1 Commits
Author SHA1 Message Date
gitea_admin 98d32642cd Initial commit
- update else condition on the line 239 in templates/Deployment
- update  st-common version from 0.1.10 to 0.1.12 on Chart.yaml file
- add gitlab ci/cd pipeline to  package the Helm chart into a .tgz. and Publish it to GitLab’s Helm package registry
2025-06-16 17:14:06 +02:00
16 changed files with 133 additions and 1338 deletions
+3 -25
View File
@@ -8,13 +8,9 @@ stages:
variables:
CHART_NAME: "freeradius"
CHART_VERSION: "1.0.9"
CHART_VERSION: "1.0.3"
PACKAGE_PATH: "packages"
ST_COMMON_PROJECT_ID: "270"
COMMON_PROJECT_URL: "${CI_API_V4_URL}/projects/${ST_COMMON_PROJECT_ID}/packages/helm/stable"
HELM_EXPERIMENTAL_OCI: "1"
GITEA_URL: "gitea.infrastructure.helmholz.cloud"
GITEA_REPO: "oci://gitea.infrastructure.helmholz.cloud/gitea_admin/helm"
package_chart:
stage: package
@@ -22,7 +18,7 @@ package_chart:
name: alpine/helm:3.14.0
entrypoint: [""]
script:
- helm repo add st-common ${COMMON_PROJECT_URL} --username gitlab-ci-token --password $CI_JOB_TOKEN
- helm repo add startechnica https://startechnica.github.io/apps
- helm dependency build .
- mkdir -p $PACKAGE_PATH
- helm package . --destination $PACKAGE_PATH
@@ -41,22 +37,4 @@ publish_chart:
--form "chart=@${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz" \
"${CI_API_V4_URL}/projects/${CI_PROJECT_ID}/packages/helm/api/stable/charts"
only:
- main
push_chart_to_gitea:
stage: publish
image:
name: alpine/helm:3.14.0
entrypoint: [""]
variables:
GITEA_URL: "https://gitea.infrastructure.helmholz.cloud"
GITEA_USERNAME: "gitea_admin"
GITEA_PASSWORD: "$GITEA_PASSWORD"
script:
- echo "$GITEA_PASSWORD" | helm registry login $GITEA_URL --username $GITEA_USERNAME --password-stdin
- helm push ${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz $GITEA_REPO
when: manual
only:
- main
dependencies:
- package_chart
- main
-1
View File
@@ -1 +0,0 @@
.git/
+3 -3
View File
@@ -1,9 +1,9 @@
dependencies:
- name: st-common
repository: https://gitlab/api/v4/projects/270/packages/helm/stable
repository: https://startechnica.github.io/apps
version: 0.1.12
- name: mariadb
repository: oci://registry-1.docker.io/bitnamicharts
version: 20.5.9
digest: sha256:55c375d2786b3554c8e0d35dfe1e2fb4c6d67d2ba7ee5cbcdc7c3e0a9c564d01
generated: "2025-11-25T11:46:23.835203402+01:00"
digest: sha256:03a311ace58596d28267595eab6c85c5d39af13a5864dbe04be8931a2262b6c7
generated: "2025-06-16T16:20:04.252816273+02:00"
+2 -2
View File
@@ -4,7 +4,7 @@ apiVersion: v2
appVersion: 3.2.7
dependencies:
- name: st-common
repository: https://gitlab/api/v4/projects/270/packages/helm/stable
repository: https://startechnica.github.io/apps
version: 0.1.12
- condition: mariadb.enabled
name: mariadb
@@ -31,4 +31,4 @@ sources:
- https://freeradius.org/
- https://github.com/FreeRADIUS/freeradius-server
type: application
version: 1.0.9
version: 1.0.3
+1 -1
View File
@@ -211,7 +211,7 @@ server radsec {
# Require a client certificate.
#
require_client_cert = no
require_client_cert = yes
#
# As of version 2.1.10, client certificates can be validated via an external command. This allows dynamic CRLs or OCSP to be used.
Binary file not shown.
Binary file not shown.
-41
View File
@@ -1,41 +0,0 @@
# -*- text -*-
#
# $Id: cc2bd5fd22aa473b98af5dde3fac7a66e39a9e9d $
# This module loads RADIUS clients as needed, rather than when the server
# starts.
#
# There are no configuration entries for this module. Instead, it
# relies on the "client" configuration. You must:
#
# 1) link raddb/sites-enabled/dynamic_clients to
# raddb/sites-available/dynamic_clients
#
# 2) Define a client network/mask (see top of the above file)
#
# 3) uncomment the "directory" entry in that client definition
#
# 4) list "dynamic_clients" in the "authorize" section of the
# "dynamic_clients' virtual server. The default example already
# does this.
#
# 5) put files into the above directory, one per IP.
# e.g. file "192.0.2.1" should contain a normal client definition
# for a client with IP address 192.0.2.1.
#
# For more documentation, see the file:
#
# raddb/sites-available/dynamic-clients
#
dynamic_clients {
sql = "SELECT secret, shortname, type FROM nas WHERE nasname = '%{Packet-Src-IP-Address}'"
key = "%{Packet-Src-IP-Address}"
client {
ipaddr = "%{Packet-Src-IP-Address}"
secret = "%{reply:secret}"
shortname = "%{reply:shortname}"
nastype = "%{reply:type}"
}
}
File diff suppressed because it is too large Load Diff
+3 -4
View File
@@ -282,7 +282,6 @@ listen {
# Make *sure* that 'preprocess' comes before any realm if you
# need to setup hints for the remote radius server
authorize {
dynamic_clients
#
# Take a User-Name, and perform some checks on it, for spaces and other
# invalid characters. If the User-Name appears invalid, reject the
@@ -604,13 +603,13 @@ accounting {
#
# Create a 'detail'ed log of the packets.
# Note that accounting requests which are proxied are also logged in the detail file.
# detail
detail
# daily
# Update the wtmp file
#
# If you don't use "radlast", you can delete this line.
# unix
unix
# For Simultaneous-Use tracking.
# Due to packet losses in the network, the data here may be incorrect. There is little we can do about it.
@@ -623,7 +622,7 @@ accounting {
# Log traffic to an SQL database.
# See "Accounting queries" in mods-available/sql
sql
-sql
#
# If you receive stop packets with zero session length,
+4 -4
View File
@@ -63,7 +63,7 @@ listen {
# Send packets to the default virtual server
virtual_server = default
# clients = radsec
clients = radsec
# Use the haproxy "PROXY protocol".
#
@@ -373,7 +373,7 @@ listen {
#
# Require a client certificate.
#
require_client_cert = no
require_client_cert = yes
#
# As of version 2.1.10, client certificates can be
@@ -525,8 +525,8 @@ home_server tls {
#
# openssl dhparam -out certs/dh 1024
#
# dh_file = ${certdir}/dh
# random_file = /dev/urandom
dh_file = ${certdir}/dh
random_file = /dev/urandom
#
# The default fragment size is 1K.
+115
View File
@@ -0,0 +1,115 @@
apiVersion: v1
entries:
freeradius:
- annotations:
category: AccessManagement
apiVersion: v2
appVersion: 3.2.7
created: "2025-06-16T16:16:37.456715181+02:00"
dependencies:
- name: st-common
repository: https://startechnica.github.io/apps
version: 0.1.12
- condition: mariadb.enabled
name: mariadb
repository: oci://registry-1.docker.io/bitnamicharts
version: 20.x.x
description: FreeRADIUS is a modular, high performance free RADIUS suite developed
and distributed under the GNU General Public License, version 2, and is free
for download and use.
digest: da3ba6c773298d8e6ff0df4cb8eb2d9effb81e92d4991a74908a136c70457920
home: https://github.com/startechnica/apps/tree/main/charts/freeradius
icon: https://freeradius.org/img/wordmark.svg
keywords:
- freeradius
- radius
- mysql
- postgresql
- ldap
kubeVersion: '>=1.24.0-0'
maintainers:
- email: firmansyah@nainggolan.id
name: firmansyahn
url: https://firmansyah.nainggolan.id
name: freeradius
sources:
- https://freeradius.org/
- https://github.com/FreeRADIUS/freeradius-server
type: application
urls:
- freeradius-1.0.3.tgz
version: 1.0.3
mariadb:
- annotations:
category: Database
images: |
- name: mariadb
image: docker.io/bitnami/mariadb:11.4.7-debian-12-r1
- name: mysqld-exporter
image: docker.io/bitnami/mysqld-exporter:0.17.2-debian-12-r11
- name: os-shell
image: docker.io/bitnami/os-shell:12-debian-12-r46
licenses: Apache-2.0
tanzuCategory: service
apiVersion: v2
appVersion: 11.4.7
created: "2025-06-16T16:16:37.459591908+02:00"
dependencies:
- name: common
repository: oci://registry-1.docker.io/bitnamicharts
tags:
- bitnami-common
version: 2.x.x
description: MariaDB is an open source, community-developed SQL database server
that is widely in use around the world due to its enterprise features, flexibility,
and collaboration with leading tech firms.
digest: 1e5034974b28d6ab585efdaf9a345ea4e4d3024417b680b83f656a4c0b1e2a84
home: https://bitnami.com
icon: https://dyltqmyl993wv.cloudfront.net/assets/stacks/mariadb/img/mariadb-stack-220x234.png
keywords:
- mariadb
- mysql
- database
- sql
- prometheus
maintainers:
- name: Broadcom, Inc. All Rights Reserved.
url: https://github.com/bitnami/charts
name: mariadb
sources:
- https://github.com/bitnami/charts/tree/main/bitnami/mariadb
urls:
- charts/mariadb-20.5.7.tgz
version: 20.5.7
st-common:
- annotations:
artifacthub.io/changes: |
- kind: added
description: Add dotenv and envvars names helper
category: Infrastructure
apiVersion: v2
appVersion: 0.1.12
created: "2025-06-16T16:16:37.460145288+02:00"
description: A Library Helm Chart for grouping common logic between Startechnica
charts. This chart is not deployable by itself.
digest: 4c1c7304cf4dbb900b6fd847cf1d38e6f8d1db46dbf080b4d52c884b84a36747
home: https://github.com/startechnica/apps/tree/main/charts/common
icon: https://startechnica.github.io/apps/images/star.png
keywords:
- common
- helper
- template
- function
kubeVersion: '>=1.20.0-0'
maintainers:
- email: firmansyah@nainggolan.id
name: firmansyahn
url: https://firmansyah.nainggolan.id
name: st-common
sources:
- https://startechnica.github.io/apps
type: library
urls:
- charts/st-common-0.1.12.tgz
version: 0.1.12
generated: "2025-06-16T16:16:37.449242718+02:00"
Binary file not shown.
-3
View File
@@ -16,9 +16,6 @@ metadata:
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
{{- end }}
data:
{{ (.Files.Glob "files/mods-available/eap").AsConfig | indent 2 }}
{{ (.Files.Glob "files/mods-available/dynamic_clients").AsConfig | indent 2 }}
{{- if .Values.modsEnabled.sql.enabled }}
{{ (.Files.Glob "files/mods-available/sql").AsConfig | indent 2 }}
{{- end }}
-6
View File
@@ -274,12 +274,6 @@ spec:
mountPath: /etc/freeradius/mods-enabled/sql
subPath: sql
{{- end }}
- name: freeradius-mods
mountPath: /etc/freeradius/mods-enabled/eap
subPath: eap
- name: freeradius-mods
mountPath: /etc/freeradius/mods-enabled/dynamic_clients
subPath: dynamic_clients
- name: freeradius-sites
mountPath: /etc/freeradius/sites-enabled/default
subPath: default
+2 -2
View File
@@ -70,8 +70,8 @@ diagnosticMode:
## @param image.debug Specify if debug logs should be enabled
##
image:
registry: gitea.infrastructure.helmholz.cloud
repository: gitea_admin/freeradius-server
registry: docker.io
repository: freeradius/freeradius-server
tag: "3.2.7"
## Specify a imagePullPolicy
## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent'