Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c285eba466 | ||
|
|
9a07062286 | ||
|
|
3d3eae8ee8 | ||
|
|
717518a333 | ||
|
|
368ad8a63f | ||
|
|
943d54d158 | ||
|
|
4d062aaa65 | ||
|
|
1817d0f0d4 |
@@ -1 +0,0 @@
|
|||||||
charts/
|
|
||||||
@@ -1,62 +0,0 @@
|
|||||||
default:
|
|
||||||
tags:
|
|
||||||
- docker-test
|
|
||||||
|
|
||||||
stages:
|
|
||||||
- package
|
|
||||||
- publish
|
|
||||||
|
|
||||||
variables:
|
|
||||||
CHART_NAME: "freeradius"
|
|
||||||
CHART_VERSION: "1.0.12"
|
|
||||||
PACKAGE_PATH: "packages"
|
|
||||||
ST_COMMON_PROJECT_ID: "270"
|
|
||||||
COMMON_PROJECT_URL: "${CI_API_V4_URL}/projects/${ST_COMMON_PROJECT_ID}/packages/helm/stable"
|
|
||||||
HELM_EXPERIMENTAL_OCI: "1"
|
|
||||||
GITEA_URL: "gitea.infrastructure.helmholz.cloud"
|
|
||||||
GITEA_REPO: "oci://gitea.infrastructure.helmholz.cloud/gitea_admin/helm"
|
|
||||||
|
|
||||||
package_chart:
|
|
||||||
stage: package
|
|
||||||
image:
|
|
||||||
name: alpine/helm:3.14.0
|
|
||||||
entrypoint: [""]
|
|
||||||
script:
|
|
||||||
- helm repo add st-common ${COMMON_PROJECT_URL} --username gitlab-ci-token --password $CI_JOB_TOKEN
|
|
||||||
- helm dependency build .
|
|
||||||
- mkdir -p $PACKAGE_PATH
|
|
||||||
- helm package . --destination $PACKAGE_PATH
|
|
||||||
artifacts:
|
|
||||||
paths:
|
|
||||||
- ${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz
|
|
||||||
|
|
||||||
|
|
||||||
publish_chart:
|
|
||||||
stage: publish
|
|
||||||
image: alpine/curl:8.14.1
|
|
||||||
script:
|
|
||||||
- |
|
|
||||||
curl --fail-with-body --request POST \
|
|
||||||
--user gitlab-ci-token:$CI_JOB_TOKEN \
|
|
||||||
--form "chart=@${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz" \
|
|
||||||
"${CI_API_V4_URL}/projects/${CI_PROJECT_ID}/packages/helm/api/stable/charts"
|
|
||||||
only:
|
|
||||||
- main
|
|
||||||
|
|
||||||
push_chart_to_gitea:
|
|
||||||
stage: publish
|
|
||||||
image:
|
|
||||||
name: alpine/helm:3.14.0
|
|
||||||
entrypoint: [""]
|
|
||||||
variables:
|
|
||||||
GITEA_URL: "https://gitea.infrastructure.helmholz.cloud"
|
|
||||||
GITEA_USERNAME: "gitea_admin"
|
|
||||||
GITEA_PASSWORD: "$GITEA_PASSWORD"
|
|
||||||
script:
|
|
||||||
- echo "$GITEA_PASSWORD" | helm registry login $GITEA_URL --username $GITEA_USERNAME --password-stdin
|
|
||||||
- helm push ${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz $GITEA_REPO
|
|
||||||
when: manual
|
|
||||||
only:
|
|
||||||
- main
|
|
||||||
dependencies:
|
|
||||||
- package_chart
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
.git/
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
dependencies:
|
|
||||||
- name: st-common
|
|
||||||
repository: https://gitlab/api/v4/projects/270/packages/helm/stable
|
|
||||||
version: 0.1.12
|
|
||||||
digest: sha256:effc27041fec14dd47ce67b96daae936455482afe0a2d3d6069ebffd7e33ba2c
|
|
||||||
generated: "2026-02-03T12:45:51.347388527+01:00"
|
|
||||||
-30
@@ -1,30 +0,0 @@
|
|||||||
annotations:
|
|
||||||
category: AccessManagement
|
|
||||||
apiVersion: v2
|
|
||||||
appVersion: 3.2.7
|
|
||||||
dependencies:
|
|
||||||
- name: st-common
|
|
||||||
repository: https://gitlab/api/v4/projects/270/packages/helm/stable
|
|
||||||
version: 0.1.12
|
|
||||||
description: FreeRADIUS is a modular, high performance free RADIUS suite developed
|
|
||||||
and distributed under the GNU General Public License, version 2, and is free for
|
|
||||||
download and use.
|
|
||||||
home: https://github.com/startechnica/apps/tree/main/charts/freeradius
|
|
||||||
icon: https://freeradius.org/img/wordmark.svg
|
|
||||||
keywords:
|
|
||||||
- freeradius
|
|
||||||
- radius
|
|
||||||
- mysql
|
|
||||||
- postgresql
|
|
||||||
- ldap
|
|
||||||
kubeVersion: '>=1.24.0-0'
|
|
||||||
maintainers:
|
|
||||||
- email: firmansyah@nainggolan.id
|
|
||||||
name: firmansyahn
|
|
||||||
url: https://firmansyah.nainggolan.id
|
|
||||||
name: freeradius
|
|
||||||
sources:
|
|
||||||
- https://freeradius.org/
|
|
||||||
- https://github.com/FreeRADIUS/freeradius-server
|
|
||||||
type: application
|
|
||||||
version: 1.0.12
|
|
||||||
@@ -1,325 +1,93 @@
|
|||||||
<!--- app-name: FreeRADIUS -->
|
# FreeRADIUS
|
||||||
|
|
||||||
# Helm chart for FreeRADIUS
|
|
||||||
|
|
||||||
FreeRADIUS is a modular, high performance free RADIUS suite developed and distributed under the GNU General Public License, version 2, and is free for download and use.
|
|
||||||
|
|
||||||
[Overview of FreeRADIUS](https://freeradius.org/)
|
## Getting started
|
||||||
|
|
||||||
**This chart is not maintained by the upstream project and any issues with the chart should be raised [here](https://github.com/startechnica/apps/issues/new/choose)**
|
To make it easy for you to get started with GitLab, here's a list of recommended next steps.
|
||||||
|
|
||||||
## TL;DR
|
Already a pro? Just edit this README.md and make it your own. Want to make it easy? [Use the template at the bottom](#editing-this-readme)!
|
||||||
|
|
||||||
```console
|
## Add your files
|
||||||
helm repo add startechnica https://startechnica.github.io/apps
|
|
||||||
helm install my-release startechnica/freeradius
|
- [ ] [Create](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#create-a-file) or [upload](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#upload-a-file) files
|
||||||
|
- [ ] [Add files using the command line](https://docs.gitlab.com/topics/git/add_files/#add-files-to-a-git-repository) or push an existing Git repository with the following command:
|
||||||
|
|
||||||
|
```
|
||||||
|
cd existing_repo
|
||||||
|
git remote add origin https://gitlab/next-gen-portal/argocd-project/freeradius.git
|
||||||
|
git branch -M main
|
||||||
|
git push -uf origin main
|
||||||
```
|
```
|
||||||
|
|
||||||
## Prerequisites
|
## Integrate with your tools
|
||||||
|
|
||||||
- Kubernetes 1.22+
|
- [ ] [Set up project integrations](https://gitlab/next-gen-portal/argocd-project/freeradius/-/settings/integrations)
|
||||||
- Helm 3.10.0+
|
|
||||||
|
|
||||||
## Installing the Chart
|
## Collaborate with your team
|
||||||
|
|
||||||
To install the chart with the release name `my-release` on `my-release` namespace:
|
- [ ] [Invite team members and collaborators](https://docs.gitlab.com/ee/user/project/members/)
|
||||||
|
- [ ] [Create a new merge request](https://docs.gitlab.com/ee/user/project/merge_requests/creating_merge_requests.html)
|
||||||
|
- [ ] [Automatically close issues from merge requests](https://docs.gitlab.com/ee/user/project/issues/managing_issues.html#closing-issues-automatically)
|
||||||
|
- [ ] [Enable merge request approvals](https://docs.gitlab.com/ee/user/project/merge_requests/approvals/)
|
||||||
|
- [ ] [Set auto-merge](https://docs.gitlab.com/user/project/merge_requests/auto_merge/)
|
||||||
|
|
||||||
```console
|
## Test and Deploy
|
||||||
helm repo add startechnica https://startechnica.github.io/apps
|
|
||||||
helm install my-release startechnica/freeradius --namespace my-release --create-namespace
|
|
||||||
```
|
|
||||||
|
|
||||||
These commands deploy FreeRADIUS on the Kubernetes cluster in the default configuration.
|
Use the built-in continuous integration in GitLab.
|
||||||
|
|
||||||
> **Tip**: List all releases using `helm list -A`
|
- [ ] [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
|
||||||
|
- [ ] [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
|
||||||
|
- [ ] [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
|
||||||
|
- [ ] [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
|
||||||
|
- [ ] [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)
|
||||||
|
|
||||||
## Uninstalling the Chart
|
***
|
||||||
|
|
||||||
To uninstall/delete the `my-release` deployment:
|
# Editing this README
|
||||||
|
|
||||||
```console
|
When you're ready to make this README your own, just edit this file and use the handy template below (or feel free to structure it however you want - this is just a starting point!). Thanks to [makeareadme.com](https://www.makeareadme.com/) for this template.
|
||||||
helm delete my-release --namespace my-release
|
|
||||||
```
|
|
||||||
|
|
||||||
The command removes all the Kubernetes components associated with the chart and deletes the release.
|
## Suggestions for a good README
|
||||||
|
|
||||||
## Parameters
|
Every project is different, so consider which of these sections apply to yours. The sections used in the template are suggestions for most open source projects. Also keep in mind that while a README can be too long and detailed, too long is better than too short. If you think your README is too long, consider utilizing another form of documentation rather than cutting out information.
|
||||||
|
|
||||||
### Global parameters
|
## Name
|
||||||
|
Choose a self-explaining name for your project.
|
||||||
|
|
||||||
| Name | Description | Value |
|
## Description
|
||||||
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ----- |
|
Let people know what your project can do specifically. Provide context and add a link to any reference visitors might be unfamiliar with. A list of Features or a Background subsection can also be added here. If there are alternatives to your project, this is a good place to list differentiating factors.
|
||||||
| `global.imageRegistry` | Global Docker image registry | `""` |
|
|
||||||
| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` |
|
|
||||||
| `global.storageClass` | Global StorageClass for Persistent Volume(s) | `""` |
|
|
||||||
| `global.namespaceOverride` | Override the namespace for resource deployed by the chart, but can itself be overridden by the local namespaceOverride | `""` |
|
|
||||||
|
|
||||||
|
## Badges
|
||||||
|
On some READMEs, you may see small images that convey metadata, such as whether or not all the tests are passing for the project. You can use Shields to add some to your README. Many services also have instructions for adding a badge.
|
||||||
|
|
||||||
### Common parameters
|
## Visuals
|
||||||
|
Depending on what you are making, it can be a good idea to include screenshots or even a video (you'll frequently see GIFs rather than actual videos). Tools like ttygif can help, but check out Asciinema for a more sophisticated method.
|
||||||
|
|
||||||
| Name | Description | Value |
|
## Installation
|
||||||
| -------------------------- | ----------------------------------------------------------------------------------------------------------------- | --------------- |
|
Within a particular ecosystem, there may be a common way of installing things, such as using Yarn, NuGet, or Homebrew. However, consider the possibility that whoever is reading your README is a novice and would like more guidance. Listing specific steps helps remove ambiguity and gets people to using your project as quickly as possible. If it only runs in a specific context like a particular programming language version or operating system or has dependencies that have to be installed manually, also add a Requirements subsection.
|
||||||
| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `""` |
|
|
||||||
| `nameOverride` | String to partially override common.names.fullname template with a string (will prepend the release name) | `""` |
|
|
||||||
| `namespaceOverride` | String to fully override common.names.namespace | `""` |
|
|
||||||
| `fullnameOverride` | String to fully override common.names.fullname template with a string | `""` |
|
|
||||||
| `commonAnnotations` | Annotations to add to all deployed objects | `{}` |
|
|
||||||
| `commonLabels` | Labels to add to all deployed objects | `{}` |
|
|
||||||
| `schedulerName` | Name of the Kubernetes scheduler (other than default) | `""` |
|
|
||||||
| `clusterDomain` | Kubernetes DNS Domain name to use | `cluster.local` |
|
|
||||||
| `extraDeploy` | Array of extra objects to deploy with the release (evaluated as a template) | `[]` |
|
|
||||||
| `diagnosticMode.enabled` | Enable diagnostic mode (all probes will be disabled and the command will be overridden) | `false` |
|
|
||||||
| `diagnosticMode.command` | Command to override all containers in the deployment | `[]` |
|
|
||||||
| `diagnosticMode.args` | Args to override all containers in the deployment | `[]` |
|
|
||||||
|
|
||||||
|
## Usage
|
||||||
|
Use examples liberally, and show the expected output if you can. It's helpful to have inline the smallest example of usage that you can demonstrate, while providing links to more sophisticated examples if they are too long to reasonably include in the README.
|
||||||
|
|
||||||
### FreeRADIUS parameters
|
## Support
|
||||||
|
Tell people where they can go to for help. It can be any combination of an issue tracker, a chat room, an email address, etc.
|
||||||
|
|
||||||
| Name | Description | Value |
|
## Roadmap
|
||||||
| ----------------------------------------------| -------------------------------------------------------------------------------------------------------------------------| -------------------------------|
|
If you have ideas for releases in the future, it is a good idea to list them in the README.
|
||||||
| `image.registry` | FreeRADIUS image registry | `docker.io` |
|
|
||||||
| `image.repository` | FreeRADIUS image repository | `freeradius/freeradius-server` |
|
|
||||||
| `image.tag` | FreeRADIUS image tag (immutable tags are recommended) | `3.2.3` |
|
|
||||||
| `image.pullPolicy` | FreeRADIUS image pull policy | `IfNotPresent` |
|
|
||||||
| `image.pullSecrets` | Specify docker-registry secret names as an array | `[]` |
|
|
||||||
| `image.debug` | Set to true if you would like to see extra information on logs | `false` |
|
|
||||||
| `hostAliases` | Deployment pod host aliases | `[]` |
|
|
||||||
| `command` | Override default container command (useful when using custom images) | `[]` |
|
|
||||||
| `args` | Override default container args (useful when using custom images) | `[]` |
|
|
||||||
| `extraEnvVars` | Extra environment variables to be set on FreeRADIUS containers | `[]` |
|
|
||||||
| `extraEnvVarsCM` | ConfigMap with extra environment variables | `""` |
|
|
||||||
| `extraEnvVarsSecret` | Secret with extra environment variables | `""` |
|
|
||||||
| `service.type` | Kubernetes service type | `ClusterIP` |
|
|
||||||
| `service.clusterIP` | Specific cluster IP when service type is cluster IP. Use `None` for headless service | `""` |
|
|
||||||
| `service.ports.auth` | FreeRADIUS Authentication and Authorization service port | `1812` |
|
|
||||||
| `service.ports.acct` | FreeRADIUS Accounting service port | `1813` |
|
|
||||||
| `service.ports.coa` | FreeRADIUS CoA service port | `3799` |
|
|
||||||
| `service.ports.radsec` | FreeRADIUS RadSec service port | `2083` |
|
|
||||||
| `service.ports.status` | FreeRADIUS Status service port | `18121` |
|
|
||||||
| `service.nodePorts.auth` | Specify the nodePort value for the LoadBalancer and NodePort for Authentication service types. | `""` |
|
|
||||||
| `service.nodePorts.acct` | Specify the nodePort value for the LoadBalancer and NodePort for Accounting service types. | `""` |
|
|
||||||
| `service.nodePorts.coa` | Specify the nodePort value for the LoadBalancer and NodePort for CoA service types. | `""` |
|
|
||||||
| `service.nodePorts.radsec` | Specify the nodePort value for the LoadBalancer and NodePort for RadSec service types. | `""` |
|
|
||||||
| `service.nodePorts.status` | Specify the nodePort value for the LoadBalancer and NodePort for Status service types. | `""` |
|
|
||||||
| `service.extraPorts` | Extra ports to expose (normally used with the `sidecar` value) | `[]` |
|
|
||||||
| `service.externalIPs` | External IP list to use with ClusterIP service type | `[]` |
|
|
||||||
| `service.loadBalancerIP` | `loadBalancerIP` if service type is `LoadBalancer` | `""` |
|
|
||||||
| `service.loadBalancerSourceRanges` | Addresses that are allowed when svc is `LoadBalancer` | `[]` |
|
|
||||||
| `service.externalTrafficPolicy` | FreeRADIUS service external traffic policy | `Cluster` |
|
|
||||||
| `service.annotations` | Additional annotations for FreeRADIUS service | `{}` |
|
|
||||||
| `service.sessionAffinity` | Session Affinity for Kubernetes service, can be `None` or `ClientIP` | `None` |
|
|
||||||
| `service.sessionAffinityConfig` | Additional settings for the sessionAffinity | `{}` |
|
|
||||||
| `serviceAccount.create` | Specify whether a ServiceAccount should be created | `false` |
|
|
||||||
| `serviceAccount.name` | Name of the service account to use. If not set and create is true, a name is generated using the fullname template. | `""` |
|
|
||||||
| `serviceAccount.automountServiceAccountToken` | Automount service account token for the server service account | `false` |
|
|
||||||
| `serviceAccount.annotations` | Annotations for service account. Evaluated as a template. Only used if `create` is `true`. | `{}` |
|
|
||||||
| `command` | Override default container command (useful when using custom images) | `[]` |
|
|
||||||
| `extraEnvVars` | Array containing extra env vars to configure FreeRADIUS | `[]` |
|
|
||||||
| `extraEnvVarsCM` | ConfigMap containing extra env vars to configure FreeRADIUS | `""` |
|
|
||||||
| `extraEnvVarsSecret` | Secret containing extra env vars to configure FreeRADIUS | `""` |
|
|
||||||
| `rbac.create` | Specify whether RBAC resources should be created and used | `false` |
|
|
||||||
| `podSecurityContext.enabled` | Enable security context | `true` |
|
|
||||||
| `podSecurityContext.fsGroup` | Group ID for the container filesystem | `101` |
|
|
||||||
| `podSecurityContext.runAsUser` | User ID for the container | `101` |
|
|
||||||
| `containerSecurityContext.enabled` | Enabled FreeRADIUS container Security Context | `true` |
|
|
||||||
| `containerSecurityContext.runAsUser` | Set FreeRADIUS container Security Context runAsUser | `101` |
|
|
||||||
| `containerSecurityContext.runAsNonRoot` | Set FreeRADIUS container Security Context runAsNonRoot | `true` |
|
|
||||||
| `tls.enabled` | Enable TLS support for replication traffic | `false` |
|
|
||||||
| `tls.autoGenerated` | Generate automatically self-signed TLS certificates | `false` |
|
|
||||||
| `tls.autoGenerator.certmanager.enabled` | | `false` |
|
|
||||||
| `tls.certificatesSecret` | Name of the secret that contains the certificates | `"false"` |
|
|
||||||
| `tls.certFilename` | Certificate filename | `""` |
|
|
||||||
| `tls.certKeyFilename` | Certificate key filename | `""` |
|
|
||||||
| `tls.certCAFilename` | CA Certificate filename | `""` |
|
|
||||||
| `configuration` | Configuration for the FreeRADIUS server (`radiusd.conf`) | `""` |
|
|
||||||
| `configurationConfigMap` | ConfigMap with the FreeRADIUS configuration files (Note: Overrides `configuration`). The value is evaluated as a template. | `""` |
|
|
||||||
| `initdbScripts` | Specify dictionary of scripts to be run at first boot | `{}` |
|
|
||||||
| `initdbScriptsConfigMap` | ConfigMap with the initdb scripts (Note: Overrides `initdbScripts`) | `""` |
|
|
||||||
| `extraFlags` | FreeRADIUS additional command line flags | `""` |
|
|
||||||
| `replicaCount` | Desired number of cluster nodes | `3` |
|
|
||||||
| `podLabels` | Extra labels for FreeRADIUS pods | `{}` |
|
|
||||||
| `podAnnotations` | Annotations for FreeRADIUS pods | `{}` |
|
|
||||||
| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` |
|
|
||||||
| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` |
|
|
||||||
| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` |
|
|
||||||
| `nodeAffinityPreset.key` | Node label key to match. Ignored if `affinity` is set. | `""` |
|
|
||||||
| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` |
|
|
||||||
| `affinity` | Affinity for pod assignment | `{}` |
|
|
||||||
| `nodeSelector` | Node labels for pod assignment | `{}` |
|
|
||||||
| `tolerations` | Tolerations for pod assignment | `[]` |
|
|
||||||
| `topologySpreadConstraints` | Topology Spread Constraints for pods assignment | `[]` |
|
|
||||||
| `lifecycleHooks` | for the galera container(s) to automate configuration before or after startup | `{}` |
|
|
||||||
| `containerPorts.auth` | Auth database container port | `1812` |
|
|
||||||
| `containerPorts.acct` | Acct cluster container port | `1813` |
|
|
||||||
| `containerPorts.coa` | CoA container port | `3799` |
|
|
||||||
| `containerPorts.radsec` | RadSec container port | `2083` |
|
|
||||||
| `containerPorts.status` | Status container port | `18121` |
|
|
||||||
| `persistence.enabled` | Enable persistence using PVC | `true` |
|
|
||||||
| `persistence.existingClaim` | Provide an existing `PersistentVolumeClaim` | `""` |
|
|
||||||
| `persistence.subPath` | Subdirectory of the volume to mount | `""` |
|
|
||||||
| `persistence.mountPath` | Path to mount the volume at | `/startechnica/freeradius` |
|
|
||||||
| `persistence.selector` | Selector to match an existing Persistent Volume (this value is evaluated as a template) | `{}` |
|
|
||||||
| `persistence.storageClass` | Persistent Volume Storage Class | `""` |
|
|
||||||
| `persistence.annotations` | Persistent Volume Claim annotations | `{}` |
|
|
||||||
| `persistence.labels` | Persistent Volume Claim Labels | `{}` |
|
|
||||||
| `persistence.accessModes` | Persistent Volume Access Modes | `["ReadWriteOnce"]` |
|
|
||||||
| `persistence.size` | Persistent Volume Size | `8Gi` |
|
|
||||||
| `priorityClassName` | Priority Class Name for Statefulset | `""` |
|
|
||||||
| `initContainers` | Additional init containers (this value is evaluated as a template) | `[]` |
|
|
||||||
| `sidecars` | Add additional sidecar containers (this value is evaluated as a template) | `[]` |
|
|
||||||
| `extraVolumes` | Extra volumes | `[]` |
|
|
||||||
| `extraVolumeMounts` | Mount extra volume(s) | `[]` |
|
|
||||||
| `resources.limits` | The resources limits for the container | `{}` |
|
|
||||||
| `resources.requests` | The requested resources for the container | `{}` |
|
|
||||||
| `livenessProbe.enabled` | Turn on and off liveness probe | `true` |
|
|
||||||
| `livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated | `120` |
|
|
||||||
| `livenessProbe.periodSeconds` | How often to perform the probe | `10` |
|
|
||||||
| `livenessProbe.timeoutSeconds` | When the probe times out | `1` |
|
|
||||||
| `livenessProbe.failureThreshold` | Minimum consecutive failures for the probe | `3` |
|
|
||||||
| `livenessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` |
|
|
||||||
| `readinessProbe.enabled` | Turn on and off readiness probe | `true` |
|
|
||||||
| `readinessProbe.initialDelaySeconds` | Delay before readiness probe is initiated | `30` |
|
|
||||||
| `readinessProbe.periodSeconds` | How often to perform the probe | `10` |
|
|
||||||
| `readinessProbe.timeoutSeconds` | When the probe times out | `1` |
|
|
||||||
| `readinessProbe.failureThreshold` | Minimum consecutive failures for the probe | `3` |
|
|
||||||
| `readinessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` |
|
|
||||||
| `startupProbe.enabled` | Turn on and off startup probe | `false` |
|
|
||||||
| `startupProbe.initialDelaySeconds` | Delay before startup probe is initiated | `120` |
|
|
||||||
| `startupProbe.periodSeconds` | How often to perform the probe | `10` |
|
|
||||||
| `startupProbe.timeoutSeconds` | When the probe times out | `1` |
|
|
||||||
| `startupProbe.failureThreshold` | Minimum consecutive failures for the probe | `48` |
|
|
||||||
| `startupProbe.successThreshold` | Minimum consecutive successes for the probe | `1` |
|
|
||||||
| `customStartupProbe` | Custom liveness probe for the Web component | `{}` |
|
|
||||||
| `customLivenessProbe` | Custom liveness probe for the Web component | `{}` |
|
|
||||||
| `customReadinessProbe` | Custom rediness probe for the Web component | `{}` |
|
|
||||||
| `podDisruptionBudget.create` | Specifies whether a Pod disruption budget should be created | `false` |
|
|
||||||
| `podDisruptionBudget.minAvailable` | Minimum number / percentage of pods that should remain scheduled | `1` |
|
|
||||||
| `podDisruptionBudget.maxUnavailable` | Maximum number / percentage of pods that may be made unavailable | `""` |
|
|
||||||
| `metrics.enabled` | Start a side-car prometheus exporter | `false` |
|
|
||||||
| `metrics.image.registry` | FreeRADIUS Prometheus exporter image registry | `""` |
|
|
||||||
| `metrics.image.repository` | FreeRADIUS Prometheus exporter image repository | `""` |
|
|
||||||
| `metrics.image.tag` | FreeRADIUS Prometheus exporter image tag (immutable tags are recommended) | `""` |
|
|
||||||
| `metrics.image.pullPolicy` | FreeRADIUS Prometheus exporter image pull policy | `IfNotPresent` |
|
|
||||||
| `metrics.image.pullSecrets` | FreeRADIUS Prometheus exporter image pull secrets | `[]` |
|
|
||||||
| `metrics.extraFlags` | FreeRADIUS Prometheus exporter additional command line flags | `[]` |
|
|
||||||
| `metrics.resources.limits` | The resources limits for the container | `{}` |
|
|
||||||
| `metrics.resources.requests` | The requested resources for the container | `{}` |
|
|
||||||
| `metrics.service.type` | Prometheus exporter service type | `ClusterIP` |
|
|
||||||
| `metrics.service.port` | Prometheus exporter service port | `9104` |
|
|
||||||
| `metrics.service.annotations` | Prometheus exporter service annotations | `{}` |
|
|
||||||
| `metrics.service.loadBalancerIP` | Load Balancer IP if the Prometheus metrics server type is `LoadBalancer` | `""` |
|
|
||||||
| `metrics.service.clusterIP` | Prometheus metrics service Cluster IP | `""` |
|
|
||||||
| `metrics.service.loadBalancerSourceRanges` | Prometheus metrics service Load Balancer sources | `[]` |
|
|
||||||
| `metrics.service.externalTrafficPolicy` | Prometheus metrics service external traffic policy | `Cluster` |
|
|
||||||
| `metrics.serviceMonitor.enabled` | if `true`, creates a Prometheus Operator ServiceMonitor (also requires `metrics.enabled` to be `true`) | `false` |
|
|
||||||
| `metrics.serviceMonitor.namespace` | Optional namespace which Prometheus is running in | `""` |
|
|
||||||
| `metrics.serviceMonitor.jobLabel` | The name of the label on the target service to use as the job name in prometheus. | `""` |
|
|
||||||
| `metrics.serviceMonitor.interval` | How frequently to scrape metrics (use by default, falling back to Prometheus' default) | `""` |
|
|
||||||
| `metrics.serviceMonitor.scrapeTimeout` | Timeout after which the scrape is ended | `""` |
|
|
||||||
| `metrics.serviceMonitor.selector` | ServiceMonitor selector labels | `{}` |
|
|
||||||
| `metrics.serviceMonitor.relabelings` | RelabelConfigs to apply to samples before scraping | `[]` |
|
|
||||||
| `metrics.serviceMonitor.metricRelabelings` | MetricRelabelConfigs to apply to samples before ingestion | `[]` |
|
|
||||||
| `metrics.serviceMonitor.honorLabels` | honorLabels chooses the metric's labels on collisions with target labels | `false` |
|
|
||||||
| `metrics.serviceMonitor.labels` | ServiceMonitor extra labels | `{}` |
|
|
||||||
| `metrics.prometheusRules.enabled` | if `true`, creates a Prometheus Operator PrometheusRule (also requires `metrics.enabled` to be `true`, and makes little sense without ServiceMonitor) | `false` |
|
|
||||||
| `metrics.prometheusRules.additionalLabels` | Additional labels to add to the PrometheusRule so it is picked up by the operator | `{}` |
|
|
||||||
| `metrics.prometheusRules.rules` | PrometheusRule rules to configure | `{}` |
|
|
||||||
|
|
||||||
|
## Contributing
|
||||||
|
State if you are open to contributions and what your requirements are for accepting them.
|
||||||
|
|
||||||
### Custom FreeRADIUS enabled mods parameters
|
For people who want to make changes to your project, it's helpful to have some documentation on how to get started. Perhaps there is a script that they should run or some environment variables that they need to set. Make these steps explicit. These instructions could also be useful to your future self.
|
||||||
|
|
||||||
| Name | Description | Value |
|
You can also document commands to lint the code or run tests. These steps help to ensure high code quality and reduce the likelihood that the changes inadvertently break something. Having instructions for running tests is especially helpful if it requires external setup, such as starting a Selenium server for testing in a browser.
|
||||||
| ------------------------------------------ | --------------------------------------------------- | ----------------- |
|
|
||||||
| `modsEnabled.sql.enabled` | Enable FreeRADIUS SQL module | `false` |
|
|
||||||
| `modsEnabled.sql.dialect` | The driver module used to execute the queries. | `mysql` |
|
|
||||||
| `modsEnabled.sql.table.acct1` | Tables containing 'accounting' items | `radacct` |
|
|
||||||
| `modsEnabled.sql.table.acct2` | Tables containing 'accounting' items | `radacct` |
|
|
||||||
| `modsEnabled.sql.table.authcheck` | Tables containing 'check' items | `radcheck` |
|
|
||||||
| `modsEnabled.sql.table.authreply` | Tables containing 'reply' items | `radreply` |
|
|
||||||
| `modsEnabled.sql.table.client` | Table to keep radius client info | `nas` |
|
|
||||||
| `modsEnabled.sql.table.groupcheck` | Tables containing 'check' items | `radgroupcheck` |
|
|
||||||
| `modsEnabled.sql.table.groupreply` | Tables containing 'reply' items | `radgroupreply` |
|
|
||||||
| `modsEnabled.sql.table.postauth` | Allow for storing data after authentication | `radpostauth` |
|
|
||||||
| `modsEnabled.sql.table.usergroup` | Table to keep group info | `radusergroup` |
|
|
||||||
| `modsEnabled.sql.tls.enabled` | Enable FreeRADIUS SQL TLS module | `false` |
|
|
||||||
| `modsEnabled.sql.tls.autoGenerated` | | `false` |
|
|
||||||
| `modsEnabled.sql.tls.certificatesSecret` | | `""` |
|
|
||||||
| `modsEnabled.sql.tls.certFilename` | | `""` |
|
|
||||||
| `modsEnabled.sql.tls.certKeyFilename` | | `""` |
|
|
||||||
| `modsEnabled.sql.tls.certCAFilename` | | `""` |
|
|
||||||
| `modsEnabled.sql.tls.existingTlsSecret` | | `""` |
|
|
||||||
| `modsEnabled.sql.tls.privateKeyPassword` | | `""` |
|
|
||||||
|
|
||||||
|
## Authors and acknowledgment
|
||||||
### Custom FreeRADIUS enabled sites parameters
|
Show your appreciation to those who have contributed to the project.
|
||||||
|
|
||||||
| Name | Description | Value |
|
|
||||||
| ------------------------------------------ | ------------------------------------------------------------------------------- | ----------------- |
|
|
||||||
| `sitesEnabled.coa.enabled` | Enable FreeRADIUS coa service | `false` |
|
|
||||||
| `sitesEnabled.status.enabled` | Enable FreeRADIUS status service | `true` |
|
|
||||||
| `sitesEnabled.tls.enabled` | Enable FreeRADIUS radsec service | `false` |
|
|
||||||
| `sitesEnabled.tls.cipher` | | `false` |
|
|
||||||
| `sitesEnabled.tls.privateKeyPassword` | | `false` |
|
|
||||||
|
|
||||||
|
|
||||||
Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example,
|
|
||||||
|
|
||||||
```console
|
|
||||||
helm install my-release \
|
|
||||||
--set imagePullPolicy=Always \
|
|
||||||
startechnica/freeradius
|
|
||||||
```
|
|
||||||
|
|
||||||
The above command sets the `imagePullPolicy` to `Always`.
|
|
||||||
|
|
||||||
Alternatively, a YAML file that specifies the values for the parameters can be provided while installing the chart. For example,
|
|
||||||
|
|
||||||
```console
|
|
||||||
helm install my-release startechnica/freeradius -f values.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
> **Tip**: You can use the default [values.yaml](values.yaml)
|
|
||||||
|
|
||||||
## Configuration and installation details
|
|
||||||
|
|
||||||
### Adding extra environment variables
|
|
||||||
|
|
||||||
In case you want to add extra environment variables (useful for advanced operations like custom init scripts), you can use the `extraEnvVars` property.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
extraEnvVars:
|
|
||||||
- name: LOG_LEVEL
|
|
||||||
value: error
|
|
||||||
```
|
|
||||||
|
|
||||||
Alternatively, you can use a ConfigMap or a Secret with the environment variables. To do so, use the `extraEnvVarsCM` or the `extraEnvVarsSecret` values.
|
|
||||||
|
|
||||||
### Setting Pod's affinity
|
|
||||||
|
|
||||||
This chart allows you to set your custom affinity using the `affinity` parameter. Find more information about Pod's affinity in the [kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity).
|
|
||||||
|
|
||||||
### Deploying extra resources
|
|
||||||
|
|
||||||
There are cases where you may want to deploy extra objects, such a ConfigMap containing your app's configuration or some extra deployment with a micro service used by your app. For covering this case, the chart allows adding the full specification of other objects using the `extraDeploy` parameter.
|
|
||||||
|
|
||||||
## Troubleshooting
|
|
||||||
|
|
||||||
Find more information about how to deal with common errors related to Startechnica's Helm charts in [this troubleshooting guide](https://startechnica.github.io/doc/troubleshoot-helm-chart-issues).
|
|
||||||
|
|
||||||
## Upgrading
|
|
||||||
|
|
||||||
## License
|
## License
|
||||||
|
For open source projects, say how it is licensed.
|
||||||
|
|
||||||
Copyright © 2023 Startechnica
|
## Project status
|
||||||
|
If you have run out of energy or time for your project, put a note at the top of the README saying that development has slowed down or stopped completely. Someone may choose to fork your project or volunteer to step in as a maintainer or owner, allowing your project to keep going. You can also make an explicit request for maintainers.
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
|
|||||||
@@ -0,0 +1,38 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: freeradius
|
||||||
|
namespace: argocd
|
||||||
|
|
||||||
|
spec:
|
||||||
|
project: default
|
||||||
|
|
||||||
|
sources:
|
||||||
|
# FreeRADIUS OCI Helm chart
|
||||||
|
- repoURL: oci://gitea.infrastructure.helmholz.cloud/gitea_admin/helm/freeradius
|
||||||
|
targetRevision: 2.0.0
|
||||||
|
path: .
|
||||||
|
helm:
|
||||||
|
valueFiles:
|
||||||
|
- $values/values.yaml
|
||||||
|
|
||||||
|
# Git repo - Kubernetes manifests
|
||||||
|
- repoURL: ssh://git@gitea-ssh.gitea.svc.cluster.local:22/gitea_admin/FreeRADIUS.git
|
||||||
|
targetRevision: main
|
||||||
|
path: manifests
|
||||||
|
|
||||||
|
# Git repo - values
|
||||||
|
- repoURL: ssh://git@gitea-ssh.gitea.svc.cluster.local:22/gitea_admin/FreeRADIUS.git
|
||||||
|
targetRevision: main
|
||||||
|
ref: values
|
||||||
|
|
||||||
|
destination:
|
||||||
|
server: "https://138.199.131.114:6443"
|
||||||
|
namespace: freeradius
|
||||||
|
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
selfHeal: true
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
@@ -1,55 +0,0 @@
|
|||||||
# -*- text -*-
|
|
||||||
######################################################################
|
|
||||||
#
|
|
||||||
# Sample virtual server for receiving a CoA or Disconnect-Request packet.
|
|
||||||
#
|
|
||||||
server coa {
|
|
||||||
namespace = $ENV{FREERADIUS_SITES_NAMESPACE}
|
|
||||||
|
|
||||||
# Listen on the CoA port.
|
|
||||||
#
|
|
||||||
# This uses the normal set of clients, with the same secret as for
|
|
||||||
# authentication and accounting.
|
|
||||||
#
|
|
||||||
listen {
|
|
||||||
type = CoA-Request
|
|
||||||
type = Disconnect-Request
|
|
||||||
|
|
||||||
transport = udp
|
|
||||||
|
|
||||||
udp {
|
|
||||||
ipaddr = $ENV{FREERADIUS_SITES_COA_LISTEN}
|
|
||||||
port = $ENV{FREERADIUS_SITES_COA_PORT}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# Receive a CoA request
|
|
||||||
recv CoA-Request {
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
|
|
||||||
# Send a CoA ACK
|
|
||||||
send CoA-ACK {
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
|
|
||||||
# Send a CoA NAK
|
|
||||||
send CoA-NAK {
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
|
|
||||||
# Receive a Disconnect request
|
|
||||||
recv Disconnect-Request {
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
|
|
||||||
# Send a Disconnect ACK
|
|
||||||
send Disconnect-ACK {
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
|
|
||||||
# Send a Disconnect NAK
|
|
||||||
send Disconnect-NAK {
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,247 +0,0 @@
|
|||||||
######################################################################
|
|
||||||
#
|
|
||||||
# RADIUS over TLS
|
|
||||||
#
|
|
||||||
######################################################################
|
|
||||||
|
|
||||||
server radsec {
|
|
||||||
listen {
|
|
||||||
transport = tls
|
|
||||||
|
|
||||||
type = Access-Request
|
|
||||||
type = Accounting-Request
|
|
||||||
|
|
||||||
tls {
|
|
||||||
|
|
||||||
ipaddr = $ENV{FREERADIUS_SITES_TLS_LISTEN}
|
|
||||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
|
||||||
|
|
||||||
# Connection limiting for sockets with "proto = tcp".
|
|
||||||
#
|
|
||||||
limit {
|
|
||||||
# Limit the number of simultaneous TCP connections to the socket
|
|
||||||
#
|
|
||||||
# The default is 16.
|
|
||||||
# Setting this to 0 means "no limit"
|
|
||||||
max_connections = 16
|
|
||||||
|
|
||||||
# The per-socket "max_requests" option does not exist.
|
|
||||||
|
|
||||||
# The lifetime, in seconds, of a TCP connection. After this lifetime, the connection will be closed.
|
|
||||||
#
|
|
||||||
# Setting this to 0 means "forever".
|
|
||||||
lifetime = 0
|
|
||||||
|
|
||||||
# The idle timeout, in seconds, of a TCP connection.
|
|
||||||
# If no packets have been received over the connection for this time, the connection will be closed.
|
|
||||||
# Setting this to 0 means "no timeout".
|
|
||||||
#
|
|
||||||
# We STRONGLY RECOMMEND that you set an idle timeout.
|
|
||||||
idle_timeout = 30
|
|
||||||
}
|
|
||||||
|
|
||||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
|
||||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
|
||||||
|
|
||||||
# If Private key & Certificate are located in the same file, then private_key_file &
|
|
||||||
# certificate_file must contain the same file name.
|
|
||||||
#
|
|
||||||
# If ca_file (below) is not used, then the certificate_file below MUST include not only the server certificate, but ALSO all
|
|
||||||
# of the CA certificates used to sign the server certificate.
|
|
||||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
|
||||||
|
|
||||||
# Trusted Root CA list
|
|
||||||
#
|
|
||||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
|
||||||
#
|
|
||||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
|
||||||
# In that case, this CA file should contain *one* CA certificate.
|
|
||||||
#
|
|
||||||
# This parameter is used only for EAP-TLS, when you issue client certificates. If you do not use client certificates, and you do not want
|
|
||||||
# to permit EAP-TLS authentication, then delete this configuration item.
|
|
||||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
|
||||||
|
|
||||||
#
|
|
||||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
|
||||||
#
|
|
||||||
# openssl dhparam -out certs/dh 1024
|
|
||||||
dh_file = ${certdir}/dh
|
|
||||||
|
|
||||||
#
|
|
||||||
# If your system doesn't have /dev/urandom, you will need to create this file, and periodically change its contents.
|
|
||||||
# For security reasons, FreeRADIUS doesn't write to files in its configuration directory.
|
|
||||||
# random_file = /dev/urandom
|
|
||||||
|
|
||||||
#
|
|
||||||
# The default fragment size is 1K. However, it's possible to send much more data than that over a TCP connection. The upper limit is 64K.
|
|
||||||
# Setting the fragment size to more than 1K means that there are fewer round trips when setting up a TLS connection. But only if the certificates are large.
|
|
||||||
fragment_size = 8192
|
|
||||||
|
|
||||||
# include_length is a flag which is by default set to yes If set to yes, Total Length of the message is
|
|
||||||
# included in EVERY packet we send.
|
|
||||||
# If set to no, Total Length of the message is included ONLY in the First packet of a fragment series.
|
|
||||||
# include_length = yes
|
|
||||||
|
|
||||||
# Check the Certificate Revocation List
|
|
||||||
#
|
|
||||||
# 1) Copy CA certificates and CRLs to same directory.
|
|
||||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
|
||||||
# 'c_rehash' is OpenSSL's command.
|
|
||||||
# 3) uncomment the line below.
|
|
||||||
# 5) Restart radiusd
|
|
||||||
# check_crl = yes
|
|
||||||
ca_path = ${cadir}
|
|
||||||
|
|
||||||
# Accept an expired Certificate Revocation List
|
|
||||||
#
|
|
||||||
# allow_expired_crl = no
|
|
||||||
|
|
||||||
# Accept a not-yet-valid Certificate Revocation List
|
|
||||||
#
|
|
||||||
# allow_not_yet_valid_crl = no
|
|
||||||
|
|
||||||
#
|
|
||||||
# If check_cert_issuer is set, the value will
|
|
||||||
# be checked against the DN of the issuer in
|
|
||||||
# the client certificate. If the values do not
|
|
||||||
# match, the certificate verification will fail,
|
|
||||||
# rejecting the user.
|
|
||||||
#
|
|
||||||
# This check can be done more generally by checking
|
|
||||||
# the value of the TLS-Client-Cert-Issuer attribute.
|
|
||||||
# This check can be done via any mechanism you choose.
|
|
||||||
#
|
|
||||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
|
||||||
|
|
||||||
#
|
|
||||||
# If check_cert_cn is set, the value will
|
|
||||||
# be xlat'ed and checked against the CN
|
|
||||||
# in the client certificate. If the values
|
|
||||||
# do not match, the certificate verification
|
|
||||||
# will fail rejecting the user.
|
|
||||||
#
|
|
||||||
# This check is done only if the previous
|
|
||||||
# "check_cert_issuer" is not set, or if
|
|
||||||
# the check succeeds.
|
|
||||||
#
|
|
||||||
# This check can be done more generally by checking
|
|
||||||
# the value of the TLS-Client-Cert-Common-Name attribute.
|
|
||||||
# This check can be done via any mechanism you choose.
|
|
||||||
#
|
|
||||||
# check_cert_cn = %{User-Name}
|
|
||||||
#
|
|
||||||
# Set this option to specify the allowed
|
|
||||||
# TLS cipher suites. The format is listed
|
|
||||||
# in "man 1 ciphers".
|
|
||||||
cipher_list = "DEFAULT"
|
|
||||||
|
|
||||||
# If enabled, OpenSSL will use server cipher list
|
|
||||||
# (possibly defined by cipher_list option above)
|
|
||||||
# for choosing right cipher suite rather than
|
|
||||||
# using client-specified list which is OpenSSl default
|
|
||||||
# behavior. Having it set to 'yes' is best practice
|
|
||||||
# for TLS.
|
|
||||||
cipher_server_preference = yes
|
|
||||||
|
|
||||||
#
|
|
||||||
# Session resumption / fast reauthentication
|
|
||||||
# cache.
|
|
||||||
#
|
|
||||||
# The cache contains the following information:
|
|
||||||
#
|
|
||||||
# session Id - unique identifier, managed by SSL
|
|
||||||
# User-Name - from the Access-Accept
|
|
||||||
# Stripped-User-Name - from the Access-Request
|
|
||||||
# Cached-Session-Policy - from the Access-Accept
|
|
||||||
#
|
|
||||||
# The "Cached-Session-Policy" is the name of a
|
|
||||||
# policy which should be applied to the cached
|
|
||||||
# session. This policy can be used to assign
|
|
||||||
# VLANs, IP addresses, etc. It serves as a useful
|
|
||||||
# way to re-apply the policy from the original
|
|
||||||
# Access-Accept to the subsequent Access-Accept
|
|
||||||
# for the cached session.
|
|
||||||
#
|
|
||||||
# On session resumption, these attributes are
|
|
||||||
# copied from the cache, and placed into the
|
|
||||||
# reply list.
|
|
||||||
#
|
|
||||||
# You probably also want "use_tunneled_reply = yes"
|
|
||||||
# when using fast session resumption.
|
|
||||||
#
|
|
||||||
cache {
|
|
||||||
#
|
|
||||||
# Lifetime of the cached entries, in hours.
|
|
||||||
# The sessions will be deleted after this
|
|
||||||
# time.
|
|
||||||
#
|
|
||||||
lifetime = 24 # hours
|
|
||||||
|
|
||||||
#
|
|
||||||
# Internal "name" of the session cache.
|
|
||||||
# Used to distinguish which TLS context
|
|
||||||
# sessions belong to.
|
|
||||||
#
|
|
||||||
# The server will generate a random value
|
|
||||||
# if unset. This will change across server
|
|
||||||
# restart so you MUST set the "name" if you
|
|
||||||
# want to persist sessions (see below).
|
|
||||||
#
|
|
||||||
# If you use IPv6, change the "ipaddr" below
|
|
||||||
# to "ipv6addr"
|
|
||||||
#
|
|
||||||
#name = "TLS ${..ipaddr} ${..port} ${..proto}"
|
|
||||||
|
|
||||||
#
|
|
||||||
# Simple directory-based storage of sessions.
|
|
||||||
# Two files per session will be written, the SSL
|
|
||||||
# state and the cached VPs. This will persist session
|
|
||||||
# across server restarts.
|
|
||||||
#
|
|
||||||
# The server will need write perms, and the directory
|
|
||||||
# should be secured from anyone else. You might want
|
|
||||||
# a script to remove old files from here periodically:
|
|
||||||
#
|
|
||||||
# find ${logdir}/tlscache -mtime +2 -exec rm -f {} \;
|
|
||||||
#
|
|
||||||
# This feature REQUIRES "name" option be set above.
|
|
||||||
#
|
|
||||||
#persist_dir = "${logdir}/tlscache"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Require a client certificate.
|
|
||||||
#
|
|
||||||
require_client_cert = no
|
|
||||||
|
|
||||||
#
|
|
||||||
# As of version 2.1.10, client certificates can be validated via an external command. This allows dynamic CRLs or OCSP to be used.
|
|
||||||
#
|
|
||||||
# This configuration is commented out in the default configuration. Uncomment it, and configure the correct paths below to enable it.
|
|
||||||
#
|
|
||||||
verify {
|
|
||||||
# A temporary directory where the client certificates are stored. This directory MUST be owned by the UID of the server,
|
|
||||||
# and MUST not be accessible by any other users. When the server starts, it will do "chmod go-rwx" on the directory, for
|
|
||||||
# security reasons. The directory MUST exist when the server starts.
|
|
||||||
#
|
|
||||||
# You should also delete all of the files in the directory when the server starts.
|
|
||||||
tmpdir = /startechnica/freeradius/tmp
|
|
||||||
|
|
||||||
# The command used to verify the client cert. We recommend using the OpenSSL command-line tool.
|
|
||||||
#
|
|
||||||
# The ${..ca_path} text is a reference to the ca_path variable defined above.
|
|
||||||
#
|
|
||||||
# The %{TLS-Client-Cert-Filename} is the name of the temporary file containing the cert in PEM format. This file is automatically
|
|
||||||
# deleted by the server when the command returns.
|
|
||||||
# client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
recv Access-Request {
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
|
|
||||||
recv Accounting-Request {
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
-----BEGIN DH PARAMETERS-----
|
||||||
|
MIIBCAKCAQEAmTz/pyBq/Z/b+3FBsJal4JIoT3jibTQ5NsLgUxVX83YayBMfB8o+
|
||||||
|
Y/kFAtspKLJtXgZ9uNwAcpqBBw19o6vbxsDcln3Gi6IO24uiZrpaWkTAoLZsuOK0
|
||||||
|
bbE0cFCruWGWv4IDDfvFffRq7mNrI1LK3IkeROu7CuE53lpwRe1JtTK4OPfeerPk
|
||||||
|
2vyojQJWzkLUz8th2bubMGYvSZ6I8mTXTzsk3eGzxAIWGwd1GvuUwX9+pHiDVbac
|
||||||
|
ZYAr6NHkSq2nyU11bb92XjR5+yoDGoKapyAxB+B9ZBRVAQ7RHMkcGNyZT/6eGRCw
|
||||||
|
kHDGqo+qiJBqB8hmvAEwoAWMRgUYd1mZPwIBAg==
|
||||||
|
-----END DH PARAMETERS-----
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIICkjCCAXqgAwIBAgIIF5vfktfGFYwwDQYJKoZIhvcNAQELBQAwADAeFw0yNTA2
|
||||||
|
MjUxMTIyMDBaFw0yNjA2MjUxMTIyMDBaMAAwggEiMA0GCSqGSIb3DQEBAQUAA4IB
|
||||||
|
DwAwggEKAoIBAQC196tFi2qulBMEQ/dyJD2Wsbi+Sog7vCOmFk0e9UMwogIMF/lC
|
||||||
|
WO6NOBtKYi8q+JHVWzgD9FqBkLPjAk87RJkGgi+/zE4gLtU3j5xmm48u5CqVmCDs
|
||||||
|
bu3Y/WDuip3MPhUb1btqQbQRsDU2UuMvQ8e/sSKGcl0BRxVnTsyeVkFXmY49KZYN
|
||||||
|
GFyXAjK/Fmj0ymWue+2kGEdsn83tqCAE4D7PkOYTOuaGW2E9qL0i11ALMZ/Wd97j
|
||||||
|
MyimM05385zcv10cr/SdwbKa83l0vawJCXLA+IyFkPJwTbMCr84HzBg43FOWfuOm
|
||||||
|
6q7cyDR7jHL+gJQj6NWmeLRWNv5mLvGXE54lAgMBAAGjEDAOMAwGA1UdEwQFMAMB
|
||||||
|
Af8wDQYJKoZIhvcNAQELBQADggEBAIw1kkJ1sgSkEPTAhxxqz22okRik6gFmx3q1
|
||||||
|
BAjK0KlAniYp2PdYMzH9QJYOjGRzNzRDpCPSED1fz5dVP8ZSKyLlS1UI9IqlZfoX
|
||||||
|
uoTRL7XUUrwpxAk5oURWqC8hMfM+bYEE8VV7KPvAU1QZneIWMoaCMR9NB7UytaK2
|
||||||
|
jFPdgJIPdtT5wBVxZPsdEYC/0u9+uiILxNCT/ghI9BwynVe1SfqN5YCtIc4uURj5
|
||||||
|
tDYWgoL4gJxihKI9tQdoCETOpGMMU81x8kSDERJy3c7Dh+m+B+mhB3pOVu3iD1F8
|
||||||
|
FgMfHEIz0iHZeAKJRQGzdDIhH1czCjc6lIavUF61lGNySzBIuUU=
|
||||||
|
-----END CERTIFICATE-----
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
-----BEGIN RSA PRIVATE KEY-----
|
||||||
|
MIIEoQIBAAKCAQEAvij0IoVdfjj7mLZJWFKj4UO96Hy6JQsHvMG/HybeorGL64Bc
|
||||||
|
vb3L7v/Nwc5hGkgrxXmFJ0eNAc7QsD9wpCi3mEd2tyZeyspZwFelwuC8XiItzO+f
|
||||||
|
YNwdXFVtwcqy2ouMhGHPnMOrQByrh8Dislz3QbST16Qhq7Qvytih+7xgP5+qnsYg
|
||||||
|
OnVFOf9Tw0fuci4Xg7mFLGx64St1K9gpeSGGK+k6HxnCC9N8Jy+ZYA/FZfzAS1s8
|
||||||
|
dVCzTFhR6pnm4+Cz/pu7UkOoCOS5mDh8UCGv+f1EjlMQ7RHJegNTpAenqPpGt26z
|
||||||
|
nYKp/wPc3qVPoZ350c1anqdf9wArsPlgvcMJaQIDAQABAoH/ZhgIiSrYQCU7YRdg
|
||||||
|
u0OjKocXxA+kxHd86NqqwfJxznW9N7MkwkhdGLshoJae4O8z5kOtVfeihB0TtRrM
|
||||||
|
Jjon5ig/PzIhsoXU/1Ly5ObgOzgee1qdNw5L0ZxE++MQzgweLEpXSUTgyPzUcGNz
|
||||||
|
/Wt6cQVJd0RSXcDuIMERxN0JCKz8jKpPqnVfhsKZhPdCYNOWM2mZ+LZY34Mxn5ie
|
||||||
|
T4bc4fIrnPNCiZicyq9HK2z6GzxcESnljr4vBwv3cJnTBAfzKjKo3b53k+qLVeAR
|
||||||
|
PIJBudhIfo6SzuPGCCIuibKT/97eKW1fkRGxSPWjPFBSvGRJ3wzqYoum3BCHrpAe
|
||||||
|
XXQRAoGBAN9a3mrFyXOUehXXlY3OYomcr7IJ37rtjZJyTDS40uESYj7Wqc9HQsk5
|
||||||
|
bmDKH2US35LJnZuWLNXon28IbrCC5WkAXWUBG41qcj8Li5CMZbM4B32ryH6iD0oh
|
||||||
|
FbjpU2ZUxZ1NdxmXlfzTuJr65NHlb6id+M8Welrdk0s/Gv0hQSv1AoGBANn0DJlQ
|
||||||
|
eDcU0clMvSMnq7+6IZQghErC1Jpzx++LQ49vWs1VQCwDVTs1bXt+5fZop5ayBU0p
|
||||||
|
R4dPoezyFP2PZsPm/yE3xwsedSYO5RUncm268P/+KCSMlCSkOZJxQPlAvog9wC0t
|
||||||
|
dMg9vW6kTt5KD2+MZTATbHxghjodDVMwcpMlAoGAQBGBwWDw012g04kelinAbDbs
|
||||||
|
0wYwDh+8P2jX4TuvCe7LDblnxlRrnOsDdXIlJUoPpbx9oDaor8dljGT/01QI2GDJ
|
||||||
|
aYKy05LYKKt4IkOTnKASzgKrpV95QUtSPtN3H+BrOx8Qbd/knzxgNNyJLIhCyjxe
|
||||||
|
NZD+EfiDGs+EP139os0CgYEAkhbbOwiNC56Q33Tocd/tZx3D1B3XjqT5DG3+3blj
|
||||||
|
F4l0O52g3d9+CanOMLDmQzvy2TeKBiZdI31k9AVvvGWaZEU5TXKtn+5SZ6gkNQGz
|
||||||
|
2YkscOpSzezMf6L0VAxFmMyk6X06iw2k8XMwvjC0DJtnrUVVrdvXI6cvUVSX0eLv
|
||||||
|
aWECgYBS07zV381/YNlmCM+E+WTZSZrngjjIeCgcqMJt1t2SpnaBQoHO6DKjJcDk
|
||||||
|
8Leg8z7B8Ym5FJfy55ZorkDV7LGI1JGwfc3p3MW2RAVhkkV0LoGHLv8VcD6t3Utq
|
||||||
|
dIMkugPE/JQQinZsDD8B3lLBi165OFfxFWS7mJDbHaw34i7ADQ==
|
||||||
|
-----END RSA PRIVATE KEY-----
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIICwjCCAaqgAwIBAgIIOxDIc7UovJkwDQYJKoZIhvcNAQELBQAwADAeFw0yNTA2
|
||||||
|
MjUxMTMzMDBaFw0yNjA2MjUxMTIyMDBaMDMxMTAvBgNVBAMTKGZyZWVyYWRpdXMu
|
||||||
|
aW5mcmFzdHJ1Y3R1cmUuaGVsbWhvbHouY2xvdWQwggEiMA0GCSqGSIb3DQEBAQUA
|
||||||
|
A4IBDwAwggEKAoIBAQC+KPQihV1+OPuYtklYUqPhQ73ofLolCwe8wb8fJt6isYvr
|
||||||
|
gFy9vcvu/83BzmEaSCvFeYUnR40BztCwP3CkKLeYR3a3Jl7KylnAV6XC4LxeIi3M
|
||||||
|
759g3B1cVW3ByrLai4yEYc+cw6tAHKuHwOKyXPdBtJPXpCGrtC/K2KH7vGA/n6qe
|
||||||
|
xiA6dUU5/1PDR+5yLheDuYUsbHrhK3Ur2Cl5IYYr6TofGcIL03wnL5lgD8Vl/MBL
|
||||||
|
Wzx1ULNMWFHqmebj4LP+m7tSQ6gI5LmYOHxQIa/5/USOUxDtEcl6A1OkB6eo+ka3
|
||||||
|
brOdgqn/A9zepU+hnfnRzVqep1/3ACuw+WC9wwlpAgMBAAGjDTALMAkGA1UdEwQC
|
||||||
|
MAAwDQYJKoZIhvcNAQELBQADggEBAJt80P4oe7aRUC3+Hr1uQlHVtATkS1jDZ8um
|
||||||
|
GJAy8EKtrPp53OR9ZFMUOTieAEAbRRqyxrqgJQDP83opS8Yc2pyIyC3H8nlm2AmW
|
||||||
|
FzRVxLFaNoUaxotbrGubJOJ6rolaWjpUTLdCZb43P/vgZ9rJHMG3HTgfDn9cYEPj
|
||||||
|
JlLVonUJkeM92Bx3ds5QCSEhTteQ0u6xIfq1FOo9lt0PxFelL3QwEc0OyqDzUIo5
|
||||||
|
n4buhEaVZiNqjXIifIv1Dqci7oZBOhVKr6LpGYjs3K9P2+qXNrsNE4zVbZZOYNpI
|
||||||
|
X+b+0e8bHb9Du84Cn5px0qeFlJPKGrORcz8MWKuGiUnn/MKokNw=
|
||||||
|
-----END CERTIFICATE-----
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
You can copy here your custom .sh, .sql or .sql.gz file so they are executed during the first boot of the image.
|
|
||||||
|
|
||||||
More info in the [freeradius/freeradius-server](https://hub.docker.com/r/freeradius/freeradius-server) repository.
|
|
||||||
@@ -1,41 +0,0 @@
|
|||||||
# -*- text -*-
|
|
||||||
#
|
|
||||||
# $Id: cc2bd5fd22aa473b98af5dde3fac7a66e39a9e9d $
|
|
||||||
|
|
||||||
# This module loads RADIUS clients as needed, rather than when the server
|
|
||||||
# starts.
|
|
||||||
#
|
|
||||||
# There are no configuration entries for this module. Instead, it
|
|
||||||
# relies on the "client" configuration. You must:
|
|
||||||
#
|
|
||||||
# 1) link raddb/sites-enabled/dynamic_clients to
|
|
||||||
# raddb/sites-available/dynamic_clients
|
|
||||||
#
|
|
||||||
# 2) Define a client network/mask (see top of the above file)
|
|
||||||
#
|
|
||||||
# 3) uncomment the "directory" entry in that client definition
|
|
||||||
#
|
|
||||||
# 4) list "dynamic_clients" in the "authorize" section of the
|
|
||||||
# "dynamic_clients' virtual server. The default example already
|
|
||||||
# does this.
|
|
||||||
#
|
|
||||||
# 5) put files into the above directory, one per IP.
|
|
||||||
# e.g. file "192.0.2.1" should contain a normal client definition
|
|
||||||
# for a client with IP address 192.0.2.1.
|
|
||||||
#
|
|
||||||
# For more documentation, see the file:
|
|
||||||
#
|
|
||||||
# raddb/sites-available/dynamic-clients
|
|
||||||
#
|
|
||||||
dynamic_clients {
|
|
||||||
sql = "SELECT secret, shortname, type FROM nas WHERE nasname = '%{Packet-Src-IP-Address}'"
|
|
||||||
|
|
||||||
key = "%{Packet-Src-IP-Address}"
|
|
||||||
|
|
||||||
client {
|
|
||||||
ipaddr = "%{Packet-Src-IP-Address}"
|
|
||||||
secret = "%{reply:secret}"
|
|
||||||
shortname = "%{reply:shortname}"
|
|
||||||
nastype = "%{reply:type}"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,366 +0,0 @@
|
|||||||
# -*- text -*-
|
|
||||||
##
|
|
||||||
## mods-available/sql -- SQL modules
|
|
||||||
##
|
|
||||||
## $Id: cfeac63ea87c30fead8457af6d10f5c3a0f48aef $
|
|
||||||
|
|
||||||
######################################################################
|
|
||||||
#
|
|
||||||
# Configuration for the SQL module
|
|
||||||
#
|
|
||||||
# The database schemas and queries are located in subdirectories:
|
|
||||||
#
|
|
||||||
# sql/<DB>/main/schema.sql Schema
|
|
||||||
# sql/<DB>/main/queries.conf Authorisation and Accounting queries
|
|
||||||
#
|
|
||||||
# Where "DB" is mysql, mssql, oracle, or postgresql.
|
|
||||||
#
|
|
||||||
# The name used to query SQL is sql_user_name, which is set in the file
|
|
||||||
#
|
|
||||||
# raddb/mods-config/sql/main/${dialect}/queries.conf
|
|
||||||
#
|
|
||||||
# If you are using realms, that configuration should be changed to use
|
|
||||||
# the Stripped-User-Name attribute. See the comments around sql_user_name
|
|
||||||
# for more information.
|
|
||||||
#
|
|
||||||
|
|
||||||
sql {
|
|
||||||
#
|
|
||||||
# The dialect of SQL being used.
|
|
||||||
#
|
|
||||||
# Allowed dialects are:
|
|
||||||
#
|
|
||||||
# mssql
|
|
||||||
# mysql
|
|
||||||
# oracle
|
|
||||||
# postgresql
|
|
||||||
# sqlite
|
|
||||||
# mongo
|
|
||||||
#
|
|
||||||
# dialect = "sqlite"
|
|
||||||
dialect = $ENV{FREERADIUS_MODS_SQL_DIALECT}
|
|
||||||
|
|
||||||
#
|
|
||||||
# The driver module used to execute the queries. Since we
|
|
||||||
# don't know which SQL drivers are being used, the default is
|
|
||||||
# "rlm_sql_null", which just logs the queries to disk via the
|
|
||||||
# "logfile" directive, below.
|
|
||||||
#
|
|
||||||
# In order to talk to a real database, delete the next line,
|
|
||||||
# and uncomment the one after it.
|
|
||||||
#
|
|
||||||
# If the dialect is "mssql", then the driver should be set to
|
|
||||||
# one of the following values, depending on your system:
|
|
||||||
#
|
|
||||||
# rlm_sql_db2
|
|
||||||
# rlm_sql_firebird
|
|
||||||
# rlm_sql_freetds
|
|
||||||
# rlm_sql_iodbc
|
|
||||||
# rlm_sql_unixodbc
|
|
||||||
#
|
|
||||||
# driver = "rlm_sql_null"
|
|
||||||
driver = "rlm_sql_${dialect}"
|
|
||||||
|
|
||||||
#
|
|
||||||
# Driver-specific subsections. They will only be loaded and
|
|
||||||
# used if "driver" is something other than "rlm_sql_null".
|
|
||||||
# When a real driver is used, the relevant driver
|
|
||||||
# configuration section is loaded, and all other driver
|
|
||||||
# configuration sections are ignored.
|
|
||||||
#
|
|
||||||
sqlite {
|
|
||||||
# Path to the sqlite database
|
|
||||||
filename = $ENV{FREERADIUS_MODS_SQL_SQLITE_FILENAME}
|
|
||||||
|
|
||||||
# How long to wait for write locks on the database to be released (in ms) before giving up.
|
|
||||||
busy_timeout = $ENV{FREERADIUS_MODS_SQL_SQLITE_BUSY_TIMEOUT}
|
|
||||||
|
|
||||||
# If the file above does not exist and bootstrap is set
|
|
||||||
# a new database file will be created, and the SQL statements
|
|
||||||
# contained within the bootstrap file will be executed.
|
|
||||||
bootstrap = "${modconfdir}/${..:name}/main/sqlite/schema.sql"
|
|
||||||
}
|
|
||||||
|
|
||||||
mysql {
|
|
||||||
# If any of the files below are set, TLS encryption is enabled
|
|
||||||
tls {
|
|
||||||
# ca_file = $ENV{FREERADIUS_MODS_SQL_TLS_CACERT}
|
|
||||||
# ca_path = "/startechnica/freeradius/certs-sql/"
|
|
||||||
# certificate_file = $ENV{FREERADIUS_MODS_SQL_TLS_CERTIFICATE}
|
|
||||||
# private_key_file = $ENV{FREERADIUS_MODS_SQL_TLS_PRIVATEKEY}
|
|
||||||
# cipher = "DHE-RSA-AES256-SHA:AES128-SHA"
|
|
||||||
# cipher = $ENV{FREERADIUS_MODS_SQL_TLS_CIPHER}
|
|
||||||
|
|
||||||
tls_required = $ENV{FREERADIUS_MODS_SQL_TLS_ENABLE}
|
|
||||||
tls_check_cert = no
|
|
||||||
tls_check_cert_cn = no
|
|
||||||
}
|
|
||||||
|
|
||||||
# If yes, (or auto and libmysqlclient reports warnings are
|
|
||||||
# available), will retrieve and log additional warnings from
|
|
||||||
# the server if an error has occured. Defaults to 'auto'
|
|
||||||
warnings = auto
|
|
||||||
}
|
|
||||||
|
|
||||||
postgresql {
|
|
||||||
|
|
||||||
# unlike MySQL, which has a tls{} connection configuration, postgresql
|
|
||||||
# uses its connection parameters - see the radius_db option below in
|
|
||||||
# this file
|
|
||||||
|
|
||||||
# Send application_name to the postgres server
|
|
||||||
# Only supported in PG 9.0 and greater. Defaults to no.
|
|
||||||
send_application_name = yes
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Configuration for Mongo.
|
|
||||||
#
|
|
||||||
# Note that the Mongo driver is experimental. The FreeRADIUS developers
|
|
||||||
# are unable to help with the syntax of the Mongo queries. Please see
|
|
||||||
# the Mongo documentation for that syntax.
|
|
||||||
#
|
|
||||||
# The Mongo driver supports only the following methods:
|
|
||||||
#
|
|
||||||
# aggregate
|
|
||||||
# findAndModify
|
|
||||||
# findOne
|
|
||||||
# insert
|
|
||||||
#
|
|
||||||
# For examples, see the query files:
|
|
||||||
#
|
|
||||||
# raddb/mods-config/sql/main/mongo/queries.conf
|
|
||||||
# raddb/mods-config/sql/main/ippool/queries.conf
|
|
||||||
#
|
|
||||||
# In order to use findAndModify with an aggretation pipleline, make
|
|
||||||
# sure that you are running MongoDB version 4.2 or greater. FreeRADIUS
|
|
||||||
# assumes that the paramaters passed to the methods are supported by the
|
|
||||||
# version of MongoDB which it is connected to.
|
|
||||||
#
|
|
||||||
mongo {
|
|
||||||
#
|
|
||||||
# The application name to use.
|
|
||||||
#
|
|
||||||
appname = "freeradius"
|
|
||||||
|
|
||||||
#
|
|
||||||
# The TLS parameters here map directly to the Mongo TLS configuration
|
|
||||||
#
|
|
||||||
tls {
|
|
||||||
certificate_file = $ENV{FREERADIUS_MODS_SQL_TLS_CERTIFICATE}
|
|
||||||
certificate_password = $ENV{FREERADIUS_MODS_SQL_TLS_PRIVATEKEY}
|
|
||||||
ca_file = $ENV{FREERADIUS_MODS_SQL_TLS_CACERT}
|
|
||||||
ca_dir = /startechnica/freeradius/certs-sql/
|
|
||||||
# crl_file = /path/to/file
|
|
||||||
weak_cert_validation = false
|
|
||||||
allow_invalid_hostname = false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# Connection info:
|
|
||||||
#
|
|
||||||
server = $ENV{FREERADIUS_MODS_SQL_SERVER}
|
|
||||||
port = $ENV{FREERADIUS_MODS_SQL_PORT}
|
|
||||||
login = $ENV{FREERADIUS_MODS_SQL_LOGIN}
|
|
||||||
password = $ENV{FREERADIUS_MODS_SQL_PASSWORD}
|
|
||||||
|
|
||||||
# Connection info for Mongo
|
|
||||||
# Authentication Without SSL
|
|
||||||
# server = "mongodb://USER:PASSWORD@192.16.0.2:PORT/DATABASE?authSource=admin&ssl=false"
|
|
||||||
|
|
||||||
# Authentication With SSL
|
|
||||||
# server = "mongodb://USER:PASSWORD@192.16.0.2:PORT/DATABASE?authSource=admin&ssl=true"
|
|
||||||
|
|
||||||
# Authentication with Certificate
|
|
||||||
# Use this command for retrieve Derived username:
|
|
||||||
# openssl x509 -in mycert.pem -inform PEM -subject -nameopt RFC2253
|
|
||||||
# server = mongodb://<DERIVED USERNAME>@192.168.0.2:PORT/DATABASE?authSource=$external&ssl=true&authMechanism=MONGODB-X509
|
|
||||||
|
|
||||||
# Database table configuration for everything except Oracle
|
|
||||||
radius_db = $ENV{FREERADIUS_MODS_SQL_DB}
|
|
||||||
|
|
||||||
# If you are using Oracle then use this instead
|
|
||||||
# radius_db = "(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=localhost)(PORT=1521))(CONNECT_DATA=(SID=your_sid)))"
|
|
||||||
|
|
||||||
# If you're using postgresql this can also be used instead of the connection info parameters
|
|
||||||
# radius_db = "dbname=$ENV{FREERADIUS_MODS_SQL_DB} host=$ENV{FREERADIUS_MODS_SQL_SERVER} port=$ENV{FREERADIUS_MODS_SQL_PORT} user=$ENV{FREERADIUS_MODS_SQL_LOGIN} password=$ENV{FREERADIUS_MODS_SQL_PASSWORD}"
|
|
||||||
|
|
||||||
# Postgreql doesn't take tls{} options in its module config like mysql does - if you want to
|
|
||||||
# use SSL connections then use this form of connection info parameter
|
|
||||||
# radius_db = "host=localhost port=5432 dbname=radius user=radius password=raddpass sslmode=verify-full sslcert=/etc/ssl/client.crt sslkey=/etc/ssl/client.key sslrootcert=/etc/ssl/ca.crt"
|
|
||||||
|
|
||||||
# If you want both stop and start records logged to the
|
|
||||||
# same SQL table, leave this as is. If you want them in
|
|
||||||
# different tables, put the start table in acct_table1
|
|
||||||
# and stop table in acct_table2
|
|
||||||
acct_table1 = $ENV{FREERADIUS_MODS_SQL_TABLE_ACCT1}
|
|
||||||
acct_table2 = $ENV{FREERADIUS_MODS_SQL_TABLE_ACCT2}
|
|
||||||
|
|
||||||
# Allow for storing data after authentication
|
|
||||||
postauth_table = $ENV{FREERADIUS_MODS_SQL_TABLE_POSTAUTH}
|
|
||||||
|
|
||||||
# Tables containing 'check' items
|
|
||||||
authcheck_table = $ENV{FREERADIUS_MODS_SQL_TABLE_AUTHCHECK}
|
|
||||||
groupcheck_table = $ENV{FREERADIUS_MODS_SQL_TABLE_GROUPCHECK}
|
|
||||||
|
|
||||||
# Tables containing 'reply' items
|
|
||||||
authreply_table = $ENV{FREERADIUS_MODS_SQL_TABLE_AUTHREPLY}
|
|
||||||
groupreply_table = $ENV{FREERADIUS_MODS_SQL_TABLE_GROUPREPLY}
|
|
||||||
|
|
||||||
# Table to keep group info
|
|
||||||
usergroup_table = $ENV{FREERADIUS_MODS_SQL_TABLE_USERGROUP}
|
|
||||||
|
|
||||||
# If set to 'yes' (default) we read the group tables unless Fall-Through = no in the reply table.
|
|
||||||
# If set to 'no' we do not read the group tables unless Fall-Through = yes in the reply table.
|
|
||||||
# read_groups = yes
|
|
||||||
|
|
||||||
# If set to 'yes' (default) we read profiles unless Fall-Through = no in the groupreply table.
|
|
||||||
# If set to 'no' we do not read profiles unless Fall-Through = yes in the groupreply table.
|
|
||||||
# read_profiles = yes
|
|
||||||
|
|
||||||
# Remove stale session if checkrad does not see a double login
|
|
||||||
delete_stale_sessions = yes
|
|
||||||
|
|
||||||
# Write SQL queries to a logfile. This is potentially useful for tracing
|
|
||||||
# issues with authorization queries. See also "logfile" directives in
|
|
||||||
# mods-config/sql/main/*/queries.conf. You can enable per-section logging
|
|
||||||
# by enabling "logfile" there, or global logging by enabling "logfile" here.
|
|
||||||
#
|
|
||||||
# Per-section logging can be disabled by setting "logfile = ''"
|
|
||||||
# logfile = ${logdir}/sqllog.sql
|
|
||||||
|
|
||||||
# Set the maximum query duration and connection timeout
|
|
||||||
# for rlm_sql_mysql.
|
|
||||||
# query_timeout = 5
|
|
||||||
|
|
||||||
# As of version 3.0, the "pool" section has replaced the
|
|
||||||
# following configuration items:
|
|
||||||
#
|
|
||||||
# num_sql_socks
|
|
||||||
# connect_failure_retry_delay
|
|
||||||
# lifetime
|
|
||||||
# max_queries
|
|
||||||
|
|
||||||
#
|
|
||||||
# The connection pool is new for 3.0, and will be used in many
|
|
||||||
# modules, for all kinds of connection-related activity.
|
|
||||||
#
|
|
||||||
# When the server is not threaded, the connection pool
|
|
||||||
# limits are ignored, and only one connection is used.
|
|
||||||
#
|
|
||||||
# If you want to have multiple SQL modules re-use the same
|
|
||||||
# connection pool, use "pool = name" instead of a "pool"
|
|
||||||
# section. e.g.
|
|
||||||
#
|
|
||||||
# sql sql1 {
|
|
||||||
# ...
|
|
||||||
# pool {
|
|
||||||
# ...
|
|
||||||
# }
|
|
||||||
# }
|
|
||||||
#
|
|
||||||
# # sql2 will use the connection pool from sql1
|
|
||||||
# sql sql2 {
|
|
||||||
# ...
|
|
||||||
# pool = sql1
|
|
||||||
# }
|
|
||||||
#
|
|
||||||
pool {
|
|
||||||
# Connections to create during module instantiation.
|
|
||||||
# If the server cannot create specified number of
|
|
||||||
# connections during instantiation it will exit.
|
|
||||||
# Set to 0 to allow the server to start without the database being available.
|
|
||||||
start = ${thread[pool].start_servers}
|
|
||||||
|
|
||||||
# Minimum number of connections to keep open
|
|
||||||
min = ${thread[pool].min_spare_servers}
|
|
||||||
|
|
||||||
# Maximum number of connections
|
|
||||||
#
|
|
||||||
# If these connections are all in use and a new one
|
|
||||||
# is requested, the request will NOT get a connection.
|
|
||||||
#
|
|
||||||
# Setting 'max' to LESS than the number of threads means
|
|
||||||
# that some threads may starve, and you will see errors
|
|
||||||
# like 'No connections available and at max connection limit'
|
|
||||||
#
|
|
||||||
# Setting 'max' to MORE than the number of threads means
|
|
||||||
# that there are more connections than necessary.
|
|
||||||
max = ${thread[pool].max_servers}
|
|
||||||
|
|
||||||
# Spare connections to be left idle
|
|
||||||
#
|
|
||||||
# NOTE: Idle connections WILL be closed if "idle_timeout"
|
|
||||||
# is set. This should be less than or equal to "max" above.
|
|
||||||
spare = ${thread[pool].max_spare_servers}
|
|
||||||
|
|
||||||
# Number of uses before the connection is closed
|
|
||||||
#
|
|
||||||
# 0 means "infinite"
|
|
||||||
uses = 0
|
|
||||||
|
|
||||||
# The number of seconds to wait after the server tries
|
|
||||||
# to open a connection, and fails. During this time,
|
|
||||||
# no new connections will be opened.
|
|
||||||
retry_delay = 30
|
|
||||||
|
|
||||||
# The lifetime (in seconds) of the connection
|
|
||||||
lifetime = 0
|
|
||||||
|
|
||||||
# idle timeout (in seconds). A connection which is
|
|
||||||
# unused for this length of time will be closed.
|
|
||||||
idle_timeout = 60
|
|
||||||
|
|
||||||
# NOTE: All configuration settings are enforced. If a
|
|
||||||
# connection is closed because of "idle_timeout",
|
|
||||||
# "uses", or "lifetime", then the total number of
|
|
||||||
# connections MAY fall below "min". When that
|
|
||||||
# happens, it will open a new connection. It will
|
|
||||||
# also log a WARNING message.
|
|
||||||
#
|
|
||||||
# The solution is to either lower the "min" connections,
|
|
||||||
# or increase lifetime/idle_timeout.
|
|
||||||
}
|
|
||||||
|
|
||||||
# Set to 'yes' to read radius clients from the database ('nas' table)
|
|
||||||
# Clients will ONLY be read on server startup.
|
|
||||||
#
|
|
||||||
# A client can be link to a virtual server via the SQL
|
|
||||||
# module. This link is done via the following process:
|
|
||||||
#
|
|
||||||
# If there is no listener in a virtual server, SQL clients
|
|
||||||
# are added to the global list for that virtual server.
|
|
||||||
#
|
|
||||||
# If there is a listener, and the first listener does not
|
|
||||||
# have a "clients=..." configuration item, SQL clients are
|
|
||||||
# added to the global list.
|
|
||||||
#
|
|
||||||
# If there is a listener, and the first one does have a
|
|
||||||
# "clients=..." configuration item, SQL clients are added to
|
|
||||||
# that list. The client { ...} ` configured in that list are
|
|
||||||
# also added for that listener.
|
|
||||||
#
|
|
||||||
# The only issue is if you have multiple listeners in a
|
|
||||||
# virtual server, each with a different client list, then
|
|
||||||
# the SQL clients are added only to the first listener.
|
|
||||||
#
|
|
||||||
read_clients = $ENV{FREERADIUS_MODS_SQL_READ_CLIENTS}
|
|
||||||
|
|
||||||
# Table to keep radius client info
|
|
||||||
client_table = $ENV{FREERADIUS_MODS_SQL_TABLE_CLIENT}
|
|
||||||
|
|
||||||
#
|
|
||||||
# The group attribute specific to this instance of rlm_sql
|
|
||||||
#
|
|
||||||
|
|
||||||
# This entry should be used for additional instances (sql foo {})
|
|
||||||
# of the SQL module.
|
|
||||||
# group_attribute = "${.:instance}-SQL-Group"
|
|
||||||
|
|
||||||
# This entry should be used for the default instance (sql {})
|
|
||||||
# of the SQL module.
|
|
||||||
group_attribute = $ENV{FREERADIUS_MODS_SQL_GROUP_ATTRIBUTE}
|
|
||||||
|
|
||||||
# Read database-specific queries
|
|
||||||
$INCLUDE ${modconfdir}/${.:name}/main/${dialect}/queries.conf
|
|
||||||
}
|
|
||||||
@@ -1,110 +0,0 @@
|
|||||||
# Configuration for the SQL based IP Pool module (rlm_sqlippool)
|
|
||||||
#
|
|
||||||
# The database schemas are available at:
|
|
||||||
#
|
|
||||||
# raddb/mods-config/sql/ippool/<DB>/schema.sql
|
|
||||||
#
|
|
||||||
# $Id: f17a9898e906d3db0ad5871d8683f731f7a6baab $
|
|
||||||
|
|
||||||
sqlippool {
|
|
||||||
# SQL instance to use (from mods-available/sql)
|
|
||||||
#
|
|
||||||
# If you have multiple sql instances, such as "sql sql1 {...}",
|
|
||||||
# use the *instance* name here: sql1.
|
|
||||||
sql_module_instance = "sql"
|
|
||||||
|
|
||||||
# This is duplicative of info available in the SQL module, but
|
|
||||||
# we have to list it here as we do not yet support nested
|
|
||||||
# reference expansions.
|
|
||||||
dialect = $ENV{FREERADIUS_MODS_SQL_DIALECT}
|
|
||||||
|
|
||||||
# Name of the check item attribute to be used as a key in the SQL queries
|
|
||||||
pool_name = "Pool-Name"
|
|
||||||
|
|
||||||
# SQL table to use for ippool range and lease info
|
|
||||||
ippool_table = $ENV{FREERADIUS_MODS_SQL_TABLE_RADIPPOOL}
|
|
||||||
|
|
||||||
# IP lease duration. (Leases expire even if Acct Stop packet is lost)
|
|
||||||
#
|
|
||||||
# Note that you SHOULD also set Session-Timeout to this value!
|
|
||||||
# That way the NAS will automatically kick the user offline when the
|
|
||||||
# lease expires.
|
|
||||||
#
|
|
||||||
lease_duration = 18000
|
|
||||||
|
|
||||||
#
|
|
||||||
# Timeout between each consecutive 'allocate_clear' queries (default: 1s)
|
|
||||||
# This will avoid having too many deadlock issues, especially on MySQL backend.
|
|
||||||
#
|
|
||||||
allocate_clear_timeout = 1
|
|
||||||
|
|
||||||
#
|
|
||||||
# The attribute to use for IP address assignment. The
|
|
||||||
# default is Framed-IP-Address. You can change this to any
|
|
||||||
# attribute which is IPv4 or IPv6.
|
|
||||||
#
|
|
||||||
# e.g. Framed-IPv6-Prefix, or Delegated-IPv6-Prefix.
|
|
||||||
#
|
|
||||||
# All of the default queries use this attribute_name. So you
|
|
||||||
# can do IPv6 address assignment simply by putting IPv6
|
|
||||||
# addresses into the pool, and changing the following line to
|
|
||||||
# "Framed-IPv6-Prefix"
|
|
||||||
#
|
|
||||||
# Note that you MUST use separate pools for each attribute. i.e. one pool
|
|
||||||
# for Framed-IP-Address, a different one for Framed-IPv6-prefix, etc.
|
|
||||||
#
|
|
||||||
# This means configuring separate "sqlippool" instances, and different
|
|
||||||
# "ippool_table" in SQL. Then, populate the pool with addresses and
|
|
||||||
# it will all just work.
|
|
||||||
#
|
|
||||||
attribute_name = Framed-IP-Address
|
|
||||||
|
|
||||||
#
|
|
||||||
# Assign the IP address, even if the above attribute already exists
|
|
||||||
# in the reply.
|
|
||||||
#
|
|
||||||
# allow_duplicates = no
|
|
||||||
|
|
||||||
# The attribute in which an IP address hint may be supplied
|
|
||||||
req_attribute_name = Framed-IP-Address
|
|
||||||
|
|
||||||
# Attribute which should be considered unique per NAS
|
|
||||||
#
|
|
||||||
# Using NAS-Port gives behaviour similar to rlm_ippool. (And ACS)
|
|
||||||
# Using Calling-Station-Id works for NAS that send fixed NAS-Port
|
|
||||||
# ONLY change this if you know what you are doing!
|
|
||||||
# pool_key = "%{NAS-Port}"
|
|
||||||
# pool_key = "%{Calling-Station-Id}"
|
|
||||||
pool_key = "%{User-Name}"
|
|
||||||
nas_ip_address = "%{NAS-IP-Address}"
|
|
||||||
################################################################
|
|
||||||
#
|
|
||||||
# WARNING: MySQL (MyISAM) has certain limitations that means it can
|
|
||||||
# hand out the same IP address to 2 different users.
|
|
||||||
#
|
|
||||||
# We suggest using an SQL DB with proper transaction
|
|
||||||
# support, such as PostgreSQL, or using MySQL
|
|
||||||
# with InnoDB.
|
|
||||||
#
|
|
||||||
################################################################
|
|
||||||
|
|
||||||
# These messages are added to the "control" items, as
|
|
||||||
# Module-Success-Message. They are not logged anywhere else,
|
|
||||||
# unlike previous versions. If you want to have them logged
|
|
||||||
# to a file, see the "linelog" module, and create an entry
|
|
||||||
# which writes Module-Success-Message message.
|
|
||||||
#
|
|
||||||
messages {
|
|
||||||
exists = "Existing IP: %{reply:${..attribute_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
|
|
||||||
|
|
||||||
success = "Allocated IP: %{reply:${..attribute_name}} from %{control:${..pool_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
|
|
||||||
|
|
||||||
clear = "Released IP %{request:${..attribute_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} user %{User-Name})"
|
|
||||||
|
|
||||||
failed = "IP Allocation FAILED from %{control:${..pool_name}} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
|
|
||||||
|
|
||||||
nopool = "No ${..pool_name} defined (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
|
|
||||||
}
|
|
||||||
|
|
||||||
$INCLUDE ${modconfdir}/sql/ippool/${dialect}/queries.conf
|
|
||||||
}
|
|
||||||
@@ -1,694 +0,0 @@
|
|||||||
# -*- text -*-
|
|
||||||
#
|
|
||||||
# main/mysql/queries.conf-- MySQL configuration for default schema (schema.sql)
|
|
||||||
#
|
|
||||||
# $Id: b31ae9c3a1bf41f030a2112d31bf3a678e76f23c $
|
|
||||||
|
|
||||||
# Use the driver specific SQL escape method.
|
|
||||||
#
|
|
||||||
# If you enable this configuration item, the "safe_characters"
|
|
||||||
# configuration is ignored. FreeRADIUS then uses the MySQL escape
|
|
||||||
# functions to escape input strings. The only downside to making this
|
|
||||||
# change is that the MySQL escaping method is not the same the one
|
|
||||||
# used by FreeRADIUS. So characters which are NOT in the
|
|
||||||
# "safe_characters" list will now be stored differently in the database.
|
|
||||||
#
|
|
||||||
#auto_escape = yes
|
|
||||||
|
|
||||||
# Safe characters list for sql queries. Everything else is replaced
|
|
||||||
# with their mime-encoded equivalents.
|
|
||||||
# The default list should be ok
|
|
||||||
# Using 'auto_escape' is preferred
|
|
||||||
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# Connection config
|
|
||||||
#######################################################################
|
|
||||||
# The character set is not configurable. The default character set of
|
|
||||||
# the mysql client library is used. To control the character set,
|
|
||||||
# create/edit my.cnf (typically in /etc/mysql/my.cnf or /etc/my.cnf)
|
|
||||||
# and enter
|
|
||||||
# [freeradius]
|
|
||||||
# default-character-set = utf8
|
|
||||||
#
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# Query config: Username
|
|
||||||
#######################################################################
|
|
||||||
# This is the username that will get substituted, escaped, and added
|
|
||||||
# as attribute 'SQL-User-Name'. '%{SQL-User-Name}' should be used below
|
|
||||||
# everywhere a username substitution is needed so you you can be sure
|
|
||||||
# the username passed from the client is escaped properly.
|
|
||||||
#
|
|
||||||
# Uncomment the next line, if you want the sql_user_name to mean:
|
|
||||||
#
|
|
||||||
# Use Stripped-User-Name, if it's there.
|
|
||||||
# Else use User-Name, if it's there,
|
|
||||||
# Else use hard-coded string "DEFAULT" as the user name.
|
|
||||||
#sql_user_name = "%{%{Stripped-User-Name}:-%{%{User-Name}:-DEFAULT}}"
|
|
||||||
#
|
|
||||||
sql_user_name = "%{User-Name}"
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# Query config: Event-Timestamp
|
|
||||||
#######################################################################
|
|
||||||
# event_timestamp_epoch is the basis for the time inserted into
|
|
||||||
# accounting records. Typically this will be the Event-Timestamp of the
|
|
||||||
# accounting request, which is usually provided by a NAS.
|
|
||||||
#
|
|
||||||
# Uncomment the next line, if you want the timestamp to be based on the
|
|
||||||
# request reception time recorded by this server, for example if you
|
|
||||||
# distrust the provided Event-Timestamp.
|
|
||||||
#event_timestamp_epoch = "%l"
|
|
||||||
|
|
||||||
event_timestamp_epoch = "%{%{integer:Event-Timestamp}:-%l}"
|
|
||||||
|
|
||||||
# event_timestamp is the SQL snippet for converting an epoch timestamp
|
|
||||||
# to an SQL date.
|
|
||||||
|
|
||||||
event_timestamp = "FROM_UNIXTIME(${event_timestamp_epoch})"
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# Query config: Class attribute
|
|
||||||
#######################################################################
|
|
||||||
#
|
|
||||||
# 3.0.22 and later have a "class" column in the accounting table.
|
|
||||||
#
|
|
||||||
# However, we do NOT want to break existing configurations by adding
|
|
||||||
# the Class attribute to the default queries. If we did that, then
|
|
||||||
# systems using newer versions of the server would fail, because
|
|
||||||
# there is no "class" column in their accounting tables.
|
|
||||||
#
|
|
||||||
# The solution to that is the following "class" subsection. If your
|
|
||||||
# database has a "class" column for the various tables, then you can
|
|
||||||
# uncomment the configuration items here. The queries below will
|
|
||||||
# then automatically insert the Class attribute into radacct,
|
|
||||||
# radpostauth, etc.
|
|
||||||
#
|
|
||||||
class {
|
|
||||||
#
|
|
||||||
# Delete the '#' character from each of the configuration
|
|
||||||
# items in this section. This change puts the Class
|
|
||||||
# attribute into the various tables. Leave the double-quoted
|
|
||||||
# string there, as the value for the configuration item.
|
|
||||||
#
|
|
||||||
# See also policy.d/accounting, and the "insert_acct_class"
|
|
||||||
# policy. You will need to list (or uncomment)
|
|
||||||
# "insert_acct_class" in the "post-auth" section in order to
|
|
||||||
# create a Class attribute.
|
|
||||||
#
|
|
||||||
column_name = # ", class"
|
|
||||||
packet_xlat = # ", '%{Class}'"
|
|
||||||
reply_xlat = # ", '%{reply:Class}'"
|
|
||||||
}
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# Default profile
|
|
||||||
#######################################################################
|
|
||||||
# This is the default profile. It is found in SQL by group membership.
|
|
||||||
# That means that this profile must be a member of at least one group
|
|
||||||
# which will contain the corresponding check and reply items.
|
|
||||||
# This profile will be queried in the authorize section for every user.
|
|
||||||
# The point is to assign all users a default profile without having to
|
|
||||||
# manually add each one to a group that will contain the profile.
|
|
||||||
# The SQL module will also honor the User-Profile attribute. This
|
|
||||||
# attribute can be set anywhere in the authorize section (ie the users
|
|
||||||
# file). It is found exactly as the default profile is found.
|
|
||||||
# If it is set then it will *overwrite* the default profile setting.
|
|
||||||
# The idea is to select profiles based on checks on the incoming packets,
|
|
||||||
# not on user group membership. For example:
|
|
||||||
# -- users file --
|
|
||||||
# DEFAULT Service-Type == Outbound-User, User-Profile := "outbound"
|
|
||||||
# DEFAULT Service-Type == Framed-User, User-Profile := "framed"
|
|
||||||
#
|
|
||||||
# By default the default_user_profile is not set
|
|
||||||
#
|
|
||||||
#default_user_profile = "DEFAULT"
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# NAS Query
|
|
||||||
#######################################################################
|
|
||||||
# This query retrieves the radius clients
|
|
||||||
#
|
|
||||||
# 0. Row ID (currently unused)
|
|
||||||
# 1. Name (or IP address)
|
|
||||||
# 2. Shortname
|
|
||||||
# 3. Type
|
|
||||||
# 4. Secret
|
|
||||||
# 5. Server
|
|
||||||
#######################################################################
|
|
||||||
|
|
||||||
client_query = "\
|
|
||||||
SELECT id, nasname, shortname, type, secret, server \
|
|
||||||
FROM ${client_table}"
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# Authorization Queries
|
|
||||||
#######################################################################
|
|
||||||
# These queries compare the check items for the user
|
|
||||||
# in ${authcheck_table} and setup the reply items in
|
|
||||||
# ${authreply_table}. You can use any query/tables
|
|
||||||
# you want, but the return data for each row MUST
|
|
||||||
# be in the following order:
|
|
||||||
#
|
|
||||||
# 0. Row ID (currently unused)
|
|
||||||
# 1. UserName/GroupName
|
|
||||||
# 2. Item Attr Name
|
|
||||||
# 3. Item Attr Value
|
|
||||||
# 4. Item Attr Operation
|
|
||||||
#######################################################################
|
|
||||||
# Use these for case sensitive usernames.
|
|
||||||
|
|
||||||
#authorize_check_query = "\
|
|
||||||
# SELECT id, username, attribute, value, op \
|
|
||||||
# FROM ${authcheck_table} \
|
|
||||||
# WHERE username = BINARY '%{SQL-User-Name}' \
|
|
||||||
# ORDER BY id"
|
|
||||||
|
|
||||||
#authorize_reply_query = "\
|
|
||||||
# SELECT id, username, attribute, value, op \
|
|
||||||
# FROM ${authreply_table} \
|
|
||||||
# WHERE username = BINARY '%{SQL-User-Name}' \
|
|
||||||
# ORDER BY id"
|
|
||||||
|
|
||||||
#
|
|
||||||
# The default queries are case insensitive. (for compatibility with
|
|
||||||
# older versions of FreeRADIUS)
|
|
||||||
#
|
|
||||||
authorize_check_query = "\
|
|
||||||
SELECT id, username, attribute, value, op \
|
|
||||||
FROM ${authcheck_table} \
|
|
||||||
WHERE username = '%{SQL-User-Name}' \
|
|
||||||
ORDER BY id"
|
|
||||||
|
|
||||||
authorize_reply_query = "\
|
|
||||||
SELECT id, username, attribute, value, op \
|
|
||||||
FROM ${authreply_table} \
|
|
||||||
WHERE username = '%{SQL-User-Name}' \
|
|
||||||
ORDER BY id"
|
|
||||||
|
|
||||||
#
|
|
||||||
# Use these for case sensitive usernames.
|
|
||||||
#
|
|
||||||
#group_membership_query = "\
|
|
||||||
# SELECT groupname \
|
|
||||||
# FROM ${usergroup_table} \
|
|
||||||
# WHERE username = BINARY '%{SQL-User-Name}' \
|
|
||||||
# ORDER BY priority"
|
|
||||||
|
|
||||||
group_membership_query = "\
|
|
||||||
SELECT groupname \
|
|
||||||
FROM ${usergroup_table} \
|
|
||||||
WHERE username = '%{SQL-User-Name}' \
|
|
||||||
ORDER BY priority"
|
|
||||||
|
|
||||||
authorize_group_check_query = "\
|
|
||||||
SELECT id, groupname, attribute, \
|
|
||||||
Value, op \
|
|
||||||
FROM ${groupcheck_table} \
|
|
||||||
WHERE groupname = '%{${group_attribute}}' \
|
|
||||||
ORDER BY id"
|
|
||||||
|
|
||||||
authorize_group_reply_query = "\
|
|
||||||
SELECT id, groupname, attribute, \
|
|
||||||
value, op \
|
|
||||||
FROM ${groupreply_table} \
|
|
||||||
WHERE groupname = '%{${group_attribute}}' \
|
|
||||||
ORDER BY id"
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# Simultaneous Use Checking Queries
|
|
||||||
#######################################################################
|
|
||||||
# simul_count_query - query for the number of current connections
|
|
||||||
# - If this is not defined, no simultaneous use checking
|
|
||||||
# - will be performed by this module instance
|
|
||||||
# simul_verify_query - query to return details of current connections
|
|
||||||
# for verification
|
|
||||||
# - Leave blank or commented out to disable verification step
|
|
||||||
# - Note that the returned field order should not be changed.
|
|
||||||
#
|
|
||||||
# Note: Sessions that started prior to the most recent reload of their NAS will
|
|
||||||
# be correctly considered inactive, even if the radacct entry itself is not
|
|
||||||
# marked as stopped.
|
|
||||||
#
|
|
||||||
#######################################################################
|
|
||||||
|
|
||||||
simul_count_query = "\
|
|
||||||
SELECT COUNT(*) \
|
|
||||||
FROM ${acct_table1} a \
|
|
||||||
LEFT OUTER JOIN nasreload n USING (nasipaddress) \
|
|
||||||
WHERE username = '%{SQL-User-Name}' \
|
|
||||||
AND acctstoptime IS NULL \
|
|
||||||
AND (a.acctstarttime > n.reloadtime OR n.reloadtime IS NULL)"
|
|
||||||
|
|
||||||
simul_verify_query = "\
|
|
||||||
SELECT \
|
|
||||||
radacctid, acctsessionid, username, nasipaddress, nasportid, framedipaddress, \
|
|
||||||
callingstationid, framedprotocol \
|
|
||||||
FROM ${acct_table1} a \
|
|
||||||
LEFT OUTER JOIN nasreload n USING (nasipaddress) \
|
|
||||||
WHERE username = '%{SQL-User-Name}' \
|
|
||||||
AND acctstoptime IS NULL \
|
|
||||||
AND (a.acctstarttime > n.reloadtime OR n.reloadtime IS NULL)"
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# Accounting and Post-Auth Queries
|
|
||||||
#######################################################################
|
|
||||||
# These queries insert/update accounting and authentication records.
|
|
||||||
# The query to use is determined by the value of 'reference'.
|
|
||||||
# This value is used as a configuration path and should resolve to one
|
|
||||||
# or more 'query's. If reference points to multiple queries, and a query
|
|
||||||
# fails, the next query is executed.
|
|
||||||
#
|
|
||||||
# Behaviour is identical to the old 1.x/2.x module, except we can now
|
|
||||||
# fail between N queries, and query selection can be based on any
|
|
||||||
# combination of attributes, or custom 'Acct-Status-Type' values.
|
|
||||||
#######################################################################
|
|
||||||
accounting {
|
|
||||||
reference = "%{tolower:type.%{%{Acct-Status-Type}:-%{Request-Processing-Stage}}.query}"
|
|
||||||
|
|
||||||
# Write SQL queries to a logfile. This is potentially useful for bulk inserts
|
|
||||||
# when used with the rlm_sql_null driver.
|
|
||||||
# logfile = ${logdir}/accounting.sql
|
|
||||||
|
|
||||||
column_list = "\
|
|
||||||
acctsessionid, acctuniqueid, username, \
|
|
||||||
realm, nasipaddress, nasportid, \
|
|
||||||
nasporttype, acctstarttime, acctupdatetime, \
|
|
||||||
acctstoptime, acctsessiontime, acctauthentic, \
|
|
||||||
connectinfo_start, connectinfo_stop, acctinputoctets, \
|
|
||||||
acctoutputoctets, calledstationid, callingstationid, \
|
|
||||||
acctterminatecause, servicetype, framedprotocol, \
|
|
||||||
framedipaddress, framedipv6address, framedipv6prefix, \
|
|
||||||
framedinterfaceid, delegatedipv6prefix ${..class.column_name}"
|
|
||||||
|
|
||||||
type {
|
|
||||||
accounting-on {
|
|
||||||
|
|
||||||
#
|
|
||||||
# "Bulk update" Accounting-On/Off strategy.
|
|
||||||
#
|
|
||||||
# Immediately terminate all sessions associated with a
|
|
||||||
# given NAS.
|
|
||||||
#
|
|
||||||
# Note: If a large number of sessions require closing
|
|
||||||
# then the bulk update may be take a long time to run
|
|
||||||
# and lock an excessive number of rows. See the
|
|
||||||
# strategy below for an alternative approach that does
|
|
||||||
# not touch the radacct session data.
|
|
||||||
#
|
|
||||||
query = "\
|
|
||||||
UPDATE ${....acct_table1} \
|
|
||||||
SET \
|
|
||||||
acctstoptime = ${....event_timestamp}, \
|
|
||||||
acctsessiontime = '${....event_timestamp_epoch}' \
|
|
||||||
- UNIX_TIMESTAMP(acctstarttime), \
|
|
||||||
acctterminatecause = '%{%{Acct-Terminate-Cause}:-NAS-Reboot}' \
|
|
||||||
WHERE acctstoptime IS NULL \
|
|
||||||
AND nasipaddress = '%{NAS-IP-Address}' \
|
|
||||||
AND acctstarttime <= ${....event_timestamp}"
|
|
||||||
|
|
||||||
#
|
|
||||||
# "Lightweight" Accounting-On/Off strategy.
|
|
||||||
#
|
|
||||||
# Record the reload time of the NAS and let the
|
|
||||||
# administrator actually close the sessions in radacct
|
|
||||||
# out-of-band, if desired.
|
|
||||||
#
|
|
||||||
# Implementation advice, together with a stored
|
|
||||||
# procedure for closing sessions and a view showing
|
|
||||||
# the effective stop time of each session is provided
|
|
||||||
# in process-radacct.sql.
|
|
||||||
#
|
|
||||||
# To enable this strategy, just change the previous
|
|
||||||
# query to "-query", and this one to "query". The
|
|
||||||
# previous one will be ignored, and this one will be
|
|
||||||
# enabled.
|
|
||||||
#
|
|
||||||
-query = "\
|
|
||||||
INSERT INTO nasreload \
|
|
||||||
SET \
|
|
||||||
nasipaddress = '%{NAS-IP-Address}', \
|
|
||||||
reloadtime = ${....event_timestamp} \
|
|
||||||
ON DUPLICATE KEY UPDATE reloadtime = ${....event_timestamp}"
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
accounting-off {
|
|
||||||
query = "${..accounting-on.query}"
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Implement the "sql_session_start" policy.
|
|
||||||
# See raddb/policy.d/accounting for more details.
|
|
||||||
#
|
|
||||||
# You also need to fix the other queries as
|
|
||||||
# documented below. Look for "sql_session_start".
|
|
||||||
#
|
|
||||||
post-auth {
|
|
||||||
query = "\
|
|
||||||
INSERT INTO ${....acct_table1} \
|
|
||||||
(${...column_list}) \
|
|
||||||
VALUES(\
|
|
||||||
'%{Acct-Session-Id}', \
|
|
||||||
'%{Acct-Unique-Session-Id}', \
|
|
||||||
'%{SQL-User-Name}', \
|
|
||||||
'%{Realm}', \
|
|
||||||
'%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}', \
|
|
||||||
NULLIF('%{%{NAS-Port-ID}:-%{NAS-Port}}', ''), \
|
|
||||||
'%{NAS-Port-Type}', \
|
|
||||||
${....event_timestamp}, \
|
|
||||||
${....event_timestamp}, \
|
|
||||||
NULL, \
|
|
||||||
0, \
|
|
||||||
'', \
|
|
||||||
'%{Connect-Info}', \
|
|
||||||
NULL, \
|
|
||||||
0, \
|
|
||||||
0, \
|
|
||||||
'%{Called-Station-Id}', \
|
|
||||||
'%{Calling-Station-Id}', \
|
|
||||||
'', \
|
|
||||||
'%{Service-Type}', \
|
|
||||||
NULL, \
|
|
||||||
'', \
|
|
||||||
'', \
|
|
||||||
'', \
|
|
||||||
'', \
|
|
||||||
'' \
|
|
||||||
${....class.packet_xlat})"
|
|
||||||
|
|
||||||
query = "\
|
|
||||||
UPDATE ${....acct_table1} SET \
|
|
||||||
AcctStartTime = ${....event_timestamp}, \
|
|
||||||
AcctUpdateTime = ${....event_timestamp}, \
|
|
||||||
ConnectInfo_start = '%{Connect-Info}', \
|
|
||||||
AcctSessionId = '%{Acct-Session-Id}' \
|
|
||||||
WHERE UserName = '%{SQL-User-Name}' \
|
|
||||||
AND NASIPAddress = '%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}' \
|
|
||||||
AND NASPortId = '%{%{NAS-Port-ID}:-%{NAS-Port}}' \
|
|
||||||
AND NASPortType = '%{NAS-Port-Type}' \
|
|
||||||
AND AcctStopTime IS NULL"
|
|
||||||
}
|
|
||||||
|
|
||||||
start {
|
|
||||||
#
|
|
||||||
# Insert a new record into the sessions table
|
|
||||||
#
|
|
||||||
query = "\
|
|
||||||
INSERT INTO ${....acct_table1} \
|
|
||||||
(${...column_list}) \
|
|
||||||
VALUES \
|
|
||||||
('%{Acct-Session-Id}', \
|
|
||||||
'%{Acct-Unique-Session-Id}', \
|
|
||||||
'%{SQL-User-Name}', \
|
|
||||||
'%{Realm}', \
|
|
||||||
'%{NAS-IP-Address}', \
|
|
||||||
'%{%{NAS-Port-ID}:-%{NAS-Port}}', \
|
|
||||||
'%{NAS-Port-Type}', \
|
|
||||||
${....event_timestamp}, \
|
|
||||||
${....event_timestamp}, \
|
|
||||||
NULL, \
|
|
||||||
'0', \
|
|
||||||
'%{Acct-Authentic}', \
|
|
||||||
'%{Connect-Info}', \
|
|
||||||
'', \
|
|
||||||
'0', \
|
|
||||||
'0', \
|
|
||||||
'%{Called-Station-Id}', \
|
|
||||||
'%{Calling-Station-Id}', \
|
|
||||||
'', \
|
|
||||||
'%{Service-Type}', \
|
|
||||||
'%{Framed-Protocol}', \
|
|
||||||
'%{Framed-IP-Address}', \
|
|
||||||
'%{Framed-IPv6-Address}', \
|
|
||||||
'%{Framed-IPv6-Prefix}', \
|
|
||||||
'%{Framed-Interface-Id}', \
|
|
||||||
'%{Delegated-IPv6-Prefix}' \
|
|
||||||
${....class.packet_xlat})"
|
|
||||||
|
|
||||||
#
|
|
||||||
# When using "sql_session_start", you should comment out
|
|
||||||
# the previous query, and enable this one.
|
|
||||||
#
|
|
||||||
# Just change the previous query to "-query",
|
|
||||||
# and this one to "query". The previous one
|
|
||||||
# will be ignored, and this one will be
|
|
||||||
# enabled.
|
|
||||||
#
|
|
||||||
-query = "\
|
|
||||||
UPDATE ${....acct_table1} \
|
|
||||||
SET \
|
|
||||||
AcctSessionId = '%{Acct-Session-Id}', \
|
|
||||||
AcctUniqueId = '%{Acct-Unique-Session-Id}', \
|
|
||||||
AcctAuthentic = '%{Acct-Authentic}', \
|
|
||||||
ConnectInfo_start = '%{Connect-Info}', \
|
|
||||||
ServiceType = '%{Service-Type}', \
|
|
||||||
FramedProtocol = '%{Framed-Protocol}', \
|
|
||||||
framedipaddress = '%{Framed-IP-Address}', \
|
|
||||||
framedipv6address = '%{Framed-IPv6-Address}', \
|
|
||||||
framedipv6prefix = '%{Framed-IPv6-Prefix}', \
|
|
||||||
framedinterfaceid = '%{Framed-Interface-Id}', \
|
|
||||||
delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', \
|
|
||||||
AcctStartTime = ${....event_timestamp}, \
|
|
||||||
AcctUpdateTime = ${....event_timestamp} \
|
|
||||||
WHERE UserName = '%{SQL-User-Name}' \
|
|
||||||
AND NASIPAddress = '%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}' \
|
|
||||||
AND NASPortId = '%{%{NAS-Port-ID}:-%{NAS-Port}}' \
|
|
||||||
AND NASPortType = '%{NAS-Port-Type}' \
|
|
||||||
AND AcctStopTime IS NULL"
|
|
||||||
|
|
||||||
#
|
|
||||||
# Key constraints prevented us from inserting a new session,
|
|
||||||
# use the alternate query to update an existing session.
|
|
||||||
#
|
|
||||||
query = "\
|
|
||||||
UPDATE ${....acct_table1} SET \
|
|
||||||
acctstarttime = ${....event_timestamp}, \
|
|
||||||
acctupdatetime = ${....event_timestamp}, \
|
|
||||||
connectinfo_start = '%{Connect-Info}' \
|
|
||||||
WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'"
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
interim-update {
|
|
||||||
#
|
|
||||||
# Update an existing session and calculate the interval
|
|
||||||
# between the last data we received for the session and this
|
|
||||||
# update. This can be used to find stale sessions.
|
|
||||||
#
|
|
||||||
query = "\
|
|
||||||
UPDATE ${....acct_table1} \
|
|
||||||
SET \
|
|
||||||
acctupdatetime = (@acctupdatetime_old:=acctupdatetime), \
|
|
||||||
acctupdatetime = ${....event_timestamp}, \
|
|
||||||
acctinterval = ${....event_timestamp_epoch} - \
|
|
||||||
UNIX_TIMESTAMP(@acctupdatetime_old), \
|
|
||||||
framedipaddress = '%{Framed-IP-Address}', \
|
|
||||||
framedipv6address = '%{Framed-IPv6-Address}', \
|
|
||||||
framedipv6prefix = '%{Framed-IPv6-Prefix}', \
|
|
||||||
framedinterfaceid = '%{Framed-Interface-Id}', \
|
|
||||||
delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', \
|
|
||||||
acctsessiontime = %{%{Acct-Session-Time}:-NULL}, \
|
|
||||||
acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' \
|
|
||||||
<< 32 | '%{%{Acct-Input-Octets}:-0}', \
|
|
||||||
acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' \
|
|
||||||
<< 32 | '%{%{Acct-Output-Octets}:-0}' \
|
|
||||||
WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'"
|
|
||||||
|
|
||||||
#
|
|
||||||
# The update condition matched no existing sessions. Use
|
|
||||||
# the values provided in the update to create a new session.
|
|
||||||
#
|
|
||||||
query = "\
|
|
||||||
INSERT INTO ${....acct_table1} \
|
|
||||||
(${...column_list}) \
|
|
||||||
VALUES \
|
|
||||||
('%{Acct-Session-Id}', \
|
|
||||||
'%{Acct-Unique-Session-Id}', \
|
|
||||||
'%{SQL-User-Name}', \
|
|
||||||
'%{Realm}', \
|
|
||||||
'%{NAS-IP-Address}', \
|
|
||||||
'%{%{NAS-Port-ID}:-%{NAS-Port}}', \
|
|
||||||
'%{NAS-Port-Type}', \
|
|
||||||
FROM_UNIXTIME(${....event_timestamp_epoch} - %{%{Acct-Session-Time}:-0}), \
|
|
||||||
${....event_timestamp}, \
|
|
||||||
NULL, \
|
|
||||||
%{%{Acct-Session-Time}:-NULL}, \
|
|
||||||
'%{Acct-Authentic}', \
|
|
||||||
'%{Connect-Info}', \
|
|
||||||
'', \
|
|
||||||
'%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Input-Octets}:-0}', \
|
|
||||||
'%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Output-Octets}:-0}', \
|
|
||||||
'%{Called-Station-Id}', \
|
|
||||||
'%{Calling-Station-Id}', \
|
|
||||||
'', \
|
|
||||||
'%{Service-Type}', \
|
|
||||||
'%{Framed-Protocol}', \
|
|
||||||
'%{Framed-IP-Address}', \
|
|
||||||
'%{Framed-IPv6-Address}', \
|
|
||||||
'%{Framed-IPv6-Prefix}', \
|
|
||||||
'%{Framed-Interface-Id}', \
|
|
||||||
'%{Delegated-IPv6-Prefix}' \
|
|
||||||
${....class.packet_xlat})"
|
|
||||||
|
|
||||||
#
|
|
||||||
# When using "sql_session_start", you should comment out
|
|
||||||
# the previous query, and enable this one.
|
|
||||||
#
|
|
||||||
# Just change the previous query to "-query",
|
|
||||||
# and this one to "query". The previous one
|
|
||||||
# will be ignored, and this one will be
|
|
||||||
# enabled.
|
|
||||||
#
|
|
||||||
-query = "\
|
|
||||||
UPDATE ${....acct_table1} \
|
|
||||||
SET \
|
|
||||||
AcctSessionId = '%{Acct-Session-Id}', \
|
|
||||||
AcctUniqueId = '%{Acct-Unique-Session-Id}', \
|
|
||||||
AcctAuthentic = '%{Acct-Authentic}', \
|
|
||||||
ConnectInfo_start = '%{Connect-Info}', \
|
|
||||||
ServiceType = '%{Service-Type}', \
|
|
||||||
FramedProtocol = '%{Framed-Protocol}', \
|
|
||||||
framedipaddress = '%{Framed-IP-Address}', \
|
|
||||||
framedipv6address = '%{Framed-IPv6-Address}', \
|
|
||||||
framedipv6prefix = '%{Framed-IPv6-Prefix}', \
|
|
||||||
framedinterfaceid = '%{Framed-Interface-Id}', \
|
|
||||||
delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', \
|
|
||||||
AcctUpdateTime = ${....event_timestamp}, \
|
|
||||||
AcctSessionTime = %{%{Acct-Session-Time}:-NULL}, \
|
|
||||||
AcctInputOctets = '%{%{Acct-Input-Gigawords}:-0}' \
|
|
||||||
<< 32 | '%{%{Acct-Input-Octets}:-0}', \
|
|
||||||
AcctOutputOctets = '%{%{Acct-Output-Gigawords}:-0}' \
|
|
||||||
<< 32 | '%{%{Acct-Output-Octets}:-0}' \
|
|
||||||
WHERE UserName = '%{SQL-User-Name}' \
|
|
||||||
AND NASIPAddress = '%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}' \
|
|
||||||
AND NASPortId = '%{%{NAS-Port-ID}:-%{NAS-Port}}' \
|
|
||||||
AND NASPortType = '%{NAS-Port-Type}' \
|
|
||||||
AND AcctStopTime IS NULL"
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
stop {
|
|
||||||
#
|
|
||||||
# Session has terminated, update the stop time and statistics.
|
|
||||||
#
|
|
||||||
query = "\
|
|
||||||
UPDATE ${....acct_table2} SET \
|
|
||||||
acctstoptime = ${....event_timestamp}, \
|
|
||||||
acctsessiontime = %{%{Acct-Session-Time}:-NULL}, \
|
|
||||||
acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' \
|
|
||||||
<< 32 | '%{%{Acct-Input-Octets}:-0}', \
|
|
||||||
acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' \
|
|
||||||
<< 32 | '%{%{Acct-Output-Octets}:-0}', \
|
|
||||||
acctterminatecause = '%{Acct-Terminate-Cause}', \
|
|
||||||
connectinfo_stop = '%{Connect-Info}' \
|
|
||||||
WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'"
|
|
||||||
|
|
||||||
#
|
|
||||||
# The update condition matched no existing sessions. Use
|
|
||||||
# the values provided in the update to create a new session.
|
|
||||||
#
|
|
||||||
query = "\
|
|
||||||
INSERT INTO ${....acct_table2} \
|
|
||||||
(${...column_list}) \
|
|
||||||
VALUES \
|
|
||||||
('%{Acct-Session-Id}', \
|
|
||||||
'%{Acct-Unique-Session-Id}', \
|
|
||||||
'%{SQL-User-Name}', \
|
|
||||||
'%{Realm}', \
|
|
||||||
'%{NAS-IP-Address}', \
|
|
||||||
'%{%{NAS-Port-ID}:-%{NAS-Port}}', \
|
|
||||||
'%{NAS-Port-Type}', \
|
|
||||||
FROM_UNIXTIME(${....event_timestamp_epoch} - %{%{Acct-Session-Time}:-0}), \
|
|
||||||
${....event_timestamp}, \
|
|
||||||
${....event_timestamp}, \
|
|
||||||
%{%{Acct-Session-Time}:-NULL}, \
|
|
||||||
'%{Acct-Authentic}', \
|
|
||||||
'', \
|
|
||||||
'%{Connect-Info}', \
|
|
||||||
'%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Input-Octets}:-0}', \
|
|
||||||
'%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Output-Octets}:-0}', \
|
|
||||||
'%{Called-Station-Id}', \
|
|
||||||
'%{Calling-Station-Id}', \
|
|
||||||
'%{Acct-Terminate-Cause}', \
|
|
||||||
'%{Service-Type}', \
|
|
||||||
'%{Framed-Protocol}', \
|
|
||||||
'%{Framed-IP-Address}', \
|
|
||||||
'%{Framed-IPv6-Address}', \
|
|
||||||
'%{Framed-IPv6-Prefix}', \
|
|
||||||
'%{Framed-Interface-Id}', \
|
|
||||||
'%{Delegated-IPv6-Prefix}' \
|
|
||||||
${....class.packet_xlat})"
|
|
||||||
|
|
||||||
#
|
|
||||||
# When using "sql_session_start", you should comment out
|
|
||||||
# the previous query, and enable this one.
|
|
||||||
#
|
|
||||||
# Just change the previous query to "-query",
|
|
||||||
# and this one to "query". The previous one
|
|
||||||
# will be ignored, and this one will be
|
|
||||||
# enabled.
|
|
||||||
#
|
|
||||||
-query = "\
|
|
||||||
UPDATE ${....acct_table1} \
|
|
||||||
SET \
|
|
||||||
AcctSessionId = '%{Acct-Session-Id}', \
|
|
||||||
AcctUniqueId = '%{Acct-Unique-Session-Id}', \
|
|
||||||
AcctAuthentic = '%{Acct-Authentic}', \
|
|
||||||
ConnectInfo_start = '%{Connect-Info}', \
|
|
||||||
ServiceType = '%{Service-Type}', \
|
|
||||||
FramedProtocol = '%{Framed-Protocol}', \
|
|
||||||
framedipaddress = '%{Framed-IP-Address}', \
|
|
||||||
framedipv6address = '%{Framed-IPv6-Address}', \
|
|
||||||
framedipv6prefix = '%{Framed-IPv6-Prefix}', \
|
|
||||||
framedinterfaceid = '%{Framed-Interface-Id}', \
|
|
||||||
delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', \
|
|
||||||
AcctStopTime = ${....event_timestamp}, \
|
|
||||||
AcctUpdateTime = ${....event_timestamp}, \
|
|
||||||
AcctSessionTime = %{Acct-Session-Time}, \
|
|
||||||
AcctInputOctets = '%{%{Acct-Input-Gigawords}:-0}' \
|
|
||||||
<< 32 | '%{%{Acct-Input-Octets}:-0}', \
|
|
||||||
AcctOutputOctets = '%{%{Acct-Output-Gigawords}:-0}' \
|
|
||||||
<< 32 | '%{%{Acct-Output-Octets}:-0}', \
|
|
||||||
AcctTerminateCause = '%{Acct-Terminate-Cause}', \
|
|
||||||
ConnectInfo_stop = '%{Connect-Info}' \
|
|
||||||
WHERE UserName = '%{SQL-User-Name}' \
|
|
||||||
AND NASIPAddress = '%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}}' \
|
|
||||||
AND NASPortId = '%{%{NAS-Port-ID}:-%{NAS-Port}}' \
|
|
||||||
AND NASPortType = '%{NAS-Port-Type}' \
|
|
||||||
AND AcctStopTime IS NULL"
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# No Acct-Status-Type == ignore the packet
|
|
||||||
#
|
|
||||||
accounting {
|
|
||||||
query = "SELECT true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
#######################################################################
|
|
||||||
# Authentication Logging Queries
|
|
||||||
#######################################################################
|
|
||||||
# postauth_query - Insert some info after authentication
|
|
||||||
#######################################################################
|
|
||||||
|
|
||||||
post-auth {
|
|
||||||
# Write SQL queries to a logfile. This is potentially useful for bulk inserts
|
|
||||||
# when used with the rlm_sql_null driver.
|
|
||||||
# logfile = ${logdir}/post-auth.sql
|
|
||||||
|
|
||||||
query = "\
|
|
||||||
INSERT INTO ${..postauth_table} \
|
|
||||||
(username, reply, reason, authdate ${..class.column_name}) \
|
|
||||||
VALUES ( \
|
|
||||||
'%{SQL-User-Name}', \
|
|
||||||
'%{reply:Packet-Type}', \
|
|
||||||
'%{reply:Reply-Message}', \
|
|
||||||
'%S.%M' \
|
|
||||||
${..class.reply_xlat})"
|
|
||||||
}
|
|
||||||
@@ -1,211 +0,0 @@
|
|||||||
#
|
|
||||||
# Example of forbidding all attempts to login via
|
|
||||||
# realms.
|
|
||||||
#
|
|
||||||
deny_realms {
|
|
||||||
if (&User-Name && (&User-Name =~ /@|\\/)) {
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Filter the username
|
|
||||||
#
|
|
||||||
# Force some sanity on User-Name. This helps to avoid issues
|
|
||||||
# issues where the back-end database is "forgiving" about
|
|
||||||
# what constitutes a user name.
|
|
||||||
#
|
|
||||||
filter_username {
|
|
||||||
if (&User-Name) {
|
|
||||||
#
|
|
||||||
# reject mixed case e.g. "UseRNaMe"
|
|
||||||
#
|
|
||||||
#if (&User-Name != "%{tolower:%{User-Name}}") {
|
|
||||||
# reject
|
|
||||||
#}
|
|
||||||
|
|
||||||
#
|
|
||||||
# reject all whitespace
|
|
||||||
# e.g. "user@ site.com", or "us er", or " user", or "user "
|
|
||||||
#
|
|
||||||
if (&User-Name =~ / /) {
|
|
||||||
update request {
|
|
||||||
&Module-Failure-Message += 'Rejected: User-Name contains whitespace'
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# reject Multiple @'s
|
|
||||||
# e.g. "user@site.com@site.com"
|
|
||||||
#
|
|
||||||
if (&User-Name =~ /@[^@]*@/ ) {
|
|
||||||
update request {
|
|
||||||
&Module-Failure-Message += 'Rejected: Multiple @ in User-Name'
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# reject double dots
|
|
||||||
# e.g. "user@site..com"
|
|
||||||
#
|
|
||||||
if (&User-Name =~ /\.\./ ) {
|
|
||||||
update request {
|
|
||||||
&Module-Failure-Message += 'Rejected: User-Name contains multiple ..s'
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# must have at least 1 string-dot-string after @
|
|
||||||
# e.g. "user@site.com"
|
|
||||||
#
|
|
||||||
# if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
|
|
||||||
# update request {
|
|
||||||
# &Module-Failure-Message += 'Rejected: Realm does not have at least one dot separator'
|
|
||||||
# }
|
|
||||||
# reject
|
|
||||||
# }
|
|
||||||
|
|
||||||
#
|
|
||||||
# Realm ends with a dot
|
|
||||||
# e.g. "user@site.com."
|
|
||||||
#
|
|
||||||
if (&User-Name =~ /\.$/) {
|
|
||||||
update request {
|
|
||||||
&Module-Failure-Message += 'Rejected: Realm ends with a dot'
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Realm begins with a dot
|
|
||||||
# e.g. "user@.site.com"
|
|
||||||
#
|
|
||||||
if (&User-Name =~ /@\./) {
|
|
||||||
update request {
|
|
||||||
&Module-Failure-Message += 'Rejected: Realm begins with a dot'
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Filter the User-Password
|
|
||||||
#
|
|
||||||
# Some equipment sends passwords with embedded zeros.
|
|
||||||
# This policy filters them out.
|
|
||||||
#
|
|
||||||
filter_password {
|
|
||||||
if (&User-Password && \
|
|
||||||
(&User-Password != "%{string:User-Password}")) {
|
|
||||||
update request {
|
|
||||||
&Tmp-String-0 := "%{string:User-Password}"
|
|
||||||
&User-Password := "%{string:Tmp-String-0}"
|
|
||||||
&Tmp-String-0 !* ""
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
filter_inner_identity {
|
|
||||||
#
|
|
||||||
# No names, reject.
|
|
||||||
#
|
|
||||||
if (!&outer.request:User-Name || !&User-Name) {
|
|
||||||
update request {
|
|
||||||
Module-Failure-Message = "User-Name is required for tunneled authentication"
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Do detailed checks only if the inner and outer
|
|
||||||
# NAIs are different.
|
|
||||||
#
|
|
||||||
# If the NAIs are the same, it violates user privacy,
|
|
||||||
# but is allowed.
|
|
||||||
#
|
|
||||||
if (&outer.request:User-Name != &User-Name) {
|
|
||||||
#
|
|
||||||
# Get the outer realm.
|
|
||||||
#
|
|
||||||
if (&outer.request:User-Name =~ /@([^@]+)$/) {
|
|
||||||
update request {
|
|
||||||
Outer-Realm-Name = "%{1}"
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# When we have an outer realm name, the user portion
|
|
||||||
# MUST either be empty, or begin with "anon".
|
|
||||||
#
|
|
||||||
# We don't check for the full "anonymous", because
|
|
||||||
# some vendors don't follow the standards.
|
|
||||||
#
|
|
||||||
if (&outer.request:User-Name !~ /^(anon|@)/) {
|
|
||||||
update request {
|
|
||||||
Module-Failure-Message = "User-Name is not anonymized"
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# There's no outer realm. The outer NAI is different from the
|
|
||||||
# inner NAI. The User-Name MUST be anonymized.
|
|
||||||
#
|
|
||||||
# Otherwise, you could log in as outer "bob", and inner "doug",
|
|
||||||
# and we'd have no idea which one was correct.
|
|
||||||
#
|
|
||||||
elsif (&outer.request:User-Name !~ /^anon/) {
|
|
||||||
update request {
|
|
||||||
Module-Failure-Message = "User-Name is not anonymized"
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Get the inner realm.
|
|
||||||
#
|
|
||||||
if (&User-Name =~ /@([^@]+)$/) {
|
|
||||||
update request {
|
|
||||||
Inner-Realm-Name = "%{1}"
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Note that we do EQUALITY checks for realm names.
|
|
||||||
# There is no simple way to do case insensitive checks
|
|
||||||
# on internationalized domain names. There is no reason
|
|
||||||
# to allow outer "anonymous@EXAMPLE.COM" and inner
|
|
||||||
# "user@example.com". The user should enter the same
|
|
||||||
# realm for both identities.
|
|
||||||
#
|
|
||||||
# If the inner realm isn't the same as the outer realm,
|
|
||||||
# the inner realm MUST be a subdomain of the outer realm.
|
|
||||||
#
|
|
||||||
if (&Outer-Realm-Name && \
|
|
||||||
(&Inner-Realm-Name != &Outer-Realm-Name) && \
|
|
||||||
(&Inner-Realm-Name !~ /\.%{Outer-Realm-Name}$/)) {
|
|
||||||
update request {
|
|
||||||
Module-Failure-Message = "Inner realm '%{Inner-Realm-Name}' and outer realm '%{Outer-Realm-Name}' are not from the same domain."
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# It's OK to have an inner realm and no outer realm.
|
|
||||||
#
|
|
||||||
# That won't work for roaming, but the local RADIUS server
|
|
||||||
# can still authenticate the user.
|
|
||||||
#
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# It's OK to have an outer realm and no inner realm.
|
|
||||||
#
|
|
||||||
# It will work for roaming, and the local RADIUS server
|
|
||||||
# can authenticate the user without the realm.
|
|
||||||
#
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
vlan_test {
|
|
||||||
|
|
||||||
if (&User-Name =~ /.+@(.+)/) {
|
|
||||||
|
|
||||||
update control {
|
|
||||||
Tmp-String-0 := "%{1}"
|
|
||||||
}
|
|
||||||
|
|
||||||
update reply {
|
|
||||||
Tunnel-Type := VLAN
|
|
||||||
Tunnel-Medium-Type := IEEE-802
|
|
||||||
Tunnel-Private-Group-Id := "%{sql:SELECT vlan_id FROM tenant_subnets WHERE tenant_id='%{control:Tmp-String-0}'}"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
-1143
File diff suppressed because it is too large
Load Diff
@@ -1,184 +0,0 @@
|
|||||||
###########################################################################
|
|
||||||
# $Id: 41fcccad1c012226d12cc721518fe91e311e55e2 $ #
|
|
||||||
# #
|
|
||||||
# schema.sql rlm_sql - FreeRADIUS SQL Module #
|
|
||||||
# #
|
|
||||||
# Database schema for MySQL rlm_sql module #
|
|
||||||
# #
|
|
||||||
# To load: #
|
|
||||||
# mysql -uroot -prootpass radius < schema.sql #
|
|
||||||
# #
|
|
||||||
# Mike Machado <mike@innercite.com> #
|
|
||||||
###########################################################################
|
|
||||||
|
|
||||||
#
|
|
||||||
# Table structure for table 'radacct'
|
|
||||||
#
|
|
||||||
CREATE TABLE IF NOT EXISTS radacct (
|
|
||||||
radacctid bigint(21) NOT NULL auto_increment,
|
|
||||||
acctsessionid varchar(64) NOT NULL default '',
|
|
||||||
acctuniqueid varchar(32) NOT NULL default '',
|
|
||||||
username varchar(64) NOT NULL default '',
|
|
||||||
realm varchar(64) default '',
|
|
||||||
nasipaddress varchar(15) NOT NULL default '',
|
|
||||||
nasportid varchar(32) default NULL,
|
|
||||||
nasporttype varchar(32) default NULL,
|
|
||||||
acctstarttime datetime NULL default NULL,
|
|
||||||
acctupdatetime datetime NULL default NULL,
|
|
||||||
acctstoptime datetime NULL default NULL,
|
|
||||||
acctinterval int(12) default NULL,
|
|
||||||
acctsessiontime int(12) unsigned default NULL,
|
|
||||||
acctauthentic varchar(32) default NULL,
|
|
||||||
connectinfo_start varchar(128) default NULL,
|
|
||||||
connectinfo_stop varchar(128) default NULL,
|
|
||||||
acctinputoctets bigint(20) default NULL,
|
|
||||||
acctoutputoctets bigint(20) default NULL,
|
|
||||||
calledstationid varchar(50) NOT NULL default '',
|
|
||||||
callingstationid varchar(50) NOT NULL default '',
|
|
||||||
acctterminatecause varchar(32) NOT NULL default '',
|
|
||||||
servicetype varchar(32) default NULL,
|
|
||||||
framedprotocol varchar(32) default NULL,
|
|
||||||
framedipaddress varchar(15) NOT NULL default '',
|
|
||||||
framedipv6address varchar(45) NOT NULL default '',
|
|
||||||
framedipv6prefix varchar(45) NOT NULL default '',
|
|
||||||
framedinterfaceid varchar(44) NOT NULL default '',
|
|
||||||
delegatedipv6prefix varchar(45) NOT NULL default '',
|
|
||||||
class varchar(64) default NULL,
|
|
||||||
PRIMARY KEY (radacctid),
|
|
||||||
UNIQUE KEY acctuniqueid (acctuniqueid),
|
|
||||||
KEY username (username),
|
|
||||||
KEY framedipaddress (framedipaddress),
|
|
||||||
KEY framedipv6address (framedipv6address),
|
|
||||||
KEY framedipv6prefix (framedipv6prefix),
|
|
||||||
KEY framedinterfaceid (framedinterfaceid),
|
|
||||||
KEY delegatedipv6prefix (delegatedipv6prefix),
|
|
||||||
KEY acctsessionid (acctsessionid),
|
|
||||||
KEY acctsessiontime (acctsessiontime),
|
|
||||||
KEY acctstarttime (acctstarttime),
|
|
||||||
KEY acctinterval (acctinterval),
|
|
||||||
KEY acctstoptime (acctstoptime),
|
|
||||||
KEY nasipaddress (nasipaddress),
|
|
||||||
KEY class (class)
|
|
||||||
) ENGINE = INNODB;
|
|
||||||
|
|
||||||
#
|
|
||||||
# Table structure for table 'radcheck'
|
|
||||||
#
|
|
||||||
CREATE TABLE IF NOT EXISTS radcheck (
|
|
||||||
id int(11) unsigned NOT NULL auto_increment,
|
|
||||||
username varchar(64) NOT NULL default '',
|
|
||||||
attribute varchar(64) NOT NULL default '',
|
|
||||||
op char(2) NOT NULL DEFAULT '==',
|
|
||||||
value varchar(253) NOT NULL default '',
|
|
||||||
PRIMARY KEY (id),
|
|
||||||
KEY username (username(32))
|
|
||||||
) ENGINE = INNODB;
|
|
||||||
|
|
||||||
#
|
|
||||||
# Table structure for table 'radgroupcheck'
|
|
||||||
#
|
|
||||||
CREATE TABLE IF NOT EXISTS radgroupcheck (
|
|
||||||
id int(11) unsigned NOT NULL auto_increment,
|
|
||||||
groupname varchar(64) NOT NULL default '',
|
|
||||||
attribute varchar(64) NOT NULL default '',
|
|
||||||
op char(2) NOT NULL DEFAULT '==',
|
|
||||||
value varchar(253) NOT NULL default '',
|
|
||||||
PRIMARY KEY (id),
|
|
||||||
KEY groupname (groupname(32))
|
|
||||||
) ENGINE = INNODB;
|
|
||||||
|
|
||||||
#
|
|
||||||
# Table structure for table 'radgroupreply'
|
|
||||||
#
|
|
||||||
CREATE TABLE IF NOT EXISTS radgroupreply (
|
|
||||||
id int(11) unsigned NOT NULL auto_increment,
|
|
||||||
groupname varchar(64) NOT NULL default '',
|
|
||||||
attribute varchar(64) NOT NULL default '',
|
|
||||||
op char(2) NOT NULL DEFAULT '=',
|
|
||||||
value varchar(253) NOT NULL default '',
|
|
||||||
PRIMARY KEY (id),
|
|
||||||
KEY groupname (groupname(32))
|
|
||||||
) ENGINE = INNODB;
|
|
||||||
|
|
||||||
#
|
|
||||||
# Table structure for table 'radreply'
|
|
||||||
#
|
|
||||||
CREATE TABLE IF NOT EXISTS radreply (
|
|
||||||
id int(11) unsigned NOT NULL auto_increment,
|
|
||||||
username varchar(64) NOT NULL default '',
|
|
||||||
attribute varchar(64) NOT NULL default '',
|
|
||||||
op char(2) NOT NULL DEFAULT '=',
|
|
||||||
value varchar(253) NOT NULL default '',
|
|
||||||
PRIMARY KEY (id),
|
|
||||||
KEY username (username(32))
|
|
||||||
) ENGINE = INNODB;
|
|
||||||
|
|
||||||
|
|
||||||
#
|
|
||||||
# Table structure for table 'radusergroup'
|
|
||||||
#
|
|
||||||
CREATE TABLE IF NOT EXISTS `radusergroup` (
|
|
||||||
id int(11) unsigned NOT NULL auto_increment,
|
|
||||||
username varchar(64) NOT NULL default '',
|
|
||||||
groupname varchar(64) NOT NULL default '',
|
|
||||||
priority int(11) NOT NULL default '1',
|
|
||||||
PRIMARY KEY (id),
|
|
||||||
KEY username (username(32))
|
|
||||||
) ENGINE = INNODB;
|
|
||||||
|
|
||||||
#
|
|
||||||
# Table structure for table 'radpostauth'
|
|
||||||
#
|
|
||||||
# Note: MySQL versions since 5.6.4 support fractional precision timestamps
|
|
||||||
# which we use here. Replace the authdate definition with the following
|
|
||||||
# if your software is too old:
|
|
||||||
#
|
|
||||||
# authdate timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
|
|
||||||
#
|
|
||||||
CREATE TABLE IF NOT EXISTS radpostauth (
|
|
||||||
id int(11) NOT NULL auto_increment,
|
|
||||||
username varchar(64) NOT NULL default '',
|
|
||||||
pass varchar(64) NOT NULL default '',
|
|
||||||
reply varchar(32) NOT NULL default '',
|
|
||||||
authdate timestamp(6) NOT NULL DEFAULT CURRENT_TIMESTAMP(6) ON UPDATE CURRENT_TIMESTAMP(6),
|
|
||||||
class varchar(64) default NULL,
|
|
||||||
PRIMARY KEY (id),
|
|
||||||
KEY username (username),
|
|
||||||
KEY class (class)
|
|
||||||
) ENGINE = INNODB;
|
|
||||||
|
|
||||||
#
|
|
||||||
# Table structure for table 'nas'
|
|
||||||
#
|
|
||||||
CREATE TABLE IF NOT EXISTS nas (
|
|
||||||
id int(10) NOT NULL auto_increment,
|
|
||||||
nasname varchar(128) NOT NULL,
|
|
||||||
shortname varchar(32),
|
|
||||||
type varchar(30) DEFAULT 'other',
|
|
||||||
ports int(5),
|
|
||||||
secret varchar(60) DEFAULT 'secret' NOT NULL,
|
|
||||||
server varchar(64),
|
|
||||||
community varchar(50),
|
|
||||||
description varchar(200) DEFAULT 'RADIUS Client',
|
|
||||||
PRIMARY KEY (id),
|
|
||||||
KEY nasname (nasname)
|
|
||||||
) ENGINE = INNODB;
|
|
||||||
|
|
||||||
#
|
|
||||||
# Table structure for table 'radippool'
|
|
||||||
#
|
|
||||||
CREATE TABLE IF NOT EXISTS radippool (
|
|
||||||
id int(11) unsigned NOT NULL auto_increment,
|
|
||||||
pool_name varchar(30) NOT NULL,
|
|
||||||
framedipaddress varchar(15) NOT NULL default '',
|
|
||||||
nasipaddress varchar(15) NOT NULL default '',
|
|
||||||
calledstationid VARCHAR(30) NOT NULL default '',
|
|
||||||
callingstationid VARCHAR(30) NOT NULL default '',
|
|
||||||
expiry_time DATETIME NOT NULL default NOW(),
|
|
||||||
username varchar(64) NOT NULL default '',
|
|
||||||
pool_key varchar(64) NOT NULL default '',
|
|
||||||
PRIMARY KEY (id),
|
|
||||||
KEY radippool_poolname_expire (pool_name, expiry_time),
|
|
||||||
UNIQUE KEY framedipaddress_unique (framedipaddress),
|
|
||||||
KEY radippool_nasip_poolkey_ipaddress (nasipaddress, pool_key, framedipaddress)
|
|
||||||
) ENGINE=InnoDB;
|
|
||||||
@@ -1,41 +0,0 @@
|
|||||||
# -*- text -*-
|
|
||||||
######################################################################
|
|
||||||
#
|
|
||||||
# Sample virtual server for receiving a CoA or Disconnect-Request packet.
|
|
||||||
#
|
|
||||||
|
|
||||||
# Listen on the CoA port.
|
|
||||||
#
|
|
||||||
# This uses the normal set of clients, with the same secret as for authentication and accounting.
|
|
||||||
#
|
|
||||||
|
|
||||||
listen {
|
|
||||||
type = coa
|
|
||||||
# ipaddr = $ENV{FREERADIUS_SITES_COA_LISTEN}
|
|
||||||
ipaddr = *
|
|
||||||
port = $ENV{FREERADIUS_SITES_COA_PORT}
|
|
||||||
virtual_server = coa
|
|
||||||
}
|
|
||||||
|
|
||||||
server coa {
|
|
||||||
# When a packet is received, it is processed through the recv-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
|
|
||||||
recv-coa {
|
|
||||||
# CoA && Disconnect packets can be proxied in the same way as authentication or accounting packets.
|
|
||||||
# Just set Proxy-To-Realm, or Home-Server-Pool, and the packets will be proxied.
|
|
||||||
|
|
||||||
# Do proxying based on realms here. You don't need "IPASS" or "ntdomain", as the proxying is based on the Operator-Name attribute. It contains the realm,
|
|
||||||
# and ONLY the realm (prefixed by a '1')
|
|
||||||
suffix
|
|
||||||
|
|
||||||
# Insert your own policies here.
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
|
|
||||||
# When a packet is sent, it is processed through the send-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
|
|
||||||
send-coa {
|
|
||||||
# Sample module.
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
|
|
||||||
# You can use pre-proxy and post-proxy sections here, too. They will be processed for sending && receiving proxy packets.
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,595 +0,0 @@
|
|||||||
# -*- text -*-
|
|
||||||
######################################################################
|
|
||||||
#
|
|
||||||
# This is a virtual server that handles DHCP.
|
|
||||||
#
|
|
||||||
# See raddb/mods-available/dhcp_sqlippool for the IP Pool configuration.
|
|
||||||
#
|
|
||||||
# See raddb/policy.d/dhcp_sqlippool for the "glue" code that allows
|
|
||||||
# the RADIUS based "sqlippool" module to be used for DHCP.
|
|
||||||
#
|
|
||||||
# See raddb/mods-config/sql/ippool/ for the schemas.
|
|
||||||
#
|
|
||||||
# See raddb/sites-available/dhcp for instructions on how to configure
|
|
||||||
# the DHCP server.
|
|
||||||
#
|
|
||||||
# $Id$
|
|
||||||
#
|
|
||||||
######################################################################
|
|
||||||
|
|
||||||
#
|
|
||||||
# The DHCP functionality goes into a virtual server.
|
|
||||||
#
|
|
||||||
server dhcp {
|
|
||||||
|
|
||||||
# Define a DHCP socket.
|
|
||||||
#
|
|
||||||
# The default port below is 6700, so you don't break your network.
|
|
||||||
# If you want it to do real DHCP, change this to 67, and good luck!
|
|
||||||
#
|
|
||||||
# You can also bind the DHCP socket to an interface.
|
|
||||||
# See below, and raddb/radiusd.conf for examples.
|
|
||||||
#
|
|
||||||
# This lets you run *one* DHCP server instance and have it listen on
|
|
||||||
# multiple interfaces, each with a separate policy.
|
|
||||||
#
|
|
||||||
# If you have multiple interfaces, it is a good idea to bind the
|
|
||||||
# listen section to an interface. You will also need one listen
|
|
||||||
# section per interface.
|
|
||||||
#
|
|
||||||
# FreeBSD does *not* support binding sockets to interfaces. Therefore,
|
|
||||||
# if you have multiple interfaces, broadcasts may go out of the wrong
|
|
||||||
# one, or even all interfaces. The solution is to use the "setfib" command.
|
|
||||||
# If you have a network "10.10.0/24" on LAN1, you will need to do:
|
|
||||||
#
|
|
||||||
# Pick any IP on the 10.10.0/24 network
|
|
||||||
# $ setfib 1 route add default 10.10.0.1
|
|
||||||
#
|
|
||||||
# Edit /etc/rc.local, and add a line:
|
|
||||||
# setfib 1 /path/to/radiusd
|
|
||||||
#
|
|
||||||
# The kern must be built with the following options:
|
|
||||||
# options ROUTETABLES=2
|
|
||||||
# or any value larger than 2.
|
|
||||||
#
|
|
||||||
# The other only solution is to update FreeRADIUS to use BPF sockets.
|
|
||||||
#
|
|
||||||
listen {
|
|
||||||
# This is a dhcp socket.
|
|
||||||
type = dhcp
|
|
||||||
|
|
||||||
# IP address to listen on. Will usually be the IP of the
|
|
||||||
# interface, or 0.0.0.0
|
|
||||||
ipaddr = 0.0.0.0
|
|
||||||
|
|
||||||
# source IP address for unicast packets sent by the
|
|
||||||
# DHCP server.
|
|
||||||
#
|
|
||||||
# The source IP for unicast packets is chosen from the first
|
|
||||||
# one of the following items which returns a valid IP
|
|
||||||
# address:
|
|
||||||
#
|
|
||||||
# src_ipaddr
|
|
||||||
# ipaddr
|
|
||||||
# reply:DHCP-Server-IP-Address
|
|
||||||
# reply:DHCP-DHCP-Server-Identifier
|
|
||||||
#
|
|
||||||
src_ipaddr = 127.0.0.1
|
|
||||||
|
|
||||||
# The port should be 67 for a production network. Don't set
|
|
||||||
# it to 67 on a production network unless you really know
|
|
||||||
# what you're doing. Even if nothing is configured below, the
|
|
||||||
# server may still NAK legitimate responses from clients.
|
|
||||||
port = 6700
|
|
||||||
|
|
||||||
# Interface name we are listening on. See comments above.
|
|
||||||
# interface = lo0
|
|
||||||
|
|
||||||
# The DHCP server defaults to allowing broadcast packets.
|
|
||||||
# Set this to "no" only when the server receives *all* packets
|
|
||||||
# from a relay agent. i.e. when *no* clients are on the same
|
|
||||||
# LAN as the DHCP server.
|
|
||||||
#
|
|
||||||
# It's set to "no" here for testing. It will usually want to
|
|
||||||
# be "yes" in production, unless you are only dealing with
|
|
||||||
# relayed packets.
|
|
||||||
broadcast = no
|
|
||||||
|
|
||||||
# On Linux if you're running the server as non-root, you
|
|
||||||
# will need to do:
|
|
||||||
#
|
|
||||||
# setcap cap_net_admin,cap_net_bind_service=eip /path/to/radiusd
|
|
||||||
#
|
|
||||||
# This will allow the server to set ARP table entries
|
|
||||||
# for newly allocated IPs, when run as the "radius" user.
|
|
||||||
#
|
|
||||||
# The above "setcap" command adds the capability to the program,
|
|
||||||
# usually so long as it is run by the "radius" user. Which means
|
|
||||||
# (oddly enough) that it no longer works when run as root!
|
|
||||||
#
|
|
||||||
# When running the server as root in debug mode, you can use:
|
|
||||||
#
|
|
||||||
# capsh --caps="cap_setpcap,cap_setuid,cap_setgid,cap_net_admin,cap_net_bind_service+eip" --keep=1 --user=radius --addamb=cap_net_admin,cap_net_bind_service -- -c "/path/to/radiusd -X"
|
|
||||||
#
|
|
||||||
# Or, simply "sudo" or "su" to the "radius" user, and then run
|
|
||||||
# the server in debug mode.
|
|
||||||
|
|
||||||
# De-duplicate DHCP packets. If clients don't receive
|
|
||||||
# a reply within their timeout, most will re-transmit.
|
|
||||||
# A reply to either packet will satisfy, so de-duplicating
|
|
||||||
# helps manage load on a busy server
|
|
||||||
performance {
|
|
||||||
skip_duplicate_checks = no
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# Packets received on the socket will be processed through one
|
|
||||||
# of the following sections, named after the DHCP packet type.
|
|
||||||
# See dictionary.dhcp for the packet types.
|
|
||||||
|
|
||||||
# Return packets will be sent to, in preference order:
|
|
||||||
# DHCP-Gateway-IP-Address
|
|
||||||
# DHCP-Client-IP-Address
|
|
||||||
# DHCP-Your-IP-Address
|
|
||||||
# At least one of these attributes should be set at the end of each
|
|
||||||
# section for a response to be sent.
|
|
||||||
|
|
||||||
# An internal attribute of DHCP-Network-Subnet is set to provide
|
|
||||||
# a basis for determining the network that a client belongs to. This
|
|
||||||
# is a hierarchical assignment based on:
|
|
||||||
#
|
|
||||||
# - DHCP-Relay-Link-Selection
|
|
||||||
# - DHCP-Subnet-Selection-Option
|
|
||||||
# - DHCP-Gateway-IP-Address
|
|
||||||
# - DHCP-Client-IP-Address
|
|
||||||
#
|
|
||||||
# Except for cases where all IP allocation is performed using a mapping from
|
|
||||||
# the device MAC address to a fixed IP address the DHCP configuration will
|
|
||||||
# involve the use of one or more pools.
|
|
||||||
#
|
|
||||||
# Each pool should be composed of a set of equally valid IP addresses for the
|
|
||||||
# devices designated as users of the pool. During IP allocation the choice of
|
|
||||||
# pool is driven by setting the Pool-Name attribute which may either be
|
|
||||||
# specified directly or chosen (usually with the help of the dhcp_network
|
|
||||||
# module) based on the initial value of DHCP-Network-Subnet.
|
|
||||||
#
|
|
||||||
# DHCP-Network-Subnet indicates the network from which the request is
|
|
||||||
# originating. In cases where the originating network alone is insufficent to
|
|
||||||
# define the required IP allocated policy, DHCP-Network-Subnet may be
|
|
||||||
# overridden to force the selection of a particular pool.
|
|
||||||
#
|
|
||||||
# IP addresses belonging to a single pool that is designated for a Layer 2
|
|
||||||
# network containing multiple subnets (a "shared-network" or "multinet"
|
|
||||||
# configuration as defined by some other DHCP servers), will by definition be
|
|
||||||
# members of distinct subnets that require their own DHCP reply parameters. In
|
|
||||||
# this case the dhcp_subnet policy can be used to set the correct
|
|
||||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address options
|
|
||||||
# based on the allocated IP.
|
|
||||||
|
|
||||||
dhcp DHCP-Discover {
|
|
||||||
|
|
||||||
# The DHCP Server Identifier is set here since is returned in OFFERs
|
|
||||||
update control {
|
|
||||||
&DHCP-DHCP-Server-Identifier = 192.0.2.2
|
|
||||||
}
|
|
||||||
|
|
||||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
|
||||||
dhcp_common
|
|
||||||
|
|
||||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
|
||||||
# Enable mods-available/dhcp_passwd to use this
|
|
||||||
#dhcp_group_membership
|
|
||||||
|
|
||||||
# If clients need to be assigned to a particular network based on
|
|
||||||
# an attribute in the packet rather than the calculated
|
|
||||||
# DHCP-Network-Subnet described above, then call a policy
|
|
||||||
# (defined in policy.d/dhcp) to perform the override
|
|
||||||
#dhcp_override_network
|
|
||||||
|
|
||||||
# Use a "files" module to lookup global and subnet options
|
|
||||||
# For multiple subnets use this in place of dhcp_common
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_network
|
|
||||||
|
|
||||||
# Do a simple mapping of MAC to assigned IP.
|
|
||||||
#
|
|
||||||
# See below for the definition of the "mac2ip"
|
|
||||||
# module.
|
|
||||||
#
|
|
||||||
#mac2ip
|
|
||||||
|
|
||||||
# Or, allocate IPs from the DHCP pool in SQL. You may need to
|
|
||||||
# set the pool name here if you haven't set it elsewhere.
|
|
||||||
#update control {
|
|
||||||
# &Pool-Name := "local"
|
|
||||||
#}
|
|
||||||
#dhcp_sqlippool
|
|
||||||
|
|
||||||
# If the IP address was not allocated, do something else.
|
|
||||||
# You could call a Perl, Python, or Java script here.
|
|
||||||
#if (notfound) {
|
|
||||||
# ...
|
|
||||||
#}
|
|
||||||
|
|
||||||
# "Shared-networks" may have multiple IP subnets co-existing in a
|
|
||||||
# single Layer 2 network. If the pool for the network contains
|
|
||||||
# addresses from more that one subnet then the setting subnet-specific
|
|
||||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
|
|
||||||
# parameters must be performed after the allocation of the IP address.
|
|
||||||
#
|
|
||||||
# Set any subnet-specific parameters using this policy.
|
|
||||||
#
|
|
||||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
|
||||||
# policy.d/dhcp to use this.
|
|
||||||
#
|
|
||||||
#dhcp_subnet
|
|
||||||
|
|
||||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_group_options
|
|
||||||
|
|
||||||
# Use a "files" module to lookup host specific options
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_hosts
|
|
||||||
|
|
||||||
# As an alternative or complement to configuration files based lookup
|
|
||||||
# for options data you can instead use an SQL database. Example
|
|
||||||
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
|
|
||||||
# will need to be adapted to your requirements.
|
|
||||||
#dhcp_policy_sql
|
|
||||||
|
|
||||||
# Set the type of packet to send in reply.
|
|
||||||
#
|
|
||||||
# The server will look at the DHCP-Message-Type attribute to
|
|
||||||
# determine which type of packet to send in reply. Common
|
|
||||||
# values would be DHCP-Offer, DHCP-Ack or DHCP-NAK. See
|
|
||||||
# dictionary.dhcp for all the possible values.
|
|
||||||
#
|
|
||||||
# DHCP-Do-Not-Respond can be used to tell the server to not
|
|
||||||
# respond.
|
|
||||||
#
|
|
||||||
# In the event that DHCP-Message-Type is not set then the
|
|
||||||
# server will fall back to determining the type of reply
|
|
||||||
# based on the rcode of this section.
|
|
||||||
#
|
|
||||||
#update reply {
|
|
||||||
# DHCP-Message-Type = DHCP-Offer
|
|
||||||
#}
|
|
||||||
#
|
|
||||||
# If DHCP-Message-Type is not set, returning "ok" or
|
|
||||||
# "updated" from this section will respond with a DHCP-Offer
|
|
||||||
# message.
|
|
||||||
#
|
|
||||||
# Other rcodes will tell the server to not return any response.
|
|
||||||
#
|
|
||||||
#ok
|
|
||||||
}
|
|
||||||
|
|
||||||
dhcp DHCP-Request {
|
|
||||||
|
|
||||||
# You must set the DHCP Server Identifier here since this is returned
|
|
||||||
# in ACKs and is used to determine whether a request containing a
|
|
||||||
# "server-ip" field is intended for this server
|
|
||||||
update control {
|
|
||||||
&DHCP-DHCP-Server-Identifier = 192.0.2.2
|
|
||||||
}
|
|
||||||
|
|
||||||
# If the request is not for this server then silently discard it
|
|
||||||
if (&request:DHCP-DHCP-Server-Identifier && \
|
|
||||||
&request:DHCP-DHCP-Server-Identifier != &control:DHCP-DHCP-Server-Identifier) {
|
|
||||||
do_not_respond
|
|
||||||
}
|
|
||||||
|
|
||||||
# Response packet type. See DHCP-Discover section above.
|
|
||||||
#update reply {
|
|
||||||
# &DHCP-Message-Type = DHCP-Ack
|
|
||||||
#}
|
|
||||||
|
|
||||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
|
||||||
dhcp_common
|
|
||||||
|
|
||||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
|
||||||
# Enable mods-available/dhcp_passwd to use this
|
|
||||||
#dhcp_group_membership
|
|
||||||
|
|
||||||
# Optionally override the network address based on client attributes
|
|
||||||
# See Discover section
|
|
||||||
#dhcp_override_network
|
|
||||||
|
|
||||||
# Use a "files" module to lookup global and subnet options
|
|
||||||
# For multiple subnets use this in place of dhcp_common
|
|
||||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
|
||||||
# policy.d/dhcp to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_network
|
|
||||||
|
|
||||||
# Do a simple mapping of MAC to assigned IP.
|
|
||||||
#
|
|
||||||
# See below for the definition of the "mac2ip"
|
|
||||||
# module.
|
|
||||||
#
|
|
||||||
#mac2ip
|
|
||||||
|
|
||||||
# Or, allocate IPs from the DHCP pool in SQL. You may need to
|
|
||||||
# set the pool name here if you haven't set it elsewhere.
|
|
||||||
# update control {
|
|
||||||
# &Pool-Name := "local"
|
|
||||||
# }
|
|
||||||
# dhcp_sqlippool_request
|
|
||||||
|
|
||||||
# If the IP was not allocated, do something else.
|
|
||||||
# You could call a Perl, Python, or Java script here.
|
|
||||||
#if (notfound) {
|
|
||||||
# ...
|
|
||||||
#}
|
|
||||||
|
|
||||||
# "Shared-networks" may have multiple IP subnets co-existing in a
|
|
||||||
# single Layer 2 network. If the pool for the network contains
|
|
||||||
# addresses from more that one subnet then the setting subnet-specific
|
|
||||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
|
|
||||||
# parameters must be performed after the allocation of the IP address.
|
|
||||||
#
|
|
||||||
# Set any subnet-specific parameters using this policy.
|
|
||||||
#
|
|
||||||
#dhcp_subnet
|
|
||||||
|
|
||||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_group_options
|
|
||||||
|
|
||||||
# Use a "files" module to lookup host specific options
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_hosts
|
|
||||||
|
|
||||||
# As an alternative or complement to configuration files based lookup
|
|
||||||
# for options data you can instead use an SQL database. Example
|
|
||||||
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
|
|
||||||
# will need to be adapted to your requirements.
|
|
||||||
#dhcp_policy_sql
|
|
||||||
|
|
||||||
# If DHCP-Message-Type is not set, returning "ok" or
|
|
||||||
# "updated" from this section will respond with a DHCP-Ack
|
|
||||||
# packet.
|
|
||||||
#
|
|
||||||
# "handled" will not return a packet, all other rcodes will
|
|
||||||
# send back a DHCP-NAK.
|
|
||||||
#
|
|
||||||
#ok
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Other DHCP packet types
|
|
||||||
#
|
|
||||||
# There should be a separate section for each DHCP message type.
|
|
||||||
# By default this configuration will ignore them all. Any packet type
|
|
||||||
# not defined here will be responded to with a DHCP-NAK.
|
|
||||||
|
|
||||||
dhcp DHCP-Decline {
|
|
||||||
|
|
||||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
|
||||||
# Enable mods-available/dhcp_passwd to use this
|
|
||||||
#dhcp_group_membership
|
|
||||||
|
|
||||||
# Optionally override the network address based on client attributes
|
|
||||||
# See Discover section
|
|
||||||
#dhcp_override_network
|
|
||||||
|
|
||||||
# Use a "files" module to lookup global and subnet options
|
|
||||||
# For multiple networks use this in place of dhcp_common
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_network
|
|
||||||
|
|
||||||
# Use a policy that set options from data stored in an SQL database
|
|
||||||
#dhcp_policy_sql
|
|
||||||
|
|
||||||
# If using IPs from a DHCP pool in SQL then you may need to set the
|
|
||||||
# pool name here if you haven't set it elsewhere and release the IP.
|
|
||||||
# update control {
|
|
||||||
# &Pool-Name := "local"
|
|
||||||
# }
|
|
||||||
# dhcp_sqlippool_decline
|
|
||||||
|
|
||||||
update reply {
|
|
||||||
&DHCP-Message-Type = DHCP-Do-Not-Respond
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# A dummy config for Inform packets - this should match the
|
|
||||||
# options set in the Request section above, except Inform replies
|
|
||||||
# must not set Your-IP-Address or IP-Address-Lease-Time
|
|
||||||
#
|
|
||||||
dhcp DHCP-Inform {
|
|
||||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
|
||||||
dhcp_common
|
|
||||||
|
|
||||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
|
||||||
# Enable mods-available/dhcp_passwd to use this
|
|
||||||
#dhcp_group_membership
|
|
||||||
|
|
||||||
# Optionally override the network address based on client attributes
|
|
||||||
# See Discover section
|
|
||||||
#dhcp_override_network
|
|
||||||
|
|
||||||
# Use a "files" module to lookup global and network options
|
|
||||||
# For multiple networks use this in place of dhcp_common
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_network
|
|
||||||
|
|
||||||
# Use a policy with calls a "files" module of the same name to lookup
|
|
||||||
# subnet options
|
|
||||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
|
||||||
# policy.d/dhcp to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_subnet
|
|
||||||
|
|
||||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_group_options
|
|
||||||
|
|
||||||
# Use a "files" module to lookup host specific options
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_hosts
|
|
||||||
|
|
||||||
# Use a policy that set options from data stored in an SQL database
|
|
||||||
#dhcp_policy_sql
|
|
||||||
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# For Windows 7 boxes
|
|
||||||
#
|
|
||||||
#dhcp DHCP-Inform {
|
|
||||||
# update reply {
|
|
||||||
# Packet-Dst-Port = 67
|
|
||||||
# DHCP-Message-Type = DHCP-ACK
|
|
||||||
# DHCP-DHCP-Server-Identifier = "%{Packet-Dst-IP-Address}"
|
|
||||||
# DHCP-Site-specific-28 = 0x0a00
|
|
||||||
# }
|
|
||||||
# ok
|
|
||||||
#}
|
|
||||||
|
|
||||||
dhcp DHCP-Release {
|
|
||||||
|
|
||||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
|
||||||
# Enable mods-available/dhcp_passwd to use this
|
|
||||||
#dhcp_group_membership
|
|
||||||
|
|
||||||
# Optionally override the network address based on client attributes
|
|
||||||
# See Discover section
|
|
||||||
#dhcp_override_network
|
|
||||||
|
|
||||||
# Use a "files" module to lookup global and subnet options
|
|
||||||
# For multiple subnets use this in place of dhcp_common
|
|
||||||
# Enable mods-available/dhcp_files to use this
|
|
||||||
# Options are set in mods-config/files/dhcp
|
|
||||||
#dhcp_network
|
|
||||||
|
|
||||||
# If using IPs from a DHCP pool in SQL then you may need to set the
|
|
||||||
# pool name here if you haven't set it elsewhere and release the IP.
|
|
||||||
# update control {
|
|
||||||
# &Pool-Name := "local"
|
|
||||||
# }
|
|
||||||
# dhcp_sqlippool_release
|
|
||||||
|
|
||||||
update reply {
|
|
||||||
&DHCP-Message-Type = DHCP-Do-Not-Respond
|
|
||||||
}
|
|
||||||
reject
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
dhcp DHCP-Lease-Query {
|
|
||||||
# The thing being queried for is implicit
|
|
||||||
# in the packets.
|
|
||||||
|
|
||||||
# has MAC, asking for IP, etc.
|
|
||||||
if (&DHCP-Client-Hardware-Address) {
|
|
||||||
# look up MAC in database
|
|
||||||
}
|
|
||||||
|
|
||||||
# has IP, asking for MAC, etc.
|
|
||||||
elsif (&DHCP-Your-IP-Address) {
|
|
||||||
# look up IP in database
|
|
||||||
}
|
|
||||||
|
|
||||||
# has host name, asking for IP, MAC, etc.
|
|
||||||
elsif (&DHCP-Client-Identifier) {
|
|
||||||
# look up identifier in database
|
|
||||||
}
|
|
||||||
else {
|
|
||||||
update reply {
|
|
||||||
&DHCP-Message-Type = DHCP-Lease-Unknown
|
|
||||||
}
|
|
||||||
|
|
||||||
ok
|
|
||||||
|
|
||||||
# stop processing
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# We presume that the database lookup returns "notfound"
|
|
||||||
# if it can't find anything.
|
|
||||||
#
|
|
||||||
if (notfound) {
|
|
||||||
update reply {
|
|
||||||
&DHCP-Message-Type = DHCP-Lease-Unknown
|
|
||||||
}
|
|
||||||
ok
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Add more logic here. Is the lease inactive?
|
|
||||||
# If so, respond with DHCP-Lease-Unassigned.
|
|
||||||
#
|
|
||||||
# Otherwise, respond with DHCP-Lease-Active
|
|
||||||
#
|
|
||||||
|
|
||||||
#
|
|
||||||
# Also be sure to return ALL information about
|
|
||||||
# the lease.
|
|
||||||
#
|
|
||||||
|
|
||||||
#
|
|
||||||
# The reply types are:
|
|
||||||
#
|
|
||||||
# DHCP-Lease-Unknown
|
|
||||||
# DHCP-Lease-Active
|
|
||||||
# DHCP-Lease-Unassigned
|
|
||||||
#
|
|
||||||
update reply {
|
|
||||||
&DHCP-Message-Type = DHCP-Lease-Unassigned
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
######################################################################
|
|
||||||
#
|
|
||||||
# This next section is a sample configuration for the "passwd"
|
|
||||||
# module, that reads flat-text files. It should go into
|
|
||||||
# radiusd.conf, in the "modules" section.
|
|
||||||
#
|
|
||||||
# The file is in the format <mac>,<ip>
|
|
||||||
#
|
|
||||||
# 00:01:02:03:04:05,192.0.2.100
|
|
||||||
# 01:01:02:03:04:05,192.0.2.101
|
|
||||||
# 02:01:02:03:04:05,192.0.2.102
|
|
||||||
#
|
|
||||||
# This lets you perform simple static IP assignment.
|
|
||||||
#
|
|
||||||
# There is a preconfigured "mac2ip" module setup in
|
|
||||||
# mods-available/mac2ip. To use it do:
|
|
||||||
#
|
|
||||||
# # cd raddb/
|
|
||||||
# # ln -s ../mods-available/mac2ip mods-enabled/mac2ip
|
|
||||||
# # mkdir mods-config/passwd
|
|
||||||
#
|
|
||||||
# Then create the file mods-config/passwd/mac2ip with the above
|
|
||||||
# format.
|
|
||||||
#
|
|
||||||
######################################################################
|
|
||||||
|
|
||||||
|
|
||||||
# This is an example only - see mods-available/mac2ip instead; do
|
|
||||||
# not uncomment these lines here.
|
|
||||||
#
|
|
||||||
#passwd mac2ip {
|
|
||||||
# filename = ${confdir}/mac2ip
|
|
||||||
# format = "*DHCP-Client-Hardware-Address:=DHCP-Your-IP-Address"
|
|
||||||
# delimiter = ","
|
|
||||||
#}
|
|
||||||
@@ -1,126 +0,0 @@
|
|||||||
######################################################################
|
|
||||||
#
|
|
||||||
# This is a virtual server that handles *only* inner tunnel
|
|
||||||
# requests for EAP-TTLS and PEAP types.
|
|
||||||
#
|
|
||||||
######################################################################
|
|
||||||
|
|
||||||
server inner-tunnel {
|
|
||||||
|
|
||||||
listen {
|
|
||||||
ipaddr = 127.0.0.1
|
|
||||||
port = 18120
|
|
||||||
type = auth
|
|
||||||
}
|
|
||||||
|
|
||||||
authorize {
|
|
||||||
filter_username
|
|
||||||
# filter_inner_identity
|
|
||||||
chap
|
|
||||||
mschap
|
|
||||||
# unix
|
|
||||||
# IPASS
|
|
||||||
suffix
|
|
||||||
# ntdomain
|
|
||||||
|
|
||||||
update control {
|
|
||||||
&Proxy-To-Realm := LOCAL
|
|
||||||
}
|
|
||||||
|
|
||||||
eap {
|
|
||||||
ok = return
|
|
||||||
}
|
|
||||||
|
|
||||||
files
|
|
||||||
-sql
|
|
||||||
# smbpasswd
|
|
||||||
-ldap
|
|
||||||
# daily
|
|
||||||
expiration
|
|
||||||
logintime
|
|
||||||
pap
|
|
||||||
}
|
|
||||||
|
|
||||||
authenticate {
|
|
||||||
Auth-Type PAP {
|
|
||||||
pap
|
|
||||||
}
|
|
||||||
|
|
||||||
Auth-Type CHAP {
|
|
||||||
chap
|
|
||||||
}
|
|
||||||
|
|
||||||
Auth-Type MS-CHAP {
|
|
||||||
mschap
|
|
||||||
}
|
|
||||||
|
|
||||||
mschap
|
|
||||||
# pam
|
|
||||||
|
|
||||||
# Auth-Type LDAP {
|
|
||||||
# ldap
|
|
||||||
# }
|
|
||||||
|
|
||||||
eap
|
|
||||||
}
|
|
||||||
|
|
||||||
session {
|
|
||||||
radutmp
|
|
||||||
# sql
|
|
||||||
}
|
|
||||||
|
|
||||||
# Post-Authentication
|
|
||||||
post-auth {
|
|
||||||
# cui-inner
|
|
||||||
|
|
||||||
# update outer.session-state {
|
|
||||||
# User-Name := &User-Name
|
|
||||||
# }
|
|
||||||
|
|
||||||
# reply_log
|
|
||||||
-sql
|
|
||||||
# ldap
|
|
||||||
# moonshot_host_tid
|
|
||||||
# moonshot_realm_tid
|
|
||||||
# moonshot_coi_tid
|
|
||||||
|
|
||||||
if (0) {
|
|
||||||
update reply {
|
|
||||||
User-Name !* ANY
|
|
||||||
Message-Authenticator !* ANY
|
|
||||||
EAP-Message !* ANY
|
|
||||||
Proxy-State !* ANY
|
|
||||||
MS-MPPE-Encryption-Types !* ANY
|
|
||||||
MS-MPPE-Encryption-Policy !* ANY
|
|
||||||
MS-MPPE-Send-Key !* ANY
|
|
||||||
MS-MPPE-Recv-Key !* ANY
|
|
||||||
}
|
|
||||||
|
|
||||||
update {
|
|
||||||
&outer.session-state: += &reply:
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
Post-Auth-Type REJECT {
|
|
||||||
-sql
|
|
||||||
attr_filter.access_reject
|
|
||||||
|
|
||||||
update outer.session-state {
|
|
||||||
&Module-Failure-Message := &request:Module-Failure-Message
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
pre-proxy {
|
|
||||||
# files
|
|
||||||
# attr_filter.pre-proxy
|
|
||||||
# pre_proxy_log
|
|
||||||
}
|
|
||||||
|
|
||||||
post-proxy {
|
|
||||||
# post_proxy_log
|
|
||||||
# attr_filter.post-proxy
|
|
||||||
eap
|
|
||||||
}
|
|
||||||
|
|
||||||
} # inner-tunnel server block
|
|
||||||
@@ -1,126 +0,0 @@
|
|||||||
# -*- text -*-
|
|
||||||
######################################################################
|
|
||||||
#
|
|
||||||
# A virtual server to handle ONLY Status-Server packets.
|
|
||||||
#
|
|
||||||
# Server statistics can be queried with a properly formatted
|
|
||||||
# Status-Server request. See dictionary.freeradius for comments.
|
|
||||||
#
|
|
||||||
# If radiusd.conf has "status_server = yes", then any client
|
|
||||||
# will be able to send a Status-Server packet to any port
|
|
||||||
# (listen section type "auth", "acct", or "status"), and the
|
|
||||||
# server will respond.
|
|
||||||
#
|
|
||||||
# If radiusd.conf has "status_server = no", then the server will
|
|
||||||
# ignore Status-Server packets to "auth" and "acct" ports. It
|
|
||||||
# will respond only if the Status-Server packet is sent to a
|
|
||||||
# "status" port.
|
|
||||||
#
|
|
||||||
# The server statistics are available ONLY on socket of type
|
|
||||||
# "status". Queries for statistics sent to any other port
|
|
||||||
# are ignored.
|
|
||||||
#
|
|
||||||
# Similarly, a socket of type "status" will not process
|
|
||||||
# authentication or accounting packets. This is for security.
|
|
||||||
#
|
|
||||||
# $Id: e7d4346310b837d56bffe4c991b4e5680742ebc0 $
|
|
||||||
#
|
|
||||||
######################################################################
|
|
||||||
|
|
||||||
server status {
|
|
||||||
listen {
|
|
||||||
# ONLY Status-Server is allowed to this port.
|
|
||||||
# ALL other packets are ignored.
|
|
||||||
type = status
|
|
||||||
|
|
||||||
ipaddr = $ENV{FREERADIUS_SITES_STATUS_LISTEN}
|
|
||||||
port = $ENV{FREERADIUS_SITES_STATUS_PORT}
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# We recommend that you list ONLY management clients here.
|
|
||||||
# i.e. NOT your NASes or Access Points, and for an ISP,
|
|
||||||
# DEFINITELY not any RADIUS servers that are proxying packets
|
|
||||||
# to you.
|
|
||||||
#
|
|
||||||
# If you do NOT list a client here, then any client that is
|
|
||||||
# globally defined (i.e. all of them) will be able to query
|
|
||||||
# these statistics.
|
|
||||||
#
|
|
||||||
# Do you really want your partners seeing the internal details
|
|
||||||
# of what your RADIUS server is doing?
|
|
||||||
#
|
|
||||||
client admin {
|
|
||||||
ipaddr = 127.0.0.1
|
|
||||||
secret = $ENV{FREERADIUS_SITES_STATUS_SECRET}
|
|
||||||
}
|
|
||||||
|
|
||||||
# Simple authorize section. The "Autz-Type Status-Server"
|
|
||||||
# section will work here, too. See "raddb/sites-available/default".
|
|
||||||
authorize {
|
|
||||||
ok
|
|
||||||
|
|
||||||
# respond to the Status-Server request.
|
|
||||||
Autz-Type Status-Server {
|
|
||||||
ok
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# Statistics can be queried via a number of methods:
|
|
||||||
#
|
|
||||||
# All packets received/sent by the server (1 = auth, 2 = acct)
|
|
||||||
# FreeRADIUS-Statistics-Type = 3
|
|
||||||
#
|
|
||||||
# All packets proxied by the server (4 = proxy-auth, 8 = proxy-acct)
|
|
||||||
# FreeRADIUS-Statistics-Type = 12
|
|
||||||
#
|
|
||||||
# All packets sent && received:
|
|
||||||
# FreeRADIUS-Statistics-Type = 15
|
|
||||||
#
|
|
||||||
# Internal server statistics:
|
|
||||||
# FreeRADIUS-Statistics-Type = 16
|
|
||||||
#
|
|
||||||
# All packets for a particular client (globally defined)
|
|
||||||
# FreeRADIUS-Statistics-Type = 35
|
|
||||||
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
|
|
||||||
#
|
|
||||||
# All packets for a client attached to a "listen" ip/port
|
|
||||||
# FreeRADIUS-Statistics-Type = 35
|
|
||||||
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
|
|
||||||
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
|
|
||||||
# FreeRADIUS-Stats-Server-Port = 1812
|
|
||||||
#
|
|
||||||
# All packets for a "listen" IP/port
|
|
||||||
# FreeRADIUS-Statistics-Type = 67
|
|
||||||
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
|
|
||||||
# FreeRADIUS-Stats-Server-Port = 1812
|
|
||||||
#
|
|
||||||
# All packets for a home server IP / port
|
|
||||||
# FreeRADIUS-Statistics-Type = 131
|
|
||||||
# FreeRADIUS-Stats-Server-IP-Address = 192.0.2.2
|
|
||||||
# FreeRADIUS-Stats-Server-Port = 1812
|
|
||||||
|
|
||||||
#
|
|
||||||
# You can also get exponentially weighted moving averages of
|
|
||||||
# response times (in usec) of home servers. Just set the config
|
|
||||||
# item "historic_average_window" in a home_server section.
|
|
||||||
#
|
|
||||||
# By default it is zero (don't calculate it). Useful values
|
|
||||||
# are between 100, and 10,000. The server will calculate and
|
|
||||||
# remember the moving average for this window, and for 10 times
|
|
||||||
# that window.
|
|
||||||
#
|
|
||||||
|
|
||||||
#
|
|
||||||
# Some of this could have been simplified. e.g. the proxy-auth and
|
|
||||||
# proxy-acct bits aren't completely necessary. But using them permits
|
|
||||||
# the server to be queried for ALL inbound && outbound packets at once.
|
|
||||||
# This gives a good snapshot of what the server is doing.
|
|
||||||
#
|
|
||||||
# Due to internal limitations, the statistics might not be exactly up
|
|
||||||
# to date. Do not expect all of the numbers to add up perfectly.
|
|
||||||
# The Status-Server packets are also counted in the total requests &&
|
|
||||||
# responses. The responses are counted only AFTER the response has
|
|
||||||
# been sent.
|
|
||||||
#
|
|
||||||
@@ -1,603 +0,0 @@
|
|||||||
######################################################################
|
|
||||||
#
|
|
||||||
# RADIUS over TLS (radsec)
|
|
||||||
#
|
|
||||||
# When a new client connects, the various TLS parameters for the
|
|
||||||
# connection are available as dynamic expansions, e.g.
|
|
||||||
#
|
|
||||||
# %{listen:TLS-Client-Cert-Common-Name}
|
|
||||||
#
|
|
||||||
# Along with other TLS-Client-Cert-... attributes.
|
|
||||||
# These expansions will only exist if the relevant fields
|
|
||||||
# are in the client certificate. Read the debug output to see
|
|
||||||
# which fields are available. Look for output like the following:
|
|
||||||
#
|
|
||||||
# (0) TLS - Creating attributes from certificate OIDs
|
|
||||||
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "one.example.org"
|
|
||||||
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "two.example.org"
|
|
||||||
# ...
|
|
||||||
#
|
|
||||||
# It is also possible to distinguish between connections which have
|
|
||||||
# TLS enables, and ones which do not. The expansion:
|
|
||||||
#
|
|
||||||
# %{listen:tls}
|
|
||||||
#
|
|
||||||
# Will return "yes" if the connection has TLS enabled. It will
|
|
||||||
# return "no" if TLS is not enabled for a particular listen section.
|
|
||||||
#
|
|
||||||
# A number of TLS-Client-Cert-.. attributes holds X509v3 extensions
|
|
||||||
# data, attributes named the way OpenSSL names them. It is possible
|
|
||||||
# to extract data for an extension not known to OpenSSL by defining
|
|
||||||
# a custom string attribute which contains extension OID in it's
|
|
||||||
# name after 'TLS-Client-Cert-' prefix. E.g.:
|
|
||||||
#
|
|
||||||
# ATTRIBUTE TLS-Client-Cert-1.3.6.1.4.1.311.21.7 3002 string
|
|
||||||
#
|
|
||||||
# which will yield something simmilar to:
|
|
||||||
#
|
|
||||||
# (0) eap_tls: TLS - Creating attributes from certificate OIDs
|
|
||||||
# (0) eap_tls: TLS-Client-Cert-1.3.6.1.4.1.311.21.7 += "0x302e06"
|
|
||||||
# ...
|
|
||||||
#
|
|
||||||
######################################################################
|
|
||||||
|
|
||||||
listen {
|
|
||||||
|
|
||||||
# ipaddr = $ENV{FREERADIUS_SITES_TLS_LISTEN}
|
|
||||||
ipaddr = *
|
|
||||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
|
||||||
|
|
||||||
#
|
|
||||||
# TCP and TLS sockets can accept Access-Request and Accounting-Request on the same socket.
|
|
||||||
#
|
|
||||||
# auth = only Access-Request
|
|
||||||
# acct = only Accounting-Request
|
|
||||||
# auth+acct = both
|
|
||||||
# coa = only CoA / Disconnect requests
|
|
||||||
#
|
|
||||||
type = auth+acct
|
|
||||||
|
|
||||||
# For now, only TCP transport is allowed.
|
|
||||||
proto = tcp
|
|
||||||
|
|
||||||
# Send packets to the default virtual server
|
|
||||||
virtual_server = default
|
|
||||||
|
|
||||||
# clients = radsec
|
|
||||||
|
|
||||||
# Use the haproxy "PROXY protocol".
|
|
||||||
#
|
|
||||||
# This configuration allows for many FreeRADIUS servers to be behind a haproxy server. The "PROXY protocol" allows haproxy to send the actual client IP to FreeRADIUS.
|
|
||||||
#
|
|
||||||
# This will work ONLY for RadSec (TLS). Both the haproxy AND the RadSec client MUST be listed as allowed RADIUS clients.
|
|
||||||
#
|
|
||||||
# haproxy needs to have "send-proxy" configured for this server. Health checks should be turned off, as haproxy does not support RADIUS health checks.
|
|
||||||
#
|
|
||||||
# The main use of this feature is for scalability. There is no longer any need to have a RADIUS proxy as a load balancer.
|
|
||||||
# haproxy is fast, stable, and supports dynamic reloads!
|
|
||||||
#
|
|
||||||
# The only problem is that many RADIUS clients do not support RadSec. That situation will hopefully change over time.
|
|
||||||
#
|
|
||||||
# proxy_protocol = no
|
|
||||||
|
|
||||||
# When this is set to "yes", new TLS connections are processed through a section called
|
|
||||||
#
|
|
||||||
# Autz-Type New-TLS-Connection {
|
|
||||||
# ...
|
|
||||||
# }
|
|
||||||
#
|
|
||||||
# The request contains TLS client certificate attributes,
|
|
||||||
# and nothing else. The debug output will print which
|
|
||||||
# attributes are available on your system.
|
|
||||||
#
|
|
||||||
# If the section returns "ok" or "updated", then the
|
|
||||||
# connection is accepted. Otherwise the connection is
|
|
||||||
# terminated.
|
|
||||||
#
|
|
||||||
# check_client_connections = yes
|
|
||||||
|
|
||||||
#
|
|
||||||
# Connection limiting for sockets with "proto = tcp".
|
|
||||||
#
|
|
||||||
limit {
|
|
||||||
# Limit the number of simultaneous TCP connections to the socket
|
|
||||||
#
|
|
||||||
# The default is 16.
|
|
||||||
# Setting this to 0 means "no limit"
|
|
||||||
max_connections = 16
|
|
||||||
|
|
||||||
# The per-socket "max_requests" option does not exist.
|
|
||||||
|
|
||||||
# The lifetime, in seconds, of a TCP connection. After this lifetime, the connection will be closed.
|
|
||||||
#
|
|
||||||
# Setting this to 0 means "forever".
|
|
||||||
lifetime = 0
|
|
||||||
|
|
||||||
# The idle timeout, in seconds, of a TCP connection. If no packets have been received over the connection for this time, the connection will be closed.
|
|
||||||
#
|
|
||||||
# Setting this to 0 means "no timeout".
|
|
||||||
# We STRONGLY RECOMMEND that you set an idle timeout.
|
|
||||||
#
|
|
||||||
idle_timeout = 30
|
|
||||||
}
|
|
||||||
|
|
||||||
# This is *exactly* the same configuration as used by the EAP-TLS
|
|
||||||
# module. It's OK for testing, but for production use it's a good
|
|
||||||
# idea to use different server certificates for EAP and for RADIUS
|
|
||||||
# transport.
|
|
||||||
#
|
|
||||||
# If you want only one TLS configuration for multiple sockets,
|
|
||||||
# then we suggest putting "tls { ...}" into radiusd.conf.
|
|
||||||
# The subsection below can then be changed into a reference:
|
|
||||||
#
|
|
||||||
# tls = ${tls}
|
|
||||||
#
|
|
||||||
# Which means "the tls sub-section is not here, but instead is in
|
|
||||||
# the top-level section called 'tls'".
|
|
||||||
#
|
|
||||||
# If you have multiple tls configurations, you can put them into
|
|
||||||
# sub-sections of a top-level "tls" section. There's no need to
|
|
||||||
# call them all "tls". You can then use:
|
|
||||||
#
|
|
||||||
# tls = ${tls.site1}
|
|
||||||
#
|
|
||||||
# to refer to the "site1" sub-section of the "tls" section.
|
|
||||||
#
|
|
||||||
tls {
|
|
||||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
|
||||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
|
||||||
|
|
||||||
# Accept an expired Certificate Revocation List
|
|
||||||
# allow_expired_crl = no
|
|
||||||
|
|
||||||
# If Private key & Certificate are located in
|
|
||||||
# the same file, then private_key_file &
|
|
||||||
# certificate_file must contain the same file
|
|
||||||
# name.
|
|
||||||
#
|
|
||||||
# If ca_file (below) is not used, then the
|
|
||||||
# certificate_file below MUST include not
|
|
||||||
# only the server certificate, but ALSO all
|
|
||||||
# of the CA certificates used to sign the
|
|
||||||
# server certificate.
|
|
||||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
|
||||||
|
|
||||||
|
|
||||||
# Trusted Root CA list
|
|
||||||
#
|
|
||||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
|
||||||
#
|
|
||||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
|
||||||
# In that case, this CA file should contain *one* CA certificate.
|
|
||||||
#
|
|
||||||
# This parameter is used only for EAP-TLS, when you issue client certificates. If you do not use client certificates, and you do not want
|
|
||||||
# to permit EAP-TLS authentication, then delete this configuration item.
|
|
||||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
|
||||||
|
|
||||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
|
||||||
#
|
|
||||||
# openssl dhparam -out certs/dh 1024
|
|
||||||
#
|
|
||||||
# dh_file = ${certdir}/dh
|
|
||||||
|
|
||||||
#
|
|
||||||
# If your system doesn't have /dev/urandom,
|
|
||||||
# you will need to create this file, and
|
|
||||||
# periodically change its contents.
|
|
||||||
#
|
|
||||||
# For security reasons, FreeRADIUS doesn't
|
|
||||||
# write to files in its configuration
|
|
||||||
# directory.
|
|
||||||
#
|
|
||||||
# random_file = /dev/urandom
|
|
||||||
|
|
||||||
#
|
|
||||||
# The default fragment size is 1K.
|
|
||||||
# However, it's possible to send much more data than
|
|
||||||
# that over a TCP connection. The upper limit is 64K.
|
|
||||||
# Setting the fragment size to more than 1K means that
|
|
||||||
# there are fewer round trips when setting up a TLS
|
|
||||||
# connection. But only if the certificates are large.
|
|
||||||
#
|
|
||||||
fragment_size = 8192
|
|
||||||
|
|
||||||
# include_length is a flag which is
|
|
||||||
# by default set to yes If set to
|
|
||||||
# yes, Total Length of the message is
|
|
||||||
# included in EVERY packet we send.
|
|
||||||
# If set to no, Total Length of the
|
|
||||||
# message is included ONLY in the
|
|
||||||
# First packet of a fragment series.
|
|
||||||
#
|
|
||||||
# include_length = yes
|
|
||||||
|
|
||||||
# Check the Certificate Revocation List
|
|
||||||
#
|
|
||||||
# 1) Copy CA certificates and CRLs to same directory.
|
|
||||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
|
||||||
# 'c_rehash' is OpenSSL's command.
|
|
||||||
# 3) uncomment the line below.
|
|
||||||
# 5) Restart radiusd
|
|
||||||
# check_crl = yes
|
|
||||||
ca_path = ${cadir}
|
|
||||||
|
|
||||||
# OpenSSL does not reload contents of ca_path dir over time.
|
|
||||||
# That means that if check_crl is enabled and CRLs are loaded
|
|
||||||
# from ca_path dir, at some point CRLs will expire and
|
|
||||||
# RADIUSd will stop authenticating NASes.
|
|
||||||
# If ca_path_reload_interval is non-zero, it will force OpenSSL
|
|
||||||
# to reload all data from ca_path periodically
|
|
||||||
#
|
|
||||||
# Flush ca_path each hour
|
|
||||||
ca_path_reload_interval = 3600
|
|
||||||
|
|
||||||
#
|
|
||||||
# If check_cert_issuer is set, the value will
|
|
||||||
# be checked against the DN of the issuer in
|
|
||||||
# the client certificate. If the values do not
|
|
||||||
# match, the certificate verification will fail,
|
|
||||||
# rejecting the user.
|
|
||||||
#
|
|
||||||
# This check can be done more generally by checking
|
|
||||||
# the value of the TLS-Client-Cert-Issuer attribute.
|
|
||||||
# This check can be done via any mechanism you choose.
|
|
||||||
#
|
|
||||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
|
||||||
|
|
||||||
#
|
|
||||||
# If check_cert_cn is set, the value will
|
|
||||||
# be xlat'ed and checked against the CN
|
|
||||||
# in the client certificate. If the values
|
|
||||||
# do not match, the certificate verification
|
|
||||||
# will fail rejecting the user.
|
|
||||||
#
|
|
||||||
# This check is done only if the previous
|
|
||||||
# "check_cert_issuer" is not set, or if
|
|
||||||
# the check succeeds.
|
|
||||||
#
|
|
||||||
# In 2.1.10 and later, this check can be done
|
|
||||||
# more generally by checking the value of the
|
|
||||||
# TLS-Client-Cert-Common-Name attribute. This check
|
|
||||||
# can be done via any mechanism you choose.
|
|
||||||
#
|
|
||||||
# check_cert_cn = %{User-Name}
|
|
||||||
#
|
|
||||||
# Set this option to specify the allowed
|
|
||||||
# TLS cipher suites. The format is listed
|
|
||||||
# in "man 1 ciphers".
|
|
||||||
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
|
|
||||||
|
|
||||||
# If enabled, OpenSSL will use server cipher list
|
|
||||||
# (possibly defined by cipher_list option above)
|
|
||||||
# for choosing right cipher suite rather than
|
|
||||||
# using client-specified list which is OpenSSl default
|
|
||||||
# behavior. Having it set to yes is a current best practice
|
|
||||||
# for TLS
|
|
||||||
cipher_server_preference = no
|
|
||||||
|
|
||||||
#
|
|
||||||
# Older TLS versions are deprecated. But for RadSec,
|
|
||||||
# we CAN allow TLS 1.3.
|
|
||||||
#
|
|
||||||
tls_min_version = "1.2"
|
|
||||||
tls_max_version = "1.3"
|
|
||||||
|
|
||||||
#
|
|
||||||
# Session resumption / fast reauthentication cache.
|
|
||||||
#
|
|
||||||
# The cache contains the following information:
|
|
||||||
#
|
|
||||||
# session Id - unique identifier, managed by SSL
|
|
||||||
# User-Name - from the Access-Accept
|
|
||||||
# Stripped-User-Name - from the Access-Request
|
|
||||||
# Cached-Session-Policy - from the Access-Accept
|
|
||||||
#
|
|
||||||
# The "Cached-Session-Policy" is the name of a
|
|
||||||
# policy which should be applied to the cached
|
|
||||||
# session. This policy can be used to assign
|
|
||||||
# VLANs, IP addresses, etc. It serves as a useful
|
|
||||||
# way to re-apply the policy from the original
|
|
||||||
# Access-Accept to the subsequent Access-Accept
|
|
||||||
# for the cached session.
|
|
||||||
#
|
|
||||||
# On session resumption, these attributes are
|
|
||||||
# copied from the cache, and placed into the
|
|
||||||
# reply list.
|
|
||||||
#
|
|
||||||
# You probably also want "use_tunneled_reply = yes" when using fast session resumption.
|
|
||||||
#
|
|
||||||
cache {
|
|
||||||
#
|
|
||||||
# Enable it. The default is "no".
|
|
||||||
# Deleting the entire "cache" subsection
|
|
||||||
# Also disables caching.
|
|
||||||
#
|
|
||||||
#
|
|
||||||
# As of version 3.0.14, the session cache requires the use
|
|
||||||
# of the "name" and "persist_dir" configuration items, below.
|
|
||||||
#
|
|
||||||
# The internal OpenSSL session cache has been permanently
|
|
||||||
# disabled.
|
|
||||||
#
|
|
||||||
# You can disallow resumption for a
|
|
||||||
# particular user by adding the following
|
|
||||||
# attribute to the control item list:
|
|
||||||
#
|
|
||||||
# Allow-Session-Resumption = No
|
|
||||||
#
|
|
||||||
# If "enable = no" below, you CANNOT
|
|
||||||
# enable resumption for just one user
|
|
||||||
# by setting the above attribute to "yes".
|
|
||||||
#
|
|
||||||
enable = no
|
|
||||||
|
|
||||||
#
|
|
||||||
# Lifetime of the cached entries, in hours.
|
|
||||||
# The sessions will be deleted after this
|
|
||||||
# time.
|
|
||||||
#
|
|
||||||
lifetime = 24 # hours
|
|
||||||
|
|
||||||
#
|
|
||||||
# Internal "name" of the session cache.
|
|
||||||
# Used to distinguish which TLS context
|
|
||||||
# sessions belong to.
|
|
||||||
#
|
|
||||||
# The server will generate a random value
|
|
||||||
# if unset. This will change across server
|
|
||||||
# restart so you MUST set the "name" if you
|
|
||||||
# want to persist sessions (see below).
|
|
||||||
#
|
|
||||||
# If you use IPv6, change the "ipaddr" below
|
|
||||||
# to "ipv6addr"
|
|
||||||
#
|
|
||||||
#name = "TLS ${..ipaddr} ${..port} ${..proto}"
|
|
||||||
|
|
||||||
#
|
|
||||||
# Simple directory-based storage of sessions.
|
|
||||||
# Two files per session will be written, the SSL
|
|
||||||
# state and the cached VPs. This will persist session
|
|
||||||
# across server restarts.
|
|
||||||
#
|
|
||||||
# The server will need write perms, and the directory
|
|
||||||
# should be secured from anyone else. You might want
|
|
||||||
# a script to remove old files from here periodically:
|
|
||||||
#
|
|
||||||
# find ${logdir}/tlscache -mtime +2 -exec rm -f {} \;
|
|
||||||
#
|
|
||||||
# This feature REQUIRES "name" option be set above.
|
|
||||||
#
|
|
||||||
#persist_dir = "${logdir}/tlscache"
|
|
||||||
}
|
|
||||||
|
|
||||||
#
|
|
||||||
# Require a client certificate.
|
|
||||||
#
|
|
||||||
require_client_cert = no
|
|
||||||
|
|
||||||
#
|
|
||||||
# As of version 2.1.10, client certificates can be
|
|
||||||
# validated via an external command. This allows
|
|
||||||
# dynamic CRLs or OCSP to be used.
|
|
||||||
#
|
|
||||||
# This configuration is commented out in the
|
|
||||||
# default configuration. Uncomment it, and configure
|
|
||||||
# the correct paths below to enable it.
|
|
||||||
#
|
|
||||||
verify {
|
|
||||||
# A temporary directory where the client
|
|
||||||
# certificates are stored. This directory
|
|
||||||
# MUST be owned by the UID of the server,
|
|
||||||
# and MUST not be accessible by any other
|
|
||||||
# users. When the server starts, it will do
|
|
||||||
# "chmod go-rwx" on the directory, for
|
|
||||||
# security reasons. The directory MUST
|
|
||||||
# exist when the server starts.
|
|
||||||
#
|
|
||||||
# You should also delete all of the files
|
|
||||||
# in the directory when the server starts.
|
|
||||||
# tmpdir = /tmp/radiusd
|
|
||||||
# tmpdir = /startechnica/freeradius/tmp
|
|
||||||
|
|
||||||
# The command used to verify the client cert.
|
|
||||||
# We recommend using the OpenSSL command-line
|
|
||||||
# tool.
|
|
||||||
#
|
|
||||||
# The ${..ca_path} text is a reference to
|
|
||||||
# the ca_path variable defined above.
|
|
||||||
#
|
|
||||||
# The %{TLS-Client-Cert-Filename} is the name
|
|
||||||
# of the temporary file containing the cert
|
|
||||||
# in PEM format. This file is automatically
|
|
||||||
# deleted by the server when the command
|
|
||||||
# returns.
|
|
||||||
# client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
clients radsec {
|
|
||||||
client 127.0.0.1 {
|
|
||||||
ipaddr = 127.0.0.1
|
|
||||||
|
|
||||||
# Ensure that this client is TLS *only*.
|
|
||||||
proto = tls
|
|
||||||
|
|
||||||
# TCP clients can have any shared secret.
|
|
||||||
# TLS clients MUST have the shared secret set to "radsec". Or, for "proto = tls", you can omit the secret, and it will
|
|
||||||
# automatically be set to "radsec".
|
|
||||||
# secret = radsec
|
|
||||||
secret = $ENV{FREERADIUS_CLIENTS_SECRET}
|
|
||||||
|
|
||||||
# You can also use a "limit" section here.
|
|
||||||
# See raddb/clients.conf for examples.
|
|
||||||
#
|
|
||||||
# Note that BOTH limits are applied. You should therefore set the "listen" limits higher than the ones for each individual
|
|
||||||
# client.
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# When a request is proxied to a TLS-enabled home server, the TLS parameters are available via the expansion:
|
|
||||||
#
|
|
||||||
# %{proxy_listen: ... }
|
|
||||||
#
|
|
||||||
# The contents of the expansion are the same as described above with the %{listen: ... } expansion, and have similar meanings. "client" in this case is the proxy (this system)
|
|
||||||
# and "server" is the remote system (home server).
|
|
||||||
#
|
|
||||||
# Note that the %{proxy_listen: ... } parameters are available only AFTER the connection has been made to the home server.
|
|
||||||
home_server tls {
|
|
||||||
ipaddr = 127.0.0.1
|
|
||||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
|
||||||
|
|
||||||
# type can be the same types as for the "listen" section/
|
|
||||||
# e.g. auth, acct, auth+acct, coa
|
|
||||||
type = auth
|
|
||||||
secret = radsec
|
|
||||||
proto = tcp
|
|
||||||
status_check = none
|
|
||||||
|
|
||||||
tls {
|
|
||||||
#
|
|
||||||
# Similarly to HTTP, the client can use Server Name
|
|
||||||
# Indication to inform the RadSec server of which
|
|
||||||
# domain it is requesting. This selection allows
|
|
||||||
# multiple sites to exist at the same IP address.
|
|
||||||
#
|
|
||||||
# For example, and identity provider could host
|
|
||||||
# multiple sites, but present itself with one public
|
|
||||||
# IP address.
|
|
||||||
#
|
|
||||||
# SNI also permits the use of a load balancer such as
|
|
||||||
# haproxy. That load balancer can terminate the TLS
|
|
||||||
# connection, and then use SNI to route the
|
|
||||||
# underlying RADIUS TCP traffic to a particular host.
|
|
||||||
#
|
|
||||||
# Note that "hostname" here is only for SNI, and is NOT
|
|
||||||
# the hostname or IP address we connect to. For that,
|
|
||||||
# see "ipaddr", above.
|
|
||||||
#
|
|
||||||
# hostname = "example.com"
|
|
||||||
|
|
||||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
|
||||||
# private_key_file = ${certdir}/client.pem
|
|
||||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
|
||||||
|
|
||||||
# If Private key & Certificate are located in
|
|
||||||
# the same file, then private_key_file &
|
|
||||||
# certificate_file must contain the same file
|
|
||||||
# name.
|
|
||||||
#
|
|
||||||
# If ca_file (below) is not used, then the
|
|
||||||
# certificate_file below MUST include not
|
|
||||||
# only the server certificate, but ALSO all
|
|
||||||
# of the CA certificates used to sign the
|
|
||||||
# server certificate.
|
|
||||||
# certificate_file = ${certdir}/client.pem
|
|
||||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
|
||||||
|
|
||||||
# Trusted Root CA list
|
|
||||||
#
|
|
||||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
|
||||||
#
|
|
||||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
|
||||||
# In that case, this CA file should contain *one* CA certificate.
|
|
||||||
#
|
|
||||||
# This parameter is used only for EAP-TLS,
|
|
||||||
# when you issue client certificates. If you do
|
|
||||||
# not use client certificates, and you do not want
|
|
||||||
# to permit EAP-TLS authentication, then delete
|
|
||||||
# this configuration item.
|
|
||||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
|
||||||
|
|
||||||
#
|
|
||||||
# For TLS-PSK, the key should be specified dynamically, instead of using a hard-coded psk_identity and psk_hexphrase.
|
|
||||||
#
|
|
||||||
# The input to the dynamic expansion will be the PSK
|
|
||||||
# identity supplied by the client, in the
|
|
||||||
# TLS-PSK-Identity attribute. The output of the
|
|
||||||
# expansion should be a hex string, of no more than
|
|
||||||
# 512 characters. The string should not be prefixed
|
|
||||||
# with "0x". e.g. "abcdef" is OK. "0xabcdef" is not.
|
|
||||||
#
|
|
||||||
# psk_query = "%{psksql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
|
|
||||||
|
|
||||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
|
||||||
#
|
|
||||||
# openssl dhparam -out certs/dh 1024
|
|
||||||
#
|
|
||||||
# dh_file = ${certdir}/dh
|
|
||||||
# random_file = /dev/urandom
|
|
||||||
|
|
||||||
#
|
|
||||||
# The default fragment size is 1K.
|
|
||||||
# However, TLS can send 64K of data at once.
|
|
||||||
# It can be useful to set it higher.
|
|
||||||
#
|
|
||||||
fragment_size = 8192
|
|
||||||
|
|
||||||
# include_length is a flag which is
|
|
||||||
# by default set to yes If set to
|
|
||||||
# yes, Total Length of the message is
|
|
||||||
# included in EVERY packet we send.
|
|
||||||
# If set to no, Total Length of the
|
|
||||||
# message is included ONLY in the
|
|
||||||
# First packet of a fragment series.
|
|
||||||
#
|
|
||||||
# include_length = yes
|
|
||||||
|
|
||||||
# Check the Certificate Revocation List
|
|
||||||
#
|
|
||||||
# 1) Copy CA certificates and CRLs to same directory.
|
|
||||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
|
||||||
# 'c_rehash' is OpenSSL's command.
|
|
||||||
# 3) uncomment the line below.
|
|
||||||
# 5) Restart radiusd
|
|
||||||
# check_crl = yes
|
|
||||||
ca_path = ${cadir}
|
|
||||||
|
|
||||||
#
|
|
||||||
# If check_cert_issuer is set, the value will
|
|
||||||
# be checked against the DN of the issuer in
|
|
||||||
# the client certificate. If the values do not
|
|
||||||
# match, the certificate verification will fail,
|
|
||||||
# rejecting the user.
|
|
||||||
#
|
|
||||||
# In 2.1.10 and later, this check can be done
|
|
||||||
# more generally by checking the value of the
|
|
||||||
# TLS-Client-Cert-Issuer attribute. This check
|
|
||||||
# can be done via any mechanism you choose.
|
|
||||||
#
|
|
||||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
|
||||||
|
|
||||||
#
|
|
||||||
# If check_cert_cn is set, the value will
|
|
||||||
# be xlat'ed and checked against the CN
|
|
||||||
# in the client certificate. If the values
|
|
||||||
# do not match, the certificate verification
|
|
||||||
# will fail rejecting the user.
|
|
||||||
#
|
|
||||||
# This check is done only if the previous
|
|
||||||
# "check_cert_issuer" is not set, or if
|
|
||||||
# the check succeeds.
|
|
||||||
#
|
|
||||||
# In 2.1.10 and later, this check can be done
|
|
||||||
# more generally by checking the value of the
|
|
||||||
# TLS-Client-Cert-Common-Name attribute. This check
|
|
||||||
# can be done via any mechanism you choose.
|
|
||||||
#
|
|
||||||
# check_cert_cn = %{User-Name}
|
|
||||||
#
|
|
||||||
# Set this option to specify the allowed TLS cipher suites. The format is listed in "man 1 ciphers".
|
|
||||||
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
home_server_pool tls {
|
|
||||||
type = fail-over
|
|
||||||
home_server = tls
|
|
||||||
}
|
|
||||||
|
|
||||||
realm tls {
|
|
||||||
auth_pool = tls
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
data:
|
||||||
|
ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNrakNDQVhxZ0F3SUJBZ0lJRjV2Zmt0ZkdGWXd3RFFZSktvWklodmNOQVFFTEJRQXdBREFlRncweU5UQTIKTWpVeE1USXlNREJhRncweU5qQTJNalV4TVRJeU1EQmFNQUF3Z2dFaU1BMEdDU3FHU0liM0RRRUJBUVVBQTRJQgpEd0F3Z2dFS0FvSUJBUUMxOTZ0RmkycXVsQk1FUS9keUpEMldzYmkrU29nN3ZDT21GazBlOVVNd29nSU1GL2xDCldPNk5PQnRLWWk4cStKSFZXemdEOUZxQmtMUGpBazg3UkprR2dpKy96RTRnTHRVM2o1eG1tNDh1NUNxVm1DRHMKYnUzWS9XRHVpcDNNUGhVYjFidHFRYlFSc0RVMlV1TXZROGUvc1NLR2NsMEJSeFZuVHN5ZVZrRlhtWTQ5S1pZTgpHRnlYQWpLL0ZtajB5bVd1ZSsya0dFZHNuODN0cUNBRTREN1BrT1lUT3VhR1cyRTlxTDBpMTFBTE1aL1dkOTdqCk15aW1NMDUzODV6Y3YxMGNyL1Nkd2JLYTgzbDB2YXdKQ1hMQStJeUZrUEp3VGJNQ3I4NEh6Qmc0M0ZPV2Z1T20KNnE3Y3lEUjdqSEwrZ0pRajZOV21lTFJXTnY1bUx2R1hFNTRsQWdNQkFBR2pFREFPTUF3R0ExVWRFd1FGTUFNQgpBZjh3RFFZSktvWklodmNOQVFFTEJRQURnZ0VCQUl3MWtrSjFzZ1NrRVBUQWh4eHF6MjJva1JpazZnRm14M3ExCkJBakswS2xBbmlZcDJQZFlNekg5UUpZT2pHUnpOelJEcENQU0VEMWZ6NWRWUDhaU0t5TGxTMVVJOUlxbFpmb1gKdW9UUkw3WFVVcndweEFrNW9VUldxQzhoTWZNK2JZRUU4VlY3S1B2QVUxUVpuZUlXTW9hQ01SOU5CN1V5dGFLMgpqRlBkZ0pJUGR0VDV3QlZ4WlBzZEVZQy8wdTkrdWlJTHhOQ1QvZ2hJOUJ3eW5WZTFTZnFONVlDdEljNHVVUmo1CnREWVdnb0w0Z0p4aWhLSTl0UWRvQ0VUT3BHTU1VODF4OGtTREVSSnkzYzdEaCttK0IrbWhCM3BPVnUzaUQxRjgKRmdNZkhFSXowaUhaZUFLSlJRR3pkREloSDFjekNqYzZsSWF2VUY2MWxHTnlTekJJdVVVPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
||||||
|
tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN3akNDQWFxZ0F3SUJBZ0lJT3hESWM3VW92Smt3RFFZSktvWklodmNOQVFFTEJRQXdBREFlRncweU5UQTIKTWpVeE1UTXpNREJhRncweU5qQTJNalV4TVRJeU1EQmFNRE14TVRBdkJnTlZCQU1US0daeVpXVnlZV1JwZFhNdQphVzVtY21GemRISjFZM1IxY21VdWFHVnNiV2h2YkhvdVkyeHZkV1F3Z2dFaU1BMEdDU3FHU0liM0RRRUJBUVVBCkE0SUJEd0F3Z2dFS0FvSUJBUUMrS1BRaWhWMStPUHVZdGtsWVVxUGhRNzNvZkxvbEN3ZTh3YjhmSnQ2aXNZdnIKZ0Z5OXZjdnUvODNCem1FYVNDdkZlWVVuUjQwQnp0Q3dQM0NrS0xlWVIzYTNKbDdLeWxuQVY2WEM0THhlSWkzTQo3NTlnM0IxY1ZXM0J5ckxhaTR5RVljK2N3NnRBSEt1SHdPS3lYUGRCdEpQWHBDR3J0Qy9LMktIN3ZHQS9uNnFlCnhpQTZkVVU1LzFQRFIrNXlMaGVEdVlVc2JIcmhLM1VyMkNsNUlZWXI2VG9mR2NJTDAzd25MNWxnRDhWbC9NQkwKV3p4MVVMTk1XRkhxbWViajRMUCttN3RTUTZnSTVMbVlPSHhRSWEvNS9VU09VeER0RWNsNkExT2tCNmVvK2thMwpick9kZ3FuL0E5emVwVStobmZuUnpWcWVwMS8zQUN1dytXQzl3d2xwQWdNQkFBR2pEVEFMTUFrR0ExVWRFd1FDCk1BQXdEUVlKS29aSWh2Y05BUUVMQlFBRGdnRUJBSnQ4MFA0b2U3YVJVQzMrSHIxdVFsSFZ0QVRrUzFqRFo4dW0KR0pBeThFS3RyUHA1M09SOVpGTVVPVGllQUVBYlJScXl4cnFnSlFEUDgzb3BTOFljMnB5SXlDM0g4bmxtMkFtVwpGelJWeExGYU5vVWF4b3Rickd1YkpPSjZyb2xhV2pwVVRMZENaYjQzUC92Z1o5ckpITUczSFRnZkRuOWNZRVBqCkpsTFZvblVKa2VNOTJCeDNkczVRQ1NFaFR0ZVEwdTZ4SWZxMUZPbzlsdDBQeEZlbEwzUXdFYzBPeXFEelVJbzUKbjRidWhFYVZaaU5xalhJaWZJdjFEcWNpN29aQk9oVktyNkxwR1lqczNLOVAyK3FYTnJzTkU0elZiWlpPWU5wSQpYK2IrMGU4YkhiOUR1ODRDbjVweDBxZUZsSlBLR3JPUmN6OE1XS3VHaVVubi9NS29rTnc9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K
|
||||||
|
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb1FJQkFBS0NBUUVBdmlqMElvVmRmamo3bUxaSldGS2o0VU85Nkh5NkpRc0h2TUcvSHliZW9yR0w2NEJjCnZiM0w3di9Od2M1aEdrZ3J4WG1GSjBlTkFjN1FzRDl3cENpM21FZDJ0eVpleXNwWndGZWx3dUM4WGlJdHpPK2YKWU53ZFhGVnR3Y3F5Mm91TWhHSFBuTU9yUUJ5cmg4RGlzbHozUWJTVDE2UWhxN1F2eXRpaCs3eGdQNStxbnNZZwpPblZGT2Y5VHcwZnVjaTRYZzdtRkxHeDY0U3QxSzlncGVTR0dLK2s2SHhuQ0M5TjhKeStaWUEvRlpmekFTMXM4CmRWQ3pURmhSNnBubTQrQ3ovcHU3VWtPb0NPUzVtRGg4VUNHditmMUVqbE1RN1JISmVnTlRwQWVucVBwR3QyNnoKbllLcC93UGMzcVZQb1ozNTBjMWFucWRmOXdBcnNQbGd2Y01KYVFJREFRQUJBb0gvWmhnSWlTcllRQ1U3WVJkZwp1ME9qS29jWHhBK2t4SGQ4Nk5xcXdmSnh6blc5TjdNa3draGRHTHNob0phZTRPOHo1a090VmZlaWhCMFR0UnJNCkpqb241aWcvUHpJaHNvWFUvMUx5NU9iZ096Z2VlMXFkTnc1TDBaeEUrK01Remd3ZUxFcFhTVVRneVB6VWNHTnoKL1d0NmNRVkpkMFJTWGNEdUlNRVJ4TjBKQ0t6OGpLcFBxblZmaHNLWmhQZENZTk9XTTJtWitMWlkzNE14bjVpZQpUNGJjNGZJcm5QTkNpWmljeXE5SEsyejZHenhjRVNubGpyNHZCd3YzY0puVEJBZnpLaktvM2I1M2srcUxWZUFSClBJSkJ1ZGhJZm82U3p1UEdDQ0l1aWJLVC85N2VLVzFma1JHeFNQV2pQRkJTdkdSSjN3enFZb3VtM0JDSHJwQWUKWFhRUkFvR0JBTjlhM21yRnlYT1VlaFhYbFkzT1lvbWNyN0lKMzdydGpaSnlURFM0MHVFU1lqN1dxYzlIUXNrNQpibURLSDJVUzM1TEpuWnVXTE5Yb24yOElickNDNVdrQVhXVUJHNDFxY2o4TGk1Q01aYk00QjMycnlINmlEMG9oCkZianBVMlpVeFoxTmR4bVhsZnpUdUpyNjVOSGxiNmlkK004V2VscmRrMHMvR3YwaFFTdjFBb0dCQU5uMERKbFEKZURjVTBjbE12U01ucTcrNklaUWdoRXJDMUpwengrK0xRNDl2V3MxVlFDd0RWVHMxYlh0KzVmWm9wNWF5QlUwcApSNGRQb2V6eUZQMlBac1BtL3lFM3h3c2VkU1lPNVJVbmNtMjY4UC8rS0NTTWxDU2tPWkp4UVBsQXZvZzl3QzB0CmRNZzl2VzZrVHQ1S0QyK01aVEFUYkh4Z2hqb2REVk13Y3BNbEFvR0FRQkdCd1dEdzAxMmcwNGtlbGluQWJEYnMKMHdZd0RoKzhQMmpYNFR1dkNlN0xEYmxueGxScm5Pc0RkWElsSlVvUHBieDlvRGFvcjhkbGpHVC8wMVFJMkdESgphWUt5MDVMWUtLdDRJa09UbktBU3pnS3JwVjk1UVV0U1B0TjNIK0JyT3g4UWJkL2tuenhnTk55SkxJaEN5anhlCk5aRCtFZmlER3MrRVAxMzlvczBDZ1lFQWtoYmJPd2lOQzU2UTMzVG9jZC90WngzRDFCM1hqcVQ1REczKzNibGoKRjRsME81MmczZDkrQ2FuT01MRG1RenZ5MlRlS0JpWmRJMzFrOUFWdnZHV2FaRVU1VFhLdG4rNVNaNmdrTlFHegoyWWtzY09wU3plek1mNkwwVkF4Rm1NeWs2WDA2aXcyazhYTXd2akMwREp0bnJVVlZyZHZYSTZjdlVWU1gwZUx2CmFXRUNnWUJTMDd6VjM4MS9ZTmxtQ00rRStXVFpTWnJuZ2pqSWVDZ2NxTUp0MXQyU3BuYUJRb0hPNkRLakpjRGsKOExlZzh6N0I4WW01RkpmeTU1Wm9ya0RWN0xHSTFKR3dmYzNwM01XMlJBVmhra1YwTG9HSEx2OFZjRDZ0M1V0cQpkSU1rdWdQRS9KUVFpblpzREQ4QjNsTEJpMTY1T0ZmeEZXUzdtSkRiSGF3MzRpN0FEUT09Ci0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg==
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: null
|
||||||
|
name: freeradius-tls
|
||||||
|
namespace: freeradius
|
||||||
|
###
|
||||||
|
# kubectl create secret generic freeradius-tls \
|
||||||
|
# -n freeradius-new \
|
||||||
|
# --from-file=tls.crt=certs/freeradius-server-tls.crt \
|
||||||
|
# --from-file=tls.key=certs/freeradius-key.pem \
|
||||||
|
# --from-file=ca.crt=certs/freeradius-auth-ca.crt \
|
||||||
|
# --dry-run=client -o yaml > secret.yaml
|
||||||
|
###
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if and (include "freeradius.createTlsSecret" .) .Values.tls.autoGenerator.certmanager.enabled }}
|
|
||||||
{{- if not (eq (include "st-common.capabilities.certManager.apiVersion" .) "false") }}
|
|
||||||
{{- $releaseNamespace := include "st-common.names.namespace" . }}
|
|
||||||
{{- $clusterDomain := .Values.clusterDomain }}
|
|
||||||
{{- $fullname := include "st-common.names.fullname" . }}
|
|
||||||
{{- $serviceName := include "st-common.names.fullname" . }}
|
|
||||||
{{- $altNames := list (printf "%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $serviceName $releaseNamespace) (printf "%s.%s" $serviceName $releaseNamespace) $fullname }}
|
|
||||||
{{/*
|
|
||||||
{{- $altNames := list (printf "*.%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $serviceName $releaseNamespace) (printf "%s.%s" $serviceName $releaseNamespace) $fullname }}
|
|
||||||
*/}}
|
|
||||||
apiVersion: {{ include "st-common.capabilities.certManager.apiVersion" . }}
|
|
||||||
kind: Certificate
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}-tls
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
secretName: {{ include "freeradius.tlsSecretName" . }}
|
|
||||||
issuerRef:
|
|
||||||
group: cert-manager.io
|
|
||||||
kind: {{ .Values.tls.autoGenerator.certmanager.issuerKind }}
|
|
||||||
name: {{ .Values.tls.autoGenerator.certmanager.issuerName }}
|
|
||||||
#name: letsencrypt-prd
|
|
||||||
privateKey:
|
|
||||||
algorithm: ECDSA
|
|
||||||
rotationPolicy: Always
|
|
||||||
size: 256
|
|
||||||
subject:
|
|
||||||
organizations:
|
|
||||||
- {{ .Release.Name | quote }}
|
|
||||||
organizationalUnits:
|
|
||||||
- {{ include "st-common.names.fullname" . }}
|
|
||||||
dnsNames:
|
|
||||||
- {{ .Values.ingress.hostname | quote }}
|
|
||||||
{{- range .Values.ingress.extraHosts }}
|
|
||||||
- {{ .name | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with $altNames }}
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if not .Values.clients.existingConfigMapName }}
|
|
||||||
{{- $client := index .Values "clients" "localhost" }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ printf "%s-clients" (include "st-common.names.fullname" .) }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
data:
|
|
||||||
clients.conf: |-
|
|
||||||
client
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,76 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ include "freeradius.names.envvars" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
data:
|
|
||||||
FREERADIUS_ENABLE_TLS: {{ ternary "true" "false" .Values.tls.enabled | quote }}
|
|
||||||
|
|
||||||
FREERADIUS_CLIENTS_SHORTNAME: ""
|
|
||||||
FREERADIUS_CLIENTS_IPV4ADDR: ""
|
|
||||||
FREERADIUS_CLIENTS_IPV6ADDR: ""
|
|
||||||
FREERADIUS_CLIENTS_SECRET: ""
|
|
||||||
|
|
||||||
{{- if .Values.modsEnabled.sql.enabled }}
|
|
||||||
FREERADIUS_MODS_SQL_DIALECT: {{ .Values.modsEnabled.sql.dialect }}
|
|
||||||
FREERADIUS_MODS_SQL_SERVER: {{ include "freeradius.database.host" . | quote }}
|
|
||||||
FREERADIUS_MODS_SQL_PORT: {{ include "freeradius.database.port" . }}
|
|
||||||
FREERADIUS_MODS_SQL_LOGIN: {{ include "freeradius.database.user" . | quote }}
|
|
||||||
FREERADIUS_MODS_SQL_DB: {{ include "freeradius.database.name" . | quote }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_ACCT1: {{ .Values.modsEnabled.sql.table.acct1 }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_ACCT2: {{ .Values.modsEnabled.sql.table.acct2 }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_AUTHCHECK: {{ .Values.modsEnabled.sql.table.authcheck }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_AUTHREPLY: {{ .Values.modsEnabled.sql.table.authreply }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_CLIENT: {{ .Values.modsEnabled.sql.table.client }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_GROUPCHECK: {{ .Values.modsEnabled.sql.table.groupcheck }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_GROUPREPLY: {{ .Values.modsEnabled.sql.table.groupreply }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_POSTAUTH: {{ .Values.modsEnabled.sql.table.postauth }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_USERGROUP: {{ .Values.modsEnabled.sql.table.usergroup }}
|
|
||||||
FREERADIUS_MODS_SQL_TABLE_RADIPPOOL: {{ .Values.modsEnabled.sql.table.sqlippool }}
|
|
||||||
FREERADIUS_MODS_SQL_TLS_ENABLE: {{ ternary "yes" "no" .Values.modsEnabled.sql.tls.enabled | quote }}
|
|
||||||
|
|
||||||
FREERADIUS_MODS_SQL_READ_CLIENTS: {{ ternary "yes" "no" .Values.modsEnabled.sql.readClients | quote }}
|
|
||||||
FREERADIUS_MODS_SQL_GROUP_ATTRIBUTE: {{ .Values.modsEnabled.sql.groupAttribute | quote }}
|
|
||||||
|
|
||||||
FREERADIUS_MODS_SQL_SQLITE_FILENAME: {{ .Values.modsEnabled.sql.sqlite.filename | quote }}
|
|
||||||
FREERADIUS_MODS_SQL_SQLITE_BUSY_TIMEOUT: {{ .Values.modsEnabled.sql.sqlite.busyTimeout | quote }}
|
|
||||||
|
|
||||||
{{- if .Values.modsEnabled.sql.tls.enabled }}
|
|
||||||
FREERADIUS_MODS_SQL_TLS_CACERT: {{ include "freeradius.sqlTlsCACert" . | quote }}
|
|
||||||
FREERADIUS_MODS_SQL_TLS_CIPHER: {{ .Values.modsEnabled.sql.tls.ciphers | quote }}
|
|
||||||
FREERADIUS_MODS_SQL_TLS_CERTIFICATE: {{ include "freeradius.sqlTlsCert" . | quote }}
|
|
||||||
FREERADIUS_MODS_SQL_TLS_PRIVATEKEY: {{ include "freeradius.sqlTlsCertKey" . | quote }}
|
|
||||||
FREERADIUS_MODS_SQL_TLS_PRIVATEKEY_PASSWORD: {{ .Values.modsEnabled.sql.tls.privateKeyPassword | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
FREERADIUS_SITES_NAMESPACE: radius
|
|
||||||
|
|
||||||
FREERADIUS_SITES_DEFAULT_AUTH_PORT: {{ .Values.containerPorts.auth | quote }}
|
|
||||||
FREERADIUS_SITES_DEFAULT_ACCT_PORT: {{ .Values.containerPorts.acct | quote }}
|
|
||||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
|
||||||
FREERADIUS_SITES_COA_PORT: {{ .Values.containerPorts.coa | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.status.enabled }}
|
|
||||||
FREERADIUS_SITES_STATUS_LISTEN: {{ .Values.sitesEnabled.status.listen | quote }}
|
|
||||||
FREERADIUS_SITES_STATUS_PORT: {{ .Values.containerPorts.status | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.tls.enabled }}
|
|
||||||
FREERADIUS_SITES_TLS_PORT: {{ .Values.containerPorts.radsec | quote }}
|
|
||||||
FREERADIUS_SITES_TLS_CA_FILE: {{ include "freeradius.tlsCACert" . | quote }}
|
|
||||||
FREERADIUS_SITES_TLS_CERTIFICATE_FILE: {{ include "freeradius.tlsCert" . | quote }}
|
|
||||||
FREERADIUS_SITES_TLS_CIPHER: {{ default "DEFAULT" .Values.sitesEnabled.tls.cipher | quote }}
|
|
||||||
FREERADIUS_SITES_TLS_PRIVKEY_FILE: {{ include "freeradius.tlsCertKey" . | quote }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
data:
|
|
||||||
{{ (.Files.Glob "files/policy/filter").AsConfig | indent 2 }}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ printf "%s-mods-config" (include "st-common.names.fullname" .) }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
data:
|
|
||||||
{{ (.Files.Glob "files/mods-config/queries.conf").AsConfig | indent 2 }}
|
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ printf "%s-mods" (include "st-common.names.fullname" .) }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
data:
|
|
||||||
{{ (.Files.Glob "files/mods-available/eap").AsConfig | indent 2 }}
|
|
||||||
{{ (.Files.Glob "files/mods-available/dynamic_clients").AsConfig | indent 2 }}
|
|
||||||
{{ (.Files.Glob "files/mods-available/sqlippool").AsConfig | indent 2 }}
|
|
||||||
{{- if .Values.modsEnabled.sql.enabled }}
|
|
||||||
{{ (.Files.Glob "files/mods-available/sql").AsConfig | indent 2 }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ printf "%s-radius-conf" (include "st-common.names.fullname" .) }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
data:
|
|
||||||
{{ (.Files.Glob "files/radius.conf").AsConfig | indent 2 }}
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ printf "%s-sites" (include "st-common.names.fullname" .) }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
data:
|
|
||||||
{{ (.Files.Glob "files/sites-available/default").AsConfig | indent 2 }}
|
|
||||||
{{ (.Files.Glob "files/sites-available/inner-tunnel").AsConfig | indent 2 }}
|
|
||||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
|
||||||
{{ (.Files.Glob "files/sites-available/coa").AsConfig | indent 2 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.status.enabled }}
|
|
||||||
{{ (.Files.Glob "files/sites-available/status").AsConfig | indent 2 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.tls.enabled }}
|
|
||||||
{{ (.Files.Glob "files/sites-available/tls").AsConfig | indent 2 }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
data:
|
|
||||||
{{ (.Files.Glob "files/policy/vlan").AsConfig | indent 2 }}
|
|
||||||
@@ -1,399 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{/* vim: set filetype=mustache: */}}
|
|
||||||
|
|
||||||
{{- $globalSecretName := printf "%s" (tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecret "context" $)) $) }}
|
|
||||||
apiVersion: {{ include "st-common.capabilities.deployment.apiVersion" . }}
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
revisionHistoryLimit: {{ .Values.revisionHistoryLimit }}
|
|
||||||
selector:
|
|
||||||
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 6 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
{{- if .Values.updateStrategy }}
|
|
||||||
strategy: {{- toYaml .Values.updateStrategy | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
checksum/configmap-env: {{ include (print $.Template.BasePath "/ConfigMap/envvars.yaml") . | sha256sum }}
|
|
||||||
checksum/configmap-mods: {{ include (print $.Template.BasePath "/ConfigMap/mods-enabled.yaml") . | sha256sum }}
|
|
||||||
checksum/configmap-sites: {{ include (print $.Template.BasePath "/ConfigMap/sites-enabled.yaml") . | sha256sum }}
|
|
||||||
checksum/secret-credentials: {{ include (print $.Template.BasePath "/Secret/credentials.yaml") . | sha256sum }}
|
|
||||||
checksum/secret-sql-tls: {{ include (print $.Template.BasePath "/Secret/sql-tls.yaml") . | sha256sum }}
|
|
||||||
checksum/secret-tls: {{ include (print $.Template.BasePath "/Secret/tls.yaml") . | sha256sum }}
|
|
||||||
{{- if .Values.podAnnotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.podAnnotations "context" $) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 8 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
{{- if .Values.podLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.podLabels "context" $) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
{{- if .Values.affinity }}
|
|
||||||
affinity: {{- include "st-common.tplvalues.render" (dict "value" .Values.affinity "context" $) | nindent 8 }}
|
|
||||||
{{- else }}
|
|
||||||
affinity:
|
|
||||||
podAffinity: {{- include "st-common.affinities.pods" (dict "type" .Values.podAffinityPreset "context" $) | nindent 10 }}
|
|
||||||
podAntiAffinity: {{- include "st-common.affinities.pods" (dict "type" .Values.podAntiAffinityPreset "context" $) | nindent 10 }}
|
|
||||||
nodeAffinity: {{- include "st-common.affinities.nodes" (dict "type" .Values.nodeAffinityPreset.type "key" .Values.nodeAffinityPreset.key "values" .Values.nodeAffinityPreset.values) | nindent 10 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- include "freeradius.imagePullSecrets" . | nindent 6 }}
|
|
||||||
{{- if .Values.hostAliases }}
|
|
||||||
hostAliases: {{- include "st-common.tplvalues.render" (dict "value" .Values.hostAliases "context" $) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.nodeSelector }}
|
|
||||||
nodeSelector: {{- include "st-common.tplvalues.render" (dict "value" .Values.nodeSelector "context" $) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.priorityClassName }}
|
|
||||||
priorityClassName: {{ .Values.priorityClassName | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.schedulerName }}
|
|
||||||
schedulerName: {{ .Values.schedulerName | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.podSecurityContext.enabled }}
|
|
||||||
securityContext: {{- omit .Values.podSecurityContext "enabled" | toYaml | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
serviceAccountName: {{ include "freeradius.serviceAccountName" . }}
|
|
||||||
{{- if .Values.tolerations }}
|
|
||||||
tolerations: {{- include "st-common.tplvalues.render" (dict "value" .Values.tolerations "context" .) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.topologySpreadConstraints }}
|
|
||||||
topologySpreadConstraints: {{- include "st-common.tplvalues.render" (dict "value" .Values.topologySpreadConstraints "context" .) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if or (and .Values.volumePermissions.enabled .Values.persistence.enabled) .Values.initContainers }}
|
|
||||||
initContainers:
|
|
||||||
{{- if .Values.initContainers }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.initContainers "context" $) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if and .Values.volumePermissions.enabled .Values.persistence.enabled }}
|
|
||||||
- name: volume-permissions
|
|
||||||
image: {{ include "freeradius.volumePermissions.image" . }}
|
|
||||||
imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }}
|
|
||||||
command:
|
|
||||||
- /bin/bash
|
|
||||||
args:
|
|
||||||
- -ec
|
|
||||||
- |
|
|
||||||
printf '%s\n' "[system] Change permission" >&2
|
|
||||||
chown -R {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }} {{ .Values.persistence.mountPath }}
|
|
||||||
chmod 0711 {{ .Values.persistence.mountPath }}
|
|
||||||
{{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }}
|
|
||||||
securityContext: {{- omit .Values.volumePermissions.securityContext "runAsUser" | toYaml | nindent 12 }}
|
|
||||||
{{- else }}
|
|
||||||
securityContext: {{- .Values.volumePermissions.securityContext | toYaml | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.volumePermissions.resources }}
|
|
||||||
resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: data
|
|
||||||
mountPath: {{ .Values.persistence.mountPath }}
|
|
||||||
{{- if .Values.persistence.subPath }}
|
|
||||||
subPath: {{ .Values.persistence.subPath }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
containers:
|
|
||||||
- name: freeradius
|
|
||||||
image: {{ include "freeradius.image" . }}
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy | quote }}
|
|
||||||
{{- if .Values.diagnosticMode.enabled }}
|
|
||||||
command: {{- include "st-common.tplvalues.render" (dict "value" .Values.diagnosticMode.command "context" $) | nindent 12 }}
|
|
||||||
{{- else if .Values.command }}
|
|
||||||
command: {{- include "st-common.tplvalues.render" (dict "value" .Values.command "context" $) | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.diagnosticMode.enabled }}
|
|
||||||
args: {{- include "st-common.tplvalues.render" (dict "value" .Values.diagnosticMode.args "context" $) | nindent 12 }}
|
|
||||||
{{- else if .Values.args }}
|
|
||||||
args: {{- include "st-common.tplvalues.render" (dict "value" .Values.args "context" $) | nindent 12 }}
|
|
||||||
{{- else }}
|
|
||||||
args:
|
|
||||||
- -fxx
|
|
||||||
- -l
|
|
||||||
- stdout
|
|
||||||
{{- end }}
|
|
||||||
env:
|
|
||||||
{{- if .Values.modsEnabled.sql.enabled }}
|
|
||||||
- name: FREERADIUS_MODS_SQL_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
{{- if .Values.auth.existingSecretPerPassword }}
|
|
||||||
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.databasePassword "context" $)) $ }}
|
|
||||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "databasePassword") }}
|
|
||||||
{{- else }}
|
|
||||||
name: {{ include "freeradius.database.secretName" . }}
|
|
||||||
key: {{ include "freeradius.database.secretKey" . }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.status.enabled }}
|
|
||||||
- name: FREERADIUS_SITES_STATUS_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
{{- if .Values.auth.existingSecretPerPassword }}
|
|
||||||
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.sitesStatusSecret "context" $)) $ }}
|
|
||||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "sitesStatusSecret") }}
|
|
||||||
{{- else }}
|
|
||||||
name: {{ $globalSecretName }}
|
|
||||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecret "key" "sites-status-secret") }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.tls.enabled }}
|
|
||||||
- name: FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
{{- if .Values.auth.existingSecretPerPassword }}
|
|
||||||
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.sitesTlsPrivKeyPassword "context" $)) $ }}
|
|
||||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "sitesTlsPrivKeyPassword") }}
|
|
||||||
{{- else }}
|
|
||||||
name: {{ $globalSecretName }}
|
|
||||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecret "key" "sites-tls-privkey-password") }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.extraEnvVars }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
envFrom:
|
|
||||||
- configMapRef:
|
|
||||||
name: {{ include "freeradius.names.envvars" . }}
|
|
||||||
{{- if .Values.extraEnvVarsCM }}
|
|
||||||
- configMapRef:
|
|
||||||
name: {{ .Values.extraEnvVarsCM }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.extraEnvVarsSecret }}
|
|
||||||
- secretRef:
|
|
||||||
name: {{ .Values.extraEnvVarsSecret }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.lifecycleHooks }}
|
|
||||||
lifecycle: {{- include "st-common.tplvalues.render" (dict "value" .Values.lifecycleHooks "context" $) | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
ports:
|
|
||||||
- name: auth
|
|
||||||
containerPort: {{ .Values.containerPorts.auth }}
|
|
||||||
protocol: UDP
|
|
||||||
- name: acct
|
|
||||||
containerPort: {{ .Values.containerPorts.acct }}
|
|
||||||
protocol: UDP
|
|
||||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
|
||||||
- name: coa
|
|
||||||
containerPort: {{ .Values.containerPorts.coa }}
|
|
||||||
protocol: UDP
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.tls.enabled }}
|
|
||||||
- name: radsec
|
|
||||||
containerPort: {{ .Values.containerPorts.radsec }}
|
|
||||||
protocol: TCP
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.status.enabled }}
|
|
||||||
- name: status
|
|
||||||
containerPort: {{ .Values.containerPorts.status }}
|
|
||||||
protocol: UDP
|
|
||||||
{{- end }}
|
|
||||||
{{- if not .Values.diagnosticMode.enabled }}
|
|
||||||
{{- if .Values.customStartupProbe }}
|
|
||||||
startupProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customStartupProbe "context" $) | nindent 12 }}
|
|
||||||
{{- else if .Values.startupProbe.enabled }}
|
|
||||||
startupProbe: {{- include "st-common.tplvalues.render" (dict "value" (omit .Values.startupProbe "enabled") "context" $) | nindent 12 }}
|
|
||||||
exec:
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
|
|
||||||
if [[ ! -f "{{ .Values.persistence.mountPath }}/.user_scripts_initialized" ]]; then
|
|
||||||
echo "Init scripts still not executed. Skipping check"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
{{- end }}
|
|
||||||
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.customLivenessProbe }}
|
|
||||||
livenessProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customLivenessProbe "context" $) | nindent 12 }}
|
|
||||||
{{- else if .Values.livenessProbe.enabled }}
|
|
||||||
livenessProbe: {{- omit .Values.livenessProbe "enabled" | toYaml | nindent 12 }}
|
|
||||||
exec:
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- >-
|
|
||||||
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.customReadinessProbe }}
|
|
||||||
readinessProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customReadinessProbe "context" $) | nindent 12 }}
|
|
||||||
{{- else if .Values.readinessProbe.enabled }}
|
|
||||||
readinessProbe: {{- omit .Values.readinessProbe "enabled" | toYaml | nindent 12 }}
|
|
||||||
exec:
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- >-
|
|
||||||
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .resources }}
|
|
||||||
resources: {{- include "st-common.tplvalues.render" (dict "value" .resources "context" $) | nindent 12 }}
|
|
||||||
{{- else if and .resourcesPreset (ne .resourcesPreset "none") }}
|
|
||||||
resources: {{- include "st-common.resources.preset" (dict "type" .resourcesPreset) | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.containerSecurityContext.enabled }}
|
|
||||||
securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: data
|
|
||||||
mountPath: {{ default "/startechnica/freeradius" .Values.persistence.mountPath }}
|
|
||||||
{{- if .Values.persistence.subPath }}
|
|
||||||
subPath: {{ .Values.persistence.subPath }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if or (.Files.Glob "files/radiusd.conf") .Values.configuration .Values.configurationConfigMap }}
|
|
||||||
- name: freeradius-config
|
|
||||||
mountPath: /etc/freeradius/radiusd.conf
|
|
||||||
subPath: radiusd.conf
|
|
||||||
{{- end }}
|
|
||||||
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
|
|
||||||
- name: custom-init-scripts
|
|
||||||
mountPath: /docker-entrypoint-initdb.d
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.modsEnabled.sql.enabled }}
|
|
||||||
- name: freeradius-mods
|
|
||||||
mountPath: /etc/freeradius/mods-enabled/sql
|
|
||||||
subPath: sql
|
|
||||||
{{- end }}
|
|
||||||
- name: freeradius-mods
|
|
||||||
mountPath: /etc/freeradius/mods-enabled/eap
|
|
||||||
subPath: eap
|
|
||||||
- name: freeradius-mods
|
|
||||||
mountPath: /etc/freeradius/mods-enabled/dynamic_clients
|
|
||||||
subPath: dynamic_clients
|
|
||||||
- name: freeradius-mods
|
|
||||||
mountPath: /etc/freeradius/mods-enabled/sqlippool
|
|
||||||
subPath: sqlippool
|
|
||||||
- name: freeradius-mods-config
|
|
||||||
mountPath: /etc/freeradius/mods-config/sql/main/mysql/queries.conf
|
|
||||||
subPath: queries.conf
|
|
||||||
- name: freeradius-radius-conf
|
|
||||||
mountPath: /etc/freeradius/radius.conf
|
|
||||||
subPath: radius.conf
|
|
||||||
- name: freeradius-filter
|
|
||||||
mountPath: /etc/freeradius/policy.d/filter
|
|
||||||
subPath: filter
|
|
||||||
- name: freeradius-vlan
|
|
||||||
mountPath: /etc/freeradius/policy.d/vlan
|
|
||||||
subPath: vlan
|
|
||||||
- name: freeradius-sites
|
|
||||||
mountPath: /etc/freeradius/sites-enabled/default
|
|
||||||
subPath: default
|
|
||||||
- name: freeradius-sites
|
|
||||||
mountPath: /etc/freeradius/sites-enabled/status
|
|
||||||
subPath: status
|
|
||||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
|
||||||
- name: freeradius-sites
|
|
||||||
mountPath: /etc/freeradius/sites-enabled/coa
|
|
||||||
subPath: coa
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.tls.enabled }}
|
|
||||||
- name: freeradius-sites
|
|
||||||
mountPath: /etc/freeradius/sites-enabled/tls
|
|
||||||
subPath: tls
|
|
||||||
- name: freeradius-tls
|
|
||||||
mountPath: /opt/startechnica/freeradius/certs
|
|
||||||
readOnly: true
|
|
||||||
{{- end }}
|
|
||||||
{{- if and .Values.modsEnabled.sql.enabled (eq .Values.modsEnabled.sql.dialect "sqlite") }}
|
|
||||||
- name: freeradius-sqlite
|
|
||||||
mountPath: {{ .Values.modsEnabled.sql.sqlite.filename | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.modsEnabled.sql.tls.enabled }}
|
|
||||||
- name: freeradius-sql-tls
|
|
||||||
mountPath: /opt/startechnica/freeradius/certs
|
|
||||||
{{- end }}
|
|
||||||
- name: shared-certs
|
|
||||||
mountPath: /opt/startechnica/freeradius/shared-certs
|
|
||||||
readOnly: true
|
|
||||||
- name: temp
|
|
||||||
mountPath: /startechnica/freeradius/tmp
|
|
||||||
{{- if .Values.extraVolumeMounts }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraVolumeMounts "context" $) | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sidecars }}
|
|
||||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.sidecars "context" $) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
volumes:
|
|
||||||
- name: freeradius-mods
|
|
||||||
configMap:
|
|
||||||
name: {{ printf "%s-mods" (include "st-common.names.fullname" .) }}
|
|
||||||
- name: freeradius-sites
|
|
||||||
configMap:
|
|
||||||
name: {{ printf "%s-sites" (include "st-common.names.fullname" .) }}
|
|
||||||
- name: freeradius-mods-config
|
|
||||||
configMap:
|
|
||||||
name: {{ printf "%s-mods-config" (include "st-common.names.fullname" .) }}
|
|
||||||
- name: freeradius-radius-conf
|
|
||||||
configMap:
|
|
||||||
name: {{ printf "%s-radius-conf" (include "st-common.names.fullname" .) }}
|
|
||||||
- name: freeradius-filter
|
|
||||||
configMap:
|
|
||||||
name: {{ printf "%s-filter" (include "st-common.names.fullname" .) }}
|
|
||||||
- name: freeradius-vlan
|
|
||||||
configMap:
|
|
||||||
name: {{ printf "%s-vlan" (include "st-common.names.fullname" .) }}
|
|
||||||
- name: temp
|
|
||||||
emptyDir: {}
|
|
||||||
- name: shared-certs
|
|
||||||
emptyDir: {}
|
|
||||||
- name: data
|
|
||||||
{{- if .Values.persistence.enabled }}
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: {{ include "freeradius.claimName" . }}
|
|
||||||
{{- else }}
|
|
||||||
emptyDir: {}
|
|
||||||
{{- end }}
|
|
||||||
{{- if and .Values.modsEnabled.sql.enabled (eq .Values.modsEnabled.sql.dialect "sqlite") }}
|
|
||||||
- name: freeradius-sqlite
|
|
||||||
emptyDir: {}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.tls.enabled }}
|
|
||||||
- name: freeradius-tls
|
|
||||||
secret:
|
|
||||||
secretName: {{ include "freeradius.tlsSecretName" . }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.modsEnabled.sql.tls.enabled }}
|
|
||||||
- name: freeradius-sql-tls
|
|
||||||
secret:
|
|
||||||
secretName: {{ include "freeradius.sqlTlsSecretName" . }}
|
|
||||||
items:
|
|
||||||
- key: tls.crt
|
|
||||||
path: sql-tls.crt
|
|
||||||
- key: tls.key
|
|
||||||
path: sql-tls.key
|
|
||||||
- key: ca.crt
|
|
||||||
path: sql-ca.crt
|
|
||||||
{{- end }}
|
|
||||||
{{- if or (.Files.Glob "files/radiusd.conf") .Values.configuration .Values.configurationConfigMap }}
|
|
||||||
- name: freeradius-config
|
|
||||||
configMap:
|
|
||||||
name: {{ include "freeradius.configurationCM" . }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
|
|
||||||
- name: custom-init-scripts
|
|
||||||
configMap:
|
|
||||||
name: {{ include "freeradius.initdbScriptsCM" . }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.extraVolumes }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraVolumes "context" $) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,69 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if and .Values.gateway.enabled (not .Values.gateway.existingGateway) }}
|
|
||||||
{{- if not (eq (include "st-common.capabilities.istioGateway.apiVersion" .) "false") }}
|
|
||||||
apiVersion: {{ include "st-common.capabilities.istioGateway.apiVersion" . }}
|
|
||||||
kind: Gateway
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations:
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
istio.io/gateway-name: {{ default "ingressgateway" .Values.gateway.name }}
|
|
||||||
servers:
|
|
||||||
- port:
|
|
||||||
name: auth
|
|
||||||
number: {{ .Values.service.ports.auth }}
|
|
||||||
protocol: UDP
|
|
||||||
hosts:
|
|
||||||
- {{ .Values.ingress.hostname }}
|
|
||||||
{{- range $host := .Values.ingress.extraHosts }}
|
|
||||||
- {{ $host.name | quote }}
|
|
||||||
{{- end }}
|
|
||||||
- port:
|
|
||||||
name: acct
|
|
||||||
number: {{ .Values.service.ports.acct }}
|
|
||||||
protocol: UDP
|
|
||||||
hosts:
|
|
||||||
- {{ .Values.ingress.hostname }}
|
|
||||||
{{- range $host := .Values.ingress.extraHosts }}
|
|
||||||
- {{ $host.name | quote }}
|
|
||||||
{{- end }}
|
|
||||||
- port:
|
|
||||||
name: coa
|
|
||||||
number: {{ .Values.service.ports.coa }}
|
|
||||||
protocol: UDP
|
|
||||||
hosts:
|
|
||||||
- {{ .Values.ingress.hostname }}
|
|
||||||
{{- range $host := .Values.ingress.extraHosts }}
|
|
||||||
- {{ $host.name | quote }}
|
|
||||||
{{- end }}
|
|
||||||
- port:
|
|
||||||
name: radsec
|
|
||||||
number: {{ .Values.service.ports.radsec }}
|
|
||||||
protocol: TLS
|
|
||||||
hosts:
|
|
||||||
- {{ .Values.ingress.hostname }}
|
|
||||||
{{- range $host := .Values.ingress.extraHosts }}
|
|
||||||
- {{ $host.name | quote }}
|
|
||||||
{{- end }}
|
|
||||||
tls:
|
|
||||||
mode: PASSTHROUGH
|
|
||||||
{{- if .Values.sitesEnabled.tls.enabled }}
|
|
||||||
credentialName: {{ include "freeradius.tlsSecretName" . }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,47 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if and .Values.gateway.enabled (not .Values.gateway.existingVirtualService) }}
|
|
||||||
{{- if not (eq (include "st-common.capabilities.istioVirtualService.apiVersion" .) "false") }}
|
|
||||||
apiVersion: {{ include "st-common.capabilities.istioVirtualService.apiVersion" . }}
|
|
||||||
kind: VirtualService
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations:
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
gateways:
|
|
||||||
- {{ printf "%s/%s" (include "st-common.names.namespace" .) (include "st-common.names.fullname" .) }}
|
|
||||||
hosts:
|
|
||||||
- {{ .Values.ingress.hostname }}
|
|
||||||
{{- range $host := .Values.ingress.extraHosts }}
|
|
||||||
- {{ $host | quote }}
|
|
||||||
{{- end }}
|
|
||||||
tls:
|
|
||||||
- match:
|
|
||||||
- port: {{ .Values.service.ports.radsec }}
|
|
||||||
sniHosts:
|
|
||||||
- {{ .Values.ingress.hostname }}
|
|
||||||
{{- range $host := .Values.ingress.extraHosts }}
|
|
||||||
- {{ $host | quote }}
|
|
||||||
{{- end }}
|
|
||||||
route:
|
|
||||||
- destination:
|
|
||||||
# host: {{ printf "%s.%s.svc.%s" (include "st-common.names.fullname" .) (include "st-common.names.namespace" .) .Values.clusterDomain }}
|
|
||||||
host: {{ printf "%s.%s.svc.cluster.local" (include "st-common.names.fullname" .) (include "st-common.names.namespace" .) }}
|
|
||||||
port:
|
|
||||||
number: {{ .Values.service.ports.radsec }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,57 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if .Values.networkPolicy.enabled }}
|
|
||||||
apiVersion: {{ include "st-common.capabilities.networkPolicy.apiVersion" . }}
|
|
||||||
kind: NetworkPolicy
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
podSelector:
|
|
||||||
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 6 }}
|
|
||||||
ingress:
|
|
||||||
- ports:
|
|
||||||
- port: {{ .Values.containerPorts.auth }}
|
|
||||||
protocol: UDP
|
|
||||||
- port: {{ .Values.containerPorts.acct }}
|
|
||||||
protocol: UDP
|
|
||||||
{{- if .Values.tls.enabled }}
|
|
||||||
- port: {{ .Values.containerPorts.radsec }}
|
|
||||||
protocol: TCP
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.metrics.enabled }}
|
|
||||||
- port: {{ .Values.containerPorts.metrics }}
|
|
||||||
protocol: TCP
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
|
||||||
- port: {{ .Values.containerPorts.coa }}
|
|
||||||
protocol: UDP
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.status.enabled }}
|
|
||||||
- port: {{ .Values.containerPorts.status }}
|
|
||||||
protocol: UDP
|
|
||||||
{{- end }}
|
|
||||||
{{- if not .Values.networkPolicy.allowExternal }}
|
|
||||||
from:
|
|
||||||
- podSelector:
|
|
||||||
matchLabels:
|
|
||||||
{{ include "st-common.names.fullname" . }}-client: "true"
|
|
||||||
- podSelector:
|
|
||||||
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 14 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
{{- if .Values.networkPolicy.additionalRules }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.networkPolicy.additionalRules "context" $) | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) -}}
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
apiVersion: v1
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if or .Values.persistence.annotations .Values.commonAnnotations }}
|
|
||||||
annotations:
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.persistence.annotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.persistence.annotations "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
{{- if not (empty .Values.persistence.accessModes) }}
|
|
||||||
{{- range .Values.persistence.accessModes }}
|
|
||||||
- {{ . | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- else }}
|
|
||||||
- {{ .Values.persistence.accessMode | quote }}
|
|
||||||
{{- end }}
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: {{ .Values.persistence.size | quote }}
|
|
||||||
{{- include "st-common.storage.class" (dict "persistence" .Values.persistence "global" .Values.global) | nindent 2 }}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,28 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if .Values.podDisruptionBudget.create }}
|
|
||||||
apiVersion: {{ include "st-common.capabilities.policy.apiVersion" . }}
|
|
||||||
kind: PodDisruptionBudget
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
{{- if .Values.podDisruptionBudget.minAvailable }}
|
|
||||||
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.podDisruptionBudget.maxUnavailable }}
|
|
||||||
maxUnavailable: {{ .Values.podDisruptionBudget.maxUnavailable }}
|
|
||||||
{{- end }}
|
|
||||||
selector:
|
|
||||||
matchLabels: {{ include "st-common.labels.matchLabels" . | nindent 6 }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{ if and .Values.metrics.enabled .Values.metrics.prometheusRules.enabled }}
|
|
||||||
apiVersion: monitoring.coreos.com/v1
|
|
||||||
kind: PrometheusRule
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ .Release.Namespace | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.metrics.prometheusRules.additionalLabels "context" $) | nindent 4 }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
groups:
|
|
||||||
- name: {{ include "st-common.names.fullname" . }}
|
|
||||||
rules:
|
|
||||||
{{- toYaml .Values.metrics.prometheusRules.rules | nindent 6 }}
|
|
||||||
{{ end }}
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if .Values.rbac.create }}
|
|
||||||
apiVersion: {{ include "st-common.capabilities.rbac.apiVersion" . }}
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- secrets
|
|
||||||
- configmaps
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,26 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if and .Values.serviceAccount.create .Values.rbac.create }}
|
|
||||||
apiVersion: {{ include "st-common.capabilities.rbac.apiVersion" . }}
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ include "freeradius.serviceAccountName" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if and (not .Values.auth.existingSecret) (not .Values.auth.existingSecretPerPassword) }}
|
|
||||||
{{- $secretName := include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecret "context" $) }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ $secretName }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
type: Opaque
|
|
||||||
data:
|
|
||||||
{{- if and (not .Values.mariadb.enabled) (not .Values.externalDatabase.existingSecret) }}
|
|
||||||
database-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "database-password" "length" 10 "providedValues" (list "externalDatabase.password") "context" $) }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if and (.Values.mariadb.enabled) (not (empty .Values.mariadb.auth.username)) }}
|
|
||||||
mariadb-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "mariadb-password" "providedValues" (list "mariadb.auth.password") "context" $) }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if (.Values.sitesEnabled.status.enabled) }}
|
|
||||||
sites-status-secret: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "sites-status-secret" "length" 10 "providedValues" (list "sitesEnabled.status.secret") "context" $) }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if (.Values.sitesEnabled.tls.enabled) }}
|
|
||||||
sites-tls-privkey-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "sites-tls-privkey-password" "length" 10 "providedValues" (list "sitesEnabled.tls.privateKeyPassword") "context" $) }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if (.Values.modsEnabled.sql.tls.enabled) }}
|
|
||||||
mods-sql-tls-privkey-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "mods-sql-tls-privkey-password" "length" 10 "providedValues" (list "modsEnabled.sql.tls.privateKeyPassword") "context" $) }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if and (include "freeradius.createSqlTlsSecret" .) (not .Values.tls.autoGenerator.certmanager.enabled) }}
|
|
||||||
{{- $ca := genCA "freeradius-ca" 365 }}
|
|
||||||
{{- $releaseNamespace := include "st-common.names.namespace" . }}
|
|
||||||
{{- $clusterDomain := .Values.clusterDomain }}
|
|
||||||
{{- $fullname := include "st-common.names.fullname" . }}
|
|
||||||
{{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $fullname $releaseNamespace) (printf "%s.%s" $fullname $releaseNamespace) $fullname }}
|
|
||||||
{{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}-sql-tls
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
type: kubernetes.io/tls
|
|
||||||
data:
|
|
||||||
ca.crt: {{ $ca.Cert | b64enc | quote }}
|
|
||||||
tls.crt: {{ $crt.Cert | b64enc | quote }}
|
|
||||||
tls.key: {{ $crt.Key | b64enc | quote }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if and (include "freeradius.createTlsSecret" .) (not .Values.tls.autoGenerator.certmanager.enabled) }}
|
|
||||||
{{- $ca := genCA "freeradius-ca" 365 }}
|
|
||||||
{{- $releaseNamespace := include "st-common.names.namespace" . }}
|
|
||||||
{{- $clusterDomain := .Values.clusterDomain }}
|
|
||||||
{{- $fullname := include "st-common.names.fullname" . }}
|
|
||||||
{{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $fullname $releaseNamespace) (printf "%s.%s" $fullname $releaseNamespace) $fullname }}
|
|
||||||
{{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}-tls
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
type: kubernetes.io/tls
|
|
||||||
data:
|
|
||||||
ca.crt: {{ $ca.Cert | b64enc | quote }}
|
|
||||||
tls.crt: {{ $crt.Cert | b64enc | quote }}
|
|
||||||
tls.key: {{ $crt.Key | b64enc | quote }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,98 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "st-common.names.fullname" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if or .Values.service.annotations .Values.commonAnnotations .Values.metrics.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.service.annotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.service.annotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if and .Values.metrics.enabled .Values.metrics.annotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.metrics.annotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
type: {{ default "ClusterIP" .Values.service.type }}
|
|
||||||
{{- if eq .Values.service.type "LoadBalancer" }}
|
|
||||||
allocateLoadBalancerNodePorts: {{ eq .Values.service.allocateLoadBalancerNodePorts "true" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if and .Values.service.clusterIP (eq .Values.service.type "ClusterIP") }}
|
|
||||||
clusterIP: {{ .Values.service.clusterIP }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if and .Values.service.externalTrafficPolicy (or (eq .Values.service.type "LoadBalancer") (eq .Values.service.type "NodePort")) }}
|
|
||||||
externalTrafficPolicy: {{ .Values.service.externalTrafficPolicy | quote }}
|
|
||||||
{{- end }}
|
|
||||||
ipFamilyPolicy: {{ .Values.service.ipFamilyPolicy }}
|
|
||||||
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerClass)) }}
|
|
||||||
loadBalancerClass: {{ .Values.service.loadBalancerClass }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if (and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerIP))) }}
|
|
||||||
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerSourceRanges)) }}
|
|
||||||
loadBalancerSourceRanges: {{ .Values.service.loadBalancerSourceRanges }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.service.sessionAffinity }}
|
|
||||||
sessionAffinity: {{ .Values.service.sessionAffinity }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.service.sessionAffinityConfig }}
|
|
||||||
sessionAffinityConfig: {{- include "st-common.tplvalues.render" (dict "value" .Values.service.sessionAffinityConfig "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
ports:
|
|
||||||
- name: udp-auth
|
|
||||||
port: {{ .Values.service.ports.auth }}
|
|
||||||
protocol: UDP
|
|
||||||
targetPort: {{ .Values.containerPorts.auth }}
|
|
||||||
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.auth) }}
|
|
||||||
nodePort: {{ coalesce .Values.service.nodePorts.auth .Values.service.nodePort }}
|
|
||||||
{{- else if eq .Values.service.type "ClusterIP" }}
|
|
||||||
nodePort: null
|
|
||||||
{{- end }}
|
|
||||||
- name: udp-acct
|
|
||||||
port: {{ .Values.service.ports.acct }}
|
|
||||||
protocol: UDP
|
|
||||||
targetPort: {{ .Values.containerPorts.acct }}
|
|
||||||
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.acct) }}
|
|
||||||
nodePort: {{ .Values.service.nodePorts.acct }}
|
|
||||||
{{- else if eq .Values.service.type "ClusterIP" }}
|
|
||||||
nodePort: null
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
|
||||||
- name: udp-coa
|
|
||||||
port: {{ .Values.service.ports.coa }}
|
|
||||||
protocol: UDP
|
|
||||||
targetPort: {{ .Values.containerPorts.coa }}
|
|
||||||
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.coa) }}
|
|
||||||
nodePort: {{ .Values.service.nodePorts.coa }}
|
|
||||||
{{- else if eq .Values.service.type "ClusterIP" }}
|
|
||||||
nodePort: null
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.tls.enabled }}
|
|
||||||
- name: tcp-radsec
|
|
||||||
port: {{ .Values.service.ports.radsec }}
|
|
||||||
protocol: TCP
|
|
||||||
targetPort: {{ .Values.containerPorts.radsec }}
|
|
||||||
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.radsec) }}
|
|
||||||
nodePort: {{ .Values.service.nodePorts.radsec }}
|
|
||||||
{{- else if eq .Values.service.type "ClusterIP" }}
|
|
||||||
nodePort: null
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
selector: {{ include "st-common.labels.matchLabels" . | nindent 4 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
---
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{- if .Values.serviceAccount.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ include "freeradius.serviceAccountName" . }}
|
|
||||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
|
||||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
|
||||||
app.kubernetes.io/component: freeradius
|
|
||||||
{{- if .Values.commonLabels }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if or .Values.serviceAccount.annotations .Values.commonAnnotations }}
|
|
||||||
annotations:
|
|
||||||
{{- if .Values.commonAnnotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.serviceAccount.annotations }}
|
|
||||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.serviceAccount.annotations "context" $) | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,95 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{/* Create a default fully qualified app name. We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). */}}
|
|
||||||
{{- define "freeradius.mariadb.fullname" -}}
|
|
||||||
{{- include "st-common.names.dependency.fullname" (dict "chartName" "mariadb" "chartValues" .Values.mariadb "context" $) -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the Database hostname */}}
|
|
||||||
{{- define "freeradius.database.host" -}}
|
|
||||||
{{- if eq .Values.mariadb.architecture "replication" }}
|
|
||||||
{{- ternary (include "freeradius.mariadb.fullname" .) .Values.externalDatabase.host .Values.mariadb.enabled -}}-primary
|
|
||||||
{{- else -}}
|
|
||||||
{{- ternary (include "freeradius.mariadb.fullname" .) .Values.externalDatabase.host .Values.mariadb.enabled -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the Database port */}}
|
|
||||||
{{- define "freeradius.database.port" -}}
|
|
||||||
{{- ternary "3306" .Values.externalDatabase.port .Values.mariadb.enabled | quote -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the Database database name */}}
|
|
||||||
{{- define "freeradius.database.name" -}}
|
|
||||||
{{- if .Values.mariadb.enabled }}
|
|
||||||
{{- if .Values.global.mariadb }}
|
|
||||||
{{- if .Values.global.mariadb.auth }}
|
|
||||||
{{- coalesce .Values.global.mariadb.auth.database .Values.mariadb.auth.database -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- .Values.mariadb.auth.database -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- .Values.mariadb.auth.database -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- .Values.externalDatabase.database -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the Database user */}}
|
|
||||||
{{- define "freeradius.database.user" -}}
|
|
||||||
{{- if .Values.mariadb.enabled }}
|
|
||||||
{{- if .Values.global.mariadb }}
|
|
||||||
{{- if .Values.global.mariadb.auth }}
|
|
||||||
{{- coalesce .Values.global.mariadb.auth.username .Values.mariadb.auth.username -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- .Values.mariadb.auth.username -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- .Values.mariadb.auth.username -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- .Values.externalDatabase.user -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the Database encrypted password */}}
|
|
||||||
{{- define "freeradius.database.secretName" -}}
|
|
||||||
{{- if .Values.mariadb.enabled }}
|
|
||||||
{{- if .Values.global.mariadb }}
|
|
||||||
{{- if .Values.global.mariadb.auth }}
|
|
||||||
{{- if .Values.global.mariadb.auth.existingSecret }}
|
|
||||||
{{- tpl .Values.global.mariadb.auth.existingSecret $ -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- default (include "st-common.secrets.name" (dict "existingSecret" .Values.mariadb.auth.existingSecret "context" $)) (tpl .Values.externalDatabase.existingSecret $) -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Add environment variables to configure database values */}}
|
|
||||||
{{- define "freeradius.database.secretKey" -}}
|
|
||||||
{{- if .Values.mariadb.enabled -}}
|
|
||||||
{{- print "mariadb-password" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- if .Values.externalDatabase.existingSecret -}}
|
|
||||||
{{- if .Values.externalDatabase.existingSecretPasswordKey -}}
|
|
||||||
{{- printf "%s" .Values.externalDatabase.existingSecretPasswordKey -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- print "database-password" -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- print "database-password" -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,140 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{/* Create the name of the service account to use */}}
|
|
||||||
{{- define "freeradius.serviceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccount.create }}
|
|
||||||
{{- default (include "st-common.names.fullname" .) .Values.serviceAccount.name }}
|
|
||||||
{{- else }}
|
|
||||||
{{- default "default" .Values.serviceAccount.name }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Return the path to the cert file. */}}
|
|
||||||
{{- define "freeradius.tlsCert" -}}
|
|
||||||
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/tls.crt" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certFilename -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the path to the cert key file. */}}
|
|
||||||
{{- define "freeradius.tlsCertKey" -}}
|
|
||||||
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/tls.key" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certKeyFilename -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the path to the CA cert file. */}}
|
|
||||||
{{- define "freeradius.tlsCACert" -}}
|
|
||||||
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/ca.crt" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certCAFilename -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Create the name of the SSL certificate to use */}}
|
|
||||||
{{- define "freeradius.tlsSecretName" -}}
|
|
||||||
{{- if .Values.tls.certificatesSecret }}
|
|
||||||
{{ .Values.tls.certificatesSecret }}
|
|
||||||
{{- else }}
|
|
||||||
{{- default (printf "%s-tls" (include "st-common.names.fullname" .)) }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return true if a TLS secret object should be created */}}
|
|
||||||
{{- define "freeradius.createTlsSecret" -}}
|
|
||||||
{{- if and .Values.tls.enabled .Values.tls.autoGenerated (not .Values.tls.certificatesSecret) }}
|
|
||||||
{{- true }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Validate values of FreeRADIUS - Auth TLS enabled */}}
|
|
||||||
{{- define "freeradius.validateValues.tls" -}}
|
|
||||||
{{- if and .Values.tls.enabled (not .Values.tls.autoGenerated) (not .Values.tls.certificatesSecret) }}
|
|
||||||
freeradius: tls.enabled
|
|
||||||
In order to enable TLS, you also need to provide
|
|
||||||
an existing secret containing the Keystore and Truststore or
|
|
||||||
enable auto-generated certificates.
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the path to the SQL cert file. */}}
|
|
||||||
{{- define "freeradius.sqlTlsCert" -}}
|
|
||||||
{{- if and .Values.modsEnabled.sql.tls.enabled }}
|
|
||||||
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/sql-tls.crt" -}}
|
|
||||||
{{- else if not (empty .Values.modsEnabled.sql.tls.certFilename) }}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certFilename -}}
|
|
||||||
{{- end }}
|
|
||||||
{{- else }}
|
|
||||||
{{- printf "" -}}
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the path to the SQL cert key file. */}}
|
|
||||||
{{- define "freeradius.sqlTlsCertKey" -}}
|
|
||||||
{{- if and .Values.modsEnabled.sql.tls.enabled }}
|
|
||||||
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/sql-tls.key" -}}
|
|
||||||
{{- else if not (empty .Values.modsEnabled.sql.tls.certKeyFilename) }}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certKeyFilename -}}
|
|
||||||
{{- end }}
|
|
||||||
{{- else }}
|
|
||||||
{{- printf "" -}}
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the path to the SQL CA cert file. */}}
|
|
||||||
{{- define "freeradius.sqlTlsCACert" -}}
|
|
||||||
{{- if and .Values.modsEnabled.sql.tls.enabled }}
|
|
||||||
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/sql-ca.crt" -}}
|
|
||||||
{{- else if not (empty .Values.modsEnabled.sql.tls.certCAFilename)}}
|
|
||||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certCAFilename -}}
|
|
||||||
{{- end }}
|
|
||||||
{{- else }}
|
|
||||||
{{- printf "" -}}
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Create the name of the secret for SQL SSL certificate to use */}}
|
|
||||||
{{- define "freeradius.sqlTlsSecretName" -}}
|
|
||||||
{{- if .Values.modsEnabled.sql.tls.certificatesSecret }}
|
|
||||||
{{ .Values.modsEnabled.sql.tls.certificatesSecret }}
|
|
||||||
{{- else }}
|
|
||||||
{{- default (printf "%s-sql-tls" (include "st-common.names.fullname" .)) }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return true if a TLS secret object should be created */}}
|
|
||||||
{{- define "freeradius.createSqlTlsSecret" -}}
|
|
||||||
{{- if and .Values.modsEnabled.sql.tls.enabled .Values.modsEnabled.sql.tls.autoGenerated (not .Values.modsEnabled.sql.tls.certificatesSecret) }}
|
|
||||||
{{- true }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Get the configuration ConfigMap name. */}}
|
|
||||||
{{- define "freeradius.configurationCM" -}}
|
|
||||||
{{- if .Values.configurationConfigMap -}}
|
|
||||||
{{- printf "%s" (tpl .Values.configurationConfigMap $) -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "%s-configuration" (include "st-common.names.fullname" .) -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Get the initialization scripts ConfigMap name. */}}
|
|
||||||
{{- define "freeradius.initdbScriptsCM" -}}
|
|
||||||
{{- if .Values.initdbScriptsConfigMap -}}
|
|
||||||
{{- printf "%s" .Values.initdbScriptsConfigMap -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "%s-init-scripts" (include "st-common.names.fullname" .) -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{/* Return the proper FreeRADIUS image name */}}
|
|
||||||
{{- define "freeradius.image" -}}
|
|
||||||
{{ include "st-common.images.image" (dict "imageRoot" .Values.image "global" .Values.global) }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the proper Docker Image Registry Secret Names */}}
|
|
||||||
{{- define "freeradius.imagePullSecrets" -}}
|
|
||||||
{{- include "st-common.images.pullSecrets" (dict "images" (list .Values.image .Values.volumePermissions.image .Values.metrics.image) "global" .Values.global) -}}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{/* vim: set filetype=mustache: */}}
|
|
||||||
|
|
||||||
{{- define "freeradius.names.envvars" -}}
|
|
||||||
{{- printf "%s-envvars" (include "st-common.names.fullname" .) -}}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
{{- /*
|
|
||||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
|
||||||
SPDX-License-Identifier: APACHE-2.0
|
|
||||||
*/}}
|
|
||||||
|
|
||||||
{{/* Return the FreeRADIUS PVC name. */}}
|
|
||||||
{{- define "freeradius.claimName" -}}
|
|
||||||
{{- if .Values.persistence.existingClaim }}
|
|
||||||
{{- printf "%s" (tpl .Values.persistence.existingClaim $) -}}
|
|
||||||
{{- else }}
|
|
||||||
{{- printf "%s" (include "st-common.names.fullname" .) -}}
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/* Return the proper image name (for the init container volume-permissions image) */}}
|
|
||||||
{{- define "freeradius.volumePermissions.image" -}}
|
|
||||||
{{ include "st-common.images.image" (dict "imageRoot" .Values.volumePermissions.image "global" .Values.global) }}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,44 +0,0 @@
|
|||||||
persistence:
|
|
||||||
enabled: true
|
|
||||||
# storageClass:
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: LoadBalancer
|
|
||||||
externalTrafficPolicy: Local
|
|
||||||
ipFamilyPolicy: PreferDualStack
|
|
||||||
|
|
||||||
modsEnabled:
|
|
||||||
sql:
|
|
||||||
enabled: true
|
|
||||||
dialect: mysql
|
|
||||||
|
|
||||||
externalDatabase:
|
|
||||||
# host: mariadb-infra-mariadb-galera.mariadb-infra.svc
|
|
||||||
host: mariadb-primary.mariadb.svc
|
|
||||||
port: 3306
|
|
||||||
user: radius_user
|
|
||||||
database: radiusdb
|
|
||||||
password: "aserfdertg"
|
|
||||||
|
|
||||||
sitesEnabled:
|
|
||||||
coa:
|
|
||||||
enabled: true
|
|
||||||
tls:
|
|
||||||
enabled: true
|
|
||||||
|
|
||||||
tls:
|
|
||||||
enabled: true
|
|
||||||
autoGenerated: true
|
|
||||||
|
|
||||||
# updateStrategy:
|
|
||||||
# type: Recreate
|
|
||||||
|
|
||||||
volumePermissions:
|
|
||||||
enabled: true
|
|
||||||
|
|
||||||
gateway:
|
|
||||||
enabled: true
|
|
||||||
dedicated: false
|
|
||||||
gatewayApi: false
|
|
||||||
name: "freeradius"
|
|
||||||
namespace: "istio-ingress"
|
|
||||||
+34
-919
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user