#
# e.g. Framed-IPv6-Prefix, or Delegated-IPv6-Prefix.
#
# All of the default queries use this attribute_name. So you
# can do IPv6 address assignment simply by putting IPv6
# addresses into the pool, and changing the following line to
# "Framed-IPv6-Prefix"
#
# Note that you MUST use separate pools for each attribute. i.e. one pool
# for Framed-IP-Address, a different one for Framed-IPv6-prefix, etc.
#
# This means configuring separate "sqlippool" instances, and different
# "ippool_table" in SQL. Then, populate the pool with addresses and
# it will all just work.
#
attribute_name = Framed-IP-Address
#
# Assign the IP address, even if the above attribute already exists
# in the reply.
#
# allow_duplicates = no
# The attribute in which an IP address hint may be supplied
req_attribute_name = Framed-IP-Address
# Attribute which should be considered unique per NAS
#
# Using NAS-Port gives behaviour similar to rlm_ippool. (And ACS)
# Using Calling-Station-Id works for NAS that send fixed NAS-Port
# ONLY change this if you know what you are doing!
# pool_key = "%{NAS-Port}"
# pool_key = "%{Calling-Station-Id}"
pool_key = "%{User-Name}"
nas_ip_address = "%{NAS-IP-Address}"
################################################################
#
# WARNING: MySQL (MyISAM) has certain limitations that means it can
# hand out the same IP address to 2 different users.
#
# We suggest using an SQL DB with proper transaction
# support, such as PostgreSQL, or using MySQL
# with InnoDB.
#
################################################################
# These messages are added to the "control" items, as
# Module-Success-Message. They are not logged anywhere else,
# unlike previous versions. If you want to have them logged
# to a file, see the "linelog" module, and create an entry
# which writes Module-Success-Message message.
#
messages {
exists = "Existing IP: %{reply:${..attribute_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
success = "Allocated IP: %{reply:${..attribute_name}} from %{control:${..pool_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
clear = "Released IP %{request:${..attribute_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} user %{User-Name})"
failed = "IP Allocation FAILED from %{control:${..pool_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
nopool = "No ${..pool_name} defined (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
}
$INCLUDE ${modconfdir}/sql/ippool/${dialect}/queries.conf
}
-694
View File
@@ -1,694 +0,0 @@
# -*- text -*-
#
# main/mysql/queries.conf-- MySQL configuration for default schema (schema.sql)
#
# $Id: b31ae9c3a1bf41f030a2112d31bf3a678e76f23c $
# Use the driver specific SQL escape method.
#
# If you enable this configuration item, the "safe_characters"
# configuration is ignored. FreeRADIUS then uses the MySQL escape
# functions to escape input strings. The only downside to making this
# change is that the MySQL escaping method is not the same the one
# used by FreeRADIUS. So characters which are NOT in the
# "safe_characters" list will now be stored differently in the database.
#
#auto_escape = yes
# Safe characters list for sql queries. Everything else is replaced
# with their mime-encoded equivalents.
# The default list should be ok
# Using 'auto_escape' is preferred
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"
#######################################################################
# Connection config
#######################################################################
# The character set is not configurable. The default character set of
# the mysql client library is used. To control the character set,
# create/edit my.cnf (typically in /etc/mysql/my.cnf or /etc/my.cnf)
# and enter
# [freeradius]
# default-character-set = utf8
#
#######################################################################
# Query config: Username
#######################################################################
# This is the username that will get substituted, escaped, and added
# as attribute 'SQL-User-Name'. '%{SQL-User-Name}' should be used below
# everywhere a username substitution is needed so you you can be sure
# the username passed from the client is escaped properly.
#
# Uncomment the next line, if you want the sql_user_name to mean:
#
# Use Stripped-User-Name, if it's there.
# Else use User-Name, if it's there,
# Else use hard-coded string "DEFAULT" as the user name.
#sql_user_name = "%{%{Stripped-User-Name}:-%{%{User-Name}:-DEFAULT}}"
#
sql_user_name = "%{User-Name}"
#######################################################################
# Query config: Event-Timestamp
#######################################################################
# event_timestamp_epoch is the basis for the time inserted into
# accounting records. Typically this will be the Event-Timestamp of the
# accounting request, which is usually provided by a NAS.
#
# Uncomment the next line, if you want the timestamp to be based on the
# request reception time recorded by this server, for example if you
# distrust the provided Event-Timestamp.
#event_timestamp_epoch = "%l"
event_timestamp_epoch = "%{%{integer:Event-Timestamp}:-%l}"
# event_timestamp is the SQL snippet for converting an epoch timestamp
# to an SQL date.
event_timestamp = "FROM_UNIXTIME(${event_timestamp_epoch})"
#######################################################################
# Query config: Class attribute
#######################################################################
#
# 3.0.22 and later have a "class" column in the accounting table.
#
# However, we do NOT want to break existing configurations by adding
# the Class attribute to the default queries. If we did that, then
# systems using newer versions of the server would fail, because
# there is no "class" column in their accounting tables.
#
# The solution to that is the following "class" subsection. If your
# database has a "class" column for the various tables, then you can
# uncomment the configuration items here. The queries below will
# then automatically insert the Class attribute into radacct,
# radpostauth, etc.
#
class {
#
# Delete the '#' character from each of the configuration
# items in this section. This change puts the Class
# attribute into the various tables. Leave the double-quoted
# string there, as the value for the configuration item.
#
# See also policy.d/accounting, and the "insert_acct_class"
# policy. You will need to list (or uncomment)
# "insert_acct_class" in the "post-auth" section in order to
# create a Class attribute.
#
column_name = # ", class"
packet_xlat = # ", '%{Class}'"
reply_xlat = # ", '%{reply:Class}'"
}
#######################################################################
# Default profile
#######################################################################
# This is the default profile. It is found in SQL by group membership.
# That means that this profile must be a member of at least one group
# which will contain the corresponding check and reply items.
# This profile will be queried in the authorize section for every user.
# The point is to assign all users a default profile without having to
# manually add each one to a group that will contain the profile.
# The SQL module will also honor the User-Profile attribute. This
# attribute can be set anywhere in the authorize section (ie the users
# file). It is found exactly as the default profile is found.
# If it is set then it will *overwrite* the default profile setting.
# The idea is to select profiles based on checks on the incoming packets,
# not on user group membership. For example:
# -- users file --
# DEFAULT Service-Type == Outbound-User, User-Profile := "outbound"
# DEFAULT Service-Type == Framed-User, User-Profile := "framed"
#
# By default the default_user_profile is not set
#
#default_user_profile = "DEFAULT"
#######################################################################
# NAS Query
#######################################################################
# This query retrieves the radius clients
#
# 0. Row ID (currently unused)
# 1. Name (or IP address)
# 2. Shortname
# 3. Type
# 4. Secret
# 5. Server
#######################################################################
client_query = "\
SELECT id, nasname, shortname, type, secret, server \
FROM ${client_table}"
#######################################################################
# Authorization Queries
#######################################################################
# These queries compare the check items for the user
# in ${authcheck_table} and setup the reply items in
# ${authreply_table}. You can use any query/tables
# you want, but the return data for each row MUST
# be in the following order:
#
# 0. Row ID (currently unused)
# 1. UserName/GroupName
# 2. Item Attr Name
# 3. Item Attr Value
# 4. Item Attr Operation
#######################################################################
# Use these for case sensitive usernames.
#authorize_check_query = "\
# SELECT id, username, attribute, value, op \
# FROM ${authcheck_table} \
# WHERE username = BINARY '%{SQL-User-Name}' \
# ORDER BY id"
#authorize_reply_query = "\
# SELECT id, username, attribute, value, op \
# FROM ${authreply_table} \
# WHERE username = BINARY '%{SQL-User-Name}' \
# ORDER BY id"
#
# The default queries are case insensitive. (for compatibility with
# older versions of FreeRADIUS)
#
authorize_check_query = "\
SELECT id, username, attribute, value, op \
FROM ${authcheck_table} \
WHERE username = '%{SQL-User-Name}' \
ORDER BY id"
authorize_reply_query = "\
SELECT id, username, attribute, value, op \
FROM ${authreply_table} \
WHERE username = '%{SQL-User-Name}' \
ORDER BY id"
#
# Use these for case sensitive usernames.
#
#group_membership_query = "\
# SELECT groupname \
# FROM ${usergroup_table} \
# WHERE username = BINARY '%{SQL-User-Name}' \
# ORDER BY priority"
group_membership_query = "\
SELECT groupname \
FROM ${usergroup_table} \
WHERE username = '%{SQL-User-Name}' \
ORDER BY priority"
authorize_group_check_query = "\
SELECT id, groupname, attribute, \
Value, op \
FROM ${groupcheck_table} \
WHERE groupname = '%{${group_attribute}}' \
ORDER BY id"
authorize_group_reply_query = "\
SELECT id, groupname, attribute, \
value, op \
FROM ${groupreply_table} \
WHERE groupname = '%{${group_attribute}}' \
ORDER BY id"
#######################################################################
# Simultaneous Use Checking Queries
#######################################################################
# simul_count_query - query for the number of current connections
# - If this is not defined, no simultaneous use checking
# - will be performed by this module instance
# simul_verify_query - query to return details of current connections
# for verification
# - Leave blank or commented out to disable verification step
# - Note that the returned field order should not be changed.
#
# Note: Sessions that started prior to the most recent reload of their NAS will
# be correctly considered inactive, even if the radacct entry itself is not
# marked as stopped.
#
#######################################################################
simul_count_query = "\
SELECT COUNT(*) \
FROM ${acct_table1} a \
LEFT OUTER JOIN nasreload n USING (nasipaddress) \
WHERE username = '%{SQL-User-Name}' \
AND acctstoptime IS NULL \
AND (a.acctstarttime > n.reloadtime OR n.reloadtime IS NULL)"
simul_verify_query = "\
SELECT \
radacctid, acctsessionid, username, nasipaddress, nasportid, framedipaddress, \
callingstationid, framedprotocol \
FROM ${acct_table1} a \
LEFT OUTER JOIN nasreload n USING (nasipaddress) \
WHERE username = '%{SQL-User-Name}' \
AND acctstoptime IS NULL \
AND (a.acctstarttime > n.reloadtime OR n.reloadtime IS NULL)"
#######################################################################
# Accounting and Post-Auth Queries
#######################################################################
# These queries insert/update accounting and authentication records.
# The query to use is determined by the value of 'reference'.
# This value is used as a configuration path and should resolve to one
# or more 'query's. If reference points to multiple queries, and a query
# fails, the next query is executed.
#
# Behaviour is identical to the old 1.x/2.x module, except we can now
# fail between N queries, and query selection can be based on any
# combination of attributes, or custom 'Acct-Status-Type' values.
#######################################################################
accounting {
reference = "%{tolower:type.%{%{Acct-Status-Type}:-%{Request-Processing-Stage}}.query}"
# Write SQL queries to a logfile. This is potentially useful for bulk inserts
# when used with the rlm_sql_null driver.
# logfile = ${logdir}/accounting.sql
column_list = "\
acctsessionid, acctuniqueid, username, \
realm, nasipaddress, nasportid, \
nasporttype, acctstarttime, acctupdatetime, \
acctstoptime, acctsessiontime, acctauthentic, \
connectinfo_start, connectinfo_stop, acctinputoctets, \
acctoutputoctets, calledstationid, callingstationid, \
acctterminatecause, servicetype, framedprotocol, \
framedipaddress, framedipv6address, framedipv6prefix, \
framedinterfaceid, delegatedipv6prefix ${..class.column_name}"
type {
accounting-on {
#
# "Bulk update" Accounting-On/Off strategy.
#
# Immediately terminate all sessions associated with a
# given NAS.
#
# Note: If a large number of sessions require closing
# then the bulk update may be take a long time to run
# and lock an excessive number of rows. See the
# strategy below for an alternative approach that does
# not touch the radacct session data.
#
query = "\
UPDATE ${....acct_table1} \
SET \
acctstoptime = ${....event_timestamp}, \
acctsessiontime = '${....event_timestamp_epoch}' \
- UNIX_TIMESTAMP(acctstarttime), \
acctterminatecause = '%{%{Acct-Terminate-Cause}:-NAS-Reboot}' \
WHERE acctstoptime IS NULL \
AND nasipaddress = '%{NAS-IP-Address}' \
AND acctstarttime <= ${....event_timestamp}"
#
# "Lightweight" Accounting-On/Off strategy.
#
# Record the reload time of the NAS and let the
# administrator actually close the sessions in radacct
# out-of-band, if desired.
#
# Implementation advice, together with a stored
# procedure for closing sessions and a view showing
# the effective stop time of each session is provided
# in process-radacct.sql.
#
# To enable this strategy, just change the previous
# query to "-query", and this one to "query". The
# previous one will be ignored, and this one will be
# enabled.
#
-query = "\
INSERT INTO nasreload \
SET \
nasipaddress = '%{NAS-IP-Address}', \
reloadtime = ${....event_timestamp} \
ON DUPLICATE KEY UPDATE reloadtime = ${....event_timestamp}"
}
accounting-off {
query = "${..accounting-on.query}"
}
#
# Implement the "sql_session_start" policy.
# See raddb/policy.d/accounting for more details.
#
# You also need to fix the other queries as
# documented below. Look for "sql_session_start".
#
post-auth {
query = "\
INSERT INTO ${....acct_table1} \
(${...column_list}) \
VALUES(\
'%{Acct-Session-Id}', \
'%{Acct-Unique-Session-Id}', \
'%{SQL-User-Name}', \
'%{Realm}', \
'%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}', \
NULLIF('%{%{NAS-Port-ID}:-%{NAS-Port}}', ''), \
'%{NAS-Port-Type}', \
${....event_timestamp}, \
${....event_timestamp}, \
NULL, \
0, \
'', \
'%{Connect-Info}', \
NULL, \
0, \
0, \
'%{Called-Station-Id}', \
'%{Calling-Station-Id}', \
'', \
'%{Service-Type}', \
NULL, \
'', \
'', \
'', \
'', \
'' \
${....class.packet_xlat})"
query = "\
UPDATE ${....acct_table1} SET \
AcctStartTime = ${....event_timestamp}, \
AcctUpdateTime = ${....event_timestamp}, \
ConnectInfo_start = '%{Connect-Info}', \
AcctSessionId = '%{Acct-Session-Id}' \
WHERE UserName = '%{SQL-User-Name}' \
AND NASIPAddress = '%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}' \
AND NASPortId = '%{%{NAS-Port-ID}:-%{NAS-Port}}' \
AND NASPortType = '%{NAS-Port-Type}' \
AND AcctStopTime IS NULL"
}
start {
#
# Insert a new record into the sessions table
#
query = "\
INSERT INTO ${....acct_table1} \
(${...column_list}) \
VALUES \
('%{Acct-Session-Id}', \
'%{Acct-Unique-Session-Id}', \
'%{SQL-User-Name}', \
'%{Realm}', \
'%{NAS-IP-Address}', \
'%{%{NAS-Port-ID}:-%{NAS-Port}}', \
'%{NAS-Port-Type}', \
${....event_timestamp}, \
${....event_timestamp}, \
NULL, \
'0', \
'%{Acct-Authentic}', \
'%{Connect-Info}', \
'', \
'0', \
'0', \
'%{Called-Station-Id}', \
'%{Calling-Station-Id}', \
'', \
'%{Service-Type}', \
'%{Framed-Protocol}', \
'%{Framed-IP-Address}', \
'%{Framed-IPv6-Address}', \
'%{Framed-IPv6-Prefix}', \
'%{Framed-Interface-Id}', \
'%{Delegated-IPv6-Prefix}' \
${....class.packet_xlat})"
#
# When using "sql_session_start", you should comment out
# the previous query, and enable this one.
#
# Just change the previous query to "-query",
# and this one to "query". The previous one
# will be ignored, and this one will be
# enabled.
#
-query = "\
UPDATE ${....acct_table1} \
SET \
AcctSessionId = '%{Acct-Session-Id}', \
AcctUniqueId = '%{Acct-Unique-Session-Id}', \
AcctAuthentic = '%{Acct-Authentic}', \
ConnectInfo_start = '%{Connect-Info}', \
ServiceType = '%{Service-Type}', \
FramedProtocol = '%{Framed-Protocol}', \
framedipaddress = '%{Framed-IP-Address}', \
framedipv6address = '%{Framed-IPv6-Address}', \
framedipv6prefix = '%{Framed-IPv6-Prefix}', \
framedinterfaceid = '%{Framed-Interface-Id}', \
delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', \
AcctStartTime = ${....event_timestamp}, \
AcctUpdateTime = ${....event_timestamp} \
WHERE UserName = '%{SQL-User-Name}' \
AND NASIPAddress = '%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}' \
AND NASPortId = '%{%{NAS-Port-ID}:-%{NAS-Port}}' \
AND NASPortType = '%{NAS-Port-Type}' \
AND AcctStopTime IS NULL"
#
# Key constraints prevented us from inserting a new session,
# use the alternate query to update an existing session.
#
query = "\
UPDATE ${....acct_table1} SET \
acctstarttime = ${....event_timestamp}, \
acctupdatetime = ${....event_timestamp}, \
connectinfo_start = '%{Connect-Info}' \
WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'"
}
interim-update {
#
# Update an existing session and calculate the interval
# between the last data we received for the session and this
# update. This can be used to find stale sessions.
#
query = "\
UPDATE ${....acct_table1} \
SET \
acctupdatetime = (@acctupdatetime_old:=acctupdatetime), \
acctupdatetime = ${....event_timestamp}, \
acctinterval = ${....event_timestamp_epoch} - \
UNIX_TIMESTAMP(@acctupdatetime_old), \
framedipaddress = '%{Framed-IP-Address}', \
framedipv6address = '%{Framed-IPv6-Address}', \
framedipv6prefix = '%{Framed-IPv6-Prefix}', \
framedinterfaceid = '%{Framed-Interface-Id}', \
delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', \
acctsessiontime = %{%{Acct-Session-Time}:-NULL}, \
acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' \
<< 32 | '%{%{Acct-Input-Octets}:-0}', \
acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' \
<< 32 | '%{%{Acct-Output-Octets}:-0}' \
WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'"
#
# The update condition matched no existing sessions. Use
# the values provided in the update to create a new session.
#
query = "\
INSERT INTO ${....acct_table1} \
(${...column_list}) \
VALUES \
('%{Acct-Session-Id}', \
'%{Acct-Unique-Session-Id}', \
'%{SQL-User-Name}', \
'%{Realm}', \
'%{NAS-IP-Address}', \
'%{%{NAS-Port-ID}:-%{NAS-Port}}', \
'%{NAS-Port-Type}', \
FROM_UNIXTIME(${....event_timestamp_epoch} - %{%{Acct-Session-Time}:-0}), \
${....event_timestamp}, \
NULL, \
%{%{Acct-Session-Time}:-NULL}, \
'%{Acct-Authentic}', \
'%{Connect-Info}', \
'', \
'%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Input-Octets}:-0}', \
'%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Output-Octets}:-0}', \
'%{Called-Station-Id}', \
'%{Calling-Station-Id}', \
'', \
'%{Service-Type}', \
'%{Framed-Protocol}', \
'%{Framed-IP-Address}', \
'%{Framed-IPv6-Address}', \
'%{Framed-IPv6-Prefix}', \
'%{Framed-Interface-Id}', \
'%{Delegated-IPv6-Prefix}' \
${....class.packet_xlat})"
#
# When using "sql_session_start", you should comment out
# the previous query, and enable this one.
#
# Just change the previous query to "-query",
# and this one to "query". The previous one
# will be ignored, and this one will be
# enabled.
#
-query = "\
UPDATE ${....acct_table1} \
SET \
AcctSessionId = '%{Acct-Session-Id}', \
AcctUniqueId = '%{Acct-Unique-Session-Id}', \
AcctAuthentic = '%{Acct-Authentic}', \
ConnectInfo_start = '%{Connect-Info}', \
ServiceType = '%{Service-Type}', \
FramedProtocol = '%{Framed-Protocol}', \
framedipaddress = '%{Framed-IP-Address}', \
framedipv6address = '%{Framed-IPv6-Address}', \
framedipv6prefix = '%{Framed-IPv6-Prefix}', \
framedinterfaceid = '%{Framed-Interface-Id}', \
delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', \
AcctUpdateTime = ${....event_timestamp}, \
AcctSessionTime = %{%{Acct-Session-Time}:-NULL}, \
AcctInputOctets = '%{%{Acct-Input-Gigawords}:-0}' \
<< 32 | '%{%{Acct-Input-Octets}:-0}', \
AcctOutputOctets = '%{%{Acct-Output-Gigawords}:-0}' \
<< 32 | '%{%{Acct-Output-Octets}:-0}' \
WHERE UserName = '%{SQL-User-Name}' \
AND NASIPAddress = '%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}' \
AND NASPortId = '%{%{NAS-Port-ID}:-%{NAS-Port}}' \
AND NASPortType = '%{NAS-Port-Type}' \
AND AcctStopTime IS NULL"
}
stop {
#
# Session has terminated, update the stop time and statistics.
#
query = "\
UPDATE ${....acct_table2} SET \
acctstoptime = ${....event_timestamp}, \
acctsessiontime = %{%{Acct-Session-Time}:-NULL}, \
acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' \
<< 32 | '%{%{Acct-Input-Octets}:-0}', \
acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' \
<< 32 | '%{%{Acct-Output-Octets}:-0}', \
acctterminatecause = '%{Acct-Terminate-Cause}', \
connectinfo_stop = '%{Connect-Info}' \
WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'"
#
# The update condition matched no existing sessions. Use
# the values provided in the update to create a new session.
#
query = "\
INSERT INTO ${....acct_table2} \
(${...column_list}) \
VALUES \
('%{Acct-Session-Id}', \
'%{Acct-Unique-Session-Id}', \
'%{SQL-User-Name}', \
'%{Realm}', \
'%{NAS-IP-Address}', \
'%{%{NAS-Port-ID}:-%{NAS-Port}}', \
'%{NAS-Port-Type}', \
FROM_UNIXTIME(${....event_timestamp_epoch} - %{%{Acct-Session-Time}:-0}), \
${....event_timestamp}, \
${....event_timestamp}, \
%{%{Acct-Session-Time}:-NULL}, \
'%{Acct-Authentic}', \
'', \
'%{Connect-Info}', \
'%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Input-Octets}:-0}', \
'%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Output-Octets}:-0}', \
'%{Called-Station-Id}', \
'%{Calling-Station-Id}', \
'%{Acct-Terminate-Cause}', \
'%{Service-Type}', \
'%{Framed-Protocol}', \
'%{Framed-IP-Address}', \
'%{Framed-IPv6-Address}', \
'%{Framed-IPv6-Prefix}', \
'%{Framed-Interface-Id}', \
'%{Delegated-IPv6-Prefix}' \
${....class.packet_xlat})"
#
# When using "sql_session_start", you should comment out
# the previous query, and enable this one.
#
# Just change the previous query to "-query",
# and this one to "query". The previous one
# will be ignored, and this one will be
# enabled.
#
-query = "\
UPDATE ${....acct_table1} \
SET \
AcctSessionId = '%{Acct-Session-Id}', \
AcctUniqueId = '%{Acct-Unique-Session-Id}', \
AcctAuthentic = '%{Acct-Authentic}', \
ConnectInfo_start = '%{Connect-Info}', \
ServiceType = '%{Service-Type}', \
FramedProtocol = '%{Framed-Protocol}', \
framedipaddress = '%{Framed-IP-Address}', \
framedipv6address = '%{Framed-IPv6-Address}', \
framedipv6prefix = '%{Framed-IPv6-Prefix}', \
framedinterfaceid = '%{Framed-Interface-Id}', \
delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', \
AcctStopTime = ${....event_timestamp}, \
AcctUpdateTime = ${....event_timestamp}, \
AcctSessionTime = %{Acct-Session-Time}, \
AcctInputOctets = '%{%{Acct-Input-Gigawords}:-0}' \
<< 32 | '%{%{Acct-Input-Octets}:-0}', \
AcctOutputOctets = '%{%{Acct-Output-Gigawords}:-0}' \
<< 32 | '%{%{Acct-Output-Octets}:-0}', \
AcctTerminateCause = '%{Acct-Terminate-Cause}', \
ConnectInfo_stop = '%{Connect-Info}' \
WHERE UserName = '%{SQL-User-Name}' \
AND NASIPAddress = '%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}' \
AND NASPortId = '%{%{NAS-Port-ID}:-%{NAS-Port}}' \
AND NASPortType = '%{NAS-Port-Type}' \
AND AcctStopTime IS NULL"
}
#
# No Acct-Status-Type == ignore the packet
#
accounting {
query = "SELECT true"
}
}
}
#######################################################################
# Authentication Logging Queries
#######################################################################
# postauth_query - Insert some info after authentication
#######################################################################
post-auth {
# Write SQL queries to a logfile. This is potentially useful for bulk inserts
# when used with the rlm_sql_null driver.
# logfile = ${logdir}/post-auth.sql
query = "\
INSERT INTO ${..postauth_table} \
(username, reply, reason, authdate ${..class.column_name}) \
VALUES ( \
'%{SQL-User-Name}', \
'%{reply:Packet-Type}', \
'%{reply:Reply-Message}', \
'%S.%M' \
${..class.reply_xlat})"
}
-211
View File
@@ -1,211 +0,0 @@
#
# Example of forbidding all attempts to login via
# realms.
#
deny_realms {
if (&User-Name && (&User-Name =~ /@|\\/)) {
reject
}
}
#
# Filter the username
#
# Force some sanity on User-Name. This helps to avoid issues
# issues where the back-end database is "forgiving" about
# what constitutes a user name.
#
filter_username {
if (&User-Name) {
#
# reject mixed case e.g. "UseRNaMe"
#
#if (&User-Name != "%{tolower:%{User-Name}}") {
# reject
#}
#
# reject all whitespace
# e.g. "user@ site.com", or "us er", or " user", or "user "
#
if (&User-Name =~ / /) {
update request {
&Module-Failure-Message += 'Rejected: User-Name contains whitespace'
}
reject
}
#
# reject Multiple @'s
# e.g. "user@site.com@site.com"
#
if (&User-Name =~ /@[^@]*@/ ) {
update request {
&Module-Failure-Message += 'Rejected: Multiple @ in User-Name'
}
reject
}
#
# reject double dots
# e.g. "user@site..com"
#
if (&User-Name =~ /\.\./ ) {
update request {
&Module-Failure-Message += 'Rejected: User-Name contains multiple ..s'
}
reject
}
#
# must have at least 1 string-dot-string after @
# e.g. "user@site.com"
#
# if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
# update request {
# &Module-Failure-Message += 'Rejected: Realm does not have at least one dot separator'
# }
# reject
# }
#
# Realm ends with a dot
# e.g. "user@site.com."
#
if (&User-Name =~ /\.$/) {
update request {
&Module-Failure-Message += 'Rejected: Realm ends with a dot'
}
reject
}
#
# Realm begins with a dot
# e.g. "user@.site.com"
#
if (&User-Name =~ /@\./) {
update request {
&Module-Failure-Message += 'Rejected: Realm begins with a dot'
}
reject
}
}
}
#
# Filter the User-Password
#
# Some equipment sends passwords with embedded zeros.
# This policy filters them out.
#
filter_password {
if (&User-Password && \
(&User-Password != "%{string:User-Password}")) {
update request {
&Tmp-String-0 := "%{string:User-Password}"
&User-Password := "%{string:Tmp-String-0}"
&Tmp-String-0 !* ""
}
}
}
filter_inner_identity {
#
# No names, reject.
#
if (!&outer.request:User-Name || !&User-Name) {
update request {
Module-Failure-Message = "User-Name is required for tunneled authentication"
}
reject
}
#
# Do detailed checks only if the inner and outer
# NAIs are different.
#
# If the NAIs are the same, it violates user privacy,
# but is allowed.
#
if (&outer.request:User-Name != &User-Name) {
#
# Get the outer realm.
#
if (&outer.request:User-Name =~ /@([^@]+)$/) {
update request {
Outer-Realm-Name = "%{1}"
}
#
# When we have an outer realm name, the user portion
# MUST either be empty, or begin with "anon".
#
# We don't check for the full "anonymous", because
# some vendors don't follow the standards.
#
if (&outer.request:User-Name !~ /^(anon|@)/) {
update request {
Module-Failure-Message = "User-Name is not anonymized"
}
reject
}
}
#
# There's no outer realm. The outer NAI is different from the
# inner NAI. The User-Name MUST be anonymized.
#
# Otherwise, you could log in as outer "bob", and inner "doug",
# and we'd have no idea which one was correct.
#
elsif (&outer.request:User-Name !~ /^anon/) {
update request {
Module-Failure-Message = "User-Name is not anonymized"
}
reject
}
#
# Get the inner realm.
#
if (&User-Name =~ /@([^@]+)$/) {
update request {
Inner-Realm-Name = "%{1}"
}
#
# Note that we do EQUALITY checks for realm names.
# There is no simple way to do case insensitive checks
# on internationalized domain names. There is no reason
# to allow outer "anonymous@EXAMPLE.COM" and inner
# "user@example.com". The user should enter the same
# realm for both identities.
#
# If the inner realm isn't the same as the outer realm,
# the inner realm MUST be a subdomain of the outer realm.
#
if (&Outer-Realm-Name && \
(&Inner-Realm-Name != &Outer-Realm-Name) && \
(&Inner-Realm-Name !~ /\.%{Outer-Realm-Name}$/)) {
update request {
Module-Failure-Message = "Inner realm '%{Inner-Realm-Name}' and outer realm '%{Outer-Realm-Name}' are not from the same domain."
}
reject
}
#
# It's OK to have an inner realm and no outer realm.
#
# That won't work for roaming, but the local RADIUS server
# can still authenticate the user.
#
}
#
# It's OK to have an outer realm and no inner realm.
#
# It will work for roaming, and the local RADIUS server
# can authenticate the user without the realm.
#
}
}
-15
View File
@@ -1,15 +0,0 @@
vlan_test {
if (&User-Name =~ /.+@(.+)/) {
update control {
Tmp-String-0 := "%{1}"
}
update reply {
Tunnel-Type := VLAN
Tunnel-Medium-Type := IEEE-802
Tunnel-Private-Group-Id := "%{sql:SELECT vlan_id FROM tenant_subnets WHERE tenant_id='%{control:Tmp-String-0}'}"
}
}
}
-1143
View File
File diff suppressed because it is too large Load Diff
-184
View File
@@ -1,184 +0,0 @@
###########################################################################
# $Id: 41fcccad1c012226d12cc721518fe91e311e55e2 $ #
# #
# schema.sql rlm_sql - FreeRADIUS SQL Module #
# #
# Database schema for MySQL rlm_sql module #
# #
# To load: #
# mysql -uroot -prootpass radius < schema.sql #
# #
# Mike Machado <mike@innercite.com> #
###########################################################################
#
# Table structure for table 'radacct'
#
CREATE TABLE IF NOT EXISTS radacct (
radacctid bigint(21) NOT NULL auto_increment,
acctsessionid varchar(64) NOT NULL default '',
acctuniqueid varchar(32) NOT NULL default '',
username varchar(64) NOT NULL default '',
realm varchar(64) default '',
nasipaddress varchar(15) NOT NULL default '',
nasportid varchar(32) default NULL,
nasporttype varchar(32) default NULL,
acctstarttime datetime NULL default NULL,
acctupdatetime datetime NULL default NULL,
acctstoptime datetime NULL default NULL,
acctinterval int(12) default NULL,
acctsessiontime int(12) unsigned default NULL,
acctauthentic varchar(32) default NULL,
connectinfo_start varchar(128) default NULL,
connectinfo_stop varchar(128) default NULL,
acctinputoctets bigint(20) default NULL,
acctoutputoctets bigint(20) default NULL,
calledstationid varchar(50) NOT NULL default '',
callingstationid varchar(50) NOT NULL default '',
acctterminatecause varchar(32) NOT NULL default '',
servicetype varchar(32) default NULL,
framedprotocol varchar(32) default NULL,
framedipaddress varchar(15) NOT NULL default '',
framedipv6address varchar(45) NOT NULL default '',
framedipv6prefix varchar(45) NOT NULL default '',
framedinterfaceid varchar(44) NOT NULL default '',
delegatedipv6prefix varchar(45) NOT NULL default '',
class varchar(64) default NULL,
PRIMARY KEY (radacctid),
UNIQUE KEY acctuniqueid (acctuniqueid),
KEY username (username),
KEY framedipaddress (framedipaddress),
KEY framedipv6address (framedipv6address),
KEY framedipv6prefix (framedipv6prefix),
KEY framedinterfaceid (framedinterfaceid),
KEY delegatedipv6prefix (delegatedipv6prefix),
KEY acctsessionid (acctsessionid),
KEY acctsessiontime (acctsessiontime),
KEY acctstarttime (acctstarttime),
KEY acctinterval (acctinterval),
KEY acctstoptime (acctstoptime),
KEY nasipaddress (nasipaddress),
KEY class (class)
) ENGINE = INNODB;
#
# Table structure for table 'radcheck'
#
CREATE TABLE IF NOT EXISTS radcheck (
id int(11) unsigned NOT NULL auto_increment,
username varchar(64) NOT NULL default '',
attribute varchar(64) NOT NULL default '',
op char(2) NOT NULL DEFAULT '==',
value varchar(253) NOT NULL default '',
PRIMARY KEY (id),
KEY username (username(32))
) ENGINE = INNODB;
#
# Table structure for table 'radgroupcheck'
#
CREATE TABLE IF NOT EXISTS radgroupcheck (
id int(11) unsigned NOT NULL auto_increment,
groupname varchar(64) NOT NULL default '',
attribute varchar(64) NOT NULL default '',
op char(2) NOT NULL DEFAULT '==',
value varchar(253) NOT NULL default '',
PRIMARY KEY (id),
KEY groupname (groupname(32))
) ENGINE = INNODB;
#
# Table structure for table 'radgroupreply'
#
CREATE TABLE IF NOT EXISTS radgroupreply (
id int(11) unsigned NOT NULL auto_increment,
groupname varchar(64) NOT NULL default '',
attribute varchar(64) NOT NULL default '',
op char(2) NOT NULL DEFAULT '=',
value varchar(253) NOT NULL default '',
PRIMARY KEY (id),
KEY groupname (groupname(32))
) ENGINE = INNODB;
#
# Table structure for table 'radreply'
#
CREATE TABLE IF NOT EXISTS radreply (
id int(11) unsigned NOT NULL auto_increment,
username varchar(64) NOT NULL default '',
attribute varchar(64) NOT NULL default '',
op char(2) NOT NULL DEFAULT '=',
value varchar(253) NOT NULL default '',
PRIMARY KEY (id),
KEY username (username(32))
) ENGINE = INNODB;
#
# Table structure for table 'radusergroup'
#
CREATE TABLE IF NOT EXISTS `radusergroup` (
id int(11) unsigned NOT NULL auto_increment,
username varchar(64) NOT NULL default '',
groupname varchar(64) NOT NULL default '',
priority int(11) NOT NULL default '1',
PRIMARY KEY (id),
KEY username (username(32))
) ENGINE = INNODB;
#
# Table structure for table 'radpostauth'
#
# Note: MySQL versions since 5.6.4 support fractional precision timestamps
# which we use here. Replace the authdate definition with the following
# if your software is too old:
#
# authdate timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
#
CREATE TABLE IF NOT EXISTS radpostauth (
id int(11) NOT NULL auto_increment,
username varchar(64) NOT NULL default '',
pass varchar(64) NOT NULL default '',
reply varchar(32) NOT NULL default '',
authdate timestamp(6) NOT NULL DEFAULT CURRENT_TIMESTAMP(6) ON UPDATE CURRENT_TIMESTAMP(6),
class varchar(64) default NULL,
PRIMARY KEY (id),
KEY username (username),
KEY class (class)
) ENGINE = INNODB;
#
# Table structure for table 'nas'
#
CREATE TABLE IF NOT EXISTS nas (
id int(10) NOT NULL auto_increment,
nasname varchar(128) NOT NULL,
shortname varchar(32),
type varchar(30) DEFAULT 'other',
ports int(5),
secret varchar(60) DEFAULT 'secret' NOT NULL,
server varchar(64),
community varchar(50),
description varchar(200) DEFAULT 'RADIUS Client',
PRIMARY KEY (id),
KEY nasname (nasname)
) ENGINE = INNODB;
#
# Table structure for table 'radippool'
#
CREATE TABLE IF NOT EXISTS radippool (
id int(11) unsigned NOT NULL auto_increment,
pool_name varchar(30) NOT NULL,
framedipaddress varchar(15) NOT NULL default '',
nasipaddress varchar(15) NOT NULL default '',
calledstationid VARCHAR(30) NOT NULL default '',
callingstationid VARCHAR(30) NOT NULL default '',
expiry_time DATETIME NOT NULL default NOW(),
username varchar(64) NOT NULL default '',
pool_key varchar(64) NOT NULL default '',
PRIMARY KEY (id),
KEY radippool_poolname_expire (pool_name, expiry_time),
UNIQUE KEY framedipaddress_unique (framedipaddress),
KEY radippool_nasip_poolkey_ipaddress (nasipaddress, pool_key, framedipaddress)
) ENGINE=InnoDB;
-41
View File
@@ -1,41 +0,0 @@
# -*- text -*-
######################################################################
#
# Sample virtual server for receiving a CoA or Disconnect-Request packet.
#
# Listen on the CoA port.
#
# This uses the normal set of clients, with the same secret as for authentication and accounting.
#
listen {
type = coa
# ipaddr = $ENV{FREERADIUS_SITES_COA_LISTEN}
ipaddr = *
port = $ENV{FREERADIUS_SITES_COA_PORT}
virtual_server = coa
}
server coa {
# When a packet is received, it is processed through the recv-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
recv-coa {
# CoA && Disconnect packets can be proxied in the same way as authentication or accounting packets.
# Just set Proxy-To-Realm, or Home-Server-Pool, and the packets will be proxied.
# Do proxying based on realms here. You don't need "IPASS" or "ntdomain", as the proxying is based on the Operator-Name attribute. It contains the realm,
# and ONLY the realm (prefixed by a '1')
suffix
# Insert your own policies here.
ok
}
# When a packet is sent, it is processed through the send-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
send-coa {
# Sample module.
ok
}
# You can use pre-proxy and post-proxy sections here, too. They will be processed for sending && receiving proxy packets.
}
File diff suppressed because it is too large Load Diff
-595
View File
@@ -1,595 +0,0 @@
# -*- text -*-
######################################################################
#
# This is a virtual server that handles DHCP.
#
# See raddb/mods-available/dhcp_sqlippool for the IP Pool configuration.
#
# See raddb/policy.d/dhcp_sqlippool for the "glue" code that allows
# the RADIUS based "sqlippool" module to be used for DHCP.
#
# See raddb/mods-config/sql/ippool/ for the schemas.
#
# See raddb/sites-available/dhcp for instructions on how to configure
# the DHCP server.
#
# $Id$
#
######################################################################
#
# The DHCP functionality goes into a virtual server.
#
server dhcp {
# Define a DHCP socket.
#
# The default port below is 6700, so you don't break your network.
# If you want it to do real DHCP, change this to 67, and good luck!
#
# You can also bind the DHCP socket to an interface.
# See below, and raddb/radiusd.conf for examples.
#
# This lets you run *one* DHCP server instance and have it listen on
# multiple interfaces, each with a separate policy.
#
# If you have multiple interfaces, it is a good idea to bind the
# listen section to an interface. You will also need one listen
# section per interface.
#
# FreeBSD does *not* support binding sockets to interfaces. Therefore,
# if you have multiple interfaces, broadcasts may go out of the wrong
# one, or even all interfaces. The solution is to use the "setfib" command.
# If you have a network "10.10.0/24" on LAN1, you will need to do:
#
# Pick any IP on the 10.10.0/24 network
# $ setfib 1 route add default 10.10.0.1
#
# Edit /etc/rc.local, and add a line:
# setfib 1 /path/to/radiusd
#
# The kern must be built with the following options:
# options ROUTETABLES=2
# or any value larger than 2.
#
# The other only solution is to update FreeRADIUS to use BPF sockets.
#
listen {
# This is a dhcp socket.
type = dhcp
# IP address to listen on. Will usually be the IP of the
# interface, or 0.0.0.0
ipaddr = 0.0.0.0
# source IP address for unicast packets sent by the
# DHCP server.
#
# The source IP for unicast packets is chosen from the first
# one of the following items which returns a valid IP
# address:
#
# src_ipaddr
# ipaddr
# reply:DHCP-Server-IP-Address
# reply:DHCP-DHCP-Server-Identifier
#
src_ipaddr = 127.0.0.1
# The port should be 67 for a production network. Don't set
# it to 67 on a production network unless you really know
# what you're doing. Even if nothing is configured below, the
# server may still NAK legitimate responses from clients.
port = 6700
# Interface name we are listening on. See comments above.
# interface = lo0
# The DHCP server defaults to allowing broadcast packets.
# Set this to "no" only when the server receives *all* packets
# from a relay agent. i.e. when *no* clients are on the same
# LAN as the DHCP server.
#
# It's set to "no" here for testing. It will usually want to
# be "yes" in production, unless you are only dealing with
# relayed packets.
broadcast = no
# On Linux if you're running the server as non-root, you
# will need to do:
#
# setcap cap_net_admin,cap_net_bind_service=eip /path/to/radiusd
#
# This will allow the server to set ARP table entries
# for newly allocated IPs, when run as the "radius" user.
#
# The above "setcap" command adds the capability to the program,
# usually so long as it is run by the "radius" user. Which means
# (oddly enough) that it no longer works when run as root!
#
# When running the server as root in debug mode, you can use:
#
# capsh --caps="cap_setpcap,cap_setuid,cap_setgid,cap_net_admin,cap_net_bind_service+eip" --keep=1 --user=radius --addamb=cap_net_admin,cap_net_bind_service -- -c "/path/to/radiusd -X"
#
# Or, simply "sudo" or "su" to the "radius" user, and then run
# the server in debug mode.
# De-duplicate DHCP packets. If clients don't receive
# a reply within their timeout, most will re-transmit.
# A reply to either packet will satisfy, so de-duplicating
# helps manage load on a busy server
performance {
skip_duplicate_checks = no
}
}
# Packets received on the socket will be processed through one
# of the following sections, named after the DHCP packet type.
# See dictionary.dhcp for the packet types.
# Return packets will be sent to, in preference order:
# DHCP-Gateway-IP-Address
# DHCP-Client-IP-Address
# DHCP-Your-IP-Address
# At least one of these attributes should be set at the end of each
# section for a response to be sent.
# An internal attribute of DHCP-Network-Subnet is set to provide
# a basis for determining the network that a client belongs to. This
# is a hierarchical assignment based on:
#
# - DHCP-Relay-Link-Selection
# - DHCP-Subnet-Selection-Option
# - DHCP-Gateway-IP-Address
# - DHCP-Client-IP-Address
#
# Except for cases where all IP allocation is performed using a mapping from
# the device MAC address to a fixed IP address the DHCP configuration will
# involve the use of one or more pools.
#
# Each pool should be composed of a set of equally valid IP addresses for the
# devices designated as users of the pool. During IP allocation the choice of
# pool is driven by setting the Pool-Name attribute which may either be
# specified directly or chosen (usually with the help of the dhcp_network
# module) based on the initial value of DHCP-Network-Subnet.
#
# DHCP-Network-Subnet indicates the network from which the request is
# originating. In cases where the originating network alone is insufficent to
# define the required IP allocated policy, DHCP-Network-Subnet may be
# overridden to force the selection of a particular pool.
#
# IP addresses belonging to a single pool that is designated for a Layer 2
# network containing multiple subnets (a "shared-network" or "multinet"
# configuration as defined by some other DHCP servers), will by definition be
# members of distinct subnets that require their own DHCP reply parameters. In
# this case the dhcp_subnet policy can be used to set the correct
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address options
# based on the allocated IP.
dhcp DHCP-Discover {
# The DHCP Server Identifier is set here since is returned in OFFERs
update control {
&DHCP-DHCP-Server-Identifier = 192.0.2.2
}
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
dhcp_common
# Use a "passwd" module to set group memberships in DHCP-Group-Name
# Enable mods-available/dhcp_passwd to use this
#dhcp_group_membership
# If clients need to be assigned to a particular network based on
# an attribute in the packet rather than the calculated
# DHCP-Network-Subnet described above, then call a policy
# (defined in policy.d/dhcp) to perform the override
#dhcp_override_network
# Use a "files" module to lookup global and subnet options
# For multiple subnets use this in place of dhcp_common
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_network
# Do a simple mapping of MAC to assigned IP.
#
# See below for the definition of the "mac2ip"
# module.
#
#mac2ip
# Or, allocate IPs from the DHCP pool in SQL. You may need to
# set the pool name here if you haven't set it elsewhere.
#update control {
# &Pool-Name := "local"
#}
#dhcp_sqlippool
# If the IP address was not allocated, do something else.
# You could call a Perl, Python, or Java script here.
#if (notfound) {
# ...
#}
# "Shared-networks" may have multiple IP subnets co-existing in a
# single Layer 2 network. If the pool for the network contains
# addresses from more that one subnet then the setting subnet-specific
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
# parameters must be performed after the allocation of the IP address.
#
# Set any subnet-specific parameters using this policy.
#
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
# policy.d/dhcp to use this.
#
#dhcp_subnet
# Use a "files" module to lookup options based on DHCP-Group-Name
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_group_options
# Use a "files" module to lookup host specific options
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_hosts
# As an alternative or complement to configuration files based lookup
# for options data you can instead use an SQL database. Example
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
# will need to be adapted to your requirements.
#dhcp_policy_sql
# Set the type of packet to send in reply.
#
# The server will look at the DHCP-Message-Type attribute to
# determine which type of packet to send in reply. Common
# values would be DHCP-Offer, DHCP-Ack or DHCP-NAK. See
# dictionary.dhcp for all the possible values.
#
# DHCP-Do-Not-Respond can be used to tell the server to not
# respond.
#
# In the event that DHCP-Message-Type is not set then the
# server will fall back to determining the type of reply
# based on the rcode of this section.
#
#update reply {
# DHCP-Message-Type = DHCP-Offer
#}
#
# If DHCP-Message-Type is not set, returning "ok" or
# "updated" from this section will respond with a DHCP-Offer
# message.
#
# Other rcodes will tell the server to not return any response.
#
#ok
}
dhcp DHCP-Request {
# You must set the DHCP Server Identifier here since this is returned
# in ACKs and is used to determine whether a request containing a
# "server-ip" field is intended for this server
update control {
&DHCP-DHCP-Server-Identifier = 192.0.2.2
}
# If the request is not for this server then silently discard it
if (&request:DHCP-DHCP-Server-Identifier && \
&request:DHCP-DHCP-Server-Identifier != &control:DHCP-DHCP-Server-Identifier) {
do_not_respond
}
# Response packet type. See DHCP-Discover section above.
#update reply {
# &DHCP-Message-Type = DHCP-Ack
#}
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
dhcp_common
# Use a "passwd" module to set group memberships in DHCP-Group-Name
# Enable mods-available/dhcp_passwd to use this
#dhcp_group_membership
# Optionally override the network address based on client attributes
# See Discover section
#dhcp_override_network
# Use a "files" module to lookup global and subnet options
# For multiple subnets use this in place of dhcp_common
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
# policy.d/dhcp to use this
# Options are set in mods-config/files/dhcp
#dhcp_network
# Do a simple mapping of MAC to assigned IP.
#
# See below for the definition of the "mac2ip"
# module.
#
#mac2ip
# Or, allocate IPs from the DHCP pool in SQL. You may need to
# set the pool name here if you haven't set it elsewhere.
# update control {
# &Pool-Name := "local"
# }
# dhcp_sqlippool_request
# If the IP was not allocated, do something else.
# You could call a Perl, Python, or Java script here.
#if (notfound) {
# ...
#}
# "Shared-networks" may have multiple IP subnets co-existing in a
# single Layer 2 network. If the pool for the network contains
# addresses from more that one subnet then the setting subnet-specific
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
# parameters must be performed after the allocation of the IP address.
#
# Set any subnet-specific parameters using this policy.
#
#dhcp_subnet
# Use a "files" module to lookup options based on DHCP-Group-Name
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_group_options
# Use a "files" module to lookup host specific options
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_hosts
# As an alternative or complement to configuration files based lookup
# for options data you can instead use an SQL database. Example
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
# will need to be adapted to your requirements.
#dhcp_policy_sql
# If DHCP-Message-Type is not set, returning "ok" or
# "updated" from this section will respond with a DHCP-Ack
# packet.
#
# "handled" will not return a packet, all other rcodes will
# send back a DHCP-NAK.
#
#ok
}
#
# Other DHCP packet types
#
# There should be a separate section for each DHCP message type.
# By default this configuration will ignore them all. Any packet type
# not defined here will be responded to with a DHCP-NAK.
dhcp DHCP-Decline {
# Use a "passwd" module to set group memberships in DHCP-Group-Name
# Enable mods-available/dhcp_passwd to use this
#dhcp_group_membership
# Optionally override the network address based on client attributes
# See Discover section
#dhcp_override_network
# Use a "files" module to lookup global and subnet options
# For multiple networks use this in place of dhcp_common
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_network
# Use a policy that set options from data stored in an SQL database
#dhcp_policy_sql
# If using IPs from a DHCP pool in SQL then you may need to set the
# pool name here if you haven't set it elsewhere and release the IP.
# update control {
# &Pool-Name := "local"
# }
# dhcp_sqlippool_decline
update reply {
&DHCP-Message-Type = DHCP-Do-Not-Respond
}
reject
}
#
# A dummy config for Inform packets - this should match the
# options set in the Request section above, except Inform replies
# must not set Your-IP-Address or IP-Address-Lease-Time
#
dhcp DHCP-Inform {
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
dhcp_common
# Use a "passwd" module to set group memberships in DHCP-Group-Name
# Enable mods-available/dhcp_passwd to use this
#dhcp_group_membership
# Optionally override the network address based on client attributes
# See Discover section
#dhcp_override_network
# Use a "files" module to lookup global and network options
# For multiple networks use this in place of dhcp_common
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_network
# Use a policy with calls a "files" module of the same name to lookup
# subnet options
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
# policy.d/dhcp to use this
# Options are set in mods-config/files/dhcp
#dhcp_subnet
# Use a "files" module to lookup options based on DHCP-Group-Name
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_group_options
# Use a "files" module to lookup host specific options
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_hosts
# Use a policy that set options from data stored in an SQL database
#dhcp_policy_sql
ok
}
#
# For Windows 7 boxes
#
#dhcp DHCP-Inform {
# update reply {
# Packet-Dst-Port = 67
# DHCP-Message-Type = DHCP-ACK
# DHCP-DHCP-Server-Identifier = "%{Packet-Dst-IP-Address}"
# DHCP-Site-specific-28 = 0x0a00
# }
# ok
#}
dhcp DHCP-Release {
# Use a "passwd" module to set group memberships in DHCP-Group-Name
# Enable mods-available/dhcp_passwd to use this
#dhcp_group_membership
# Optionally override the network address based on client attributes
# See Discover section
#dhcp_override_network
# Use a "files" module to lookup global and subnet options
# For multiple subnets use this in place of dhcp_common
# Enable mods-available/dhcp_files to use this
# Options are set in mods-config/files/dhcp
#dhcp_network
# If using IPs from a DHCP pool in SQL then you may need to set the
# pool name here if you haven't set it elsewhere and release the IP.
# update control {
# &Pool-Name := "local"
# }
# dhcp_sqlippool_release
update reply {
&DHCP-Message-Type = DHCP-Do-Not-Respond
}
reject
}
dhcp DHCP-Lease-Query {
# The thing being queried for is implicit
# in the packets.
# has MAC, asking for IP, etc.
if (&DHCP-Client-Hardware-Address) {
# look up MAC in database
}
# has IP, asking for MAC, etc.
elsif (&DHCP-Your-IP-Address) {
# look up IP in database
}
# has host name, asking for IP, MAC, etc.
elsif (&DHCP-Client-Identifier) {
# look up identifier in database
}
else {
update reply {
&DHCP-Message-Type = DHCP-Lease-Unknown
}
ok
# stop processing
return
}
#
# We presume that the database lookup returns "notfound"
# if it can't find anything.
#
if (notfound) {
update reply {
&DHCP-Message-Type = DHCP-Lease-Unknown
}
ok
return
}
#
# Add more logic here. Is the lease inactive?
# If so, respond with DHCP-Lease-Unassigned.
#
# Otherwise, respond with DHCP-Lease-Active
#
#
# Also be sure to return ALL information about
# the lease.
#
#
# The reply types are:
#
# DHCP-Lease-Unknown
# DHCP-Lease-Active
# DHCP-Lease-Unassigned
#
update reply {
&DHCP-Message-Type = DHCP-Lease-Unassigned
}
}
}
######################################################################
#
# This next section is a sample configuration for the "passwd"
# module, that reads flat-text files. It should go into
# radiusd.conf, in the "modules" section.
#
# The file is in the format <mac>,<ip>
#
# 00:01:02:03:04:05,192.0.2.100
# 01:01:02:03:04:05,192.0.2.101
# 02:01:02:03:04:05,192.0.2.102
#
# This lets you perform simple static IP assignment.
#
# There is a preconfigured "mac2ip" module setup in
# mods-available/mac2ip. To use it do:
#
# # cd raddb/
# # ln -s ../mods-available/mac2ip mods-enabled/mac2ip
# # mkdir mods-config/passwd
#
# Then create the file mods-config/passwd/mac2ip with the above
# format.
#
######################################################################
# This is an example only - see mods-available/mac2ip instead; do
# not uncomment these lines here.
#
#passwd mac2ip {
# filename = ${confdir}/mac2ip
# format = "*DHCP-Client-Hardware-Address:=DHCP-Your-IP-Address"
# delimiter = ","
#}
-126
View File
@@ -1,126 +0,0 @@
######################################################################
#
# This is a virtual server that handles *only* inner tunnel
# requests for EAP-TTLS and PEAP types.
#
######################################################################
server inner-tunnel {
listen {
ipaddr = 127.0.0.1
port = 18120
type = auth
}
authorize {
filter_username
# filter_inner_identity
chap
mschap
# unix
# IPASS
suffix
# ntdomain
update control {
&Proxy-To-Realm := LOCAL
}
eap {
ok = return
}
files
-sql
# smbpasswd
-ldap
# daily
expiration
logintime
pap
}
authenticate {
Auth-Type PAP {
pap
}
Auth-Type CHAP {
chap
}
Auth-Type MS-CHAP {
mschap
}
mschap
# pam
# Auth-Type LDAP {
# ldap
# }
eap
}
session {
radutmp
# sql
}
# Post-Authentication
post-auth {
# cui-inner
# update outer.session-state {
# User-Name := &User-Name
# }
# reply_log
-sql
# ldap
# moonshot_host_tid
# moonshot_realm_tid
# moonshot_coi_tid
if (0) {
update reply {
User-Name !* ANY
Message-Authenticator !* ANY
EAP-Message !* ANY
Proxy-State !* ANY
MS-MPPE-Encryption-Types !* ANY
MS-MPPE-Encryption-Policy !* ANY
MS-MPPE-Send-Key !* ANY
MS-MPPE-Recv-Key !* ANY
}
update {
&outer.session-state: += &reply:
}
}
Post-Auth-Type REJECT {
-sql
attr_filter.access_reject
update outer.session-state {
&Module-Failure-Message := &request:Module-Failure-Message
}
}
}
pre-proxy {
# files
# attr_filter.pre-proxy
# pre_proxy_log
}
post-proxy {
# post_proxy_log
# attr_filter.post-proxy
eap
}
} # inner-tunnel server block
-126
View File
@@ -1,126 +0,0 @@
# -*- text -*-
######################################################################
#
# A virtual server to handle ONLY Status-Server packets.
#
# Server statistics can be queried with a properly formatted
# Status-Server request. See dictionary.freeradius for comments.
#
# If radiusd.conf has "status_server = yes", then any client
# will be able to send a Status-Server packet to any port
# (listen section type "auth", "acct", or "status"), and the
# server will respond.
#
# If radiusd.conf has "status_server = no", then the server will
# ignore Status-Server packets to "auth" and "acct" ports. It
# will respond only if the Status-Server packet is sent to a
# "status" port.
#
# The server statistics are available ONLY on socket of type
# "status". Queries for statistics sent to any other port
# are ignored.
#
# Similarly, a socket of type "status" will not process
# authentication or accounting packets. This is for security.
#
# $Id: e7d4346310b837d56bffe4c991b4e5680742ebc0 $
#
######################################################################
server status {
listen {
# ONLY Status-Server is allowed to this port.
# ALL other packets are ignored.
type = status
ipaddr = $ENV{FREERADIUS_SITES_STATUS_LISTEN}
port = $ENV{FREERADIUS_SITES_STATUS_PORT}
}
#
# We recommend that you list ONLY management clients here.
# i.e. NOT your NASes or Access Points, and for an ISP,
# DEFINITELY not any RADIUS servers that are proxying packets
# to you.
#
# If you do NOT list a client here, then any client that is
# globally defined (i.e. all of them) will be able to query
# these statistics.
#
# Do you really want your partners seeing the internal details
# of what your RADIUS server is doing?
#
client admin {
ipaddr = 127.0.0.1
secret = $ENV{FREERADIUS_SITES_STATUS_SECRET}
}
# Simple authorize section. The "Autz-Type Status-Server"
# section will work here, too. See "raddb/sites-available/default".
authorize {
ok
# respond to the Status-Server request.
Autz-Type Status-Server {
ok
}
}
}
# Statistics can be queried via a number of methods:
#
# All packets received/sent by the server (1 = auth, 2 = acct)
# FreeRADIUS-Statistics-Type = 3
#
# All packets proxied by the server (4 = proxy-auth, 8 = proxy-acct)
# FreeRADIUS-Statistics-Type = 12
#
# All packets sent && received:
# FreeRADIUS-Statistics-Type = 15
#
# Internal server statistics:
# FreeRADIUS-Statistics-Type = 16
#
# All packets for a particular client (globally defined)
# FreeRADIUS-Statistics-Type = 35
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
#
# All packets for a client attached to a "listen" ip/port
# FreeRADIUS-Statistics-Type = 35
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
# FreeRADIUS-Stats-Server-Port = 1812
#
# All packets for a "listen" IP/port
# FreeRADIUS-Statistics-Type = 67
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
# FreeRADIUS-Stats-Server-Port = 1812
#
# All packets for a home server IP / port
# FreeRADIUS-Statistics-Type = 131
# FreeRADIUS-Stats-Server-IP-Address = 192.0.2.2
# FreeRADIUS-Stats-Server-Port = 1812
#
# You can also get exponentially weighted moving averages of
# response times (in usec) of home servers. Just set the config
# item "historic_average_window" in a home_server section.
#
# By default it is zero (don't calculate it). Useful values
# are between 100, and 10,000. The server will calculate and
# remember the moving average for this window, and for 10 times
# that window.
#
#
# Some of this could have been simplified. e.g. the proxy-auth and
# proxy-acct bits aren't completely necessary. But using them permits
# the server to be queried for ALL inbound && outbound packets at once.
# This gives a good snapshot of what the server is doing.
#
# Due to internal limitations, the statistics might not be exactly up
# to date. Do not expect all of the numbers to add up perfectly.
# The Status-Server packets are also counted in the total requests &&
# responses. The responses are counted only AFTER the response has
# been sent.
#
-603
View File
@@ -1,603 +0,0 @@
######################################################################
#
# RADIUS over TLS (radsec)
#
# When a new client connects, the various TLS parameters for the
# connection are available as dynamic expansions, e.g.
#
# %{listen:TLS-Client-Cert-Common-Name}
#
# Along with other TLS-Client-Cert-... attributes.
# These expansions will only exist if the relevant fields
# are in the client certificate. Read the debug output to see
# which fields are available. Look for output like the following:
#
# (0) TLS - Creating attributes from certificate OIDs
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "one.example.org"
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "two.example.org"
# ...
#
# It is also possible to distinguish between connections which have
# TLS enables, and ones which do not. The expansion:
#
# %{listen:tls}
#
# Will return "yes" if the connection has TLS enabled. It will
# return "no" if TLS is not enabled for a particular listen section.
#
# A number of TLS-Client-Cert-.. attributes holds X509v3 extensions
# data, attributes named the way OpenSSL names them. It is possible
# to extract data for an extension not known to OpenSSL by defining
# a custom string attribute which contains extension OID in it's
# name after 'TLS-Client-Cert-' prefix. E.g.:
#
# ATTRIBUTE TLS-Client-Cert-1.3.6.1.4.1.311.21.7 3002 string
#
# which will yield something simmilar to:
#
# (0) eap_tls: TLS - Creating attributes from certificate OIDs
# (0) eap_tls: TLS-Client-Cert-1.3.6.1.4.1.311.21.7 += "0x302e06"
# ...
#
######################################################################
listen {
# ipaddr = $ENV{FREERADIUS_SITES_TLS_LISTEN}
ipaddr = *
port = $ENV{FREERADIUS_SITES_TLS_PORT}
#
# TCP and TLS sockets can accept Access-Request and Accounting-Request on the same socket.
#
# auth = only Access-Request
# acct = only Accounting-Request
# auth+acct = both
# coa = only CoA / Disconnect requests
#
type = auth+acct
# For now, only TCP transport is allowed.
proto = tcp
# Send packets to the default virtual server
virtual_server = default
# clients = radsec
# Use the haproxy "PROXY protocol".
#
# This configuration allows for many FreeRADIUS servers to be behind a haproxy server. The "PROXY protocol" allows haproxy to send the actual client IP to FreeRADIUS.
#
# This will work ONLY for RadSec (TLS). Both the haproxy AND the RadSec client MUST be listed as allowed RADIUS clients.
#
# haproxy needs to have "send-proxy" configured for this server. Health checks should be turned off, as haproxy does not support RADIUS health checks.
#
# The main use of this feature is for scalability. There is no longer any need to have a RADIUS proxy as a load balancer.
# haproxy is fast, stable, and supports dynamic reloads!
#
# The only problem is that many RADIUS clients do not support RadSec. That situation will hopefully change over time.
#
# proxy_protocol = no
# When this is set to "yes", new TLS connections are processed through a section called
#
# Autz-Type New-TLS-Connection {
# ...
# }
#
# The request contains TLS client certificate attributes,
# and nothing else. The debug output will print which
# attributes are available on your system.
#
# If the section returns "ok" or "updated", then the
# connection is accepted. Otherwise the connection is
# terminated.
#
# check_client_connections = yes
#
# Connection limiting for sockets with "proto = tcp".
#
limit {
# Limit the number of simultaneous TCP connections to the socket
#
# The default is 16.
# Setting this to 0 means "no limit"
max_connections = 16
# The per-socket "max_requests" option does not exist.
# The lifetime, in seconds, of a TCP connection. After this lifetime, the connection will be closed.
#
# Setting this to 0 means "forever".
lifetime = 0
# The idle timeout, in seconds, of a TCP connection. If no packets have been received over the connection for this time, the connection will be closed.
#
# Setting this to 0 means "no timeout".
# We STRONGLY RECOMMEND that you set an idle timeout.
#
idle_timeout = 30
}
# This is *exactly* the same configuration as used by the EAP-TLS
# module. It's OK for testing, but for production use it's a good
# idea to use different server certificates for EAP and for RADIUS
# transport.
#
# If you want only one TLS configuration for multiple sockets,
# then we suggest putting "tls { ...}" into radiusd.conf.
# The subsection below can then be changed into a reference:
#
# tls = ${tls}
#
# Which means "the tls sub-section is not here, but instead is in
# the top-level section called 'tls'".
#
# If you have multiple tls configurations, you can put them into
# sub-sections of a top-level "tls" section. There's no need to
# call them all "tls". You can then use:
#
# tls = ${tls.site1}
#
# to refer to the "site1" sub-section of the "tls" section.
#
tls {
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
# Accept an expired Certificate Revocation List
# allow_expired_crl = no
# If Private key & Certificate are located in
# the same file, then private_key_file &
# certificate_file must contain the same file
# name.
#
# If ca_file (below) is not used, then the
# certificate_file below MUST include not
# only the server certificate, but ALSO all
# of the CA certificates used to sign the
# server certificate.
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
# Trusted Root CA list
#
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
#
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
# In that case, this CA file should contain *one* CA certificate.
#
# This parameter is used only for EAP-TLS, when you issue client certificates. If you do not use client certificates, and you do not want
# to permit EAP-TLS authentication, then delete this configuration item.
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
#
# openssl dhparam -out certs/dh 1024
#
# dh_file = ${certdir}/dh
#
# If your system doesn't have /dev/urandom,
# you will need to create this file, and
# periodically change its contents.
#
# For security reasons, FreeRADIUS doesn't
# write to files in its configuration
# directory.
#
# random_file = /dev/urandom
#
# The default fragment size is 1K.
# However, it's possible to send much more data than
# that over a TCP connection. The upper limit is 64K.
# Setting the fragment size to more than 1K means that
# there are fewer round trips when setting up a TLS
# connection. But only if the certificates are large.
#
fragment_size = 8192
# include_length is a flag which is
# by default set to yes If set to
# yes, Total Length of the message is
# included in EVERY packet we send.
# If set to no, Total Length of the
# message is included ONLY in the
# First packet of a fragment series.
#
# include_length = yes
# Check the Certificate Revocation List
#
# 1) Copy CA certificates and CRLs to same directory.
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
# 'c_rehash' is OpenSSL's command.
# 3) uncomment the line below.
# 5) Restart radiusd
# check_crl = yes
ca_path = ${cadir}
# OpenSSL does not reload contents of ca_path dir over time.
# That means that if check_crl is enabled and CRLs are loaded
# from ca_path dir, at some point CRLs will expire and
# RADIUSd will stop authenticating NASes.
# If ca_path_reload_interval is non-zero, it will force OpenSSL
# to reload all data from ca_path periodically
#
# Flush ca_path each hour
ca_path_reload_interval = 3600
#
# If check_cert_issuer is set, the value will
# be checked against the DN of the issuer in
# the client certificate. If the values do not
# match, the certificate verification will fail,
# rejecting the user.
#
# This check can be done more generally by checking
# the value of the TLS-Client-Cert-Issuer attribute.
# This check can be done via any mechanism you choose.
#
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
#
# If check_cert_cn is set, the value will
# be xlat'ed and checked against the CN
# in the client certificate. If the values
# do not match, the certificate verification
# will fail rejecting the user.
#
# This check is done only if the previous
# "check_cert_issuer" is not set, or if
# the check succeeds.
#
# In 2.1.10 and later, this check can be done
# more generally by checking the value of the
# TLS-Client-Cert-Common-Name attribute. This check
# can be done via any mechanism you choose.
#
# check_cert_cn = %{User-Name}
#
# Set this option to specify the allowed
# TLS cipher suites. The format is listed
# in "man 1 ciphers".
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
# If enabled, OpenSSL will use server cipher list
# (possibly defined by cipher_list option above)
# for choosing right cipher suite rather than
# using client-specified list which is OpenSSl default
# behavior. Having it set to yes is a current best practice
# for TLS
cipher_server_preference = no
#
# Older TLS versions are deprecated. But for RadSec,
# we CAN allow TLS 1.3.
#
tls_min_version = "1.2"
tls_max_version = "1.3"
#
# Session resumption / fast reauthentication cache.
#
# The cache contains the following information:
#
# session Id - unique identifier, managed by SSL
# User-Name - from the Access-Accept
# Stripped-User-Name - from the Access-Request
# Cached-Session-Policy - from the Access-Accept
#
# The "Cached-Session-Policy" is the name of a
# policy which should be applied to the cached
# session. This policy can be used to assign
# VLANs, IP addresses, etc. It serves as a useful
# way to re-apply the policy from the original
# Access-Accept to the subsequent Access-Accept
# for the cached session.
#
# On session resumption, these attributes are
# copied from the cache, and placed into the
# reply list.
#
# You probably also want "use_tunneled_reply = yes" when using fast session resumption.
#
cache {
#
# Enable it. The default is "no".
# Deleting the entire "cache" subsection
# Also disables caching.
#
#
# As of version 3.0.14, the session cache requires the use
# of the "name" and "persist_dir" configuration items, below.
#
# The internal OpenSSL session cache has been permanently
# disabled.
#
# You can disallow resumption for a
# particular user by adding the following
# attribute to the control item list:
#
# Allow-Session-Resumption = No
#
# If "enable = no" below, you CANNOT
# enable resumption for just one user
# by setting the above attribute to "yes".
#
enable = no
#
# Lifetime of the cached entries, in hours.
# The sessions will be deleted after this
# time.
#
lifetime = 24 # hours
#
# Internal "name" of the session cache.
# Used to distinguish which TLS context
# sessions belong to.
#
# The server will generate a random value
# if unset. This will change across server
# restart so you MUST set the "name" if you
# want to persist sessions (see below).
#
# If you use IPv6, change the "ipaddr" below
# to "ipv6addr"
#
#name = "TLS ${..ipaddr} ${..port} ${..proto}"
#
# Simple directory-based storage of sessions.
# Two files per session will be written, the SSL
# state and the cached VPs. This will persist session
# across server restarts.
#
# The server will need write perms, and the directory
# should be secured from anyone else. You might want
# a script to remove old files from here periodically:
#
# find ${logdir}/tlscache -mtime +2 -exec rm -f {} \;
#
# This feature REQUIRES "name" option be set above.
#
#persist_dir = "${logdir}/tlscache"
}
#
# Require a client certificate.
#
require_client_cert = no
#
# As of version 2.1.10, client certificates can be
# validated via an external command. This allows
# dynamic CRLs or OCSP to be used.
#
# This configuration is commented out in the
# default configuration. Uncomment it, and configure
# the correct paths below to enable it.
#
verify {
# A temporary directory where the client
# certificates are stored. This directory
# MUST be owned by the UID of the server,
# and MUST not be accessible by any other
# users. When the server starts, it will do
# "chmod go-rwx" on the directory, for
# security reasons. The directory MUST
# exist when the server starts.
#
# You should also delete all of the files
# in the directory when the server starts.
# tmpdir = /tmp/radiusd
# tmpdir = /startechnica/freeradius/tmp
# The command used to verify the client cert.
# We recommend using the OpenSSL command-line
# tool.
#
# The ${..ca_path} text is a reference to
# the ca_path variable defined above.
#
# The %{TLS-Client-Cert-Filename} is the name
# of the temporary file containing the cert
# in PEM format. This file is automatically
# deleted by the server when the command
# returns.
# client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
}
}
}
clients radsec {
client 127.0.0.1 {
ipaddr = 127.0.0.1
# Ensure that this client is TLS *only*.
proto = tls
# TCP clients can have any shared secret.
# TLS clients MUST have the shared secret set to "radsec". Or, for "proto = tls", you can omit the secret, and it will
# automatically be set to "radsec".
# secret = radsec
secret = $ENV{FREERADIUS_CLIENTS_SECRET}
# You can also use a "limit" section here.
# See raddb/clients.conf for examples.
#
# Note that BOTH limits are applied. You should therefore set the "listen" limits higher than the ones for each individual
# client.
}
}
# When a request is proxied to a TLS-enabled home server, the TLS parameters are available via the expansion:
#
# %{proxy_listen: ... }
#
# The contents of the expansion are the same as described above with the %{listen: ... } expansion, and have similar meanings. "client" in this case is the proxy (this system)
# and "server" is the remote system (home server).
#
# Note that the %{proxy_listen: ... } parameters are available only AFTER the connection has been made to the home server.
home_server tls {
ipaddr = 127.0.0.1
port = $ENV{FREERADIUS_SITES_TLS_PORT}
# type can be the same types as for the "listen" section/
# e.g. auth, acct, auth+acct, coa
type = auth
secret = radsec
proto = tcp
status_check = none
tls {
#
# Similarly to HTTP, the client can use Server Name
# Indication to inform the RadSec server of which
# domain it is requesting. This selection allows
# multiple sites to exist at the same IP address.
#
# For example, and identity provider could host
# multiple sites, but present itself with one public
# IP address.
#
# SNI also permits the use of a load balancer such as
# haproxy. That load balancer can terminate the TLS
# connection, and then use SNI to route the
# underlying RADIUS TCP traffic to a particular host.
#
# Note that "hostname" here is only for SNI, and is NOT
# the hostname or IP address we connect to. For that,
# see "ipaddr", above.
#
# hostname = "example.com"
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
# private_key_file = ${certdir}/client.pem
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
# If Private key & Certificate are located in
# the same file, then private_key_file &
# certificate_file must contain the same file
# name.
#
# If ca_file (below) is not used, then the
# certificate_file below MUST include not
# only the server certificate, but ALSO all
# of the CA certificates used to sign the
# server certificate.
# certificate_file = ${certdir}/client.pem
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
# Trusted Root CA list
#
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
#
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
# In that case, this CA file should contain *one* CA certificate.
#
# This parameter is used only for EAP-TLS,
# when you issue client certificates. If you do
# not use client certificates, and you do not want
# to permit EAP-TLS authentication, then delete
# this configuration item.
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
#
# For TLS-PSK, the key should be specified dynamically, instead of using a hard-coded psk_identity and psk_hexphrase.
#
# The input to the dynamic expansion will be the PSK
# identity supplied by the client, in the
# TLS-PSK-Identity attribute. The output of the
# expansion should be a hex string, of no more than
# 512 characters. The string should not be prefixed
# with "0x". e.g. "abcdef" is OK. "0xabcdef" is not.
#
# psk_query = "%{psksql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
#
# openssl dhparam -out certs/dh 1024
#
# dh_file = ${certdir}/dh
# random_file = /dev/urandom
#
# The default fragment size is 1K.
# However, TLS can send 64K of data at once.
# It can be useful to set it higher.
#
fragment_size = 8192
# include_length is a flag which is
# by default set to yes If set to
# yes, Total Length of the message is
# included in EVERY packet we send.
# If set to no, Total Length of the
# message is included ONLY in the
# First packet of a fragment series.
#
# include_length = yes
# Check the Certificate Revocation List
#
# 1) Copy CA certificates and CRLs to same directory.
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
# 'c_rehash' is OpenSSL's command.
# 3) uncomment the line below.
# 5) Restart radiusd
# check_crl = yes
ca_path = ${cadir}
#
# If check_cert_issuer is set, the value will
# be checked against the DN of the issuer in
# the client certificate. If the values do not
# match, the certificate verification will fail,
# rejecting the user.
#
# In 2.1.10 and later, this check can be done
# more generally by checking the value of the
# TLS-Client-Cert-Issuer attribute. This check
# can be done via any mechanism you choose.
#
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
#
# If check_cert_cn is set, the value will
# be xlat'ed and checked against the CN
# in the client certificate. If the values
# do not match, the certificate verification
# will fail rejecting the user.
#
# This check is done only if the previous
# "check_cert_issuer" is not set, or if
# the check succeeds.
#
# In 2.1.10 and later, this check can be done
# more generally by checking the value of the
# TLS-Client-Cert-Common-Name attribute. This check
# can be done via any mechanism you choose.
#
# check_cert_cn = %{User-Name}
#
# Set this option to specify the allowed TLS cipher suites. The format is listed in "man 1 ciphers".
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
}
}
home_server_pool tls {
type = fail-over
home_server = tls
}
realm tls {
auth_pool = tls
}
+18
View File
@@ -0,0 +1,18 @@
apiVersion: v1
data:
ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNrakNDQVhxZ0F3SUJBZ0lJRjV2Zmt0ZkdGWXd3RFFZSktvWklodmNOQVFFTEJRQXdBREFlRncweU5UQTIKTWpVeE1USXlNREJhRncweU5qQTJNalV4TVRJeU1EQmFNQUF3Z2dFaU1BMEdDU3FHU0liM0RRRUJBUVVBQTRJQgpEd0F3Z2dFS0FvSUJBUUMxOTZ0RmkycXVsQk1FUS9keUpEMldzYmkrU29nN3ZDT21GazBlOVVNd29nSU1GL2xDCldPNk5PQnRLWWk4cStKSFZXemdEOUZxQmtMUGpBazg3UkprR2dpKy96RTRnTHRVM2o1eG1tNDh1NUNxVm1DRHMKYnUzWS9XRHVpcDNNUGhVYjFidHFRYlFSc0RVMlV1TXZROGUvc1NLR2NsMEJSeFZuVHN5ZVZrRlhtWTQ5S1pZTgpHRnlYQWpLL0ZtajB5bVd1ZSsya0dFZHNuODN0cUNBRTREN1BrT1lUT3VhR1cyRTlxTDBpMTFBTE1aL1dkOTdqCk15aW1NMDUzODV6Y3YxMGNyL1Nkd2JLYTgzbDB2YXdKQ1hMQStJeUZrUEp3VGJNQ3I4NEh6Qmc0M0ZPV2Z1T20KNnE3Y3lEUjdqSEwrZ0pRajZOV21lTFJXTnY1bUx2R1hFNTRsQWdNQkFBR2pFREFPTUF3R0ExVWRFd1FGTUFNQgpBZjh3RFFZSktvWklodmNOQVFFTEJRQURnZ0VCQUl3MWtrSjFzZ1NrRVBUQWh4eHF6MjJva1JpazZnRm14M3ExCkJBakswS2xBbmlZcDJQZFlNekg5UUpZT2pHUnpOelJEcENQU0VEMWZ6NWRWUDhaU0t5TGxTMVVJOUlxbFpmb1gKdW9UUkw3WFVVcndweEFrNW9VUldxQzhoTWZNK2JZRUU4VlY3S1B2QVUxUVpuZUlXTW9hQ01SOU5CN1V5dGFLMgpqRlBkZ0pJUGR0VDV3QlZ4WlBzZEVZQy8wdTkrdWlJTHhOQ1QvZ2hJOUJ3eW5WZTFTZnFONVlDdEljNHVVUmo1CnREWVdnb0w0Z0p4aWhLSTl0UWRvQ0VUT3BHTU1VODF4OGtTREVSSnkzYzdEaCttK0IrbWhCM3BPVnUzaUQxRjgKRmdNZkhFSXowaUhaZUFLSlJRR3pkREloSDFjekNqYzZsSWF2VUY2MWxHTnlTekJJdVVVPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN3akNDQWFxZ0F3SUJBZ0lJT3hESWM3VW92Smt3RFFZSktvWklodmNOQVFFTEJRQXdBREFlRncweU5UQTIKTWpVeE1UTXpNREJhRncweU5qQTJNalV4TVRJeU1EQmFNRE14TVRBdkJnTlZCQU1US0daeVpXVnlZV1JwZFhNdQphVzVtY21GemRISjFZM1IxY21VdWFHVnNiV2h2YkhvdVkyeHZkV1F3Z2dFaU1BMEdDU3FHU0liM0RRRUJBUVVBCkE0SUJEd0F3Z2dFS0FvSUJBUUMrS1BRaWhWMStPUHVZdGtsWVVxUGhRNzNvZkxvbEN3ZTh3YjhmSnQ2aXNZdnIKZ0Z5OXZjdnUvODNCem1FYVNDdkZlWVVuUjQwQnp0Q3dQM0NrS0xlWVIzYTNKbDdLeWxuQVY2WEM0THhlSWkzTQo3NTlnM0IxY1ZXM0J5ckxhaTR5RVljK2N3NnRBSEt1SHdPS3lYUGRCdEpQWHBDR3J0Qy9LMktIN3ZHQS9uNnFlCnhpQTZkVVU1LzFQRFIrNXlMaGVEdVlVc2JIcmhLM1VyMkNsNUlZWXI2VG9mR2NJTDAzd25MNWxnRDhWbC9NQkwKV3p4MVVMTk1XRkhxbWViajRMUCttN3RTUTZnSTVMbVlPSHhRSWEvNS9VU09VeER0RWNsNkExT2tCNmVvK2thMwpick9kZ3FuL0E5emVwVStobmZuUnpWcWVwMS8zQUN1dytXQzl3d2xwQWdNQkFBR2pEVEFMTUFrR0ExVWRFd1FDCk1BQXdEUVlKS29aSWh2Y05BUUVMQlFBRGdnRUJBSnQ4MFA0b2U3YVJVQzMrSHIxdVFsSFZ0QVRrUzFqRFo4dW0KR0pBeThFS3RyUHA1M09SOVpGTVVPVGllQUVBYlJScXl4cnFnSlFEUDgzb3BTOFljMnB5SXlDM0g4bmxtMkFtVwpGelJWeExGYU5vVWF4b3Rickd1YkpPSjZyb2xhV2pwVVRMZENaYjQzUC92Z1o5ckpITUczSFRnZkRuOWNZRVBqCkpsTFZvblVKa2VNOTJCeDNkczVRQ1NFaFR0ZVEwdTZ4SWZxMUZPbzlsdDBQeEZlbEwzUXdFYzBPeXFEelVJbzUKbjRidWhFYVZaaU5xalhJaWZJdjFEcWNpN29aQk9oVktyNkxwR1lqczNLOVAyK3FYTnJzTkU0elZiWlpPWU5wSQpYK2IrMGU4YkhiOUR1ODRDbjVweDBxZUZsSlBLR3JPUmN6OE1XS3VHaVVubi9NS29rTnc9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb1FJQkFBS0NBUUVBdmlqMElvVmRmamo3bUxaSldGS2o0VU85Nkh5NkpRc0h2TUcvSHliZW9yR0w2NEJjCnZiM0w3di9Od2M1aEdrZ3J4WG1GSjBlTkFjN1FzRDl3cENpM21FZDJ0eVpleXNwWndGZWx3dUM4WGlJdHpPK2YKWU53ZFhGVnR3Y3F5Mm91TWhHSFBuTU9yUUJ5cmg4RGlzbHozUWJTVDE2UWhxN1F2eXRpaCs3eGdQNStxbnNZZwpPblZGT2Y5VHcwZnVjaTRYZzdtRkxHeDY0U3QxSzlncGVTR0dLK2s2SHhuQ0M5TjhKeStaWUEvRlpmekFTMXM4CmRWQ3pURmhSNnBubTQrQ3ovcHU3VWtPb0NPUzVtRGg4VUNHditmMUVqbE1RN1JISmVnTlRwQWVucVBwR3QyNnoKbllLcC93UGMzcVZQb1ozNTBjMWFucWRmOXdBcnNQbGd2Y01KYVFJREFRQUJBb0gvWmhnSWlTcllRQ1U3WVJkZwp1ME9qS29jWHhBK2t4SGQ4Nk5xcXdmSnh6blc5TjdNa3draGRHTHNob0phZTRPOHo1a090VmZlaWhCMFR0UnJNCkpqb241aWcvUHpJaHNvWFUvMUx5NU9iZ096Z2VlMXFkTnc1TDBaeEUrK01Remd3ZUxFcFhTVVRneVB6VWNHTnoKL1d0NmNRVkpkMFJTWGNEdUlNRVJ4TjBKQ0t6OGpLcFBxblZmaHNLWmhQZENZTk9XTTJtWitMWlkzNE14bjVpZQpUNGJjNGZJcm5QTkNpWmljeXE5SEsyejZHenhjRVNubGpyNHZCd3YzY0puVEJBZnpLaktvM2I1M2srcUxWZUFSClBJSkJ1ZGhJZm82U3p1UEdDQ0l1aWJLVC85N2VLVzFma1JHeFNQV2pQRkJTdkdSSjN3enFZb3VtM0JDSHJwQWUKWFhRUkFvR0JBTjlhM21yRnlYT1VlaFhYbFkzT1lvbWNyN0lKMzdydGpaSnlURFM0MHVFU1lqN1dxYzlIUXNrNQpibURLSDJVUzM1TEpuWnVXTE5Yb24yOElickNDNVdrQVhXVUJHNDFxY2o4TGk1Q01aYk00QjMycnlINmlEMG9oCkZianBVMlpVeFoxTmR4bVhsZnpUdUpyNjVOSGxiNmlkK004V2VscmRrMHMvR3YwaFFTdjFBb0dCQU5uMERKbFEKZURjVTBjbE12U01ucTcrNklaUWdoRXJDMUpwengrK0xRNDl2V3MxVlFDd0RWVHMxYlh0KzVmWm9wNWF5QlUwcApSNGRQb2V6eUZQMlBac1BtL3lFM3h3c2VkU1lPNVJVbmNtMjY4UC8rS0NTTWxDU2tPWkp4UVBsQXZvZzl3QzB0CmRNZzl2VzZrVHQ1S0QyK01aVEFUYkh4Z2hqb2REVk13Y3BNbEFvR0FRQkdCd1dEdzAxMmcwNGtlbGluQWJEYnMKMHdZd0RoKzhQMmpYNFR1dkNlN0xEYmxueGxScm5Pc0RkWElsSlVvUHBieDlvRGFvcjhkbGpHVC8wMVFJMkdESgphWUt5MDVMWUtLdDRJa09UbktBU3pnS3JwVjk1UVV0U1B0TjNIK0JyT3g4UWJkL2tuenhnTk55SkxJaEN5anhlCk5aRCtFZmlER3MrRVAxMzlvczBDZ1lFQWtoYmJPd2lOQzU2UTMzVG9jZC90WngzRDFCM1hqcVQ1REczKzNibGoKRjRsME81MmczZDkrQ2FuT01MRG1RenZ5MlRlS0JpWmRJMzFrOUFWdnZHV2FaRVU1VFhLdG4rNVNaNmdrTlFHegoyWWtzY09wU3plek1mNkwwVkF4Rm1NeWs2WDA2aXcyazhYTXd2akMwREp0bnJVVlZyZHZYSTZjdlVWU1gwZUx2CmFXRUNnWUJTMDd6VjM4MS9ZTmxtQ00rRStXVFpTWnJuZ2pqSWVDZ2NxTUp0MXQyU3BuYUJRb0hPNkRLakpjRGsKOExlZzh6N0I4WW01RkpmeTU1Wm9ya0RWN0xHSTFKR3dmYzNwM01XMlJBVmhra1YwTG9HSEx2OFZjRDZ0M1V0cQpkSU1rdWdQRS9KUVFpblpzREQ4QjNsTEJpMTY1T0ZmeEZXUzdtSkRiSGF3MzRpN0FEUT09Ci0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg==
kind: Secret
metadata:
creationTimestamp: null
name: freeradius-tls
namespace: freeradius
###
# kubectl create secret generic freeradius-tls \
# -n freeradius-new \
# --from-file=tls.crt=certs/freeradius-server-tls.crt \
# --from-file=tls.key=certs/freeradius-key.pem \
# --from-file=ca.crt=certs/freeradius-auth-ca.crt \
# --dry-run=client -o yaml > secret.yaml
###
-54
View File
@@ -1,54 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and (include "freeradius.createTlsSecret" .) .Values.tls.autoGenerator.certmanager.enabled }}
{{- if not (eq (include "st-common.capabilities.certManager.apiVersion" .) "false") }}
{{- $releaseNamespace := include "st-common.names.namespace" . }}
{{- $clusterDomain := .Values.clusterDomain }}
{{- $fullname := include "st-common.names.fullname" . }}
{{- $serviceName := include "st-common.names.fullname" . }}
{{- $altNames := list (printf "%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $serviceName $releaseNamespace) (printf "%s.%s" $serviceName $releaseNamespace) $fullname }}
{{/*
{{- $altNames := list (printf "*.%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $serviceName $releaseNamespace) (printf "%s.%s" $serviceName $releaseNamespace) $fullname }}
*/}}
apiVersion: {{ include "st-common.capabilities.certManager.apiVersion" . }}
kind: Certificate
metadata:
name: {{ include "st-common.names.fullname" . }}-tls
namespace: {{ include "st-common.names.namespace" . | quote }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
spec:
secretName: {{ include "freeradius.tlsSecretName" . }}
issuerRef:
group: cert-manager.io
kind: {{ .Values.tls.autoGenerator.certmanager.issuerKind }}
name: {{ .Values.tls.autoGenerator.certmanager.issuerName }}
#name: letsencrypt-prd
privateKey:
algorithm: ECDSA
rotationPolicy: Always
size: 256
subject:
organizations:
- {{ .Release.Name | quote }}
organizationalUnits:
- {{ include "st-common.names.fullname" . }}
dnsNames:
- {{ .Values.ingress.hostname | quote }}
{{- range .Values.ingress.extraHosts }}
- {{ .name | quote }}
{{- end }}
{{- with $altNames }}
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
{{- end }}
---
-23
View File
@@ -1,23 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if not .Values.clients.existingConfigMapName }}
{{- $client := index .Values "clients" "localhost" }}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-clients" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
clients.conf: |-
client
{{- end }}
-76
View File
@@ -1,76 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ include "freeradius.names.envvars" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
FREERADIUS_ENABLE_TLS: {{ ternary "true" "false" .Values.tls.enabled | quote }}
FREERADIUS_CLIENTS_SHORTNAME: ""
FREERADIUS_CLIENTS_IPV4ADDR: ""
FREERADIUS_CLIENTS_IPV6ADDR: ""
FREERADIUS_CLIENTS_SECRET: ""
{{- if .Values.modsEnabled.sql.enabled }}
FREERADIUS_MODS_SQL_DIALECT: {{ .Values.modsEnabled.sql.dialect }}
FREERADIUS_MODS_SQL_SERVER: {{ include "freeradius.database.host" . | quote }}
FREERADIUS_MODS_SQL_PORT: {{ include "freeradius.database.port" . }}
FREERADIUS_MODS_SQL_LOGIN: {{ include "freeradius.database.user" . | quote }}
FREERADIUS_MODS_SQL_DB: {{ include "freeradius.database.name" . | quote }}
FREERADIUS_MODS_SQL_TABLE_ACCT1: {{ .Values.modsEnabled.sql.table.acct1 }}
FREERADIUS_MODS_SQL_TABLE_ACCT2: {{ .Values.modsEnabled.sql.table.acct2 }}
FREERADIUS_MODS_SQL_TABLE_AUTHCHECK: {{ .Values.modsEnabled.sql.table.authcheck }}
FREERADIUS_MODS_SQL_TABLE_AUTHREPLY: {{ .Values.modsEnabled.sql.table.authreply }}
FREERADIUS_MODS_SQL_TABLE_CLIENT: {{ .Values.modsEnabled.sql.table.client }}
FREERADIUS_MODS_SQL_TABLE_GROUPCHECK: {{ .Values.modsEnabled.sql.table.groupcheck }}
FREERADIUS_MODS_SQL_TABLE_GROUPREPLY: {{ .Values.modsEnabled.sql.table.groupreply }}
FREERADIUS_MODS_SQL_TABLE_POSTAUTH: {{ .Values.modsEnabled.sql.table.postauth }}
FREERADIUS_MODS_SQL_TABLE_USERGROUP: {{ .Values.modsEnabled.sql.table.usergroup }}
FREERADIUS_MODS_SQL_TABLE_RADIPPOOL: {{ .Values.modsEnabled.sql.table.sqlippool }}
FREERADIUS_MODS_SQL_TLS_ENABLE: {{ ternary "yes" "no" .Values.modsEnabled.sql.tls.enabled | quote }}
FREERADIUS_MODS_SQL_READ_CLIENTS: {{ ternary "yes" "no" .Values.modsEnabled.sql.readClients | quote }}
FREERADIUS_MODS_SQL_GROUP_ATTRIBUTE: {{ .Values.modsEnabled.sql.groupAttribute | quote }}
FREERADIUS_MODS_SQL_SQLITE_FILENAME: {{ .Values.modsEnabled.sql.sqlite.filename | quote }}
FREERADIUS_MODS_SQL_SQLITE_BUSY_TIMEOUT: {{ .Values.modsEnabled.sql.sqlite.busyTimeout | quote }}
{{- if .Values.modsEnabled.sql.tls.enabled }}
FREERADIUS_MODS_SQL_TLS_CACERT: {{ include "freeradius.sqlTlsCACert" . | quote }}
FREERADIUS_MODS_SQL_TLS_CIPHER: {{ .Values.modsEnabled.sql.tls.ciphers | quote }}
FREERADIUS_MODS_SQL_TLS_CERTIFICATE: {{ include "freeradius.sqlTlsCert" . | quote }}
FREERADIUS_MODS_SQL_TLS_PRIVATEKEY: {{ include "freeradius.sqlTlsCertKey" . | quote }}
FREERADIUS_MODS_SQL_TLS_PRIVATEKEY_PASSWORD: {{ .Values.modsEnabled.sql.tls.privateKeyPassword | quote }}
{{- end }}
{{- end }}
FREERADIUS_SITES_NAMESPACE: radius
FREERADIUS_SITES_DEFAULT_AUTH_PORT: {{ .Values.containerPorts.auth | quote }}
FREERADIUS_SITES_DEFAULT_ACCT_PORT: {{ .Values.containerPorts.acct | quote }}
{{- if .Values.sitesEnabled.coa.enabled }}
FREERADIUS_SITES_COA_PORT: {{ .Values.containerPorts.coa | quote }}
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
FREERADIUS_SITES_STATUS_LISTEN: {{ .Values.sitesEnabled.status.listen | quote }}
FREERADIUS_SITES_STATUS_PORT: {{ .Values.containerPorts.status | quote }}
{{- end }}
{{- if .Values.sitesEnabled.tls.enabled }}
FREERADIUS_SITES_TLS_PORT: {{ .Values.containerPorts.radsec | quote }}
FREERADIUS_SITES_TLS_CA_FILE: {{ include "freeradius.tlsCACert" . | quote }}
FREERADIUS_SITES_TLS_CERTIFICATE_FILE: {{ include "freeradius.tlsCert" . | quote }}
FREERADIUS_SITES_TLS_CIPHER: {{ default "DEFAULT" .Values.sitesEnabled.tls.cipher | quote }}
FREERADIUS_SITES_TLS_PRIVKEY_FILE: {{ include "freeradius.tlsCertKey" . | quote }}
{{- end }}
-19
View File
@@ -1,19 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{ (.Files.Glob "files/policy/filter").AsConfig | indent 2 }}
-19
View File
@@ -1,19 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-mods-config" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{ (.Files.Glob "files/mods-config/queries.conf").AsConfig | indent 2 }}
-25
View File
@@ -1,25 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-mods" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{ (.Files.Glob "files/mods-available/eap").AsConfig | indent 2 }}
{{ (.Files.Glob "files/mods-available/dynamic_clients").AsConfig | indent 2 }}
{{ (.Files.Glob "files/mods-available/sqlippool").AsConfig | indent 2 }}
{{- if .Values.modsEnabled.sql.enabled }}
{{ (.Files.Glob "files/mods-available/sql").AsConfig | indent 2 }}
{{- end }}
-19
View File
@@ -1,19 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-radius-conf" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{ (.Files.Glob "files/radius.conf").AsConfig | indent 2 }}
-29
View File
@@ -1,29 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-sites" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{ (.Files.Glob "files/sites-available/default").AsConfig | indent 2 }}
{{ (.Files.Glob "files/sites-available/inner-tunnel").AsConfig | indent 2 }}
{{- if .Values.sitesEnabled.coa.enabled }}
{{ (.Files.Glob "files/sites-available/coa").AsConfig | indent 2 }}
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
{{ (.Files.Glob "files/sites-available/status").AsConfig | indent 2 }}
{{- end }}
{{- if .Values.sitesEnabled.tls.enabled }}
{{ (.Files.Glob "files/sites-available/tls").AsConfig | indent 2 }}
{{- end }}
-19
View File
@@ -1,19 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{ (.Files.Glob "files/policy/vlan").AsConfig | indent 2 }}
-399
View File
@@ -1,399 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* vim: set filetype=mustache: */}}
{{- $globalSecretName := printf "%s" (tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecret "context" $)) $) }}
apiVersion: {{ include "st-common.capabilities.deployment.apiVersion" . }}
kind: Deployment
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
spec:
replicas: {{ .Values.replicaCount }}
revisionHistoryLimit: {{ .Values.revisionHistoryLimit }}
selector:
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 6 }}
app.kubernetes.io/component: freeradius
{{- if .Values.updateStrategy }}
strategy: {{- toYaml .Values.updateStrategy | nindent 4 }}
{{- end }}
template:
metadata:
annotations:
checksum/configmap-env: {{ include (print $.Template.BasePath "/ConfigMap/envvars.yaml") . | sha256sum }}
checksum/configmap-mods: {{ include (print $.Template.BasePath "/ConfigMap/mods-enabled.yaml") . | sha256sum }}
checksum/configmap-sites: {{ include (print $.Template.BasePath "/ConfigMap/sites-enabled.yaml") . | sha256sum }}
checksum/secret-credentials: {{ include (print $.Template.BasePath "/Secret/credentials.yaml") . | sha256sum }}
checksum/secret-sql-tls: {{ include (print $.Template.BasePath "/Secret/sql-tls.yaml") . | sha256sum }}
checksum/secret-tls: {{ include (print $.Template.BasePath "/Secret/tls.yaml") . | sha256sum }}
{{- if .Values.podAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.podAnnotations "context" $) | nindent 8 }}
{{- end }}
labels: {{- include "st-common.labels.standard" . | nindent 8 }}
app.kubernetes.io/component: freeradius
{{- if .Values.podLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.podLabels "context" $) | nindent 8 }}
{{- end }}
spec:
{{- if .Values.affinity }}
affinity: {{- include "st-common.tplvalues.render" (dict "value" .Values.affinity "context" $) | nindent 8 }}
{{- else }}
affinity:
podAffinity: {{- include "st-common.affinities.pods" (dict "type" .Values.podAffinityPreset "context" $) | nindent 10 }}
podAntiAffinity: {{- include "st-common.affinities.pods" (dict "type" .Values.podAntiAffinityPreset "context" $) | nindent 10 }}
nodeAffinity: {{- include "st-common.affinities.nodes" (dict "type" .Values.nodeAffinityPreset.type "key" .Values.nodeAffinityPreset.key "values" .Values.nodeAffinityPreset.values) | nindent 10 }}
{{- end }}
{{- include "freeradius.imagePullSecrets" . | nindent 6 }}
{{- if .Values.hostAliases }}
hostAliases: {{- include "st-common.tplvalues.render" (dict "value" .Values.hostAliases "context" $) | nindent 8 }}
{{- end }}
{{- if .Values.nodeSelector }}
nodeSelector: {{- include "st-common.tplvalues.render" (dict "value" .Values.nodeSelector "context" $) | nindent 8 }}
{{- end }}
{{- if .Values.priorityClassName }}
priorityClassName: {{ .Values.priorityClassName | quote }}
{{- end }}
{{- if .Values.schedulerName }}
schedulerName: {{ .Values.schedulerName | quote }}
{{- end }}
{{- if .Values.podSecurityContext.enabled }}
securityContext: {{- omit .Values.podSecurityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
serviceAccountName: {{ include "freeradius.serviceAccountName" . }}
{{- if .Values.tolerations }}
tolerations: {{- include "st-common.tplvalues.render" (dict "value" .Values.tolerations "context" .) | nindent 8 }}
{{- end }}
{{- if .Values.topologySpreadConstraints }}
topologySpreadConstraints: {{- include "st-common.tplvalues.render" (dict "value" .Values.topologySpreadConstraints "context" .) | nindent 8 }}
{{- end }}
{{- if or (and .Values.volumePermissions.enabled .Values.persistence.enabled) .Values.initContainers }}
initContainers:
{{- if .Values.initContainers }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.initContainers "context" $) | nindent 8 }}
{{- end }}
{{- if and .Values.volumePermissions.enabled .Values.persistence.enabled }}
- name: volume-permissions
image: {{ include "freeradius.volumePermissions.image" . }}
imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }}
command:
- /bin/bash
args:
- -ec
- |
printf '%s\n' "[system] Change permission" >&2
chown -R {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }} {{ .Values.persistence.mountPath }}
chmod 0711 {{ .Values.persistence.mountPath }}
{{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }}
securityContext: {{- omit .Values.volumePermissions.securityContext "runAsUser" | toYaml | nindent 12 }}
{{- else }}
securityContext: {{- .Values.volumePermissions.securityContext | toYaml | nindent 12 }}
{{- end }}
{{- if .Values.volumePermissions.resources }}
resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }}
{{- end }}
volumeMounts:
- name: data
mountPath: {{ .Values.persistence.mountPath }}
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- end }}
{{- end }}
{{- end }}
containers:
- name: freeradius
image: {{ include "freeradius.image" . }}
imagePullPolicy: {{ .Values.image.pullPolicy | quote }}
{{- if .Values.diagnosticMode.enabled }}
command: {{- include "st-common.tplvalues.render" (dict "value" .Values.diagnosticMode.command "context" $) | nindent 12 }}
{{- else if .Values.command }}
command: {{- include "st-common.tplvalues.render" (dict "value" .Values.command "context" $) | nindent 12 }}
{{- end }}
{{- if .Values.diagnosticMode.enabled }}
args: {{- include "st-common.tplvalues.render" (dict "value" .Values.diagnosticMode.args "context" $) | nindent 12 }}
{{- else if .Values.args }}
args: {{- include "st-common.tplvalues.render" (dict "value" .Values.args "context" $) | nindent 12 }}
{{- else }}
args:
- -fxx
- -l
- stdout
{{- end }}
env:
{{- if .Values.modsEnabled.sql.enabled }}
- name: FREERADIUS_MODS_SQL_PASSWORD
valueFrom:
secretKeyRef:
{{- if .Values.auth.existingSecretPerPassword }}
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.databasePassword "context" $)) $ }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "databasePassword") }}
{{- else }}
name: {{ include "freeradius.database.secretName" . }}
key: {{ include "freeradius.database.secretKey" . }}
{{- end }}
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
- name: FREERADIUS_SITES_STATUS_SECRET
valueFrom:
secretKeyRef:
{{- if .Values.auth.existingSecretPerPassword }}
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.sitesStatusSecret "context" $)) $ }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "sitesStatusSecret") }}
{{- else }}
name: {{ $globalSecretName }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecret "key" "sites-status-secret") }}
{{- end }}
{{- end }}
{{- if .Values.sitesEnabled.tls.enabled }}
- name: FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD
valueFrom:
secretKeyRef:
{{- if .Values.auth.existingSecretPerPassword }}
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.sitesTlsPrivKeyPassword "context" $)) $ }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "sitesTlsPrivKeyPassword") }}
{{- else }}
name: {{ $globalSecretName }}
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecret "key" "sites-tls-privkey-password") }}
{{- end }}
{{- end }}
{{- if .Values.extraEnvVars }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }}
{{- end }}
envFrom:
- configMapRef:
name: {{ include "freeradius.names.envvars" . }}
{{- if .Values.extraEnvVarsCM }}
- configMapRef:
name: {{ .Values.extraEnvVarsCM }}
{{- end }}
{{- if .Values.extraEnvVarsSecret }}
- secretRef:
name: {{ .Values.extraEnvVarsSecret }}
{{- end }}
{{- if .Values.lifecycleHooks }}
lifecycle: {{- include "st-common.tplvalues.render" (dict "value" .Values.lifecycleHooks "context" $) | nindent 12 }}
{{- end }}
ports:
- name: auth
containerPort: {{ .Values.containerPorts.auth }}
protocol: UDP
- name: acct
containerPort: {{ .Values.containerPorts.acct }}
protocol: UDP
{{- if .Values.sitesEnabled.coa.enabled }}
- name: coa
containerPort: {{ .Values.containerPorts.coa }}
protocol: UDP
{{- end }}
{{- if .Values.tls.enabled }}
- name: radsec
containerPort: {{ .Values.containerPorts.radsec }}
protocol: TCP
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
- name: status
containerPort: {{ .Values.containerPorts.status }}
protocol: UDP
{{- end }}
{{- if not .Values.diagnosticMode.enabled }}
{{- if .Values.customStartupProbe }}
startupProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customStartupProbe "context" $) | nindent 12 }}
{{- else if .Values.startupProbe.enabled }}
startupProbe: {{- include "st-common.tplvalues.render" (dict "value" (omit .Values.startupProbe "enabled") "context" $) | nindent 12 }}
exec:
command:
- sh
- -c
- |
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
if [[ ! -f "{{ .Values.persistence.mountPath }}/.user_scripts_initialized" ]]; then
echo "Init scripts still not executed. Skipping check"
exit 1
fi
{{- end }}
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
{{- end }}
{{- if .Values.customLivenessProbe }}
livenessProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customLivenessProbe "context" $) | nindent 12 }}
{{- else if .Values.livenessProbe.enabled }}
livenessProbe: {{- omit .Values.livenessProbe "enabled" | toYaml | nindent 12 }}
exec:
command:
- sh
- -c
- >-
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
{{- end }}
{{- if .Values.customReadinessProbe }}
readinessProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customReadinessProbe "context" $) | nindent 12 }}
{{- else if .Values.readinessProbe.enabled }}
readinessProbe: {{- omit .Values.readinessProbe "enabled" | toYaml | nindent 12 }}
exec:
command:
- sh
- -c
- >-
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
{{- end }}
{{- end }}
{{- if .resources }}
resources: {{- include "st-common.tplvalues.render" (dict "value" .resources "context" $) | nindent 12 }}
{{- else if and .resourcesPreset (ne .resourcesPreset "none") }}
resources: {{- include "st-common.resources.preset" (dict "type" .resourcesPreset) | nindent 12 }}
{{- end }}
{{- if .Values.containerSecurityContext.enabled }}
securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }}
{{- end }}
volumeMounts:
- name: data
mountPath: {{ default "/startechnica/freeradius" .Values.persistence.mountPath }}
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- end }}
{{- if or (.Files.Glob "files/radiusd.conf") .Values.configuration .Values.configurationConfigMap }}
- name: freeradius-config
mountPath: /etc/freeradius/radiusd.conf
subPath: radiusd.conf
{{- end }}
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
- name: custom-init-scripts
mountPath: /docker-entrypoint-initdb.d
{{- end }}
{{- if .Values.modsEnabled.sql.enabled }}
- name: freeradius-mods
mountPath: /etc/freeradius/mods-enabled/sql
subPath: sql
{{- end }}
- name: freeradius-mods
mountPath: /etc/freeradius/mods-enabled/eap
subPath: eap
- name: freeradius-mods
mountPath: /etc/freeradius/mods-enabled/dynamic_clients
subPath: dynamic_clients
- name: freeradius-mods
mountPath: /etc/freeradius/mods-enabled/sqlippool
subPath: sqlippool
- name: freeradius-mods-config
mountPath: /etc/freeradius/mods-config/sql/main/mysql/queries.conf
subPath: queries.conf
- name: freeradius-radius-conf
mountPath: /etc/freeradius/radius.conf
subPath: radius.conf
- name: freeradius-filter
mountPath: /etc/freeradius/policy.d/filter
subPath: filter
- name: freeradius-vlan
mountPath: /etc/freeradius/policy.d/vlan
subPath: vlan
- name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/default
subPath: default
- name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/status
subPath: status
{{- if .Values.sitesEnabled.coa.enabled }}
- name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/coa
subPath: coa
{{- end }}
{{- if .Values.tls.enabled }}
- name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/tls
subPath: tls
- name: freeradius-tls
mountPath: /opt/startechnica/freeradius/certs
readOnly: true
{{- end }}
{{- if and .Values.modsEnabled.sql.enabled (eq .Values.modsEnabled.sql.dialect "sqlite") }}
- name: freeradius-sqlite
mountPath: {{ .Values.modsEnabled.sql.sqlite.filename | quote }}
{{- end }}
{{- if .Values.modsEnabled.sql.tls.enabled }}
- name: freeradius-sql-tls
mountPath: /opt/startechnica/freeradius/certs
{{- end }}
- name: shared-certs
mountPath: /opt/startechnica/freeradius/shared-certs
readOnly: true
- name: temp
mountPath: /startechnica/freeradius/tmp
{{- if .Values.extraVolumeMounts }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraVolumeMounts "context" $) | nindent 12 }}
{{- end }}
{{- if .Values.sidecars }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.sidecars "context" $) | nindent 8 }}
{{- end }}
volumes:
- name: freeradius-mods
configMap:
name: {{ printf "%s-mods" (include "st-common.names.fullname" .) }}
- name: freeradius-sites
configMap:
name: {{ printf "%s-sites" (include "st-common.names.fullname" .) }}
- name: freeradius-mods-config
configMap:
name: {{ printf "%s-mods-config" (include "st-common.names.fullname" .) }}
- name: freeradius-radius-conf
configMap:
name: {{ printf "%s-radius-conf" (include "st-common.names.fullname" .) }}
- name: freeradius-filter
configMap:
name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }}
- name: freeradius-vlan
configMap:
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
- name: temp
emptyDir: {}
- name: shared-certs
emptyDir: {}
- name: data
{{- if .Values.persistence.enabled }}
persistentVolumeClaim:
claimName: {{ include "freeradius.claimName" . }}
{{- else }}
emptyDir: {}
{{- end }}
{{- if and .Values.modsEnabled.sql.enabled (eq .Values.modsEnabled.sql.dialect "sqlite") }}
- name: freeradius-sqlite
emptyDir: {}
{{- end }}
{{- if .Values.tls.enabled }}
- name: freeradius-tls
secret:
secretName: {{ include "freeradius.tlsSecretName" . }}
{{- end }}
{{- if .Values.modsEnabled.sql.tls.enabled }}
- name: freeradius-sql-tls
secret:
secretName: {{ include "freeradius.sqlTlsSecretName" . }}
items:
- key: tls.crt
path: sql-tls.crt
- key: tls.key
path: sql-tls.key
- key: ca.crt
path: sql-ca.crt
{{- end }}
{{- if or (.Files.Glob "files/radiusd.conf") .Values.configuration .Values.configurationConfigMap }}
- name: freeradius-config
configMap:
name: {{ include "freeradius.configurationCM" . }}
{{- end }}
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
- name: custom-init-scripts
configMap:
name: {{ include "freeradius.initdbScriptsCM" . }}
{{- end }}
{{- if .Values.extraVolumes }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraVolumes "context" $) | nindent 8 }}
{{- end }}
-69
View File
@@ -1,69 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.gateway.enabled (not .Values.gateway.existingGateway) }}
{{- if not (eq (include "st-common.capabilities.istioGateway.apiVersion" .) "false") }}
apiVersion: {{ include "st-common.capabilities.istioGateway.apiVersion" . }}
kind: Gateway
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
{{- end }}
spec:
selector:
istio.io/gateway-name: {{ default "ingressgateway" .Values.gateway.name }}
servers:
- port:
name: auth
number: {{ .Values.service.ports.auth }}
protocol: UDP
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host.name | quote }}
{{- end }}
- port:
name: acct
number: {{ .Values.service.ports.acct }}
protocol: UDP
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host.name | quote }}
{{- end }}
- port:
name: coa
number: {{ .Values.service.ports.coa }}
protocol: UDP
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host.name | quote }}
{{- end }}
- port:
name: radsec
number: {{ .Values.service.ports.radsec }}
protocol: TLS
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host.name | quote }}
{{- end }}
tls:
mode: PASSTHROUGH
{{- if .Values.sitesEnabled.tls.enabled }}
credentialName: {{ include "freeradius.tlsSecretName" . }}
{{- end }}
{{- end }}
{{- end }}
-47
View File
@@ -1,47 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.gateway.enabled (not .Values.gateway.existingVirtualService) }}
{{- if not (eq (include "st-common.capabilities.istioVirtualService.apiVersion" .) "false") }}
apiVersion: {{ include "st-common.capabilities.istioVirtualService.apiVersion" . }}
kind: VirtualService
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
{{- end }}
spec:
gateways:
- {{ printf "%s/%s" (include "st-common.names.namespace" .) (include "st-common.names.fullname" .) }}
hosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host | quote }}
{{- end }}
tls:
- match:
- port: {{ .Values.service.ports.radsec }}
sniHosts:
- {{ .Values.ingress.hostname }}
{{- range $host := .Values.ingress.extraHosts }}
- {{ $host | quote }}
{{- end }}
route:
- destination:
# host: {{ printf "%s.%s.svc.%s" (include "st-common.names.fullname" .) (include "st-common.names.namespace" .) .Values.clusterDomain }}
host: {{ printf "%s.%s.svc.cluster.local" (include "st-common.names.fullname" .) (include "st-common.names.namespace" .) }}
port:
number: {{ .Values.service.ports.radsec }}
{{- end }}
{{- end }}
-57
View File
@@ -1,57 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.networkPolicy.enabled }}
apiVersion: {{ include "st-common.capabilities.networkPolicy.apiVersion" . }}
kind: NetworkPolicy
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
spec:
podSelector:
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 6 }}
ingress:
- ports:
- port: {{ .Values.containerPorts.auth }}
protocol: UDP
- port: {{ .Values.containerPorts.acct }}
protocol: UDP
{{- if .Values.tls.enabled }}
- port: {{ .Values.containerPorts.radsec }}
protocol: TCP
{{- end }}
{{- if .Values.metrics.enabled }}
- port: {{ .Values.containerPorts.metrics }}
protocol: TCP
{{- end }}
{{- if .Values.sitesEnabled.coa.enabled }}
- port: {{ .Values.containerPorts.coa }}
protocol: UDP
{{- end }}
{{- if .Values.sitesEnabled.status.enabled }}
- port: {{ .Values.containerPorts.status }}
protocol: UDP
{{- end }}
{{- if not .Values.networkPolicy.allowExternal }}
from:
- podSelector:
matchLabels:
{{ include "st-common.names.fullname" . }}-client: "true"
- podSelector:
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 14 }}
app.kubernetes.io/component: freeradius
{{- if .Values.networkPolicy.additionalRules }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.networkPolicy.additionalRules "context" $) | nindent 8 }}
{{- end }}
{{- end }}
{{- end }}
-38
View File
@@ -1,38 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) -}}
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
{{- if or .Values.persistence.annotations .Values.commonAnnotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
{{- if .Values.persistence.annotations }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.persistence.annotations "context" $ ) | nindent 4 }}
{{- end }}
{{- end }}
spec:
accessModes:
{{- if not (empty .Values.persistence.accessModes) }}
{{- range .Values.persistence.accessModes }}
- {{ . | quote }}
{{- end }}
{{- else }}
- {{ .Values.persistence.accessMode | quote }}
{{- end }}
resources:
requests:
storage: {{ .Values.persistence.size | quote }}
{{- include "st-common.storage.class" (dict "persistence" .Values.persistence "global" .Values.global) | nindent 2 }}
{{- end -}}
-28
View File
@@ -1,28 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.podDisruptionBudget.create }}
apiVersion: {{ include "st-common.capabilities.policy.apiVersion" . }}
kind: PodDisruptionBudget
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
spec:
{{- if .Values.podDisruptionBudget.minAvailable }}
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
{{- end }}
{{- if .Values.podDisruptionBudget.maxUnavailable }}
maxUnavailable: {{ .Values.podDisruptionBudget.maxUnavailable }}
{{- end }}
selector:
matchLabels: {{ include "st-common.labels.matchLabels" . | nindent 6 }}
{{- end }}
-25
View File
@@ -1,25 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{ if and .Values.metrics.enabled .Values.metrics.prometheusRules.enabled }}
apiVersion: monitoring.coreos.com/v1
kind: PrometheusRule
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.metrics.prometheusRules.additionalLabels "context" $) | nindent 4 }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
spec:
groups:
- name: {{ include "st-common.names.fullname" . }}
rules:
{{- toYaml .Values.metrics.prometheusRules.rules | nindent 6 }}
{{ end }}
-29
View File
@@ -1,29 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.rbac.create }}
apiVersion: {{ include "st-common.capabilities.rbac.apiVersion" . }}
kind: Role
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
rules:
- apiGroups:
- ""
resources:
- secrets
- configmaps
verbs:
- get
- list
- watch
{{- end }}
-26
View File
@@ -1,26 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.serviceAccount.create .Values.rbac.create }}
apiVersion: {{ include "st-common.capabilities.rbac.apiVersion" . }}
kind: RoleBinding
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
subjects:
- kind: ServiceAccount
name: {{ include "freeradius.serviceAccountName" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: {{ include "st-common.names.fullname" . }}
{{- end }}
-38
View File
@@ -1,38 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and (not .Values.auth.existingSecret) (not .Values.auth.existingSecretPerPassword) }}
{{- $secretName := include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecret "context" $) }}
apiVersion: v1
kind: Secret
metadata:
name: {{ $secretName }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
type: Opaque
data:
{{- if and (not .Values.mariadb.enabled) (not .Values.externalDatabase.existingSecret) }}
database-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "database-password" "length" 10 "providedValues" (list "externalDatabase.password") "context" $) }}
{{- end }}
{{- if and (.Values.mariadb.enabled) (not (empty .Values.mariadb.auth.username)) }}
mariadb-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "mariadb-password" "providedValues" (list "mariadb.auth.password") "context" $) }}
{{- end }}
{{- if (.Values.sitesEnabled.status.enabled) }}
sites-status-secret: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "sites-status-secret" "length" 10 "providedValues" (list "sitesEnabled.status.secret") "context" $) }}
{{- end }}
{{- if (.Values.sitesEnabled.tls.enabled) }}
sites-tls-privkey-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "sites-tls-privkey-password" "length" 10 "providedValues" (list "sitesEnabled.tls.privateKeyPassword") "context" $) }}
{{- end }}
{{- if (.Values.modsEnabled.sql.tls.enabled) }}
mods-sql-tls-privkey-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "mods-sql-tls-privkey-password" "length" 10 "providedValues" (list "modsEnabled.sql.tls.privateKeyPassword") "context" $) }}
{{- end }}
{{- end }}
-30
View File
@@ -1,30 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and (include "freeradius.createSqlTlsSecret" .) (not .Values.tls.autoGenerator.certmanager.enabled) }}
{{- $ca := genCA "freeradius-ca" 365 }}
{{- $releaseNamespace := include "st-common.names.namespace" . }}
{{- $clusterDomain := .Values.clusterDomain }}
{{- $fullname := include "st-common.names.fullname" . }}
{{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $fullname $releaseNamespace) (printf "%s.%s" $fullname $releaseNamespace) $fullname }}
{{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
apiVersion: v1
kind: Secret
metadata:
name: {{ include "st-common.names.fullname" . }}-sql-tls
namespace: {{ include "st-common.names.namespace" . | quote }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
type: kubernetes.io/tls
data:
ca.crt: {{ $ca.Cert | b64enc | quote }}
tls.crt: {{ $crt.Cert | b64enc | quote }}
tls.key: {{ $crt.Key | b64enc | quote }}
{{- end }}
-30
View File
@@ -1,30 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and (include "freeradius.createTlsSecret" .) (not .Values.tls.autoGenerator.certmanager.enabled) }}
{{- $ca := genCA "freeradius-ca" 365 }}
{{- $releaseNamespace := include "st-common.names.namespace" . }}
{{- $clusterDomain := .Values.clusterDomain }}
{{- $fullname := include "st-common.names.fullname" . }}
{{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $fullname $releaseNamespace) (printf "%s.%s" $fullname $releaseNamespace) $fullname }}
{{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
apiVersion: v1
kind: Secret
metadata:
name: {{ include "st-common.names.fullname" . }}-tls
namespace: {{ include "st-common.names.namespace" . | quote }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
type: kubernetes.io/tls
data:
ca.crt: {{ $ca.Cert | b64enc | quote }}
tls.crt: {{ $crt.Cert | b64enc | quote }}
tls.key: {{ $crt.Key | b64enc | quote }}
{{- end }}
-98
View File
@@ -1,98 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: Service
metadata:
name: {{ include "st-common.names.fullname" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if or .Values.service.annotations .Values.commonAnnotations .Values.metrics.annotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.service.annotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.service.annotations "context" $) | nindent 4 }}
{{- end }}
{{- if and .Values.metrics.enabled .Values.metrics.annotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.metrics.annotations "context" $) | nindent 4 }}
{{- end }}
{{- end }}
spec:
type: {{ default "ClusterIP" .Values.service.type }}
{{- if eq .Values.service.type "LoadBalancer" }}
allocateLoadBalancerNodePorts: {{ eq .Values.service.allocateLoadBalancerNodePorts "true" }}
{{- end }}
{{- if and .Values.service.clusterIP (eq .Values.service.type "ClusterIP") }}
clusterIP: {{ .Values.service.clusterIP }}
{{- end }}
{{- if and .Values.service.externalTrafficPolicy (or (eq .Values.service.type "LoadBalancer") (eq .Values.service.type "NodePort")) }}
externalTrafficPolicy: {{ .Values.service.externalTrafficPolicy | quote }}
{{- end }}
ipFamilyPolicy: {{ .Values.service.ipFamilyPolicy }}
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerClass)) }}
loadBalancerClass: {{ .Values.service.loadBalancerClass }}
{{- end }}
{{- if (and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerIP))) }}
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
{{- end }}
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerSourceRanges)) }}
loadBalancerSourceRanges: {{ .Values.service.loadBalancerSourceRanges }}
{{- end }}
{{- if .Values.service.sessionAffinity }}
sessionAffinity: {{ .Values.service.sessionAffinity }}
{{- end }}
{{- if .Values.service.sessionAffinityConfig }}
sessionAffinityConfig: {{- include "st-common.tplvalues.render" (dict "value" .Values.service.sessionAffinityConfig "context" $) | nindent 4 }}
{{- end }}
ports:
- name: udp-auth
port: {{ .Values.service.ports.auth }}
protocol: UDP
targetPort: {{ .Values.containerPorts.auth }}
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.auth) }}
nodePort: {{ coalesce .Values.service.nodePorts.auth .Values.service.nodePort }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
- name: udp-acct
port: {{ .Values.service.ports.acct }}
protocol: UDP
targetPort: {{ .Values.containerPorts.acct }}
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.acct) }}
nodePort: {{ .Values.service.nodePorts.acct }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- if .Values.sitesEnabled.coa.enabled }}
- name: udp-coa
port: {{ .Values.service.ports.coa }}
protocol: UDP
targetPort: {{ .Values.containerPorts.coa }}
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.coa) }}
nodePort: {{ .Values.service.nodePorts.coa }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- end }}
{{- if .Values.tls.enabled }}
- name: tcp-radsec
port: {{ .Values.service.ports.radsec }}
protocol: TCP
targetPort: {{ .Values.containerPorts.radsec }}
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.radsec) }}
nodePort: {{ .Values.service.nodePorts.radsec }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- end }}
selector: {{ include "st-common.labels.matchLabels" . | nindent 4 }}
app.kubernetes.io/component: freeradius
---
-27
View File
@@ -1,27 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.serviceAccount.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "freeradius.serviceAccountName" . }}
namespace: {{ include "st-common.names.namespace" . | quote }}
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: freeradius
{{- if .Values.commonLabels }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
{{- end }}
{{- if or .Values.serviceAccount.annotations .Values.commonAnnotations }}
annotations:
{{- if .Values.commonAnnotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
{{- if .Values.serviceAccount.annotations }}
{{- include "st-common.tplvalues.render" (dict "value" .Values.serviceAccount.annotations "context" $) | nindent 4 }}
{{- end }}
{{- end }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
{{- end }}
-95
View File
@@ -1,95 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* Create a default fully qualified app name. We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). */}}
{{- define "freeradius.mariadb.fullname" -}}
{{- include "st-common.names.dependency.fullname" (dict "chartName" "mariadb" "chartValues" .Values.mariadb "context" $) -}}
{{- end -}}
{{/* Return the Database hostname */}}
{{- define "freeradius.database.host" -}}
{{- if eq .Values.mariadb.architecture "replication" }}
{{- ternary (include "freeradius.mariadb.fullname" .) .Values.externalDatabase.host .Values.mariadb.enabled -}}-primary
{{- else -}}
{{- ternary (include "freeradius.mariadb.fullname" .) .Values.externalDatabase.host .Values.mariadb.enabled -}}
{{- end -}}
{{- end -}}
{{/* Return the Database port */}}
{{- define "freeradius.database.port" -}}
{{- ternary "3306" .Values.externalDatabase.port .Values.mariadb.enabled | quote -}}
{{- end -}}
{{/* Return the Database database name */}}
{{- define "freeradius.database.name" -}}
{{- if .Values.mariadb.enabled }}
{{- if .Values.global.mariadb }}
{{- if .Values.global.mariadb.auth }}
{{- coalesce .Values.global.mariadb.auth.database .Values.mariadb.auth.database -}}
{{- else -}}
{{- .Values.mariadb.auth.database -}}
{{- end -}}
{{- else -}}
{{- .Values.mariadb.auth.database -}}
{{- end -}}
{{- else -}}
{{- .Values.externalDatabase.database -}}
{{- end -}}
{{- end -}}
{{/* Return the Database user */}}
{{- define "freeradius.database.user" -}}
{{- if .Values.mariadb.enabled }}
{{- if .Values.global.mariadb }}
{{- if .Values.global.mariadb.auth }}
{{- coalesce .Values.global.mariadb.auth.username .Values.mariadb.auth.username -}}
{{- else -}}
{{- .Values.mariadb.auth.username -}}
{{- end -}}
{{- else -}}
{{- .Values.mariadb.auth.username -}}
{{- end -}}
{{- else -}}
{{- .Values.externalDatabase.user -}}
{{- end -}}
{{- end -}}
{{/* Return the Database encrypted password */}}
{{- define "freeradius.database.secretName" -}}
{{- if .Values.mariadb.enabled }}
{{- if .Values.global.mariadb }}
{{- if .Values.global.mariadb.auth }}
{{- if .Values.global.mariadb.auth.existingSecret }}
{{- tpl .Values.global.mariadb.auth.existingSecret $ -}}
{{- else -}}
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
{{- end -}}
{{- else -}}
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
{{- end -}}
{{- else -}}
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
{{- end -}}
{{- else -}}
{{- default (include "st-common.secrets.name" (dict "existingSecret" .Values.mariadb.auth.existingSecret "context" $)) (tpl .Values.externalDatabase.existingSecret $) -}}
{{- end -}}
{{- end -}}
{{/* Add environment variables to configure database values */}}
{{- define "freeradius.database.secretKey" -}}
{{- if .Values.mariadb.enabled -}}
{{- print "mariadb-password" -}}
{{- else -}}
{{- if .Values.externalDatabase.existingSecret -}}
{{- if .Values.externalDatabase.existingSecretPasswordKey -}}
{{- printf "%s" .Values.externalDatabase.existingSecretPasswordKey -}}
{{- else -}}
{{- print "database-password" -}}
{{- end -}}
{{- else -}}
{{- print "database-password" -}}
{{- end -}}
{{- end -}}
{{- end -}}
-140
View File
@@ -1,140 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* Create the name of the service account to use */}}
{{- define "freeradius.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "st-common.names.fullname" .) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}
{{/* Return the path to the cert file. */}}
{{- define "freeradius.tlsCert" -}}
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/tls.crt" -}}
{{- else -}}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certFilename -}}
{{- end -}}
{{- end -}}
{{/* Return the path to the cert key file. */}}
{{- define "freeradius.tlsCertKey" -}}
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/tls.key" -}}
{{- else -}}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certKeyFilename -}}
{{- end -}}
{{- end -}}
{{/* Return the path to the CA cert file. */}}
{{- define "freeradius.tlsCACert" -}}
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/ca.crt" -}}
{{- else -}}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certCAFilename -}}
{{- end -}}
{{- end -}}
{{/* Create the name of the SSL certificate to use */}}
{{- define "freeradius.tlsSecretName" -}}
{{- if .Values.tls.certificatesSecret }}
{{ .Values.tls.certificatesSecret }}
{{- else }}
{{- default (printf "%s-tls" (include "st-common.names.fullname" .)) }}
{{- end }}
{{- end -}}
{{/* Return true if a TLS secret object should be created */}}
{{- define "freeradius.createTlsSecret" -}}
{{- if and .Values.tls.enabled .Values.tls.autoGenerated (not .Values.tls.certificatesSecret) }}
{{- true }}
{{- end }}
{{- end -}}
{{/* Validate values of FreeRADIUS - Auth TLS enabled */}}
{{- define "freeradius.validateValues.tls" -}}
{{- if and .Values.tls.enabled (not .Values.tls.autoGenerated) (not .Values.tls.certificatesSecret) }}
freeradius: tls.enabled
In order to enable TLS, you also need to provide
an existing secret containing the Keystore and Truststore or
enable auto-generated certificates.
{{- end }}
{{- end -}}
{{/* Return the path to the SQL cert file. */}}
{{- define "freeradius.sqlTlsCert" -}}
{{- if and .Values.modsEnabled.sql.tls.enabled }}
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/sql-tls.crt" -}}
{{- else if not (empty .Values.modsEnabled.sql.tls.certFilename) }}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certFilename -}}
{{- end }}
{{- else }}
{{- printf "" -}}
{{- end }}
{{- end -}}
{{/* Return the path to the SQL cert key file. */}}
{{- define "freeradius.sqlTlsCertKey" -}}
{{- if and .Values.modsEnabled.sql.tls.enabled }}
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/sql-tls.key" -}}
{{- else if not (empty .Values.modsEnabled.sql.tls.certKeyFilename) }}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certKeyFilename -}}
{{- end }}
{{- else }}
{{- printf "" -}}
{{- end }}
{{- end -}}
{{/* Return the path to the SQL CA cert file. */}}
{{- define "freeradius.sqlTlsCACert" -}}
{{- if and .Values.modsEnabled.sql.tls.enabled }}
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
{{- printf "/opt/startechnica/freeradius/certs/sql-ca.crt" -}}
{{- else if not (empty .Values.modsEnabled.sql.tls.certCAFilename)}}
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certCAFilename -}}
{{- end }}
{{- else }}
{{- printf "" -}}
{{- end }}
{{- end -}}
{{/* Create the name of the secret for SQL SSL certificate to use */}}
{{- define "freeradius.sqlTlsSecretName" -}}
{{- if .Values.modsEnabled.sql.tls.certificatesSecret }}
{{ .Values.modsEnabled.sql.tls.certificatesSecret }}
{{- else }}
{{- default (printf "%s-sql-tls" (include "st-common.names.fullname" .)) }}
{{- end }}
{{- end -}}
{{/* Return true if a TLS secret object should be created */}}
{{- define "freeradius.createSqlTlsSecret" -}}
{{- if and .Values.modsEnabled.sql.tls.enabled .Values.modsEnabled.sql.tls.autoGenerated (not .Values.modsEnabled.sql.tls.certificatesSecret) }}
{{- true }}
{{- end }}
{{- end -}}
{{/* Get the configuration ConfigMap name. */}}
{{- define "freeradius.configurationCM" -}}
{{- if .Values.configurationConfigMap -}}
{{- printf "%s" (tpl .Values.configurationConfigMap $) -}}
{{- else -}}
{{- printf "%s-configuration" (include "st-common.names.fullname" .) -}}
{{- end -}}
{{- end -}}
{{/* Get the initialization scripts ConfigMap name. */}}
{{- define "freeradius.initdbScriptsCM" -}}
{{- if .Values.initdbScriptsConfigMap -}}
{{- printf "%s" .Values.initdbScriptsConfigMap -}}
{{- else -}}
{{- printf "%s-init-scripts" (include "st-common.names.fullname" .) -}}
{{- end -}}
{{- end -}}
-14
View File
@@ -1,14 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* Return the proper FreeRADIUS image name */}}
{{- define "freeradius.image" -}}
{{ include "st-common.images.image" (dict "imageRoot" .Values.image "global" .Values.global) }}
{{- end -}}
{{/* Return the proper Docker Image Registry Secret Names */}}
{{- define "freeradius.imagePullSecrets" -}}
{{- include "st-common.images.pullSecrets" (dict "images" (list .Values.image .Values.volumePermissions.image .Values.metrics.image) "global" .Values.global) -}}
{{- end -}}
-10
View File
@@ -1,10 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* vim: set filetype=mustache: */}}
{{- define "freeradius.names.envvars" -}}
{{- printf "%s-envvars" (include "st-common.names.fullname" .) -}}
{{- end -}}
-18
View File
@@ -1,18 +0,0 @@
{{- /*
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/* Return the FreeRADIUS PVC name. */}}
{{- define "freeradius.claimName" -}}
{{- if .Values.persistence.existingClaim }}
{{- printf "%s" (tpl .Values.persistence.existingClaim $) -}}
{{- else }}
{{- printf "%s" (include "st-common.names.fullname" .) -}}
{{- end }}
{{- end -}}
{{/* Return the proper image name (for the init container volume-permissions image) */}}
{{- define "freeradius.volumePermissions.image" -}}
{{ include "st-common.images.image" (dict "imageRoot" .Values.volumePermissions.image "global" .Values.global) }}
{{- end -}}
-44
View File
@@ -1,44 +0,0 @@
persistence:
enabled: true
# storageClass:
service:
type: LoadBalancer
externalTrafficPolicy: Local
ipFamilyPolicy: PreferDualStack
modsEnabled:
sql:
enabled: true
dialect: mysql
externalDatabase:
# host: mariadb-infra-mariadb-galera.mariadb-infra.svc
host: mariadb-primary.mariadb.svc
port: 3306
user: radius_user
database: radiusdb
password: "aserfdertg"
sitesEnabled:
coa:
enabled: true
tls:
enabled: true
tls:
enabled: true
autoGenerated: true
# updateStrategy:
# type: Recreate
volumePermissions:
enabled: true
gateway:
enabled: true
dedicated: false
gatewayApi: false
name: "freeradius"
namespace: "istio-ingress"
+35 -920
View File
File diff suppressed because it is too large Load Diff