Initial commit
- update else condition on the line 239 in templates/Deployment - update st-common version from 0.1.10 to 0.1.12 on Chart.yaml file - add gitlab ci/cd pipeline to package the Helm chart into a .tgz. and Publish it to GitLab’s Helm package registry
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
default:
|
||||
tags:
|
||||
- docker-test
|
||||
|
||||
stages:
|
||||
- package
|
||||
- publish
|
||||
|
||||
variables:
|
||||
CHART_NAME: "freeradius"
|
||||
CHART_VERSION: "1.0.3"
|
||||
PACKAGE_PATH: "packages"
|
||||
HELM_EXPERIMENTAL_OCI: "1"
|
||||
|
||||
package_chart:
|
||||
stage: package
|
||||
image:
|
||||
name: alpine/helm:3.14.0
|
||||
entrypoint: [""]
|
||||
script:
|
||||
- helm repo add startechnica https://startechnica.github.io/apps
|
||||
- helm dependency build .
|
||||
- mkdir -p $PACKAGE_PATH
|
||||
- helm package . --destination $PACKAGE_PATH
|
||||
artifacts:
|
||||
paths:
|
||||
- ${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz
|
||||
|
||||
|
||||
publish_chart:
|
||||
stage: publish
|
||||
image: alpine/curl:8.14.1
|
||||
script:
|
||||
- |
|
||||
curl --fail-with-body --request POST \
|
||||
--user gitlab-ci-token:$CI_JOB_TOKEN \
|
||||
--form "chart=@${PACKAGE_PATH}/${CHART_NAME}-${CHART_VERSION}.tgz" \
|
||||
"${CI_API_V4_URL}/projects/${CI_PROJECT_ID}/packages/helm/api/stable/charts"
|
||||
only:
|
||||
- main
|
||||
@@ -0,0 +1,9 @@
|
||||
dependencies:
|
||||
- name: st-common
|
||||
repository: https://startechnica.github.io/apps
|
||||
version: 0.1.12
|
||||
- name: mariadb
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 20.5.9
|
||||
digest: sha256:03a311ace58596d28267595eab6c85c5d39af13a5864dbe04be8931a2262b6c7
|
||||
generated: "2025-06-16T16:20:04.252816273+02:00"
|
||||
+34
@@ -0,0 +1,34 @@
|
||||
annotations:
|
||||
category: AccessManagement
|
||||
apiVersion: v2
|
||||
appVersion: 3.2.7
|
||||
dependencies:
|
||||
- name: st-common
|
||||
repository: https://startechnica.github.io/apps
|
||||
version: 0.1.12
|
||||
- condition: mariadb.enabled
|
||||
name: mariadb
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 20.x.x
|
||||
description: FreeRADIUS is a modular, high performance free RADIUS suite developed
|
||||
and distributed under the GNU General Public License, version 2, and is free for
|
||||
download and use.
|
||||
home: https://github.com/startechnica/apps/tree/main/charts/freeradius
|
||||
icon: https://freeradius.org/img/wordmark.svg
|
||||
keywords:
|
||||
- freeradius
|
||||
- radius
|
||||
- mysql
|
||||
- postgresql
|
||||
- ldap
|
||||
kubeVersion: '>=1.24.0-0'
|
||||
maintainers:
|
||||
- email: firmansyah@nainggolan.id
|
||||
name: firmansyahn
|
||||
url: https://firmansyah.nainggolan.id
|
||||
name: freeradius
|
||||
sources:
|
||||
- https://freeradius.org/
|
||||
- https://github.com/FreeRADIUS/freeradius-server
|
||||
type: application
|
||||
version: 1.0.3
|
||||
@@ -0,0 +1,325 @@
|
||||
<!--- app-name: FreeRADIUS -->
|
||||
|
||||
# Helm chart for FreeRADIUS
|
||||
|
||||
FreeRADIUS is a modular, high performance free RADIUS suite developed and distributed under the GNU General Public License, version 2, and is free for download and use.
|
||||
|
||||
[Overview of FreeRADIUS](https://freeradius.org/)
|
||||
|
||||
**This chart is not maintained by the upstream project and any issues with the chart should be raised [here](https://github.com/startechnica/apps/issues/new/choose)**
|
||||
|
||||
## TL;DR
|
||||
|
||||
```console
|
||||
helm repo add startechnica https://startechnica.github.io/apps
|
||||
helm install my-release startechnica/freeradius
|
||||
```
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Kubernetes 1.22+
|
||||
- Helm 3.10.0+
|
||||
|
||||
## Installing the Chart
|
||||
|
||||
To install the chart with the release name `my-release` on `my-release` namespace:
|
||||
|
||||
```console
|
||||
helm repo add startechnica https://startechnica.github.io/apps
|
||||
helm install my-release startechnica/freeradius --namespace my-release --create-namespace
|
||||
```
|
||||
|
||||
These commands deploy FreeRADIUS on the Kubernetes cluster in the default configuration.
|
||||
|
||||
> **Tip**: List all releases using `helm list -A`
|
||||
|
||||
## Uninstalling the Chart
|
||||
|
||||
To uninstall/delete the `my-release` deployment:
|
||||
|
||||
```console
|
||||
helm delete my-release --namespace my-release
|
||||
```
|
||||
|
||||
The command removes all the Kubernetes components associated with the chart and deletes the release.
|
||||
|
||||
## Parameters
|
||||
|
||||
### Global parameters
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ----- |
|
||||
| `global.imageRegistry` | Global Docker image registry | `""` |
|
||||
| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` |
|
||||
| `global.storageClass` | Global StorageClass for Persistent Volume(s) | `""` |
|
||||
| `global.namespaceOverride` | Override the namespace for resource deployed by the chart, but can itself be overridden by the local namespaceOverride | `""` |
|
||||
|
||||
|
||||
### Common parameters
|
||||
|
||||
| Name | Description | Value |
|
||||
| -------------------------- | ----------------------------------------------------------------------------------------------------------------- | --------------- |
|
||||
| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `""` |
|
||||
| `nameOverride` | String to partially override common.names.fullname template with a string (will prepend the release name) | `""` |
|
||||
| `namespaceOverride` | String to fully override common.names.namespace | `""` |
|
||||
| `fullnameOverride` | String to fully override common.names.fullname template with a string | `""` |
|
||||
| `commonAnnotations` | Annotations to add to all deployed objects | `{}` |
|
||||
| `commonLabels` | Labels to add to all deployed objects | `{}` |
|
||||
| `schedulerName` | Name of the Kubernetes scheduler (other than default) | `""` |
|
||||
| `clusterDomain` | Kubernetes DNS Domain name to use | `cluster.local` |
|
||||
| `extraDeploy` | Array of extra objects to deploy with the release (evaluated as a template) | `[]` |
|
||||
| `diagnosticMode.enabled` | Enable diagnostic mode (all probes will be disabled and the command will be overridden) | `false` |
|
||||
| `diagnosticMode.command` | Command to override all containers in the deployment | `[]` |
|
||||
| `diagnosticMode.args` | Args to override all containers in the deployment | `[]` |
|
||||
|
||||
|
||||
### FreeRADIUS parameters
|
||||
|
||||
| Name | Description | Value |
|
||||
| ----------------------------------------------| -------------------------------------------------------------------------------------------------------------------------| -------------------------------|
|
||||
| `image.registry` | FreeRADIUS image registry | `docker.io` |
|
||||
| `image.repository` | FreeRADIUS image repository | `freeradius/freeradius-server` |
|
||||
| `image.tag` | FreeRADIUS image tag (immutable tags are recommended) | `3.2.3` |
|
||||
| `image.pullPolicy` | FreeRADIUS image pull policy | `IfNotPresent` |
|
||||
| `image.pullSecrets` | Specify docker-registry secret names as an array | `[]` |
|
||||
| `image.debug` | Set to true if you would like to see extra information on logs | `false` |
|
||||
| `hostAliases` | Deployment pod host aliases | `[]` |
|
||||
| `command` | Override default container command (useful when using custom images) | `[]` |
|
||||
| `args` | Override default container args (useful when using custom images) | `[]` |
|
||||
| `extraEnvVars` | Extra environment variables to be set on FreeRADIUS containers | `[]` |
|
||||
| `extraEnvVarsCM` | ConfigMap with extra environment variables | `""` |
|
||||
| `extraEnvVarsSecret` | Secret with extra environment variables | `""` |
|
||||
| `service.type` | Kubernetes service type | `ClusterIP` |
|
||||
| `service.clusterIP` | Specific cluster IP when service type is cluster IP. Use `None` for headless service | `""` |
|
||||
| `service.ports.auth` | FreeRADIUS Authentication and Authorization service port | `1812` |
|
||||
| `service.ports.acct` | FreeRADIUS Accounting service port | `1813` |
|
||||
| `service.ports.coa` | FreeRADIUS CoA service port | `3799` |
|
||||
| `service.ports.radsec` | FreeRADIUS RadSec service port | `2083` |
|
||||
| `service.ports.status` | FreeRADIUS Status service port | `18121` |
|
||||
| `service.nodePorts.auth` | Specify the nodePort value for the LoadBalancer and NodePort for Authentication service types. | `""` |
|
||||
| `service.nodePorts.acct` | Specify the nodePort value for the LoadBalancer and NodePort for Accounting service types. | `""` |
|
||||
| `service.nodePorts.coa` | Specify the nodePort value for the LoadBalancer and NodePort for CoA service types. | `""` |
|
||||
| `service.nodePorts.radsec` | Specify the nodePort value for the LoadBalancer and NodePort for RadSec service types. | `""` |
|
||||
| `service.nodePorts.status` | Specify the nodePort value for the LoadBalancer and NodePort for Status service types. | `""` |
|
||||
| `service.extraPorts` | Extra ports to expose (normally used with the `sidecar` value) | `[]` |
|
||||
| `service.externalIPs` | External IP list to use with ClusterIP service type | `[]` |
|
||||
| `service.loadBalancerIP` | `loadBalancerIP` if service type is `LoadBalancer` | `""` |
|
||||
| `service.loadBalancerSourceRanges` | Addresses that are allowed when svc is `LoadBalancer` | `[]` |
|
||||
| `service.externalTrafficPolicy` | FreeRADIUS service external traffic policy | `Cluster` |
|
||||
| `service.annotations` | Additional annotations for FreeRADIUS service | `{}` |
|
||||
| `service.sessionAffinity` | Session Affinity for Kubernetes service, can be `None` or `ClientIP` | `None` |
|
||||
| `service.sessionAffinityConfig` | Additional settings for the sessionAffinity | `{}` |
|
||||
| `serviceAccount.create` | Specify whether a ServiceAccount should be created | `false` |
|
||||
| `serviceAccount.name` | Name of the service account to use. If not set and create is true, a name is generated using the fullname template. | `""` |
|
||||
| `serviceAccount.automountServiceAccountToken` | Automount service account token for the server service account | `false` |
|
||||
| `serviceAccount.annotations` | Annotations for service account. Evaluated as a template. Only used if `create` is `true`. | `{}` |
|
||||
| `command` | Override default container command (useful when using custom images) | `[]` |
|
||||
| `extraEnvVars` | Array containing extra env vars to configure FreeRADIUS | `[]` |
|
||||
| `extraEnvVarsCM` | ConfigMap containing extra env vars to configure FreeRADIUS | `""` |
|
||||
| `extraEnvVarsSecret` | Secret containing extra env vars to configure FreeRADIUS | `""` |
|
||||
| `rbac.create` | Specify whether RBAC resources should be created and used | `false` |
|
||||
| `podSecurityContext.enabled` | Enable security context | `true` |
|
||||
| `podSecurityContext.fsGroup` | Group ID for the container filesystem | `101` |
|
||||
| `podSecurityContext.runAsUser` | User ID for the container | `101` |
|
||||
| `containerSecurityContext.enabled` | Enabled FreeRADIUS container Security Context | `true` |
|
||||
| `containerSecurityContext.runAsUser` | Set FreeRADIUS container Security Context runAsUser | `101` |
|
||||
| `containerSecurityContext.runAsNonRoot` | Set FreeRADIUS container Security Context runAsNonRoot | `true` |
|
||||
| `tls.enabled` | Enable TLS support for replication traffic | `false` |
|
||||
| `tls.autoGenerated` | Generate automatically self-signed TLS certificates | `false` |
|
||||
| `tls.autoGenerator.certmanager.enabled` | | `false` |
|
||||
| `tls.certificatesSecret` | Name of the secret that contains the certificates | `"false"` |
|
||||
| `tls.certFilename` | Certificate filename | `""` |
|
||||
| `tls.certKeyFilename` | Certificate key filename | `""` |
|
||||
| `tls.certCAFilename` | CA Certificate filename | `""` |
|
||||
| `configuration` | Configuration for the FreeRADIUS server (`radiusd.conf`) | `""` |
|
||||
| `configurationConfigMap` | ConfigMap with the FreeRADIUS configuration files (Note: Overrides `configuration`). The value is evaluated as a template. | `""` |
|
||||
| `initdbScripts` | Specify dictionary of scripts to be run at first boot | `{}` |
|
||||
| `initdbScriptsConfigMap` | ConfigMap with the initdb scripts (Note: Overrides `initdbScripts`) | `""` |
|
||||
| `extraFlags` | FreeRADIUS additional command line flags | `""` |
|
||||
| `replicaCount` | Desired number of cluster nodes | `3` |
|
||||
| `podLabels` | Extra labels for FreeRADIUS pods | `{}` |
|
||||
| `podAnnotations` | Annotations for FreeRADIUS pods | `{}` |
|
||||
| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` |
|
||||
| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` |
|
||||
| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` |
|
||||
| `nodeAffinityPreset.key` | Node label key to match. Ignored if `affinity` is set. | `""` |
|
||||
| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` |
|
||||
| `affinity` | Affinity for pod assignment | `{}` |
|
||||
| `nodeSelector` | Node labels for pod assignment | `{}` |
|
||||
| `tolerations` | Tolerations for pod assignment | `[]` |
|
||||
| `topologySpreadConstraints` | Topology Spread Constraints for pods assignment | `[]` |
|
||||
| `lifecycleHooks` | for the galera container(s) to automate configuration before or after startup | `{}` |
|
||||
| `containerPorts.auth` | Auth database container port | `1812` |
|
||||
| `containerPorts.acct` | Acct cluster container port | `1813` |
|
||||
| `containerPorts.coa` | CoA container port | `3799` |
|
||||
| `containerPorts.radsec` | RadSec container port | `2083` |
|
||||
| `containerPorts.status` | Status container port | `18121` |
|
||||
| `persistence.enabled` | Enable persistence using PVC | `true` |
|
||||
| `persistence.existingClaim` | Provide an existing `PersistentVolumeClaim` | `""` |
|
||||
| `persistence.subPath` | Subdirectory of the volume to mount | `""` |
|
||||
| `persistence.mountPath` | Path to mount the volume at | `/startechnica/freeradius` |
|
||||
| `persistence.selector` | Selector to match an existing Persistent Volume (this value is evaluated as a template) | `{}` |
|
||||
| `persistence.storageClass` | Persistent Volume Storage Class | `""` |
|
||||
| `persistence.annotations` | Persistent Volume Claim annotations | `{}` |
|
||||
| `persistence.labels` | Persistent Volume Claim Labels | `{}` |
|
||||
| `persistence.accessModes` | Persistent Volume Access Modes | `["ReadWriteOnce"]` |
|
||||
| `persistence.size` | Persistent Volume Size | `8Gi` |
|
||||
| `priorityClassName` | Priority Class Name for Statefulset | `""` |
|
||||
| `initContainers` | Additional init containers (this value is evaluated as a template) | `[]` |
|
||||
| `sidecars` | Add additional sidecar containers (this value is evaluated as a template) | `[]` |
|
||||
| `extraVolumes` | Extra volumes | `[]` |
|
||||
| `extraVolumeMounts` | Mount extra volume(s) | `[]` |
|
||||
| `resources.limits` | The resources limits for the container | `{}` |
|
||||
| `resources.requests` | The requested resources for the container | `{}` |
|
||||
| `livenessProbe.enabled` | Turn on and off liveness probe | `true` |
|
||||
| `livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated | `120` |
|
||||
| `livenessProbe.periodSeconds` | How often to perform the probe | `10` |
|
||||
| `livenessProbe.timeoutSeconds` | When the probe times out | `1` |
|
||||
| `livenessProbe.failureThreshold` | Minimum consecutive failures for the probe | `3` |
|
||||
| `livenessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` |
|
||||
| `readinessProbe.enabled` | Turn on and off readiness probe | `true` |
|
||||
| `readinessProbe.initialDelaySeconds` | Delay before readiness probe is initiated | `30` |
|
||||
| `readinessProbe.periodSeconds` | How often to perform the probe | `10` |
|
||||
| `readinessProbe.timeoutSeconds` | When the probe times out | `1` |
|
||||
| `readinessProbe.failureThreshold` | Minimum consecutive failures for the probe | `3` |
|
||||
| `readinessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` |
|
||||
| `startupProbe.enabled` | Turn on and off startup probe | `false` |
|
||||
| `startupProbe.initialDelaySeconds` | Delay before startup probe is initiated | `120` |
|
||||
| `startupProbe.periodSeconds` | How often to perform the probe | `10` |
|
||||
| `startupProbe.timeoutSeconds` | When the probe times out | `1` |
|
||||
| `startupProbe.failureThreshold` | Minimum consecutive failures for the probe | `48` |
|
||||
| `startupProbe.successThreshold` | Minimum consecutive successes for the probe | `1` |
|
||||
| `customStartupProbe` | Custom liveness probe for the Web component | `{}` |
|
||||
| `customLivenessProbe` | Custom liveness probe for the Web component | `{}` |
|
||||
| `customReadinessProbe` | Custom rediness probe for the Web component | `{}` |
|
||||
| `podDisruptionBudget.create` | Specifies whether a Pod disruption budget should be created | `false` |
|
||||
| `podDisruptionBudget.minAvailable` | Minimum number / percentage of pods that should remain scheduled | `1` |
|
||||
| `podDisruptionBudget.maxUnavailable` | Maximum number / percentage of pods that may be made unavailable | `""` |
|
||||
| `metrics.enabled` | Start a side-car prometheus exporter | `false` |
|
||||
| `metrics.image.registry` | FreeRADIUS Prometheus exporter image registry | `""` |
|
||||
| `metrics.image.repository` | FreeRADIUS Prometheus exporter image repository | `""` |
|
||||
| `metrics.image.tag` | FreeRADIUS Prometheus exporter image tag (immutable tags are recommended) | `""` |
|
||||
| `metrics.image.pullPolicy` | FreeRADIUS Prometheus exporter image pull policy | `IfNotPresent` |
|
||||
| `metrics.image.pullSecrets` | FreeRADIUS Prometheus exporter image pull secrets | `[]` |
|
||||
| `metrics.extraFlags` | FreeRADIUS Prometheus exporter additional command line flags | `[]` |
|
||||
| `metrics.resources.limits` | The resources limits for the container | `{}` |
|
||||
| `metrics.resources.requests` | The requested resources for the container | `{}` |
|
||||
| `metrics.service.type` | Prometheus exporter service type | `ClusterIP` |
|
||||
| `metrics.service.port` | Prometheus exporter service port | `9104` |
|
||||
| `metrics.service.annotations` | Prometheus exporter service annotations | `{}` |
|
||||
| `metrics.service.loadBalancerIP` | Load Balancer IP if the Prometheus metrics server type is `LoadBalancer` | `""` |
|
||||
| `metrics.service.clusterIP` | Prometheus metrics service Cluster IP | `""` |
|
||||
| `metrics.service.loadBalancerSourceRanges` | Prometheus metrics service Load Balancer sources | `[]` |
|
||||
| `metrics.service.externalTrafficPolicy` | Prometheus metrics service external traffic policy | `Cluster` |
|
||||
| `metrics.serviceMonitor.enabled` | if `true`, creates a Prometheus Operator ServiceMonitor (also requires `metrics.enabled` to be `true`) | `false` |
|
||||
| `metrics.serviceMonitor.namespace` | Optional namespace which Prometheus is running in | `""` |
|
||||
| `metrics.serviceMonitor.jobLabel` | The name of the label on the target service to use as the job name in prometheus. | `""` |
|
||||
| `metrics.serviceMonitor.interval` | How frequently to scrape metrics (use by default, falling back to Prometheus' default) | `""` |
|
||||
| `metrics.serviceMonitor.scrapeTimeout` | Timeout after which the scrape is ended | `""` |
|
||||
| `metrics.serviceMonitor.selector` | ServiceMonitor selector labels | `{}` |
|
||||
| `metrics.serviceMonitor.relabelings` | RelabelConfigs to apply to samples before scraping | `[]` |
|
||||
| `metrics.serviceMonitor.metricRelabelings` | MetricRelabelConfigs to apply to samples before ingestion | `[]` |
|
||||
| `metrics.serviceMonitor.honorLabels` | honorLabels chooses the metric's labels on collisions with target labels | `false` |
|
||||
| `metrics.serviceMonitor.labels` | ServiceMonitor extra labels | `{}` |
|
||||
| `metrics.prometheusRules.enabled` | if `true`, creates a Prometheus Operator PrometheusRule (also requires `metrics.enabled` to be `true`, and makes little sense without ServiceMonitor) | `false` |
|
||||
| `metrics.prometheusRules.additionalLabels` | Additional labels to add to the PrometheusRule so it is picked up by the operator | `{}` |
|
||||
| `metrics.prometheusRules.rules` | PrometheusRule rules to configure | `{}` |
|
||||
|
||||
|
||||
### Custom FreeRADIUS enabled mods parameters
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------------------------ | --------------------------------------------------- | ----------------- |
|
||||
| `modsEnabled.sql.enabled` | Enable FreeRADIUS SQL module | `false` |
|
||||
| `modsEnabled.sql.dialect` | The driver module used to execute the queries. | `mysql` |
|
||||
| `modsEnabled.sql.table.acct1` | Tables containing 'accounting' items | `radacct` |
|
||||
| `modsEnabled.sql.table.acct2` | Tables containing 'accounting' items | `radacct` |
|
||||
| `modsEnabled.sql.table.authcheck` | Tables containing 'check' items | `radcheck` |
|
||||
| `modsEnabled.sql.table.authreply` | Tables containing 'reply' items | `radreply` |
|
||||
| `modsEnabled.sql.table.client` | Table to keep radius client info | `nas` |
|
||||
| `modsEnabled.sql.table.groupcheck` | Tables containing 'check' items | `radgroupcheck` |
|
||||
| `modsEnabled.sql.table.groupreply` | Tables containing 'reply' items | `radgroupreply` |
|
||||
| `modsEnabled.sql.table.postauth` | Allow for storing data after authentication | `radpostauth` |
|
||||
| `modsEnabled.sql.table.usergroup` | Table to keep group info | `radusergroup` |
|
||||
| `modsEnabled.sql.tls.enabled` | Enable FreeRADIUS SQL TLS module | `false` |
|
||||
| `modsEnabled.sql.tls.autoGenerated` | | `false` |
|
||||
| `modsEnabled.sql.tls.certificatesSecret` | | `""` |
|
||||
| `modsEnabled.sql.tls.certFilename` | | `""` |
|
||||
| `modsEnabled.sql.tls.certKeyFilename` | | `""` |
|
||||
| `modsEnabled.sql.tls.certCAFilename` | | `""` |
|
||||
| `modsEnabled.sql.tls.existingTlsSecret` | | `""` |
|
||||
| `modsEnabled.sql.tls.privateKeyPassword` | | `""` |
|
||||
|
||||
|
||||
### Custom FreeRADIUS enabled sites parameters
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------------------------ | ------------------------------------------------------------------------------- | ----------------- |
|
||||
| `sitesEnabled.coa.enabled` | Enable FreeRADIUS coa service | `false` |
|
||||
| `sitesEnabled.status.enabled` | Enable FreeRADIUS status service | `true` |
|
||||
| `sitesEnabled.tls.enabled` | Enable FreeRADIUS radsec service | `false` |
|
||||
| `sitesEnabled.tls.cipher` | | `false` |
|
||||
| `sitesEnabled.tls.privateKeyPassword` | | `false` |
|
||||
|
||||
|
||||
Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example,
|
||||
|
||||
```console
|
||||
helm install my-release \
|
||||
--set imagePullPolicy=Always \
|
||||
startechnica/freeradius
|
||||
```
|
||||
|
||||
The above command sets the `imagePullPolicy` to `Always`.
|
||||
|
||||
Alternatively, a YAML file that specifies the values for the parameters can be provided while installing the chart. For example,
|
||||
|
||||
```console
|
||||
helm install my-release startechnica/freeradius -f values.yaml
|
||||
```
|
||||
|
||||
> **Tip**: You can use the default [values.yaml](values.yaml)
|
||||
|
||||
## Configuration and installation details
|
||||
|
||||
### Adding extra environment variables
|
||||
|
||||
In case you want to add extra environment variables (useful for advanced operations like custom init scripts), you can use the `extraEnvVars` property.
|
||||
|
||||
```yaml
|
||||
extraEnvVars:
|
||||
- name: LOG_LEVEL
|
||||
value: error
|
||||
```
|
||||
|
||||
Alternatively, you can use a ConfigMap or a Secret with the environment variables. To do so, use the `extraEnvVarsCM` or the `extraEnvVarsSecret` values.
|
||||
|
||||
### Setting Pod's affinity
|
||||
|
||||
This chart allows you to set your custom affinity using the `affinity` parameter. Find more information about Pod's affinity in the [kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity).
|
||||
|
||||
### Deploying extra resources
|
||||
|
||||
There are cases where you may want to deploy extra objects, such a ConfigMap containing your app's configuration or some extra deployment with a micro service used by your app. For covering this case, the chart allows adding the full specification of other objects using the `extraDeploy` parameter.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
Find more information about how to deal with common errors related to Startechnica's Helm charts in [this troubleshooting guide](https://startechnica.github.io/doc/troubleshoot-helm-chart-issues).
|
||||
|
||||
## Upgrading
|
||||
|
||||
## License
|
||||
|
||||
Copyright © 2023 Startechnica
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
@@ -0,0 +1,55 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# Sample virtual server for receiving a CoA or Disconnect-Request packet.
|
||||
#
|
||||
server coa {
|
||||
namespace = $ENV{FREERADIUS_SITES_NAMESPACE}
|
||||
|
||||
# Listen on the CoA port.
|
||||
#
|
||||
# This uses the normal set of clients, with the same secret as for
|
||||
# authentication and accounting.
|
||||
#
|
||||
listen {
|
||||
type = CoA-Request
|
||||
type = Disconnect-Request
|
||||
|
||||
transport = udp
|
||||
|
||||
udp {
|
||||
ipaddr = $ENV{FREERADIUS_SITES_COA_LISTEN}
|
||||
port = $ENV{FREERADIUS_SITES_COA_PORT}
|
||||
}
|
||||
}
|
||||
|
||||
# Receive a CoA request
|
||||
recv CoA-Request {
|
||||
ok
|
||||
}
|
||||
|
||||
# Send a CoA ACK
|
||||
send CoA-ACK {
|
||||
ok
|
||||
}
|
||||
|
||||
# Send a CoA NAK
|
||||
send CoA-NAK {
|
||||
ok
|
||||
}
|
||||
|
||||
# Receive a Disconnect request
|
||||
recv Disconnect-Request {
|
||||
ok
|
||||
}
|
||||
|
||||
# Send a Disconnect ACK
|
||||
send Disconnect-ACK {
|
||||
ok
|
||||
}
|
||||
|
||||
# Send a Disconnect NAK
|
||||
send Disconnect-NAK {
|
||||
ok
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,247 @@
|
||||
######################################################################
|
||||
#
|
||||
# RADIUS over TLS
|
||||
#
|
||||
######################################################################
|
||||
|
||||
server radsec {
|
||||
listen {
|
||||
transport = tls
|
||||
|
||||
type = Access-Request
|
||||
type = Accounting-Request
|
||||
|
||||
tls {
|
||||
|
||||
ipaddr = $ENV{FREERADIUS_SITES_TLS_LISTEN}
|
||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
||||
|
||||
# Connection limiting for sockets with "proto = tcp".
|
||||
#
|
||||
limit {
|
||||
# Limit the number of simultaneous TCP connections to the socket
|
||||
#
|
||||
# The default is 16.
|
||||
# Setting this to 0 means "no limit"
|
||||
max_connections = 16
|
||||
|
||||
# The per-socket "max_requests" option does not exist.
|
||||
|
||||
# The lifetime, in seconds, of a TCP connection. After this lifetime, the connection will be closed.
|
||||
#
|
||||
# Setting this to 0 means "forever".
|
||||
lifetime = 0
|
||||
|
||||
# The idle timeout, in seconds, of a TCP connection.
|
||||
# If no packets have been received over the connection for this time, the connection will be closed.
|
||||
# Setting this to 0 means "no timeout".
|
||||
#
|
||||
# We STRONGLY RECOMMEND that you set an idle timeout.
|
||||
idle_timeout = 30
|
||||
}
|
||||
|
||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
||||
|
||||
# If Private key & Certificate are located in the same file, then private_key_file &
|
||||
# certificate_file must contain the same file name.
|
||||
#
|
||||
# If ca_file (below) is not used, then the certificate_file below MUST include not only the server certificate, but ALSO all
|
||||
# of the CA certificates used to sign the server certificate.
|
||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
||||
|
||||
# Trusted Root CA list
|
||||
#
|
||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
||||
#
|
||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
||||
# In that case, this CA file should contain *one* CA certificate.
|
||||
#
|
||||
# This parameter is used only for EAP-TLS, when you issue client certificates. If you do not use client certificates, and you do not want
|
||||
# to permit EAP-TLS authentication, then delete this configuration item.
|
||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
||||
|
||||
#
|
||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
||||
#
|
||||
# openssl dhparam -out certs/dh 1024
|
||||
dh_file = ${certdir}/dh
|
||||
|
||||
#
|
||||
# If your system doesn't have /dev/urandom, you will need to create this file, and periodically change its contents.
|
||||
# For security reasons, FreeRADIUS doesn't write to files in its configuration directory.
|
||||
# random_file = /dev/urandom
|
||||
|
||||
#
|
||||
# The default fragment size is 1K. However, it's possible to send much more data than that over a TCP connection. The upper limit is 64K.
|
||||
# Setting the fragment size to more than 1K means that there are fewer round trips when setting up a TLS connection. But only if the certificates are large.
|
||||
fragment_size = 8192
|
||||
|
||||
# include_length is a flag which is by default set to yes If set to yes, Total Length of the message is
|
||||
# included in EVERY packet we send.
|
||||
# If set to no, Total Length of the message is included ONLY in the First packet of a fragment series.
|
||||
# include_length = yes
|
||||
|
||||
# Check the Certificate Revocation List
|
||||
#
|
||||
# 1) Copy CA certificates and CRLs to same directory.
|
||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
||||
# 'c_rehash' is OpenSSL's command.
|
||||
# 3) uncomment the line below.
|
||||
# 5) Restart radiusd
|
||||
# check_crl = yes
|
||||
ca_path = ${cadir}
|
||||
|
||||
# Accept an expired Certificate Revocation List
|
||||
#
|
||||
# allow_expired_crl = no
|
||||
|
||||
# Accept a not-yet-valid Certificate Revocation List
|
||||
#
|
||||
# allow_not_yet_valid_crl = no
|
||||
|
||||
#
|
||||
# If check_cert_issuer is set, the value will
|
||||
# be checked against the DN of the issuer in
|
||||
# the client certificate. If the values do not
|
||||
# match, the certificate verification will fail,
|
||||
# rejecting the user.
|
||||
#
|
||||
# This check can be done more generally by checking
|
||||
# the value of the TLS-Client-Cert-Issuer attribute.
|
||||
# This check can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
||||
|
||||
#
|
||||
# If check_cert_cn is set, the value will
|
||||
# be xlat'ed and checked against the CN
|
||||
# in the client certificate. If the values
|
||||
# do not match, the certificate verification
|
||||
# will fail rejecting the user.
|
||||
#
|
||||
# This check is done only if the previous
|
||||
# "check_cert_issuer" is not set, or if
|
||||
# the check succeeds.
|
||||
#
|
||||
# This check can be done more generally by checking
|
||||
# the value of the TLS-Client-Cert-Common-Name attribute.
|
||||
# This check can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_cn = %{User-Name}
|
||||
#
|
||||
# Set this option to specify the allowed
|
||||
# TLS cipher suites. The format is listed
|
||||
# in "man 1 ciphers".
|
||||
cipher_list = "DEFAULT"
|
||||
|
||||
# If enabled, OpenSSL will use server cipher list
|
||||
# (possibly defined by cipher_list option above)
|
||||
# for choosing right cipher suite rather than
|
||||
# using client-specified list which is OpenSSl default
|
||||
# behavior. Having it set to 'yes' is best practice
|
||||
# for TLS.
|
||||
cipher_server_preference = yes
|
||||
|
||||
#
|
||||
# Session resumption / fast reauthentication
|
||||
# cache.
|
||||
#
|
||||
# The cache contains the following information:
|
||||
#
|
||||
# session Id - unique identifier, managed by SSL
|
||||
# User-Name - from the Access-Accept
|
||||
# Stripped-User-Name - from the Access-Request
|
||||
# Cached-Session-Policy - from the Access-Accept
|
||||
#
|
||||
# The "Cached-Session-Policy" is the name of a
|
||||
# policy which should be applied to the cached
|
||||
# session. This policy can be used to assign
|
||||
# VLANs, IP addresses, etc. It serves as a useful
|
||||
# way to re-apply the policy from the original
|
||||
# Access-Accept to the subsequent Access-Accept
|
||||
# for the cached session.
|
||||
#
|
||||
# On session resumption, these attributes are
|
||||
# copied from the cache, and placed into the
|
||||
# reply list.
|
||||
#
|
||||
# You probably also want "use_tunneled_reply = yes"
|
||||
# when using fast session resumption.
|
||||
#
|
||||
cache {
|
||||
#
|
||||
# Lifetime of the cached entries, in hours.
|
||||
# The sessions will be deleted after this
|
||||
# time.
|
||||
#
|
||||
lifetime = 24 # hours
|
||||
|
||||
#
|
||||
# Internal "name" of the session cache.
|
||||
# Used to distinguish which TLS context
|
||||
# sessions belong to.
|
||||
#
|
||||
# The server will generate a random value
|
||||
# if unset. This will change across server
|
||||
# restart so you MUST set the "name" if you
|
||||
# want to persist sessions (see below).
|
||||
#
|
||||
# If you use IPv6, change the "ipaddr" below
|
||||
# to "ipv6addr"
|
||||
#
|
||||
#name = "TLS ${..ipaddr} ${..port} ${..proto}"
|
||||
|
||||
#
|
||||
# Simple directory-based storage of sessions.
|
||||
# Two files per session will be written, the SSL
|
||||
# state and the cached VPs. This will persist session
|
||||
# across server restarts.
|
||||
#
|
||||
# The server will need write perms, and the directory
|
||||
# should be secured from anyone else. You might want
|
||||
# a script to remove old files from here periodically:
|
||||
#
|
||||
# find ${logdir}/tlscache -mtime +2 -exec rm -f {} \;
|
||||
#
|
||||
# This feature REQUIRES "name" option be set above.
|
||||
#
|
||||
#persist_dir = "${logdir}/tlscache"
|
||||
}
|
||||
|
||||
# Require a client certificate.
|
||||
#
|
||||
require_client_cert = yes
|
||||
|
||||
#
|
||||
# As of version 2.1.10, client certificates can be validated via an external command. This allows dynamic CRLs or OCSP to be used.
|
||||
#
|
||||
# This configuration is commented out in the default configuration. Uncomment it, and configure the correct paths below to enable it.
|
||||
#
|
||||
verify {
|
||||
# A temporary directory where the client certificates are stored. This directory MUST be owned by the UID of the server,
|
||||
# and MUST not be accessible by any other users. When the server starts, it will do "chmod go-rwx" on the directory, for
|
||||
# security reasons. The directory MUST exist when the server starts.
|
||||
#
|
||||
# You should also delete all of the files in the directory when the server starts.
|
||||
tmpdir = /startechnica/freeradius/tmp
|
||||
|
||||
# The command used to verify the client cert. We recommend using the OpenSSL command-line tool.
|
||||
#
|
||||
# The ${..ca_path} text is a reference to the ca_path variable defined above.
|
||||
#
|
||||
# The %{TLS-Client-Cert-Filename} is the name of the temporary file containing the cert in PEM format. This file is automatically
|
||||
# deleted by the server when the command returns.
|
||||
# client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
recv Access-Request {
|
||||
ok
|
||||
}
|
||||
|
||||
recv Accounting-Request {
|
||||
ok
|
||||
}
|
||||
}
|
||||
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,3 @@
|
||||
You can copy here your custom .sh, .sql or .sql.gz file so they are executed during the first boot of the image.
|
||||
|
||||
More info in the [freeradius/freeradius-server](https://hub.docker.com/r/freeradius/freeradius-server) repository.
|
||||
@@ -0,0 +1,366 @@
|
||||
# -*- text -*-
|
||||
##
|
||||
## mods-available/sql -- SQL modules
|
||||
##
|
||||
## $Id: cfeac63ea87c30fead8457af6d10f5c3a0f48aef $
|
||||
|
||||
######################################################################
|
||||
#
|
||||
# Configuration for the SQL module
|
||||
#
|
||||
# The database schemas and queries are located in subdirectories:
|
||||
#
|
||||
# sql/<DB>/main/schema.sql Schema
|
||||
# sql/<DB>/main/queries.conf Authorisation and Accounting queries
|
||||
#
|
||||
# Where "DB" is mysql, mssql, oracle, or postgresql.
|
||||
#
|
||||
# The name used to query SQL is sql_user_name, which is set in the file
|
||||
#
|
||||
# raddb/mods-config/sql/main/${dialect}/queries.conf
|
||||
#
|
||||
# If you are using realms, that configuration should be changed to use
|
||||
# the Stripped-User-Name attribute. See the comments around sql_user_name
|
||||
# for more information.
|
||||
#
|
||||
|
||||
sql {
|
||||
#
|
||||
# The dialect of SQL being used.
|
||||
#
|
||||
# Allowed dialects are:
|
||||
#
|
||||
# mssql
|
||||
# mysql
|
||||
# oracle
|
||||
# postgresql
|
||||
# sqlite
|
||||
# mongo
|
||||
#
|
||||
# dialect = "sqlite"
|
||||
dialect = $ENV{FREERADIUS_MODS_SQL_DIALECT}
|
||||
|
||||
#
|
||||
# The driver module used to execute the queries. Since we
|
||||
# don't know which SQL drivers are being used, the default is
|
||||
# "rlm_sql_null", which just logs the queries to disk via the
|
||||
# "logfile" directive, below.
|
||||
#
|
||||
# In order to talk to a real database, delete the next line,
|
||||
# and uncomment the one after it.
|
||||
#
|
||||
# If the dialect is "mssql", then the driver should be set to
|
||||
# one of the following values, depending on your system:
|
||||
#
|
||||
# rlm_sql_db2
|
||||
# rlm_sql_firebird
|
||||
# rlm_sql_freetds
|
||||
# rlm_sql_iodbc
|
||||
# rlm_sql_unixodbc
|
||||
#
|
||||
# driver = "rlm_sql_null"
|
||||
driver = "rlm_sql_${dialect}"
|
||||
|
||||
#
|
||||
# Driver-specific subsections. They will only be loaded and
|
||||
# used if "driver" is something other than "rlm_sql_null".
|
||||
# When a real driver is used, the relevant driver
|
||||
# configuration section is loaded, and all other driver
|
||||
# configuration sections are ignored.
|
||||
#
|
||||
sqlite {
|
||||
# Path to the sqlite database
|
||||
filename = $ENV{FREERADIUS_MODS_SQL_SQLITE_FILENAME}
|
||||
|
||||
# How long to wait for write locks on the database to be released (in ms) before giving up.
|
||||
busy_timeout = $ENV{FREERADIUS_MODS_SQL_SQLITE_BUSY_TIMEOUT}
|
||||
|
||||
# If the file above does not exist and bootstrap is set
|
||||
# a new database file will be created, and the SQL statements
|
||||
# contained within the bootstrap file will be executed.
|
||||
bootstrap = "${modconfdir}/${..:name}/main/sqlite/schema.sql"
|
||||
}
|
||||
|
||||
mysql {
|
||||
# If any of the files below are set, TLS encryption is enabled
|
||||
tls {
|
||||
# ca_file = $ENV{FREERADIUS_MODS_SQL_TLS_CACERT}
|
||||
# ca_path = "/startechnica/freeradius/certs-sql/"
|
||||
# certificate_file = $ENV{FREERADIUS_MODS_SQL_TLS_CERTIFICATE}
|
||||
# private_key_file = $ENV{FREERADIUS_MODS_SQL_TLS_PRIVATEKEY}
|
||||
# cipher = "DHE-RSA-AES256-SHA:AES128-SHA"
|
||||
# cipher = $ENV{FREERADIUS_MODS_SQL_TLS_CIPHER}
|
||||
|
||||
tls_required = $ENV{FREERADIUS_MODS_SQL_TLS_ENABLE}
|
||||
tls_check_cert = no
|
||||
tls_check_cert_cn = no
|
||||
}
|
||||
|
||||
# If yes, (or auto and libmysqlclient reports warnings are
|
||||
# available), will retrieve and log additional warnings from
|
||||
# the server if an error has occured. Defaults to 'auto'
|
||||
warnings = auto
|
||||
}
|
||||
|
||||
postgresql {
|
||||
|
||||
# unlike MySQL, which has a tls{} connection configuration, postgresql
|
||||
# uses its connection parameters - see the radius_db option below in
|
||||
# this file
|
||||
|
||||
# Send application_name to the postgres server
|
||||
# Only supported in PG 9.0 and greater. Defaults to no.
|
||||
send_application_name = yes
|
||||
}
|
||||
|
||||
#
|
||||
# Configuration for Mongo.
|
||||
#
|
||||
# Note that the Mongo driver is experimental. The FreeRADIUS developers
|
||||
# are unable to help with the syntax of the Mongo queries. Please see
|
||||
# the Mongo documentation for that syntax.
|
||||
#
|
||||
# The Mongo driver supports only the following methods:
|
||||
#
|
||||
# aggregate
|
||||
# findAndModify
|
||||
# findOne
|
||||
# insert
|
||||
#
|
||||
# For examples, see the query files:
|
||||
#
|
||||
# raddb/mods-config/sql/main/mongo/queries.conf
|
||||
# raddb/mods-config/sql/main/ippool/queries.conf
|
||||
#
|
||||
# In order to use findAndModify with an aggretation pipleline, make
|
||||
# sure that you are running MongoDB version 4.2 or greater. FreeRADIUS
|
||||
# assumes that the paramaters passed to the methods are supported by the
|
||||
# version of MongoDB which it is connected to.
|
||||
#
|
||||
mongo {
|
||||
#
|
||||
# The application name to use.
|
||||
#
|
||||
appname = "freeradius"
|
||||
|
||||
#
|
||||
# The TLS parameters here map directly to the Mongo TLS configuration
|
||||
#
|
||||
tls {
|
||||
certificate_file = $ENV{FREERADIUS_MODS_SQL_TLS_CERTIFICATE}
|
||||
certificate_password = $ENV{FREERADIUS_MODS_SQL_TLS_PRIVATEKEY}
|
||||
ca_file = $ENV{FREERADIUS_MODS_SQL_TLS_CACERT}
|
||||
ca_dir = /startechnica/freeradius/certs-sql/
|
||||
# crl_file = /path/to/file
|
||||
weak_cert_validation = false
|
||||
allow_invalid_hostname = false
|
||||
}
|
||||
}
|
||||
|
||||
# Connection info:
|
||||
#
|
||||
server = $ENV{FREERADIUS_MODS_SQL_SERVER}
|
||||
port = $ENV{FREERADIUS_MODS_SQL_PORT}
|
||||
login = $ENV{FREERADIUS_MODS_SQL_LOGIN}
|
||||
password = $ENV{FREERADIUS_MODS_SQL_PASSWORD}
|
||||
|
||||
# Connection info for Mongo
|
||||
# Authentication Without SSL
|
||||
# server = "mongodb://USER:PASSWORD@192.16.0.2:PORT/DATABASE?authSource=admin&ssl=false"
|
||||
|
||||
# Authentication With SSL
|
||||
# server = "mongodb://USER:PASSWORD@192.16.0.2:PORT/DATABASE?authSource=admin&ssl=true"
|
||||
|
||||
# Authentication with Certificate
|
||||
# Use this command for retrieve Derived username:
|
||||
# openssl x509 -in mycert.pem -inform PEM -subject -nameopt RFC2253
|
||||
# server = mongodb://<DERIVED USERNAME>@192.168.0.2:PORT/DATABASE?authSource=$external&ssl=true&authMechanism=MONGODB-X509
|
||||
|
||||
# Database table configuration for everything except Oracle
|
||||
radius_db = $ENV{FREERADIUS_MODS_SQL_DB}
|
||||
|
||||
# If you are using Oracle then use this instead
|
||||
# radius_db = "(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=localhost)(PORT=1521))(CONNECT_DATA=(SID=your_sid)))"
|
||||
|
||||
# If you're using postgresql this can also be used instead of the connection info parameters
|
||||
# radius_db = "dbname=$ENV{FREERADIUS_MODS_SQL_DB} host=$ENV{FREERADIUS_MODS_SQL_SERVER} port=$ENV{FREERADIUS_MODS_SQL_PORT} user=$ENV{FREERADIUS_MODS_SQL_LOGIN} password=$ENV{FREERADIUS_MODS_SQL_PASSWORD}"
|
||||
|
||||
# Postgreql doesn't take tls{} options in its module config like mysql does - if you want to
|
||||
# use SSL connections then use this form of connection info parameter
|
||||
# radius_db = "host=localhost port=5432 dbname=radius user=radius password=raddpass sslmode=verify-full sslcert=/etc/ssl/client.crt sslkey=/etc/ssl/client.key sslrootcert=/etc/ssl/ca.crt"
|
||||
|
||||
# If you want both stop and start records logged to the
|
||||
# same SQL table, leave this as is. If you want them in
|
||||
# different tables, put the start table in acct_table1
|
||||
# and stop table in acct_table2
|
||||
acct_table1 = $ENV{FREERADIUS_MODS_SQL_TABLE_ACCT1}
|
||||
acct_table2 = $ENV{FREERADIUS_MODS_SQL_TABLE_ACCT2}
|
||||
|
||||
# Allow for storing data after authentication
|
||||
postauth_table = $ENV{FREERADIUS_MODS_SQL_TABLE_POSTAUTH}
|
||||
|
||||
# Tables containing 'check' items
|
||||
authcheck_table = $ENV{FREERADIUS_MODS_SQL_TABLE_AUTHCHECK}
|
||||
groupcheck_table = $ENV{FREERADIUS_MODS_SQL_TABLE_GROUPCHECK}
|
||||
|
||||
# Tables containing 'reply' items
|
||||
authreply_table = $ENV{FREERADIUS_MODS_SQL_TABLE_AUTHREPLY}
|
||||
groupreply_table = $ENV{FREERADIUS_MODS_SQL_TABLE_GROUPREPLY}
|
||||
|
||||
# Table to keep group info
|
||||
usergroup_table = $ENV{FREERADIUS_MODS_SQL_TABLE_USERGROUP}
|
||||
|
||||
# If set to 'yes' (default) we read the group tables unless Fall-Through = no in the reply table.
|
||||
# If set to 'no' we do not read the group tables unless Fall-Through = yes in the reply table.
|
||||
# read_groups = yes
|
||||
|
||||
# If set to 'yes' (default) we read profiles unless Fall-Through = no in the groupreply table.
|
||||
# If set to 'no' we do not read profiles unless Fall-Through = yes in the groupreply table.
|
||||
# read_profiles = yes
|
||||
|
||||
# Remove stale session if checkrad does not see a double login
|
||||
delete_stale_sessions = yes
|
||||
|
||||
# Write SQL queries to a logfile. This is potentially useful for tracing
|
||||
# issues with authorization queries. See also "logfile" directives in
|
||||
# mods-config/sql/main/*/queries.conf. You can enable per-section logging
|
||||
# by enabling "logfile" there, or global logging by enabling "logfile" here.
|
||||
#
|
||||
# Per-section logging can be disabled by setting "logfile = ''"
|
||||
# logfile = ${logdir}/sqllog.sql
|
||||
|
||||
# Set the maximum query duration and connection timeout
|
||||
# for rlm_sql_mysql.
|
||||
# query_timeout = 5
|
||||
|
||||
# As of version 3.0, the "pool" section has replaced the
|
||||
# following configuration items:
|
||||
#
|
||||
# num_sql_socks
|
||||
# connect_failure_retry_delay
|
||||
# lifetime
|
||||
# max_queries
|
||||
|
||||
#
|
||||
# The connection pool is new for 3.0, and will be used in many
|
||||
# modules, for all kinds of connection-related activity.
|
||||
#
|
||||
# When the server is not threaded, the connection pool
|
||||
# limits are ignored, and only one connection is used.
|
||||
#
|
||||
# If you want to have multiple SQL modules re-use the same
|
||||
# connection pool, use "pool = name" instead of a "pool"
|
||||
# section. e.g.
|
||||
#
|
||||
# sql sql1 {
|
||||
# ...
|
||||
# pool {
|
||||
# ...
|
||||
# }
|
||||
# }
|
||||
#
|
||||
# # sql2 will use the connection pool from sql1
|
||||
# sql sql2 {
|
||||
# ...
|
||||
# pool = sql1
|
||||
# }
|
||||
#
|
||||
pool {
|
||||
# Connections to create during module instantiation.
|
||||
# If the server cannot create specified number of
|
||||
# connections during instantiation it will exit.
|
||||
# Set to 0 to allow the server to start without the database being available.
|
||||
start = ${thread[pool].start_servers}
|
||||
|
||||
# Minimum number of connections to keep open
|
||||
min = ${thread[pool].min_spare_servers}
|
||||
|
||||
# Maximum number of connections
|
||||
#
|
||||
# If these connections are all in use and a new one
|
||||
# is requested, the request will NOT get a connection.
|
||||
#
|
||||
# Setting 'max' to LESS than the number of threads means
|
||||
# that some threads may starve, and you will see errors
|
||||
# like 'No connections available and at max connection limit'
|
||||
#
|
||||
# Setting 'max' to MORE than the number of threads means
|
||||
# that there are more connections than necessary.
|
||||
max = ${thread[pool].max_servers}
|
||||
|
||||
# Spare connections to be left idle
|
||||
#
|
||||
# NOTE: Idle connections WILL be closed if "idle_timeout"
|
||||
# is set. This should be less than or equal to "max" above.
|
||||
spare = ${thread[pool].max_spare_servers}
|
||||
|
||||
# Number of uses before the connection is closed
|
||||
#
|
||||
# 0 means "infinite"
|
||||
uses = 0
|
||||
|
||||
# The number of seconds to wait after the server tries
|
||||
# to open a connection, and fails. During this time,
|
||||
# no new connections will be opened.
|
||||
retry_delay = 30
|
||||
|
||||
# The lifetime (in seconds) of the connection
|
||||
lifetime = 0
|
||||
|
||||
# idle timeout (in seconds). A connection which is
|
||||
# unused for this length of time will be closed.
|
||||
idle_timeout = 60
|
||||
|
||||
# NOTE: All configuration settings are enforced. If a
|
||||
# connection is closed because of "idle_timeout",
|
||||
# "uses", or "lifetime", then the total number of
|
||||
# connections MAY fall below "min". When that
|
||||
# happens, it will open a new connection. It will
|
||||
# also log a WARNING message.
|
||||
#
|
||||
# The solution is to either lower the "min" connections,
|
||||
# or increase lifetime/idle_timeout.
|
||||
}
|
||||
|
||||
# Set to 'yes' to read radius clients from the database ('nas' table)
|
||||
# Clients will ONLY be read on server startup.
|
||||
#
|
||||
# A client can be link to a virtual server via the SQL
|
||||
# module. This link is done via the following process:
|
||||
#
|
||||
# If there is no listener in a virtual server, SQL clients
|
||||
# are added to the global list for that virtual server.
|
||||
#
|
||||
# If there is a listener, and the first listener does not
|
||||
# have a "clients=..." configuration item, SQL clients are
|
||||
# added to the global list.
|
||||
#
|
||||
# If there is a listener, and the first one does have a
|
||||
# "clients=..." configuration item, SQL clients are added to
|
||||
# that list. The client { ...} ` configured in that list are
|
||||
# also added for that listener.
|
||||
#
|
||||
# The only issue is if you have multiple listeners in a
|
||||
# virtual server, each with a different client list, then
|
||||
# the SQL clients are added only to the first listener.
|
||||
#
|
||||
read_clients = $ENV{FREERADIUS_MODS_SQL_READ_CLIENTS}
|
||||
|
||||
# Table to keep radius client info
|
||||
client_table = $ENV{FREERADIUS_MODS_SQL_TABLE_CLIENT}
|
||||
|
||||
#
|
||||
# The group attribute specific to this instance of rlm_sql
|
||||
#
|
||||
|
||||
# This entry should be used for additional instances (sql foo {})
|
||||
# of the SQL module.
|
||||
# group_attribute = "${.:instance}-SQL-Group"
|
||||
|
||||
# This entry should be used for the default instance (sql {})
|
||||
# of the SQL module.
|
||||
group_attribute = $ENV{FREERADIUS_MODS_SQL_GROUP_ATTRIBUTE}
|
||||
|
||||
# Read database-specific queries
|
||||
$INCLUDE ${modconfdir}/${.:name}/main/${dialect}/queries.conf
|
||||
}
|
||||
@@ -0,0 +1,165 @@
|
||||
###########################################################################
|
||||
# $Id: 41fcccad1c012226d12cc721518fe91e311e55e2 $ #
|
||||
# #
|
||||
# schema.sql rlm_sql - FreeRADIUS SQL Module #
|
||||
# #
|
||||
# Database schema for MySQL rlm_sql module #
|
||||
# #
|
||||
# To load: #
|
||||
# mysql -uroot -prootpass radius < schema.sql #
|
||||
# #
|
||||
# Mike Machado <mike@innercite.com> #
|
||||
###########################################################################
|
||||
|
||||
#
|
||||
# Table structure for table 'radacct'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radacct (
|
||||
radacctid bigint(21) NOT NULL auto_increment,
|
||||
acctsessionid varchar(64) NOT NULL default '',
|
||||
acctuniqueid varchar(32) NOT NULL default '',
|
||||
username varchar(64) NOT NULL default '',
|
||||
realm varchar(64) default '',
|
||||
nasipaddress varchar(15) NOT NULL default '',
|
||||
nasportid varchar(32) default NULL,
|
||||
nasporttype varchar(32) default NULL,
|
||||
acctstarttime datetime NULL default NULL,
|
||||
acctupdatetime datetime NULL default NULL,
|
||||
acctstoptime datetime NULL default NULL,
|
||||
acctinterval int(12) default NULL,
|
||||
acctsessiontime int(12) unsigned default NULL,
|
||||
acctauthentic varchar(32) default NULL,
|
||||
connectinfo_start varchar(128) default NULL,
|
||||
connectinfo_stop varchar(128) default NULL,
|
||||
acctinputoctets bigint(20) default NULL,
|
||||
acctoutputoctets bigint(20) default NULL,
|
||||
calledstationid varchar(50) NOT NULL default '',
|
||||
callingstationid varchar(50) NOT NULL default '',
|
||||
acctterminatecause varchar(32) NOT NULL default '',
|
||||
servicetype varchar(32) default NULL,
|
||||
framedprotocol varchar(32) default NULL,
|
||||
framedipaddress varchar(15) NOT NULL default '',
|
||||
framedipv6address varchar(45) NOT NULL default '',
|
||||
framedipv6prefix varchar(45) NOT NULL default '',
|
||||
framedinterfaceid varchar(44) NOT NULL default '',
|
||||
delegatedipv6prefix varchar(45) NOT NULL default '',
|
||||
class varchar(64) default NULL,
|
||||
PRIMARY KEY (radacctid),
|
||||
UNIQUE KEY acctuniqueid (acctuniqueid),
|
||||
KEY username (username),
|
||||
KEY framedipaddress (framedipaddress),
|
||||
KEY framedipv6address (framedipv6address),
|
||||
KEY framedipv6prefix (framedipv6prefix),
|
||||
KEY framedinterfaceid (framedinterfaceid),
|
||||
KEY delegatedipv6prefix (delegatedipv6prefix),
|
||||
KEY acctsessionid (acctsessionid),
|
||||
KEY acctsessiontime (acctsessiontime),
|
||||
KEY acctstarttime (acctstarttime),
|
||||
KEY acctinterval (acctinterval),
|
||||
KEY acctstoptime (acctstoptime),
|
||||
KEY nasipaddress (nasipaddress),
|
||||
KEY class (class)
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radcheck'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radcheck (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
username varchar(64) NOT NULL default '',
|
||||
attribute varchar(64) NOT NULL default '',
|
||||
op char(2) NOT NULL DEFAULT '==',
|
||||
value varchar(253) NOT NULL default '',
|
||||
PRIMARY KEY (id),
|
||||
KEY username (username(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radgroupcheck'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radgroupcheck (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
groupname varchar(64) NOT NULL default '',
|
||||
attribute varchar(64) NOT NULL default '',
|
||||
op char(2) NOT NULL DEFAULT '==',
|
||||
value varchar(253) NOT NULL default '',
|
||||
PRIMARY KEY (id),
|
||||
KEY groupname (groupname(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radgroupreply'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radgroupreply (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
groupname varchar(64) NOT NULL default '',
|
||||
attribute varchar(64) NOT NULL default '',
|
||||
op char(2) NOT NULL DEFAULT '=',
|
||||
value varchar(253) NOT NULL default '',
|
||||
PRIMARY KEY (id),
|
||||
KEY groupname (groupname(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radreply'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radreply (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
username varchar(64) NOT NULL default '',
|
||||
attribute varchar(64) NOT NULL default '',
|
||||
op char(2) NOT NULL DEFAULT '=',
|
||||
value varchar(253) NOT NULL default '',
|
||||
PRIMARY KEY (id),
|
||||
KEY username (username(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
|
||||
#
|
||||
# Table structure for table 'radusergroup'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS `radusergroup` (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
username varchar(64) NOT NULL default '',
|
||||
groupname varchar(64) NOT NULL default '',
|
||||
priority int(11) NOT NULL default '1',
|
||||
PRIMARY KEY (id),
|
||||
KEY username (username(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radpostauth'
|
||||
#
|
||||
# Note: MySQL versions since 5.6.4 support fractional precision timestamps
|
||||
# which we use here. Replace the authdate definition with the following
|
||||
# if your software is too old:
|
||||
#
|
||||
# authdate timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radpostauth (
|
||||
id int(11) NOT NULL auto_increment,
|
||||
username varchar(64) NOT NULL default '',
|
||||
pass varchar(64) NOT NULL default '',
|
||||
reply varchar(32) NOT NULL default '',
|
||||
authdate timestamp(6) NOT NULL DEFAULT CURRENT_TIMESTAMP(6) ON UPDATE CURRENT_TIMESTAMP(6),
|
||||
class varchar(64) default NULL,
|
||||
PRIMARY KEY (id),
|
||||
KEY username (username),
|
||||
KEY class (class)
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'nas'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS nas (
|
||||
id int(10) NOT NULL auto_increment,
|
||||
nasname varchar(128) NOT NULL,
|
||||
shortname varchar(32),
|
||||
type varchar(30) DEFAULT 'other',
|
||||
ports int(5),
|
||||
secret varchar(60) DEFAULT 'secret' NOT NULL,
|
||||
server varchar(64),
|
||||
community varchar(50),
|
||||
description varchar(200) DEFAULT 'RADIUS Client',
|
||||
PRIMARY KEY (id),
|
||||
KEY nasname (nasname)
|
||||
) ENGINE = INNODB;
|
||||
@@ -0,0 +1,41 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# Sample virtual server for receiving a CoA or Disconnect-Request packet.
|
||||
#
|
||||
|
||||
# Listen on the CoA port.
|
||||
#
|
||||
# This uses the normal set of clients, with the same secret as for authentication and accounting.
|
||||
#
|
||||
|
||||
listen {
|
||||
type = coa
|
||||
# ipaddr = $ENV{FREERADIUS_SITES_COA_LISTEN}
|
||||
ipaddr = *
|
||||
port = $ENV{FREERADIUS_SITES_COA_PORT}
|
||||
virtual_server = coa
|
||||
}
|
||||
|
||||
server coa {
|
||||
# When a packet is received, it is processed through the recv-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
|
||||
recv-coa {
|
||||
# CoA && Disconnect packets can be proxied in the same way as authentication or accounting packets.
|
||||
# Just set Proxy-To-Realm, or Home-Server-Pool, and the packets will be proxied.
|
||||
|
||||
# Do proxying based on realms here. You don't need "IPASS" or "ntdomain", as the proxying is based on the Operator-Name attribute. It contains the realm,
|
||||
# and ONLY the realm (prefixed by a '1')
|
||||
suffix
|
||||
|
||||
# Insert your own policies here.
|
||||
ok
|
||||
}
|
||||
|
||||
# When a packet is sent, it is processed through the send-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
|
||||
send-coa {
|
||||
# Sample module.
|
||||
ok
|
||||
}
|
||||
|
||||
# You can use pre-proxy and post-proxy sections here, too. They will be processed for sending && receiving proxy packets.
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,595 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# This is a virtual server that handles DHCP.
|
||||
#
|
||||
# See raddb/mods-available/dhcp_sqlippool for the IP Pool configuration.
|
||||
#
|
||||
# See raddb/policy.d/dhcp_sqlippool for the "glue" code that allows
|
||||
# the RADIUS based "sqlippool" module to be used for DHCP.
|
||||
#
|
||||
# See raddb/mods-config/sql/ippool/ for the schemas.
|
||||
#
|
||||
# See raddb/sites-available/dhcp for instructions on how to configure
|
||||
# the DHCP server.
|
||||
#
|
||||
# $Id$
|
||||
#
|
||||
######################################################################
|
||||
|
||||
#
|
||||
# The DHCP functionality goes into a virtual server.
|
||||
#
|
||||
server dhcp {
|
||||
|
||||
# Define a DHCP socket.
|
||||
#
|
||||
# The default port below is 6700, so you don't break your network.
|
||||
# If you want it to do real DHCP, change this to 67, and good luck!
|
||||
#
|
||||
# You can also bind the DHCP socket to an interface.
|
||||
# See below, and raddb/radiusd.conf for examples.
|
||||
#
|
||||
# This lets you run *one* DHCP server instance and have it listen on
|
||||
# multiple interfaces, each with a separate policy.
|
||||
#
|
||||
# If you have multiple interfaces, it is a good idea to bind the
|
||||
# listen section to an interface. You will also need one listen
|
||||
# section per interface.
|
||||
#
|
||||
# FreeBSD does *not* support binding sockets to interfaces. Therefore,
|
||||
# if you have multiple interfaces, broadcasts may go out of the wrong
|
||||
# one, or even all interfaces. The solution is to use the "setfib" command.
|
||||
# If you have a network "10.10.0/24" on LAN1, you will need to do:
|
||||
#
|
||||
# Pick any IP on the 10.10.0/24 network
|
||||
# $ setfib 1 route add default 10.10.0.1
|
||||
#
|
||||
# Edit /etc/rc.local, and add a line:
|
||||
# setfib 1 /path/to/radiusd
|
||||
#
|
||||
# The kern must be built with the following options:
|
||||
# options ROUTETABLES=2
|
||||
# or any value larger than 2.
|
||||
#
|
||||
# The other only solution is to update FreeRADIUS to use BPF sockets.
|
||||
#
|
||||
listen {
|
||||
# This is a dhcp socket.
|
||||
type = dhcp
|
||||
|
||||
# IP address to listen on. Will usually be the IP of the
|
||||
# interface, or 0.0.0.0
|
||||
ipaddr = 0.0.0.0
|
||||
|
||||
# source IP address for unicast packets sent by the
|
||||
# DHCP server.
|
||||
#
|
||||
# The source IP for unicast packets is chosen from the first
|
||||
# one of the following items which returns a valid IP
|
||||
# address:
|
||||
#
|
||||
# src_ipaddr
|
||||
# ipaddr
|
||||
# reply:DHCP-Server-IP-Address
|
||||
# reply:DHCP-DHCP-Server-Identifier
|
||||
#
|
||||
src_ipaddr = 127.0.0.1
|
||||
|
||||
# The port should be 67 for a production network. Don't set
|
||||
# it to 67 on a production network unless you really know
|
||||
# what you're doing. Even if nothing is configured below, the
|
||||
# server may still NAK legitimate responses from clients.
|
||||
port = 6700
|
||||
|
||||
# Interface name we are listening on. See comments above.
|
||||
# interface = lo0
|
||||
|
||||
# The DHCP server defaults to allowing broadcast packets.
|
||||
# Set this to "no" only when the server receives *all* packets
|
||||
# from a relay agent. i.e. when *no* clients are on the same
|
||||
# LAN as the DHCP server.
|
||||
#
|
||||
# It's set to "no" here for testing. It will usually want to
|
||||
# be "yes" in production, unless you are only dealing with
|
||||
# relayed packets.
|
||||
broadcast = no
|
||||
|
||||
# On Linux if you're running the server as non-root, you
|
||||
# will need to do:
|
||||
#
|
||||
# setcap cap_net_admin,cap_net_bind_service=eip /path/to/radiusd
|
||||
#
|
||||
# This will allow the server to set ARP table entries
|
||||
# for newly allocated IPs, when run as the "radius" user.
|
||||
#
|
||||
# The above "setcap" command adds the capability to the program,
|
||||
# usually so long as it is run by the "radius" user. Which means
|
||||
# (oddly enough) that it no longer works when run as root!
|
||||
#
|
||||
# When running the server as root in debug mode, you can use:
|
||||
#
|
||||
# capsh --caps="cap_setpcap,cap_setuid,cap_setgid,cap_net_admin,cap_net_bind_service+eip" --keep=1 --user=radius --addamb=cap_net_admin,cap_net_bind_service -- -c "/path/to/radiusd -X"
|
||||
#
|
||||
# Or, simply "sudo" or "su" to the "radius" user, and then run
|
||||
# the server in debug mode.
|
||||
|
||||
# De-duplicate DHCP packets. If clients don't receive
|
||||
# a reply within their timeout, most will re-transmit.
|
||||
# A reply to either packet will satisfy, so de-duplicating
|
||||
# helps manage load on a busy server
|
||||
performance {
|
||||
skip_duplicate_checks = no
|
||||
}
|
||||
}
|
||||
|
||||
# Packets received on the socket will be processed through one
|
||||
# of the following sections, named after the DHCP packet type.
|
||||
# See dictionary.dhcp for the packet types.
|
||||
|
||||
# Return packets will be sent to, in preference order:
|
||||
# DHCP-Gateway-IP-Address
|
||||
# DHCP-Client-IP-Address
|
||||
# DHCP-Your-IP-Address
|
||||
# At least one of these attributes should be set at the end of each
|
||||
# section for a response to be sent.
|
||||
|
||||
# An internal attribute of DHCP-Network-Subnet is set to provide
|
||||
# a basis for determining the network that a client belongs to. This
|
||||
# is a hierarchical assignment based on:
|
||||
#
|
||||
# - DHCP-Relay-Link-Selection
|
||||
# - DHCP-Subnet-Selection-Option
|
||||
# - DHCP-Gateway-IP-Address
|
||||
# - DHCP-Client-IP-Address
|
||||
#
|
||||
# Except for cases where all IP allocation is performed using a mapping from
|
||||
# the device MAC address to a fixed IP address the DHCP configuration will
|
||||
# involve the use of one or more pools.
|
||||
#
|
||||
# Each pool should be composed of a set of equally valid IP addresses for the
|
||||
# devices designated as users of the pool. During IP allocation the choice of
|
||||
# pool is driven by setting the Pool-Name attribute which may either be
|
||||
# specified directly or chosen (usually with the help of the dhcp_network
|
||||
# module) based on the initial value of DHCP-Network-Subnet.
|
||||
#
|
||||
# DHCP-Network-Subnet indicates the network from which the request is
|
||||
# originating. In cases where the originating network alone is insufficent to
|
||||
# define the required IP allocated policy, DHCP-Network-Subnet may be
|
||||
# overridden to force the selection of a particular pool.
|
||||
#
|
||||
# IP addresses belonging to a single pool that is designated for a Layer 2
|
||||
# network containing multiple subnets (a "shared-network" or "multinet"
|
||||
# configuration as defined by some other DHCP servers), will by definition be
|
||||
# members of distinct subnets that require their own DHCP reply parameters. In
|
||||
# this case the dhcp_subnet policy can be used to set the correct
|
||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address options
|
||||
# based on the allocated IP.
|
||||
|
||||
dhcp DHCP-Discover {
|
||||
|
||||
# The DHCP Server Identifier is set here since is returned in OFFERs
|
||||
update control {
|
||||
&DHCP-DHCP-Server-Identifier = 192.0.2.2
|
||||
}
|
||||
|
||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
||||
dhcp_common
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# If clients need to be assigned to a particular network based on
|
||||
# an attribute in the packet rather than the calculated
|
||||
# DHCP-Network-Subnet described above, then call a policy
|
||||
# (defined in policy.d/dhcp) to perform the override
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple subnets use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Do a simple mapping of MAC to assigned IP.
|
||||
#
|
||||
# See below for the definition of the "mac2ip"
|
||||
# module.
|
||||
#
|
||||
#mac2ip
|
||||
|
||||
# Or, allocate IPs from the DHCP pool in SQL. You may need to
|
||||
# set the pool name here if you haven't set it elsewhere.
|
||||
#update control {
|
||||
# &Pool-Name := "local"
|
||||
#}
|
||||
#dhcp_sqlippool
|
||||
|
||||
# If the IP address was not allocated, do something else.
|
||||
# You could call a Perl, Python, or Java script here.
|
||||
#if (notfound) {
|
||||
# ...
|
||||
#}
|
||||
|
||||
# "Shared-networks" may have multiple IP subnets co-existing in a
|
||||
# single Layer 2 network. If the pool for the network contains
|
||||
# addresses from more that one subnet then the setting subnet-specific
|
||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
|
||||
# parameters must be performed after the allocation of the IP address.
|
||||
#
|
||||
# Set any subnet-specific parameters using this policy.
|
||||
#
|
||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
||||
# policy.d/dhcp to use this.
|
||||
#
|
||||
#dhcp_subnet
|
||||
|
||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_group_options
|
||||
|
||||
# Use a "files" module to lookup host specific options
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_hosts
|
||||
|
||||
# As an alternative or complement to configuration files based lookup
|
||||
# for options data you can instead use an SQL database. Example
|
||||
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
|
||||
# will need to be adapted to your requirements.
|
||||
#dhcp_policy_sql
|
||||
|
||||
# Set the type of packet to send in reply.
|
||||
#
|
||||
# The server will look at the DHCP-Message-Type attribute to
|
||||
# determine which type of packet to send in reply. Common
|
||||
# values would be DHCP-Offer, DHCP-Ack or DHCP-NAK. See
|
||||
# dictionary.dhcp for all the possible values.
|
||||
#
|
||||
# DHCP-Do-Not-Respond can be used to tell the server to not
|
||||
# respond.
|
||||
#
|
||||
# In the event that DHCP-Message-Type is not set then the
|
||||
# server will fall back to determining the type of reply
|
||||
# based on the rcode of this section.
|
||||
#
|
||||
#update reply {
|
||||
# DHCP-Message-Type = DHCP-Offer
|
||||
#}
|
||||
#
|
||||
# If DHCP-Message-Type is not set, returning "ok" or
|
||||
# "updated" from this section will respond with a DHCP-Offer
|
||||
# message.
|
||||
#
|
||||
# Other rcodes will tell the server to not return any response.
|
||||
#
|
||||
#ok
|
||||
}
|
||||
|
||||
dhcp DHCP-Request {
|
||||
|
||||
# You must set the DHCP Server Identifier here since this is returned
|
||||
# in ACKs and is used to determine whether a request containing a
|
||||
# "server-ip" field is intended for this server
|
||||
update control {
|
||||
&DHCP-DHCP-Server-Identifier = 192.0.2.2
|
||||
}
|
||||
|
||||
# If the request is not for this server then silently discard it
|
||||
if (&request:DHCP-DHCP-Server-Identifier && \
|
||||
&request:DHCP-DHCP-Server-Identifier != &control:DHCP-DHCP-Server-Identifier) {
|
||||
do_not_respond
|
||||
}
|
||||
|
||||
# Response packet type. See DHCP-Discover section above.
|
||||
#update reply {
|
||||
# &DHCP-Message-Type = DHCP-Ack
|
||||
#}
|
||||
|
||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
||||
dhcp_common
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple subnets use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
||||
# policy.d/dhcp to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Do a simple mapping of MAC to assigned IP.
|
||||
#
|
||||
# See below for the definition of the "mac2ip"
|
||||
# module.
|
||||
#
|
||||
#mac2ip
|
||||
|
||||
# Or, allocate IPs from the DHCP pool in SQL. You may need to
|
||||
# set the pool name here if you haven't set it elsewhere.
|
||||
# update control {
|
||||
# &Pool-Name := "local"
|
||||
# }
|
||||
# dhcp_sqlippool_request
|
||||
|
||||
# If the IP was not allocated, do something else.
|
||||
# You could call a Perl, Python, or Java script here.
|
||||
#if (notfound) {
|
||||
# ...
|
||||
#}
|
||||
|
||||
# "Shared-networks" may have multiple IP subnets co-existing in a
|
||||
# single Layer 2 network. If the pool for the network contains
|
||||
# addresses from more that one subnet then the setting subnet-specific
|
||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
|
||||
# parameters must be performed after the allocation of the IP address.
|
||||
#
|
||||
# Set any subnet-specific parameters using this policy.
|
||||
#
|
||||
#dhcp_subnet
|
||||
|
||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_group_options
|
||||
|
||||
# Use a "files" module to lookup host specific options
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_hosts
|
||||
|
||||
# As an alternative or complement to configuration files based lookup
|
||||
# for options data you can instead use an SQL database. Example
|
||||
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
|
||||
# will need to be adapted to your requirements.
|
||||
#dhcp_policy_sql
|
||||
|
||||
# If DHCP-Message-Type is not set, returning "ok" or
|
||||
# "updated" from this section will respond with a DHCP-Ack
|
||||
# packet.
|
||||
#
|
||||
# "handled" will not return a packet, all other rcodes will
|
||||
# send back a DHCP-NAK.
|
||||
#
|
||||
#ok
|
||||
}
|
||||
|
||||
#
|
||||
# Other DHCP packet types
|
||||
#
|
||||
# There should be a separate section for each DHCP message type.
|
||||
# By default this configuration will ignore them all. Any packet type
|
||||
# not defined here will be responded to with a DHCP-NAK.
|
||||
|
||||
dhcp DHCP-Decline {
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple networks use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Use a policy that set options from data stored in an SQL database
|
||||
#dhcp_policy_sql
|
||||
|
||||
# If using IPs from a DHCP pool in SQL then you may need to set the
|
||||
# pool name here if you haven't set it elsewhere and release the IP.
|
||||
# update control {
|
||||
# &Pool-Name := "local"
|
||||
# }
|
||||
# dhcp_sqlippool_decline
|
||||
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Do-Not-Respond
|
||||
}
|
||||
reject
|
||||
}
|
||||
|
||||
#
|
||||
# A dummy config for Inform packets - this should match the
|
||||
# options set in the Request section above, except Inform replies
|
||||
# must not set Your-IP-Address or IP-Address-Lease-Time
|
||||
#
|
||||
dhcp DHCP-Inform {
|
||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
||||
dhcp_common
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and network options
|
||||
# For multiple networks use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Use a policy with calls a "files" module of the same name to lookup
|
||||
# subnet options
|
||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
||||
# policy.d/dhcp to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_subnet
|
||||
|
||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_group_options
|
||||
|
||||
# Use a "files" module to lookup host specific options
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_hosts
|
||||
|
||||
# Use a policy that set options from data stored in an SQL database
|
||||
#dhcp_policy_sql
|
||||
|
||||
ok
|
||||
}
|
||||
|
||||
#
|
||||
# For Windows 7 boxes
|
||||
#
|
||||
#dhcp DHCP-Inform {
|
||||
# update reply {
|
||||
# Packet-Dst-Port = 67
|
||||
# DHCP-Message-Type = DHCP-ACK
|
||||
# DHCP-DHCP-Server-Identifier = "%{Packet-Dst-IP-Address}"
|
||||
# DHCP-Site-specific-28 = 0x0a00
|
||||
# }
|
||||
# ok
|
||||
#}
|
||||
|
||||
dhcp DHCP-Release {
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple subnets use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# If using IPs from a DHCP pool in SQL then you may need to set the
|
||||
# pool name here if you haven't set it elsewhere and release the IP.
|
||||
# update control {
|
||||
# &Pool-Name := "local"
|
||||
# }
|
||||
# dhcp_sqlippool_release
|
||||
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Do-Not-Respond
|
||||
}
|
||||
reject
|
||||
}
|
||||
|
||||
|
||||
dhcp DHCP-Lease-Query {
|
||||
# The thing being queried for is implicit
|
||||
# in the packets.
|
||||
|
||||
# has MAC, asking for IP, etc.
|
||||
if (&DHCP-Client-Hardware-Address) {
|
||||
# look up MAC in database
|
||||
}
|
||||
|
||||
# has IP, asking for MAC, etc.
|
||||
elsif (&DHCP-Your-IP-Address) {
|
||||
# look up IP in database
|
||||
}
|
||||
|
||||
# has host name, asking for IP, MAC, etc.
|
||||
elsif (&DHCP-Client-Identifier) {
|
||||
# look up identifier in database
|
||||
}
|
||||
else {
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Lease-Unknown
|
||||
}
|
||||
|
||||
ok
|
||||
|
||||
# stop processing
|
||||
return
|
||||
}
|
||||
|
||||
#
|
||||
# We presume that the database lookup returns "notfound"
|
||||
# if it can't find anything.
|
||||
#
|
||||
if (notfound) {
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Lease-Unknown
|
||||
}
|
||||
ok
|
||||
return
|
||||
}
|
||||
|
||||
#
|
||||
# Add more logic here. Is the lease inactive?
|
||||
# If so, respond with DHCP-Lease-Unassigned.
|
||||
#
|
||||
# Otherwise, respond with DHCP-Lease-Active
|
||||
#
|
||||
|
||||
#
|
||||
# Also be sure to return ALL information about
|
||||
# the lease.
|
||||
#
|
||||
|
||||
#
|
||||
# The reply types are:
|
||||
#
|
||||
# DHCP-Lease-Unknown
|
||||
# DHCP-Lease-Active
|
||||
# DHCP-Lease-Unassigned
|
||||
#
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Lease-Unassigned
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
######################################################################
|
||||
#
|
||||
# This next section is a sample configuration for the "passwd"
|
||||
# module, that reads flat-text files. It should go into
|
||||
# radiusd.conf, in the "modules" section.
|
||||
#
|
||||
# The file is in the format <mac>,<ip>
|
||||
#
|
||||
# 00:01:02:03:04:05,192.0.2.100
|
||||
# 01:01:02:03:04:05,192.0.2.101
|
||||
# 02:01:02:03:04:05,192.0.2.102
|
||||
#
|
||||
# This lets you perform simple static IP assignment.
|
||||
#
|
||||
# There is a preconfigured "mac2ip" module setup in
|
||||
# mods-available/mac2ip. To use it do:
|
||||
#
|
||||
# # cd raddb/
|
||||
# # ln -s ../mods-available/mac2ip mods-enabled/mac2ip
|
||||
# # mkdir mods-config/passwd
|
||||
#
|
||||
# Then create the file mods-config/passwd/mac2ip with the above
|
||||
# format.
|
||||
#
|
||||
######################################################################
|
||||
|
||||
|
||||
# This is an example only - see mods-available/mac2ip instead; do
|
||||
# not uncomment these lines here.
|
||||
#
|
||||
#passwd mac2ip {
|
||||
# filename = ${confdir}/mac2ip
|
||||
# format = "*DHCP-Client-Hardware-Address:=DHCP-Your-IP-Address"
|
||||
# delimiter = ","
|
||||
#}
|
||||
@@ -0,0 +1,126 @@
|
||||
######################################################################
|
||||
#
|
||||
# This is a virtual server that handles *only* inner tunnel
|
||||
# requests for EAP-TTLS and PEAP types.
|
||||
#
|
||||
######################################################################
|
||||
|
||||
server inner-tunnel {
|
||||
|
||||
listen {
|
||||
ipaddr = 127.0.0.1
|
||||
port = 18120
|
||||
type = auth
|
||||
}
|
||||
|
||||
authorize {
|
||||
filter_username
|
||||
# filter_inner_identity
|
||||
chap
|
||||
mschap
|
||||
# unix
|
||||
# IPASS
|
||||
suffix
|
||||
# ntdomain
|
||||
|
||||
update control {
|
||||
&Proxy-To-Realm := LOCAL
|
||||
}
|
||||
|
||||
eap {
|
||||
ok = return
|
||||
}
|
||||
|
||||
files
|
||||
-sql
|
||||
# smbpasswd
|
||||
-ldap
|
||||
# daily
|
||||
expiration
|
||||
logintime
|
||||
pap
|
||||
}
|
||||
|
||||
authenticate {
|
||||
Auth-Type PAP {
|
||||
pap
|
||||
}
|
||||
|
||||
Auth-Type CHAP {
|
||||
chap
|
||||
}
|
||||
|
||||
Auth-Type MS-CHAP {
|
||||
mschap
|
||||
}
|
||||
|
||||
mschap
|
||||
# pam
|
||||
|
||||
# Auth-Type LDAP {
|
||||
# ldap
|
||||
# }
|
||||
|
||||
eap
|
||||
}
|
||||
|
||||
session {
|
||||
radutmp
|
||||
# sql
|
||||
}
|
||||
|
||||
# Post-Authentication
|
||||
post-auth {
|
||||
# cui-inner
|
||||
|
||||
# update outer.session-state {
|
||||
# User-Name := &User-Name
|
||||
# }
|
||||
|
||||
# reply_log
|
||||
-sql
|
||||
# ldap
|
||||
# moonshot_host_tid
|
||||
# moonshot_realm_tid
|
||||
# moonshot_coi_tid
|
||||
|
||||
if (0) {
|
||||
update reply {
|
||||
User-Name !* ANY
|
||||
Message-Authenticator !* ANY
|
||||
EAP-Message !* ANY
|
||||
Proxy-State !* ANY
|
||||
MS-MPPE-Encryption-Types !* ANY
|
||||
MS-MPPE-Encryption-Policy !* ANY
|
||||
MS-MPPE-Send-Key !* ANY
|
||||
MS-MPPE-Recv-Key !* ANY
|
||||
}
|
||||
|
||||
update {
|
||||
&outer.session-state: += &reply:
|
||||
}
|
||||
}
|
||||
|
||||
Post-Auth-Type REJECT {
|
||||
-sql
|
||||
attr_filter.access_reject
|
||||
|
||||
update outer.session-state {
|
||||
&Module-Failure-Message := &request:Module-Failure-Message
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
pre-proxy {
|
||||
# files
|
||||
# attr_filter.pre-proxy
|
||||
# pre_proxy_log
|
||||
}
|
||||
|
||||
post-proxy {
|
||||
# post_proxy_log
|
||||
# attr_filter.post-proxy
|
||||
eap
|
||||
}
|
||||
|
||||
} # inner-tunnel server block
|
||||
@@ -0,0 +1,126 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# A virtual server to handle ONLY Status-Server packets.
|
||||
#
|
||||
# Server statistics can be queried with a properly formatted
|
||||
# Status-Server request. See dictionary.freeradius for comments.
|
||||
#
|
||||
# If radiusd.conf has "status_server = yes", then any client
|
||||
# will be able to send a Status-Server packet to any port
|
||||
# (listen section type "auth", "acct", or "status"), and the
|
||||
# server will respond.
|
||||
#
|
||||
# If radiusd.conf has "status_server = no", then the server will
|
||||
# ignore Status-Server packets to "auth" and "acct" ports. It
|
||||
# will respond only if the Status-Server packet is sent to a
|
||||
# "status" port.
|
||||
#
|
||||
# The server statistics are available ONLY on socket of type
|
||||
# "status". Queries for statistics sent to any other port
|
||||
# are ignored.
|
||||
#
|
||||
# Similarly, a socket of type "status" will not process
|
||||
# authentication or accounting packets. This is for security.
|
||||
#
|
||||
# $Id: e7d4346310b837d56bffe4c991b4e5680742ebc0 $
|
||||
#
|
||||
######################################################################
|
||||
|
||||
server status {
|
||||
listen {
|
||||
# ONLY Status-Server is allowed to this port.
|
||||
# ALL other packets are ignored.
|
||||
type = status
|
||||
|
||||
ipaddr = $ENV{FREERADIUS_SITES_STATUS_LISTEN}
|
||||
port = $ENV{FREERADIUS_SITES_STATUS_PORT}
|
||||
}
|
||||
|
||||
#
|
||||
# We recommend that you list ONLY management clients here.
|
||||
# i.e. NOT your NASes or Access Points, and for an ISP,
|
||||
# DEFINITELY not any RADIUS servers that are proxying packets
|
||||
# to you.
|
||||
#
|
||||
# If you do NOT list a client here, then any client that is
|
||||
# globally defined (i.e. all of them) will be able to query
|
||||
# these statistics.
|
||||
#
|
||||
# Do you really want your partners seeing the internal details
|
||||
# of what your RADIUS server is doing?
|
||||
#
|
||||
client admin {
|
||||
ipaddr = 127.0.0.1
|
||||
secret = $ENV{FREERADIUS_SITES_STATUS_SECRET}
|
||||
}
|
||||
|
||||
# Simple authorize section. The "Autz-Type Status-Server"
|
||||
# section will work here, too. See "raddb/sites-available/default".
|
||||
authorize {
|
||||
ok
|
||||
|
||||
# respond to the Status-Server request.
|
||||
Autz-Type Status-Server {
|
||||
ok
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# Statistics can be queried via a number of methods:
|
||||
#
|
||||
# All packets received/sent by the server (1 = auth, 2 = acct)
|
||||
# FreeRADIUS-Statistics-Type = 3
|
||||
#
|
||||
# All packets proxied by the server (4 = proxy-auth, 8 = proxy-acct)
|
||||
# FreeRADIUS-Statistics-Type = 12
|
||||
#
|
||||
# All packets sent && received:
|
||||
# FreeRADIUS-Statistics-Type = 15
|
||||
#
|
||||
# Internal server statistics:
|
||||
# FreeRADIUS-Statistics-Type = 16
|
||||
#
|
||||
# All packets for a particular client (globally defined)
|
||||
# FreeRADIUS-Statistics-Type = 35
|
||||
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
|
||||
#
|
||||
# All packets for a client attached to a "listen" ip/port
|
||||
# FreeRADIUS-Statistics-Type = 35
|
||||
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
|
||||
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
|
||||
# FreeRADIUS-Stats-Server-Port = 1812
|
||||
#
|
||||
# All packets for a "listen" IP/port
|
||||
# FreeRADIUS-Statistics-Type = 67
|
||||
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
|
||||
# FreeRADIUS-Stats-Server-Port = 1812
|
||||
#
|
||||
# All packets for a home server IP / port
|
||||
# FreeRADIUS-Statistics-Type = 131
|
||||
# FreeRADIUS-Stats-Server-IP-Address = 192.0.2.2
|
||||
# FreeRADIUS-Stats-Server-Port = 1812
|
||||
|
||||
#
|
||||
# You can also get exponentially weighted moving averages of
|
||||
# response times (in usec) of home servers. Just set the config
|
||||
# item "historic_average_window" in a home_server section.
|
||||
#
|
||||
# By default it is zero (don't calculate it). Useful values
|
||||
# are between 100, and 10,000. The server will calculate and
|
||||
# remember the moving average for this window, and for 10 times
|
||||
# that window.
|
||||
#
|
||||
|
||||
#
|
||||
# Some of this could have been simplified. e.g. the proxy-auth and
|
||||
# proxy-acct bits aren't completely necessary. But using them permits
|
||||
# the server to be queried for ALL inbound && outbound packets at once.
|
||||
# This gives a good snapshot of what the server is doing.
|
||||
#
|
||||
# Due to internal limitations, the statistics might not be exactly up
|
||||
# to date. Do not expect all of the numbers to add up perfectly.
|
||||
# The Status-Server packets are also counted in the total requests &&
|
||||
# responses. The responses are counted only AFTER the response has
|
||||
# been sent.
|
||||
#
|
||||
@@ -0,0 +1,603 @@
|
||||
######################################################################
|
||||
#
|
||||
# RADIUS over TLS (radsec)
|
||||
#
|
||||
# When a new client connects, the various TLS parameters for the
|
||||
# connection are available as dynamic expansions, e.g.
|
||||
#
|
||||
# %{listen:TLS-Client-Cert-Common-Name}
|
||||
#
|
||||
# Along with other TLS-Client-Cert-... attributes.
|
||||
# These expansions will only exist if the relevant fields
|
||||
# are in the client certificate. Read the debug output to see
|
||||
# which fields are available. Look for output like the following:
|
||||
#
|
||||
# (0) TLS - Creating attributes from certificate OIDs
|
||||
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "one.example.org"
|
||||
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "two.example.org"
|
||||
# ...
|
||||
#
|
||||
# It is also possible to distinguish between connections which have
|
||||
# TLS enables, and ones which do not. The expansion:
|
||||
#
|
||||
# %{listen:tls}
|
||||
#
|
||||
# Will return "yes" if the connection has TLS enabled. It will
|
||||
# return "no" if TLS is not enabled for a particular listen section.
|
||||
#
|
||||
# A number of TLS-Client-Cert-.. attributes holds X509v3 extensions
|
||||
# data, attributes named the way OpenSSL names them. It is possible
|
||||
# to extract data for an extension not known to OpenSSL by defining
|
||||
# a custom string attribute which contains extension OID in it's
|
||||
# name after 'TLS-Client-Cert-' prefix. E.g.:
|
||||
#
|
||||
# ATTRIBUTE TLS-Client-Cert-1.3.6.1.4.1.311.21.7 3002 string
|
||||
#
|
||||
# which will yield something simmilar to:
|
||||
#
|
||||
# (0) eap_tls: TLS - Creating attributes from certificate OIDs
|
||||
# (0) eap_tls: TLS-Client-Cert-1.3.6.1.4.1.311.21.7 += "0x302e06"
|
||||
# ...
|
||||
#
|
||||
######################################################################
|
||||
|
||||
listen {
|
||||
|
||||
# ipaddr = $ENV{FREERADIUS_SITES_TLS_LISTEN}
|
||||
ipaddr = *
|
||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
||||
|
||||
#
|
||||
# TCP and TLS sockets can accept Access-Request and Accounting-Request on the same socket.
|
||||
#
|
||||
# auth = only Access-Request
|
||||
# acct = only Accounting-Request
|
||||
# auth+acct = both
|
||||
# coa = only CoA / Disconnect requests
|
||||
#
|
||||
type = auth+acct
|
||||
|
||||
# For now, only TCP transport is allowed.
|
||||
proto = tcp
|
||||
|
||||
# Send packets to the default virtual server
|
||||
virtual_server = default
|
||||
|
||||
clients = radsec
|
||||
|
||||
# Use the haproxy "PROXY protocol".
|
||||
#
|
||||
# This configuration allows for many FreeRADIUS servers to be behind a haproxy server. The "PROXY protocol" allows haproxy to send the actual client IP to FreeRADIUS.
|
||||
#
|
||||
# This will work ONLY for RadSec (TLS). Both the haproxy AND the RadSec client MUST be listed as allowed RADIUS clients.
|
||||
#
|
||||
# haproxy needs to have "send-proxy" configured for this server. Health checks should be turned off, as haproxy does not support RADIUS health checks.
|
||||
#
|
||||
# The main use of this feature is for scalability. There is no longer any need to have a RADIUS proxy as a load balancer.
|
||||
# haproxy is fast, stable, and supports dynamic reloads!
|
||||
#
|
||||
# The only problem is that many RADIUS clients do not support RadSec. That situation will hopefully change over time.
|
||||
#
|
||||
# proxy_protocol = no
|
||||
|
||||
# When this is set to "yes", new TLS connections are processed through a section called
|
||||
#
|
||||
# Autz-Type New-TLS-Connection {
|
||||
# ...
|
||||
# }
|
||||
#
|
||||
# The request contains TLS client certificate attributes,
|
||||
# and nothing else. The debug output will print which
|
||||
# attributes are available on your system.
|
||||
#
|
||||
# If the section returns "ok" or "updated", then the
|
||||
# connection is accepted. Otherwise the connection is
|
||||
# terminated.
|
||||
#
|
||||
# check_client_connections = yes
|
||||
|
||||
#
|
||||
# Connection limiting for sockets with "proto = tcp".
|
||||
#
|
||||
limit {
|
||||
# Limit the number of simultaneous TCP connections to the socket
|
||||
#
|
||||
# The default is 16.
|
||||
# Setting this to 0 means "no limit"
|
||||
max_connections = 16
|
||||
|
||||
# The per-socket "max_requests" option does not exist.
|
||||
|
||||
# The lifetime, in seconds, of a TCP connection. After this lifetime, the connection will be closed.
|
||||
#
|
||||
# Setting this to 0 means "forever".
|
||||
lifetime = 0
|
||||
|
||||
# The idle timeout, in seconds, of a TCP connection. If no packets have been received over the connection for this time, the connection will be closed.
|
||||
#
|
||||
# Setting this to 0 means "no timeout".
|
||||
# We STRONGLY RECOMMEND that you set an idle timeout.
|
||||
#
|
||||
idle_timeout = 30
|
||||
}
|
||||
|
||||
# This is *exactly* the same configuration as used by the EAP-TLS
|
||||
# module. It's OK for testing, but for production use it's a good
|
||||
# idea to use different server certificates for EAP and for RADIUS
|
||||
# transport.
|
||||
#
|
||||
# If you want only one TLS configuration for multiple sockets,
|
||||
# then we suggest putting "tls { ...}" into radiusd.conf.
|
||||
# The subsection below can then be changed into a reference:
|
||||
#
|
||||
# tls = ${tls}
|
||||
#
|
||||
# Which means "the tls sub-section is not here, but instead is in
|
||||
# the top-level section called 'tls'".
|
||||
#
|
||||
# If you have multiple tls configurations, you can put them into
|
||||
# sub-sections of a top-level "tls" section. There's no need to
|
||||
# call them all "tls". You can then use:
|
||||
#
|
||||
# tls = ${tls.site1}
|
||||
#
|
||||
# to refer to the "site1" sub-section of the "tls" section.
|
||||
#
|
||||
tls {
|
||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
||||
|
||||
# Accept an expired Certificate Revocation List
|
||||
# allow_expired_crl = no
|
||||
|
||||
# If Private key & Certificate are located in
|
||||
# the same file, then private_key_file &
|
||||
# certificate_file must contain the same file
|
||||
# name.
|
||||
#
|
||||
# If ca_file (below) is not used, then the
|
||||
# certificate_file below MUST include not
|
||||
# only the server certificate, but ALSO all
|
||||
# of the CA certificates used to sign the
|
||||
# server certificate.
|
||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
||||
|
||||
|
||||
# Trusted Root CA list
|
||||
#
|
||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
||||
#
|
||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
||||
# In that case, this CA file should contain *one* CA certificate.
|
||||
#
|
||||
# This parameter is used only for EAP-TLS, when you issue client certificates. If you do not use client certificates, and you do not want
|
||||
# to permit EAP-TLS authentication, then delete this configuration item.
|
||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
||||
|
||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
||||
#
|
||||
# openssl dhparam -out certs/dh 1024
|
||||
#
|
||||
# dh_file = ${certdir}/dh
|
||||
|
||||
#
|
||||
# If your system doesn't have /dev/urandom,
|
||||
# you will need to create this file, and
|
||||
# periodically change its contents.
|
||||
#
|
||||
# For security reasons, FreeRADIUS doesn't
|
||||
# write to files in its configuration
|
||||
# directory.
|
||||
#
|
||||
# random_file = /dev/urandom
|
||||
|
||||
#
|
||||
# The default fragment size is 1K.
|
||||
# However, it's possible to send much more data than
|
||||
# that over a TCP connection. The upper limit is 64K.
|
||||
# Setting the fragment size to more than 1K means that
|
||||
# there are fewer round trips when setting up a TLS
|
||||
# connection. But only if the certificates are large.
|
||||
#
|
||||
fragment_size = 8192
|
||||
|
||||
# include_length is a flag which is
|
||||
# by default set to yes If set to
|
||||
# yes, Total Length of the message is
|
||||
# included in EVERY packet we send.
|
||||
# If set to no, Total Length of the
|
||||
# message is included ONLY in the
|
||||
# First packet of a fragment series.
|
||||
#
|
||||
# include_length = yes
|
||||
|
||||
# Check the Certificate Revocation List
|
||||
#
|
||||
# 1) Copy CA certificates and CRLs to same directory.
|
||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
||||
# 'c_rehash' is OpenSSL's command.
|
||||
# 3) uncomment the line below.
|
||||
# 5) Restart radiusd
|
||||
# check_crl = yes
|
||||
ca_path = ${cadir}
|
||||
|
||||
# OpenSSL does not reload contents of ca_path dir over time.
|
||||
# That means that if check_crl is enabled and CRLs are loaded
|
||||
# from ca_path dir, at some point CRLs will expire and
|
||||
# RADIUSd will stop authenticating NASes.
|
||||
# If ca_path_reload_interval is non-zero, it will force OpenSSL
|
||||
# to reload all data from ca_path periodically
|
||||
#
|
||||
# Flush ca_path each hour
|
||||
ca_path_reload_interval = 3600
|
||||
|
||||
#
|
||||
# If check_cert_issuer is set, the value will
|
||||
# be checked against the DN of the issuer in
|
||||
# the client certificate. If the values do not
|
||||
# match, the certificate verification will fail,
|
||||
# rejecting the user.
|
||||
#
|
||||
# This check can be done more generally by checking
|
||||
# the value of the TLS-Client-Cert-Issuer attribute.
|
||||
# This check can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
||||
|
||||
#
|
||||
# If check_cert_cn is set, the value will
|
||||
# be xlat'ed and checked against the CN
|
||||
# in the client certificate. If the values
|
||||
# do not match, the certificate verification
|
||||
# will fail rejecting the user.
|
||||
#
|
||||
# This check is done only if the previous
|
||||
# "check_cert_issuer" is not set, or if
|
||||
# the check succeeds.
|
||||
#
|
||||
# In 2.1.10 and later, this check can be done
|
||||
# more generally by checking the value of the
|
||||
# TLS-Client-Cert-Common-Name attribute. This check
|
||||
# can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_cn = %{User-Name}
|
||||
#
|
||||
# Set this option to specify the allowed
|
||||
# TLS cipher suites. The format is listed
|
||||
# in "man 1 ciphers".
|
||||
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
|
||||
|
||||
# If enabled, OpenSSL will use server cipher list
|
||||
# (possibly defined by cipher_list option above)
|
||||
# for choosing right cipher suite rather than
|
||||
# using client-specified list which is OpenSSl default
|
||||
# behavior. Having it set to yes is a current best practice
|
||||
# for TLS
|
||||
cipher_server_preference = no
|
||||
|
||||
#
|
||||
# Older TLS versions are deprecated. But for RadSec,
|
||||
# we CAN allow TLS 1.3.
|
||||
#
|
||||
tls_min_version = "1.2"
|
||||
tls_max_version = "1.3"
|
||||
|
||||
#
|
||||
# Session resumption / fast reauthentication cache.
|
||||
#
|
||||
# The cache contains the following information:
|
||||
#
|
||||
# session Id - unique identifier, managed by SSL
|
||||
# User-Name - from the Access-Accept
|
||||
# Stripped-User-Name - from the Access-Request
|
||||
# Cached-Session-Policy - from the Access-Accept
|
||||
#
|
||||
# The "Cached-Session-Policy" is the name of a
|
||||
# policy which should be applied to the cached
|
||||
# session. This policy can be used to assign
|
||||
# VLANs, IP addresses, etc. It serves as a useful
|
||||
# way to re-apply the policy from the original
|
||||
# Access-Accept to the subsequent Access-Accept
|
||||
# for the cached session.
|
||||
#
|
||||
# On session resumption, these attributes are
|
||||
# copied from the cache, and placed into the
|
||||
# reply list.
|
||||
#
|
||||
# You probably also want "use_tunneled_reply = yes" when using fast session resumption.
|
||||
#
|
||||
cache {
|
||||
#
|
||||
# Enable it. The default is "no".
|
||||
# Deleting the entire "cache" subsection
|
||||
# Also disables caching.
|
||||
#
|
||||
#
|
||||
# As of version 3.0.14, the session cache requires the use
|
||||
# of the "name" and "persist_dir" configuration items, below.
|
||||
#
|
||||
# The internal OpenSSL session cache has been permanently
|
||||
# disabled.
|
||||
#
|
||||
# You can disallow resumption for a
|
||||
# particular user by adding the following
|
||||
# attribute to the control item list:
|
||||
#
|
||||
# Allow-Session-Resumption = No
|
||||
#
|
||||
# If "enable = no" below, you CANNOT
|
||||
# enable resumption for just one user
|
||||
# by setting the above attribute to "yes".
|
||||
#
|
||||
enable = no
|
||||
|
||||
#
|
||||
# Lifetime of the cached entries, in hours.
|
||||
# The sessions will be deleted after this
|
||||
# time.
|
||||
#
|
||||
lifetime = 24 # hours
|
||||
|
||||
#
|
||||
# Internal "name" of the session cache.
|
||||
# Used to distinguish which TLS context
|
||||
# sessions belong to.
|
||||
#
|
||||
# The server will generate a random value
|
||||
# if unset. This will change across server
|
||||
# restart so you MUST set the "name" if you
|
||||
# want to persist sessions (see below).
|
||||
#
|
||||
# If you use IPv6, change the "ipaddr" below
|
||||
# to "ipv6addr"
|
||||
#
|
||||
#name = "TLS ${..ipaddr} ${..port} ${..proto}"
|
||||
|
||||
#
|
||||
# Simple directory-based storage of sessions.
|
||||
# Two files per session will be written, the SSL
|
||||
# state and the cached VPs. This will persist session
|
||||
# across server restarts.
|
||||
#
|
||||
# The server will need write perms, and the directory
|
||||
# should be secured from anyone else. You might want
|
||||
# a script to remove old files from here periodically:
|
||||
#
|
||||
# find ${logdir}/tlscache -mtime +2 -exec rm -f {} \;
|
||||
#
|
||||
# This feature REQUIRES "name" option be set above.
|
||||
#
|
||||
#persist_dir = "${logdir}/tlscache"
|
||||
}
|
||||
|
||||
#
|
||||
# Require a client certificate.
|
||||
#
|
||||
require_client_cert = yes
|
||||
|
||||
#
|
||||
# As of version 2.1.10, client certificates can be
|
||||
# validated via an external command. This allows
|
||||
# dynamic CRLs or OCSP to be used.
|
||||
#
|
||||
# This configuration is commented out in the
|
||||
# default configuration. Uncomment it, and configure
|
||||
# the correct paths below to enable it.
|
||||
#
|
||||
verify {
|
||||
# A temporary directory where the client
|
||||
# certificates are stored. This directory
|
||||
# MUST be owned by the UID of the server,
|
||||
# and MUST not be accessible by any other
|
||||
# users. When the server starts, it will do
|
||||
# "chmod go-rwx" on the directory, for
|
||||
# security reasons. The directory MUST
|
||||
# exist when the server starts.
|
||||
#
|
||||
# You should also delete all of the files
|
||||
# in the directory when the server starts.
|
||||
# tmpdir = /tmp/radiusd
|
||||
# tmpdir = /startechnica/freeradius/tmp
|
||||
|
||||
# The command used to verify the client cert.
|
||||
# We recommend using the OpenSSL command-line
|
||||
# tool.
|
||||
#
|
||||
# The ${..ca_path} text is a reference to
|
||||
# the ca_path variable defined above.
|
||||
#
|
||||
# The %{TLS-Client-Cert-Filename} is the name
|
||||
# of the temporary file containing the cert
|
||||
# in PEM format. This file is automatically
|
||||
# deleted by the server when the command
|
||||
# returns.
|
||||
# client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
clients radsec {
|
||||
client 127.0.0.1 {
|
||||
ipaddr = 127.0.0.1
|
||||
|
||||
# Ensure that this client is TLS *only*.
|
||||
proto = tls
|
||||
|
||||
# TCP clients can have any shared secret.
|
||||
# TLS clients MUST have the shared secret set to "radsec". Or, for "proto = tls", you can omit the secret, and it will
|
||||
# automatically be set to "radsec".
|
||||
# secret = radsec
|
||||
secret = $ENV{FREERADIUS_CLIENTS_SECRET}
|
||||
|
||||
# You can also use a "limit" section here.
|
||||
# See raddb/clients.conf for examples.
|
||||
#
|
||||
# Note that BOTH limits are applied. You should therefore set the "listen" limits higher than the ones for each individual
|
||||
# client.
|
||||
}
|
||||
}
|
||||
|
||||
# When a request is proxied to a TLS-enabled home server, the TLS parameters are available via the expansion:
|
||||
#
|
||||
# %{proxy_listen: ... }
|
||||
#
|
||||
# The contents of the expansion are the same as described above with the %{listen: ... } expansion, and have similar meanings. "client" in this case is the proxy (this system)
|
||||
# and "server" is the remote system (home server).
|
||||
#
|
||||
# Note that the %{proxy_listen: ... } parameters are available only AFTER the connection has been made to the home server.
|
||||
home_server tls {
|
||||
ipaddr = 127.0.0.1
|
||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
||||
|
||||
# type can be the same types as for the "listen" section/
|
||||
# e.g. auth, acct, auth+acct, coa
|
||||
type = auth
|
||||
secret = radsec
|
||||
proto = tcp
|
||||
status_check = none
|
||||
|
||||
tls {
|
||||
#
|
||||
# Similarly to HTTP, the client can use Server Name
|
||||
# Indication to inform the RadSec server of which
|
||||
# domain it is requesting. This selection allows
|
||||
# multiple sites to exist at the same IP address.
|
||||
#
|
||||
# For example, and identity provider could host
|
||||
# multiple sites, but present itself with one public
|
||||
# IP address.
|
||||
#
|
||||
# SNI also permits the use of a load balancer such as
|
||||
# haproxy. That load balancer can terminate the TLS
|
||||
# connection, and then use SNI to route the
|
||||
# underlying RADIUS TCP traffic to a particular host.
|
||||
#
|
||||
# Note that "hostname" here is only for SNI, and is NOT
|
||||
# the hostname or IP address we connect to. For that,
|
||||
# see "ipaddr", above.
|
||||
#
|
||||
# hostname = "example.com"
|
||||
|
||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
||||
# private_key_file = ${certdir}/client.pem
|
||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
||||
|
||||
# If Private key & Certificate are located in
|
||||
# the same file, then private_key_file &
|
||||
# certificate_file must contain the same file
|
||||
# name.
|
||||
#
|
||||
# If ca_file (below) is not used, then the
|
||||
# certificate_file below MUST include not
|
||||
# only the server certificate, but ALSO all
|
||||
# of the CA certificates used to sign the
|
||||
# server certificate.
|
||||
# certificate_file = ${certdir}/client.pem
|
||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
||||
|
||||
# Trusted Root CA list
|
||||
#
|
||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
||||
#
|
||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
||||
# In that case, this CA file should contain *one* CA certificate.
|
||||
#
|
||||
# This parameter is used only for EAP-TLS,
|
||||
# when you issue client certificates. If you do
|
||||
# not use client certificates, and you do not want
|
||||
# to permit EAP-TLS authentication, then delete
|
||||
# this configuration item.
|
||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
||||
|
||||
#
|
||||
# For TLS-PSK, the key should be specified dynamically, instead of using a hard-coded psk_identity and psk_hexphrase.
|
||||
#
|
||||
# The input to the dynamic expansion will be the PSK
|
||||
# identity supplied by the client, in the
|
||||
# TLS-PSK-Identity attribute. The output of the
|
||||
# expansion should be a hex string, of no more than
|
||||
# 512 characters. The string should not be prefixed
|
||||
# with "0x". e.g. "abcdef" is OK. "0xabcdef" is not.
|
||||
#
|
||||
# psk_query = "%{psksql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
|
||||
|
||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
||||
#
|
||||
# openssl dhparam -out certs/dh 1024
|
||||
#
|
||||
dh_file = ${certdir}/dh
|
||||
random_file = /dev/urandom
|
||||
|
||||
#
|
||||
# The default fragment size is 1K.
|
||||
# However, TLS can send 64K of data at once.
|
||||
# It can be useful to set it higher.
|
||||
#
|
||||
fragment_size = 8192
|
||||
|
||||
# include_length is a flag which is
|
||||
# by default set to yes If set to
|
||||
# yes, Total Length of the message is
|
||||
# included in EVERY packet we send.
|
||||
# If set to no, Total Length of the
|
||||
# message is included ONLY in the
|
||||
# First packet of a fragment series.
|
||||
#
|
||||
# include_length = yes
|
||||
|
||||
# Check the Certificate Revocation List
|
||||
#
|
||||
# 1) Copy CA certificates and CRLs to same directory.
|
||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
||||
# 'c_rehash' is OpenSSL's command.
|
||||
# 3) uncomment the line below.
|
||||
# 5) Restart radiusd
|
||||
# check_crl = yes
|
||||
ca_path = ${cadir}
|
||||
|
||||
#
|
||||
# If check_cert_issuer is set, the value will
|
||||
# be checked against the DN of the issuer in
|
||||
# the client certificate. If the values do not
|
||||
# match, the certificate verification will fail,
|
||||
# rejecting the user.
|
||||
#
|
||||
# In 2.1.10 and later, this check can be done
|
||||
# more generally by checking the value of the
|
||||
# TLS-Client-Cert-Issuer attribute. This check
|
||||
# can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
||||
|
||||
#
|
||||
# If check_cert_cn is set, the value will
|
||||
# be xlat'ed and checked against the CN
|
||||
# in the client certificate. If the values
|
||||
# do not match, the certificate verification
|
||||
# will fail rejecting the user.
|
||||
#
|
||||
# This check is done only if the previous
|
||||
# "check_cert_issuer" is not set, or if
|
||||
# the check succeeds.
|
||||
#
|
||||
# In 2.1.10 and later, this check can be done
|
||||
# more generally by checking the value of the
|
||||
# TLS-Client-Cert-Common-Name attribute. This check
|
||||
# can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_cn = %{User-Name}
|
||||
#
|
||||
# Set this option to specify the allowed TLS cipher suites. The format is listed in "man 1 ciphers".
|
||||
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
home_server_pool tls {
|
||||
type = fail-over
|
||||
home_server = tls
|
||||
}
|
||||
|
||||
realm tls {
|
||||
auth_pool = tls
|
||||
}
|
||||
+115
@@ -0,0 +1,115 @@
|
||||
apiVersion: v1
|
||||
entries:
|
||||
freeradius:
|
||||
- annotations:
|
||||
category: AccessManagement
|
||||
apiVersion: v2
|
||||
appVersion: 3.2.7
|
||||
created: "2025-06-16T16:16:37.456715181+02:00"
|
||||
dependencies:
|
||||
- name: st-common
|
||||
repository: https://startechnica.github.io/apps
|
||||
version: 0.1.12
|
||||
- condition: mariadb.enabled
|
||||
name: mariadb
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 20.x.x
|
||||
description: FreeRADIUS is a modular, high performance free RADIUS suite developed
|
||||
and distributed under the GNU General Public License, version 2, and is free
|
||||
for download and use.
|
||||
digest: da3ba6c773298d8e6ff0df4cb8eb2d9effb81e92d4991a74908a136c70457920
|
||||
home: https://github.com/startechnica/apps/tree/main/charts/freeradius
|
||||
icon: https://freeradius.org/img/wordmark.svg
|
||||
keywords:
|
||||
- freeradius
|
||||
- radius
|
||||
- mysql
|
||||
- postgresql
|
||||
- ldap
|
||||
kubeVersion: '>=1.24.0-0'
|
||||
maintainers:
|
||||
- email: firmansyah@nainggolan.id
|
||||
name: firmansyahn
|
||||
url: https://firmansyah.nainggolan.id
|
||||
name: freeradius
|
||||
sources:
|
||||
- https://freeradius.org/
|
||||
- https://github.com/FreeRADIUS/freeradius-server
|
||||
type: application
|
||||
urls:
|
||||
- freeradius-1.0.3.tgz
|
||||
version: 1.0.3
|
||||
mariadb:
|
||||
- annotations:
|
||||
category: Database
|
||||
images: |
|
||||
- name: mariadb
|
||||
image: docker.io/bitnami/mariadb:11.4.7-debian-12-r1
|
||||
- name: mysqld-exporter
|
||||
image: docker.io/bitnami/mysqld-exporter:0.17.2-debian-12-r11
|
||||
- name: os-shell
|
||||
image: docker.io/bitnami/os-shell:12-debian-12-r46
|
||||
licenses: Apache-2.0
|
||||
tanzuCategory: service
|
||||
apiVersion: v2
|
||||
appVersion: 11.4.7
|
||||
created: "2025-06-16T16:16:37.459591908+02:00"
|
||||
dependencies:
|
||||
- name: common
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
tags:
|
||||
- bitnami-common
|
||||
version: 2.x.x
|
||||
description: MariaDB is an open source, community-developed SQL database server
|
||||
that is widely in use around the world due to its enterprise features, flexibility,
|
||||
and collaboration with leading tech firms.
|
||||
digest: 1e5034974b28d6ab585efdaf9a345ea4e4d3024417b680b83f656a4c0b1e2a84
|
||||
home: https://bitnami.com
|
||||
icon: https://dyltqmyl993wv.cloudfront.net/assets/stacks/mariadb/img/mariadb-stack-220x234.png
|
||||
keywords:
|
||||
- mariadb
|
||||
- mysql
|
||||
- database
|
||||
- sql
|
||||
- prometheus
|
||||
maintainers:
|
||||
- name: Broadcom, Inc. All Rights Reserved.
|
||||
url: https://github.com/bitnami/charts
|
||||
name: mariadb
|
||||
sources:
|
||||
- https://github.com/bitnami/charts/tree/main/bitnami/mariadb
|
||||
urls:
|
||||
- charts/mariadb-20.5.7.tgz
|
||||
version: 20.5.7
|
||||
st-common:
|
||||
- annotations:
|
||||
artifacthub.io/changes: |
|
||||
- kind: added
|
||||
description: Add dotenv and envvars names helper
|
||||
category: Infrastructure
|
||||
apiVersion: v2
|
||||
appVersion: 0.1.12
|
||||
created: "2025-06-16T16:16:37.460145288+02:00"
|
||||
description: A Library Helm Chart for grouping common logic between Startechnica
|
||||
charts. This chart is not deployable by itself.
|
||||
digest: 4c1c7304cf4dbb900b6fd847cf1d38e6f8d1db46dbf080b4d52c884b84a36747
|
||||
home: https://github.com/startechnica/apps/tree/main/charts/common
|
||||
icon: https://startechnica.github.io/apps/images/star.png
|
||||
keywords:
|
||||
- common
|
||||
- helper
|
||||
- template
|
||||
- function
|
||||
kubeVersion: '>=1.20.0-0'
|
||||
maintainers:
|
||||
- email: firmansyah@nainggolan.id
|
||||
name: firmansyahn
|
||||
url: https://firmansyah.nainggolan.id
|
||||
name: st-common
|
||||
sources:
|
||||
- https://startechnica.github.io/apps
|
||||
type: library
|
||||
urls:
|
||||
- charts/st-common-0.1.12.tgz
|
||||
version: 0.1.12
|
||||
generated: "2025-06-16T16:16:37.449242718+02:00"
|
||||
Binary file not shown.
@@ -0,0 +1,54 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if and (include "freeradius.createTlsSecret" .) .Values.tls.autoGenerator.certmanager.enabled }}
|
||||
{{- if not (eq (include "st-common.capabilities.certManager.apiVersion" .) "false") }}
|
||||
{{- $releaseNamespace := include "st-common.names.namespace" . }}
|
||||
{{- $clusterDomain := .Values.clusterDomain }}
|
||||
{{- $fullname := include "st-common.names.fullname" . }}
|
||||
{{- $serviceName := include "st-common.names.fullname" . }}
|
||||
{{- $altNames := list (printf "%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $serviceName $releaseNamespace) (printf "%s.%s" $serviceName $releaseNamespace) $fullname }}
|
||||
{{/*
|
||||
{{- $altNames := list (printf "*.%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $serviceName $releaseNamespace) (printf "%s.%s" $serviceName $releaseNamespace) $fullname }}
|
||||
*/}}
|
||||
apiVersion: {{ include "st-common.capabilities.certManager.apiVersion" . }}
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}-tls
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
secretName: {{ include "freeradius.tlsSecretName" . }}
|
||||
issuerRef:
|
||||
group: cert-manager.io
|
||||
kind: {{ .Values.tls.autoGenerator.certmanager.issuerKind }}
|
||||
name: {{ .Values.tls.autoGenerator.certmanager.issuerName }}
|
||||
#name: letsencrypt-prd
|
||||
privateKey:
|
||||
algorithm: ECDSA
|
||||
rotationPolicy: Always
|
||||
size: 256
|
||||
subject:
|
||||
organizations:
|
||||
- {{ .Release.Name | quote }}
|
||||
organizationalUnits:
|
||||
- {{ include "st-common.names.fullname" . }}
|
||||
dnsNames:
|
||||
- {{ .Values.ingress.hostname | quote }}
|
||||
{{- range .Values.ingress.extraHosts }}
|
||||
- {{ .name | quote }}
|
||||
{{- end }}
|
||||
{{- with $altNames }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
---
|
||||
@@ -0,0 +1,23 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if not .Values.clients.existingConfigMapName }}
|
||||
{{- $client := index .Values "clients" "localhost" }}
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ printf "%s-clients" (include "st-common.names.fullname" .) }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
data:
|
||||
clients.conf: |-
|
||||
client
|
||||
{{- end }}
|
||||
@@ -0,0 +1,75 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ include "freeradius.names.envvars" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
data:
|
||||
FREERADIUS_ENABLE_TLS: {{ ternary "true" "false" .Values.tls.enabled | quote }}
|
||||
|
||||
FREERADIUS_CLIENTS_SHORTNAME: ""
|
||||
FREERADIUS_CLIENTS_IPV4ADDR: ""
|
||||
FREERADIUS_CLIENTS_IPV6ADDR: ""
|
||||
FREERADIUS_CLIENTS_SECRET: ""
|
||||
|
||||
{{- if .Values.modsEnabled.sql.enabled }}
|
||||
FREERADIUS_MODS_SQL_DIALECT: {{ .Values.modsEnabled.sql.dialect }}
|
||||
FREERADIUS_MODS_SQL_SERVER: {{ include "freeradius.database.host" . | quote }}
|
||||
FREERADIUS_MODS_SQL_PORT: {{ include "freeradius.database.port" . }}
|
||||
FREERADIUS_MODS_SQL_LOGIN: {{ include "freeradius.database.user" . | quote }}
|
||||
FREERADIUS_MODS_SQL_DB: {{ include "freeradius.database.name" . | quote }}
|
||||
FREERADIUS_MODS_SQL_TABLE_ACCT1: {{ .Values.modsEnabled.sql.table.acct1 }}
|
||||
FREERADIUS_MODS_SQL_TABLE_ACCT2: {{ .Values.modsEnabled.sql.table.acct2 }}
|
||||
FREERADIUS_MODS_SQL_TABLE_AUTHCHECK: {{ .Values.modsEnabled.sql.table.authcheck }}
|
||||
FREERADIUS_MODS_SQL_TABLE_AUTHREPLY: {{ .Values.modsEnabled.sql.table.authreply }}
|
||||
FREERADIUS_MODS_SQL_TABLE_CLIENT: {{ .Values.modsEnabled.sql.table.client }}
|
||||
FREERADIUS_MODS_SQL_TABLE_GROUPCHECK: {{ .Values.modsEnabled.sql.table.groupcheck }}
|
||||
FREERADIUS_MODS_SQL_TABLE_GROUPREPLY: {{ .Values.modsEnabled.sql.table.groupreply }}
|
||||
FREERADIUS_MODS_SQL_TABLE_POSTAUTH: {{ .Values.modsEnabled.sql.table.postauth }}
|
||||
FREERADIUS_MODS_SQL_TABLE_USERGROUP: {{ .Values.modsEnabled.sql.table.usergroup }}
|
||||
FREERADIUS_MODS_SQL_TLS_ENABLE: {{ ternary "yes" "no" .Values.modsEnabled.sql.tls.enabled | quote }}
|
||||
|
||||
FREERADIUS_MODS_SQL_READ_CLIENTS: {{ ternary "yes" "no" .Values.modsEnabled.sql.readClients | quote }}
|
||||
FREERADIUS_MODS_SQL_GROUP_ATTRIBUTE: {{ .Values.modsEnabled.sql.groupAttribute | quote }}
|
||||
|
||||
FREERADIUS_MODS_SQL_SQLITE_FILENAME: {{ .Values.modsEnabled.sql.sqlite.filename | quote }}
|
||||
FREERADIUS_MODS_SQL_SQLITE_BUSY_TIMEOUT: {{ .Values.modsEnabled.sql.sqlite.busyTimeout | quote }}
|
||||
|
||||
{{- if .Values.modsEnabled.sql.tls.enabled }}
|
||||
FREERADIUS_MODS_SQL_TLS_CACERT: {{ include "freeradius.sqlTlsCACert" . | quote }}
|
||||
FREERADIUS_MODS_SQL_TLS_CIPHER: {{ .Values.modsEnabled.sql.tls.ciphers | quote }}
|
||||
FREERADIUS_MODS_SQL_TLS_CERTIFICATE: {{ include "freeradius.sqlTlsCert" . | quote }}
|
||||
FREERADIUS_MODS_SQL_TLS_PRIVATEKEY: {{ include "freeradius.sqlTlsCertKey" . | quote }}
|
||||
FREERADIUS_MODS_SQL_TLS_PRIVATEKEY_PASSWORD: {{ .Values.modsEnabled.sql.tls.privateKeyPassword | quote }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
FREERADIUS_SITES_NAMESPACE: radius
|
||||
|
||||
FREERADIUS_SITES_DEFAULT_AUTH_PORT: {{ .Values.containerPorts.auth | quote }}
|
||||
FREERADIUS_SITES_DEFAULT_ACCT_PORT: {{ .Values.containerPorts.acct | quote }}
|
||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
||||
FREERADIUS_SITES_COA_PORT: {{ .Values.containerPorts.coa | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.status.enabled }}
|
||||
FREERADIUS_SITES_STATUS_LISTEN: {{ .Values.sitesEnabled.status.listen | quote }}
|
||||
FREERADIUS_SITES_STATUS_PORT: {{ .Values.containerPorts.status | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.tls.enabled }}
|
||||
FREERADIUS_SITES_TLS_PORT: {{ .Values.containerPorts.radsec | quote }}
|
||||
FREERADIUS_SITES_TLS_CA_FILE: {{ include "freeradius.tlsCACert" . | quote }}
|
||||
FREERADIUS_SITES_TLS_CERTIFICATE_FILE: {{ include "freeradius.tlsCert" . | quote }}
|
||||
FREERADIUS_SITES_TLS_CIPHER: {{ default "DEFAULT" .Values.sitesEnabled.tls.cipher | quote }}
|
||||
FREERADIUS_SITES_TLS_PRIVKEY_FILE: {{ include "freeradius.tlsCertKey" . | quote }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,21 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ printf "%s-mods" (include "st-common.names.fullname" .) }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
data:
|
||||
{{- if .Values.modsEnabled.sql.enabled }}
|
||||
{{ (.Files.Glob "files/mods-available/sql").AsConfig | indent 2 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,29 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ printf "%s-sites" (include "st-common.names.fullname" .) }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
data:
|
||||
{{ (.Files.Glob "files/sites-available/default").AsConfig | indent 2 }}
|
||||
{{ (.Files.Glob "files/sites-available/inner-tunnel").AsConfig | indent 2 }}
|
||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
||||
{{ (.Files.Glob "files/sites-available/coa").AsConfig | indent 2 }}
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.status.enabled }}
|
||||
{{ (.Files.Glob "files/sites-available/status").AsConfig | indent 2 }}
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.tls.enabled }}
|
||||
{{ (.Files.Glob "files/sites-available/tls").AsConfig | indent 2 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,366 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
|
||||
{{- $globalSecretName := printf "%s" (tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecret "context" $)) $) }}
|
||||
apiVersion: {{ include "st-common.capabilities.deployment.apiVersion" . }}
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
revisionHistoryLimit: {{ .Values.revisionHistoryLimit }}
|
||||
selector:
|
||||
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 6 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
{{- if .Values.updateStrategy }}
|
||||
strategy: {{- toYaml .Values.updateStrategy | nindent 4 }}
|
||||
{{- end }}
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
checksum/configmap-env: {{ include (print $.Template.BasePath "/ConfigMap/envvars.yaml") . | sha256sum }}
|
||||
checksum/configmap-mods: {{ include (print $.Template.BasePath "/ConfigMap/mods-enabled.yaml") . | sha256sum }}
|
||||
checksum/configmap-sites: {{ include (print $.Template.BasePath "/ConfigMap/sites-enabled.yaml") . | sha256sum }}
|
||||
checksum/secret-credentials: {{ include (print $.Template.BasePath "/Secret/credentials.yaml") . | sha256sum }}
|
||||
checksum/secret-sql-tls: {{ include (print $.Template.BasePath "/Secret/sql-tls.yaml") . | sha256sum }}
|
||||
checksum/secret-tls: {{ include (print $.Template.BasePath "/Secret/tls.yaml") . | sha256sum }}
|
||||
{{- if .Values.podAnnotations }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.podAnnotations "context" $) | nindent 8 }}
|
||||
{{- end }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 8 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
{{- if .Values.podLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.podLabels "context" $) | nindent 8 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if .Values.affinity }}
|
||||
affinity: {{- include "st-common.tplvalues.render" (dict "value" .Values.affinity "context" $) | nindent 8 }}
|
||||
{{- else }}
|
||||
affinity:
|
||||
podAffinity: {{- include "st-common.affinities.pods" (dict "type" .Values.podAffinityPreset "context" $) | nindent 10 }}
|
||||
podAntiAffinity: {{- include "st-common.affinities.pods" (dict "type" .Values.podAntiAffinityPreset "context" $) | nindent 10 }}
|
||||
nodeAffinity: {{- include "st-common.affinities.nodes" (dict "type" .Values.nodeAffinityPreset.type "key" .Values.nodeAffinityPreset.key "values" .Values.nodeAffinityPreset.values) | nindent 10 }}
|
||||
{{- end }}
|
||||
{{- include "freeradius.imagePullSecrets" . | nindent 6 }}
|
||||
{{- if .Values.hostAliases }}
|
||||
hostAliases: {{- include "st-common.tplvalues.render" (dict "value" .Values.hostAliases "context" $) | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.nodeSelector }}
|
||||
nodeSelector: {{- include "st-common.tplvalues.render" (dict "value" .Values.nodeSelector "context" $) | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.priorityClassName }}
|
||||
priorityClassName: {{ .Values.priorityClassName | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.schedulerName }}
|
||||
schedulerName: {{ .Values.schedulerName | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.podSecurityContext.enabled }}
|
||||
securityContext: {{- omit .Values.podSecurityContext "enabled" | toYaml | nindent 8 }}
|
||||
{{- end }}
|
||||
serviceAccountName: {{ include "freeradius.serviceAccountName" . }}
|
||||
{{- if .Values.tolerations }}
|
||||
tolerations: {{- include "st-common.tplvalues.render" (dict "value" .Values.tolerations "context" .) | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.topologySpreadConstraints }}
|
||||
topologySpreadConstraints: {{- include "st-common.tplvalues.render" (dict "value" .Values.topologySpreadConstraints "context" .) | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if or (and .Values.volumePermissions.enabled .Values.persistence.enabled) .Values.initContainers }}
|
||||
initContainers:
|
||||
{{- if .Values.initContainers }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.initContainers "context" $) | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and .Values.volumePermissions.enabled .Values.persistence.enabled }}
|
||||
- name: volume-permissions
|
||||
image: {{ include "freeradius.volumePermissions.image" . }}
|
||||
imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }}
|
||||
command:
|
||||
- /bin/bash
|
||||
args:
|
||||
- -ec
|
||||
- |
|
||||
printf '%s\n' "[system] Change permission" >&2
|
||||
chown -R {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }} {{ .Values.persistence.mountPath }}
|
||||
chmod 0711 {{ .Values.persistence.mountPath }}
|
||||
{{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }}
|
||||
securityContext: {{- omit .Values.volumePermissions.securityContext "runAsUser" | toYaml | nindent 12 }}
|
||||
{{- else }}
|
||||
securityContext: {{- .Values.volumePermissions.securityContext | toYaml | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if .Values.volumePermissions.resources }}
|
||||
resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: data
|
||||
mountPath: {{ .Values.persistence.mountPath }}
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: freeradius
|
||||
image: {{ include "freeradius.image" . }}
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy | quote }}
|
||||
{{- if .Values.diagnosticMode.enabled }}
|
||||
command: {{- include "st-common.tplvalues.render" (dict "value" .Values.diagnosticMode.command "context" $) | nindent 12 }}
|
||||
{{- else if .Values.command }}
|
||||
command: {{- include "st-common.tplvalues.render" (dict "value" .Values.command "context" $) | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if .Values.diagnosticMode.enabled }}
|
||||
args: {{- include "st-common.tplvalues.render" (dict "value" .Values.diagnosticMode.args "context" $) | nindent 12 }}
|
||||
{{- else if .Values.args }}
|
||||
args: {{- include "st-common.tplvalues.render" (dict "value" .Values.args "context" $) | nindent 12 }}
|
||||
{{- else }}
|
||||
args:
|
||||
- -fxx
|
||||
- -l
|
||||
- stdout
|
||||
{{- end }}
|
||||
env:
|
||||
{{- if .Values.modsEnabled.sql.enabled }}
|
||||
- name: FREERADIUS_MODS_SQL_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
{{- if .Values.auth.existingSecretPerPassword }}
|
||||
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.databasePassword "context" $)) $ }}
|
||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "databasePassword") }}
|
||||
{{- else }}
|
||||
name: {{ include "freeradius.database.secretName" . }}
|
||||
key: {{ include "freeradius.database.secretKey" . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.status.enabled }}
|
||||
- name: FREERADIUS_SITES_STATUS_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
{{- if .Values.auth.existingSecretPerPassword }}
|
||||
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.sitesStatusSecret "context" $)) $ }}
|
||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "sitesStatusSecret") }}
|
||||
{{- else }}
|
||||
name: {{ $globalSecretName }}
|
||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecret "key" "sites-status-secret") }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.tls.enabled }}
|
||||
- name: FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
{{- if .Values.auth.existingSecretPerPassword }}
|
||||
name: {{ tpl (include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecretPerPassword.sitesTlsPrivKeyPassword "context" $)) $ }}
|
||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecretPerPassword "key" "sitesTlsPrivKeyPassword") }}
|
||||
{{- else }}
|
||||
name: {{ $globalSecretName }}
|
||||
key: {{ include "st-common.secrets.key" (dict "existingSecret" .Values.auth.existingSecret "key" "sites-tls-privkey-password") }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraEnvVars }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: {{ include "freeradius.names.envvars" . }}
|
||||
{{- if .Values.extraEnvVarsCM }}
|
||||
- configMapRef:
|
||||
name: {{ .Values.extraEnvVarsCM }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraEnvVarsSecret }}
|
||||
- secretRef:
|
||||
name: {{ .Values.extraEnvVarsSecret }}
|
||||
{{- end }}
|
||||
{{- if .Values.lifecycleHooks }}
|
||||
lifecycle: {{- include "st-common.tplvalues.render" (dict "value" .Values.lifecycleHooks "context" $) | nindent 12 }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: auth
|
||||
containerPort: {{ .Values.containerPorts.auth }}
|
||||
protocol: UDP
|
||||
- name: acct
|
||||
containerPort: {{ .Values.containerPorts.acct }}
|
||||
protocol: UDP
|
||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
||||
- name: coa
|
||||
containerPort: {{ .Values.containerPorts.coa }}
|
||||
protocol: UDP
|
||||
{{- end }}
|
||||
{{- if .Values.tls.enabled }}
|
||||
- name: radsec
|
||||
containerPort: {{ .Values.containerPorts.radsec }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.status.enabled }}
|
||||
- name: status
|
||||
containerPort: {{ .Values.containerPorts.status }}
|
||||
protocol: UDP
|
||||
{{- end }}
|
||||
{{- if not .Values.diagnosticMode.enabled }}
|
||||
{{- if .Values.customStartupProbe }}
|
||||
startupProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customStartupProbe "context" $) | nindent 12 }}
|
||||
{{- else if .Values.startupProbe.enabled }}
|
||||
startupProbe: {{- include "st-common.tplvalues.render" (dict "value" (omit .Values.startupProbe "enabled") "context" $) | nindent 12 }}
|
||||
exec:
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
|
||||
if [[ ! -f "{{ .Values.persistence.mountPath }}/.user_scripts_initialized" ]]; then
|
||||
echo "Init scripts still not executed. Skipping check"
|
||||
exit 1
|
||||
fi
|
||||
{{- end }}
|
||||
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
|
||||
{{- end }}
|
||||
{{- if .Values.customLivenessProbe }}
|
||||
livenessProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customLivenessProbe "context" $) | nindent 12 }}
|
||||
{{- else if .Values.livenessProbe.enabled }}
|
||||
livenessProbe: {{- omit .Values.livenessProbe "enabled" | toYaml | nindent 12 }}
|
||||
exec:
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- >-
|
||||
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
|
||||
{{- end }}
|
||||
{{- if .Values.customReadinessProbe }}
|
||||
readinessProbe: {{- include "st-common.tplvalues.render" (dict "value" .Values.customReadinessProbe "context" $) | nindent 12 }}
|
||||
{{- else if .Values.readinessProbe.enabled }}
|
||||
readinessProbe: {{- omit .Values.readinessProbe "enabled" | toYaml | nindent 12 }}
|
||||
exec:
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- >-
|
||||
/bin/echo "Message-Authenticator = 0x00" | /usr/bin/radclient 127.0.0.1:${FREERADIUS_SITES_STATUS_PORT} status ${FREERADIUS_SITES_STATUS_SECRET}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .resources }}
|
||||
resources: {{- include "st-common.tplvalues.render" (dict "value" .resources "context" $) | nindent 12 }}
|
||||
{{- else if and .resourcesPreset (ne .resourcesPreset "none") }}
|
||||
resources: {{- include "st-common.resources.preset" (dict "type" .resourcesPreset) | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if .Values.containerSecurityContext.enabled }}
|
||||
securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: data
|
||||
mountPath: {{ default "/startechnica/freeradius" .Values.persistence.mountPath }}
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
{{- if or (.Files.Glob "files/radiusd.conf") .Values.configuration .Values.configurationConfigMap }}
|
||||
- name: freeradius-config
|
||||
mountPath: /etc/freeradius/radiusd.conf
|
||||
subPath: radiusd.conf
|
||||
{{- end }}
|
||||
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
|
||||
- name: custom-init-scripts
|
||||
mountPath: /docker-entrypoint-initdb.d
|
||||
{{- end }}
|
||||
{{- if .Values.modsEnabled.sql.enabled }}
|
||||
- name: freeradius-mods
|
||||
mountPath: /etc/freeradius/mods-enabled/sql
|
||||
subPath: sql
|
||||
{{- end }}
|
||||
- name: freeradius-sites
|
||||
mountPath: /etc/freeradius/sites-enabled/default
|
||||
subPath: default
|
||||
- name: freeradius-sites
|
||||
mountPath: /etc/freeradius/sites-enabled/status
|
||||
subPath: status
|
||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
||||
- name: freeradius-sites
|
||||
mountPath: /etc/freeradius/sites-enabled/coa
|
||||
subPath: coa
|
||||
{{- end }}
|
||||
{{- if .Values.tls.enabled }}
|
||||
- name: freeradius-sites
|
||||
mountPath: /etc/freeradius/sites-enabled/tls
|
||||
subPath: tls
|
||||
- name: freeradius-tls
|
||||
mountPath: /opt/startechnica/freeradius/certs
|
||||
readOnly: true
|
||||
{{- end }}
|
||||
{{- if and .Values.modsEnabled.sql.enabled (eq .Values.modsEnabled.sql.dialect "sqlite") }}
|
||||
- name: freeradius-sqlite
|
||||
mountPath: {{ .Values.modsEnabled.sql.sqlite.filename | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.modsEnabled.sql.tls.enabled }}
|
||||
- name: freeradius-sql-tls
|
||||
mountPath: /opt/startechnica/freeradius/certs
|
||||
{{- end }}
|
||||
- name: shared-certs
|
||||
mountPath: /opt/startechnica/freeradius/shared-certs
|
||||
readOnly: true
|
||||
- name: temp
|
||||
mountPath: /startechnica/freeradius/tmp
|
||||
{{- if .Values.extraVolumeMounts }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraVolumeMounts "context" $) | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if .Values.sidecars }}
|
||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.sidecars "context" $) | nindent 8 }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
- name: freeradius-mods
|
||||
configMap:
|
||||
name: {{ printf "%s-mods" (include "st-common.names.fullname" .) }}
|
||||
- name: freeradius-sites
|
||||
configMap:
|
||||
name: {{ printf "%s-sites" (include "st-common.names.fullname" .) }}
|
||||
- name: temp
|
||||
emptyDir: {}
|
||||
- name: shared-certs
|
||||
emptyDir: {}
|
||||
- name: data
|
||||
{{- if .Values.persistence.enabled }}
|
||||
persistentVolumeClaim:
|
||||
claimName: {{ include "freeradius.claimName" . }}
|
||||
{{- else }}
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
{{- if and .Values.modsEnabled.sql.enabled (eq .Values.modsEnabled.sql.dialect "sqlite") }}
|
||||
- name: freeradius-sqlite
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
{{- if .Values.tls.enabled }}
|
||||
- name: freeradius-tls
|
||||
secret:
|
||||
secretName: {{ include "freeradius.tlsSecretName" . }}
|
||||
{{- end }}
|
||||
{{- if .Values.modsEnabled.sql.tls.enabled }}
|
||||
- name: freeradius-sql-tls
|
||||
secret:
|
||||
secretName: {{ include "freeradius.sqlTlsSecretName" . }}
|
||||
items:
|
||||
- key: tls.crt
|
||||
path: sql-tls.crt
|
||||
- key: tls.key
|
||||
path: sql-tls.key
|
||||
- key: ca.crt
|
||||
path: sql-ca.crt
|
||||
{{- end }}
|
||||
{{- if or (.Files.Glob "files/radiusd.conf") .Values.configuration .Values.configurationConfigMap }}
|
||||
- name: freeradius-config
|
||||
configMap:
|
||||
name: {{ include "freeradius.configurationCM" . }}
|
||||
{{- end }}
|
||||
{{- if or (.Files.Glob "files/docker-entrypoint-initdb.d/*.{sh,sql,sql.gz}") .Values.initdbScriptsConfigMap .Values.initdbScripts }}
|
||||
- name: custom-init-scripts
|
||||
configMap:
|
||||
name: {{ include "freeradius.initdbScriptsCM" . }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraVolumes }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.extraVolumes "context" $) | nindent 8 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,69 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if and .Values.gateway.enabled (not .Values.gateway.existingGateway) }}
|
||||
{{- if not (eq (include "st-common.capabilities.istioGateway.apiVersion" .) "false") }}
|
||||
apiVersion: {{ include "st-common.capabilities.istioGateway.apiVersion" . }}
|
||||
kind: Gateway
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations:
|
||||
{{- if .Values.commonAnnotations }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
spec:
|
||||
selector:
|
||||
istio.io/gateway-name: {{ default "ingressgateway" .Values.gateway.name }}
|
||||
servers:
|
||||
- port:
|
||||
name: auth
|
||||
number: {{ .Values.service.ports.auth }}
|
||||
protocol: UDP
|
||||
hosts:
|
||||
- {{ .Values.ingress.hostname }}
|
||||
{{- range $host := .Values.ingress.extraHosts }}
|
||||
- {{ $host.name | quote }}
|
||||
{{- end }}
|
||||
- port:
|
||||
name: acct
|
||||
number: {{ .Values.service.ports.acct }}
|
||||
protocol: UDP
|
||||
hosts:
|
||||
- {{ .Values.ingress.hostname }}
|
||||
{{- range $host := .Values.ingress.extraHosts }}
|
||||
- {{ $host.name | quote }}
|
||||
{{- end }}
|
||||
- port:
|
||||
name: coa
|
||||
number: {{ .Values.service.ports.coa }}
|
||||
protocol: UDP
|
||||
hosts:
|
||||
- {{ .Values.ingress.hostname }}
|
||||
{{- range $host := .Values.ingress.extraHosts }}
|
||||
- {{ $host.name | quote }}
|
||||
{{- end }}
|
||||
- port:
|
||||
name: radsec
|
||||
number: {{ .Values.service.ports.radsec }}
|
||||
protocol: TLS
|
||||
hosts:
|
||||
- {{ .Values.ingress.hostname }}
|
||||
{{- range $host := .Values.ingress.extraHosts }}
|
||||
- {{ $host.name | quote }}
|
||||
{{- end }}
|
||||
tls:
|
||||
mode: PASSTHROUGH
|
||||
{{- if .Values.sitesEnabled.tls.enabled }}
|
||||
credentialName: {{ include "freeradius.tlsSecretName" . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,47 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if and .Values.gateway.enabled (not .Values.gateway.existingVirtualService) }}
|
||||
{{- if not (eq (include "st-common.capabilities.istioVirtualService.apiVersion" .) "false") }}
|
||||
apiVersion: {{ include "st-common.capabilities.istioVirtualService.apiVersion" . }}
|
||||
kind: VirtualService
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations:
|
||||
{{- if .Values.commonAnnotations }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
spec:
|
||||
gateways:
|
||||
- {{ printf "%s/%s" (include "st-common.names.namespace" .) (include "st-common.names.fullname" .) }}
|
||||
hosts:
|
||||
- {{ .Values.ingress.hostname }}
|
||||
{{- range $host := .Values.ingress.extraHosts }}
|
||||
- {{ $host | quote }}
|
||||
{{- end }}
|
||||
tls:
|
||||
- match:
|
||||
- port: {{ .Values.service.ports.radsec }}
|
||||
sniHosts:
|
||||
- {{ .Values.ingress.hostname }}
|
||||
{{- range $host := .Values.ingress.extraHosts }}
|
||||
- {{ $host | quote }}
|
||||
{{- end }}
|
||||
route:
|
||||
- destination:
|
||||
# host: {{ printf "%s.%s.svc.%s" (include "st-common.names.fullname" .) (include "st-common.names.namespace" .) .Values.clusterDomain }}
|
||||
host: {{ printf "%s.%s.svc.cluster.local" (include "st-common.names.fullname" .) (include "st-common.names.namespace" .) }}
|
||||
port:
|
||||
number: {{ .Values.service.ports.radsec }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,57 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if .Values.networkPolicy.enabled }}
|
||||
apiVersion: {{ include "st-common.capabilities.networkPolicy.apiVersion" . }}
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 6 }}
|
||||
ingress:
|
||||
- ports:
|
||||
- port: {{ .Values.containerPorts.auth }}
|
||||
protocol: UDP
|
||||
- port: {{ .Values.containerPorts.acct }}
|
||||
protocol: UDP
|
||||
{{- if .Values.tls.enabled }}
|
||||
- port: {{ .Values.containerPorts.radsec }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- if .Values.metrics.enabled }}
|
||||
- port: {{ .Values.containerPorts.metrics }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
||||
- port: {{ .Values.containerPorts.coa }}
|
||||
protocol: UDP
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.status.enabled }}
|
||||
- port: {{ .Values.containerPorts.status }}
|
||||
protocol: UDP
|
||||
{{- end }}
|
||||
{{- if not .Values.networkPolicy.allowExternal }}
|
||||
from:
|
||||
- podSelector:
|
||||
matchLabels:
|
||||
{{ include "st-common.names.fullname" . }}-client: "true"
|
||||
- podSelector:
|
||||
matchLabels: {{- include "st-common.labels.matchLabels" . | nindent 14 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
{{- if .Values.networkPolicy.additionalRules }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.networkPolicy.additionalRules "context" $) | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,38 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) -}}
|
||||
kind: PersistentVolumeClaim
|
||||
apiVersion: v1
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.persistence.annotations .Values.commonAnnotations }}
|
||||
annotations:
|
||||
{{- if .Values.commonAnnotations }}
|
||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.persistence.annotations }}
|
||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.persistence.annotations "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
spec:
|
||||
accessModes:
|
||||
{{- if not (empty .Values.persistence.accessModes) }}
|
||||
{{- range .Values.persistence.accessModes }}
|
||||
- {{ . | quote }}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
- {{ .Values.persistence.accessMode | quote }}
|
||||
{{- end }}
|
||||
resources:
|
||||
requests:
|
||||
storage: {{ .Values.persistence.size | quote }}
|
||||
{{- include "st-common.storage.class" (dict "persistence" .Values.persistence "global" .Values.global) | nindent 2 }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,28 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if .Values.podDisruptionBudget.create }}
|
||||
apiVersion: {{ include "st-common.capabilities.policy.apiVersion" . }}
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if .Values.podDisruptionBudget.minAvailable }}
|
||||
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
|
||||
{{- end }}
|
||||
{{- if .Values.podDisruptionBudget.maxUnavailable }}
|
||||
maxUnavailable: {{ .Values.podDisruptionBudget.maxUnavailable }}
|
||||
{{- end }}
|
||||
selector:
|
||||
matchLabels: {{ include "st-common.labels.matchLabels" . | nindent 6 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,25 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{ if and .Values.metrics.enabled .Values.metrics.prometheusRules.enabled }}
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: PrometheusRule
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ .Release.Namespace | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.metrics.prometheusRules.additionalLabels "context" $) | nindent 4 }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
groups:
|
||||
- name: {{ include "st-common.names.fullname" . }}
|
||||
rules:
|
||||
{{- toYaml .Values.metrics.prometheusRules.rules | nindent 6 }}
|
||||
{{ end }}
|
||||
@@ -0,0 +1,29 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if .Values.rbac.create }}
|
||||
apiVersion: {{ include "st-common.capabilities.rbac.apiVersion" . }}
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- secrets
|
||||
- configmaps
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
{{- end }}
|
||||
@@ -0,0 +1,26 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if and .Values.serviceAccount.create .Values.rbac.create }}
|
||||
apiVersion: {{ include "st-common.capabilities.rbac.apiVersion" . }}
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ include "freeradius.serviceAccountName" . }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,38 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if and (not .Values.auth.existingSecret) (not .Values.auth.existingSecretPerPassword) }}
|
||||
{{- $secretName := include "st-common.secrets.name" (dict "existingSecret" .Values.auth.existingSecret "context" $) }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ $secretName }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
type: Opaque
|
||||
data:
|
||||
{{- if and (not .Values.mariadb.enabled) (not .Values.externalDatabase.existingSecret) }}
|
||||
database-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "database-password" "length" 10 "providedValues" (list "externalDatabase.password") "context" $) }}
|
||||
{{- end }}
|
||||
{{- if and (.Values.mariadb.enabled) (not (empty .Values.mariadb.auth.username)) }}
|
||||
mariadb-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "mariadb-password" "providedValues" (list "mariadb.auth.password") "context" $) }}
|
||||
{{- end }}
|
||||
{{- if (.Values.sitesEnabled.status.enabled) }}
|
||||
sites-status-secret: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "sites-status-secret" "length" 10 "providedValues" (list "sitesEnabled.status.secret") "context" $) }}
|
||||
{{- end }}
|
||||
{{- if (.Values.sitesEnabled.tls.enabled) }}
|
||||
sites-tls-privkey-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "sites-tls-privkey-password" "length" 10 "providedValues" (list "sitesEnabled.tls.privateKeyPassword") "context" $) }}
|
||||
{{- end }}
|
||||
{{- if (.Values.modsEnabled.sql.tls.enabled) }}
|
||||
mods-sql-tls-privkey-password: {{ include "st-common.secrets.passwords.manage" (dict "secret" $secretName "key" "mods-sql-tls-privkey-password" "length" 10 "providedValues" (list "modsEnabled.sql.tls.privateKeyPassword") "context" $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,30 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if and (include "freeradius.createSqlTlsSecret" .) (not .Values.tls.autoGenerator.certmanager.enabled) }}
|
||||
{{- $ca := genCA "freeradius-ca" 365 }}
|
||||
{{- $releaseNamespace := include "st-common.names.namespace" . }}
|
||||
{{- $clusterDomain := .Values.clusterDomain }}
|
||||
{{- $fullname := include "st-common.names.fullname" . }}
|
||||
{{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $fullname $releaseNamespace) (printf "%s.%s" $fullname $releaseNamespace) $fullname }}
|
||||
{{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}-sql-tls
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
type: kubernetes.io/tls
|
||||
data:
|
||||
ca.crt: {{ $ca.Cert | b64enc | quote }}
|
||||
tls.crt: {{ $crt.Cert | b64enc | quote }}
|
||||
tls.key: {{ $crt.Key | b64enc | quote }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,30 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if and (include "freeradius.createTlsSecret" .) (not .Values.tls.autoGenerator.certmanager.enabled) }}
|
||||
{{- $ca := genCA "freeradius-ca" 365 }}
|
||||
{{- $releaseNamespace := include "st-common.names.namespace" . }}
|
||||
{{- $clusterDomain := .Values.clusterDomain }}
|
||||
{{- $fullname := include "st-common.names.fullname" . }}
|
||||
{{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc" $fullname $releaseNamespace) (printf "%s.%s" $fullname $releaseNamespace) $fullname }}
|
||||
{{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}-tls
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
{{- if .Values.commonAnnotations }}
|
||||
annotations: {{- include "st-common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||
{{- end }}
|
||||
type: kubernetes.io/tls
|
||||
data:
|
||||
ca.crt: {{ $ca.Cert | b64enc | quote }}
|
||||
tls.crt: {{ $crt.Cert | b64enc | quote }}
|
||||
tls.key: {{ $crt.Key | b64enc | quote }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,98 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "st-common.names.fullname" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.service.annotations .Values.commonAnnotations .Values.metrics.annotations }}
|
||||
annotations:
|
||||
{{- if .Values.commonAnnotations }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.service.annotations }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.service.annotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if and .Values.metrics.enabled .Values.metrics.annotations }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.metrics.annotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
spec:
|
||||
type: {{ default "ClusterIP" .Values.service.type }}
|
||||
{{- if eq .Values.service.type "LoadBalancer" }}
|
||||
allocateLoadBalancerNodePorts: {{ eq .Values.service.allocateLoadBalancerNodePorts "true" }}
|
||||
{{- end }}
|
||||
{{- if and .Values.service.clusterIP (eq .Values.service.type "ClusterIP") }}
|
||||
clusterIP: {{ .Values.service.clusterIP }}
|
||||
{{- end }}
|
||||
{{- if and .Values.service.externalTrafficPolicy (or (eq .Values.service.type "LoadBalancer") (eq .Values.service.type "NodePort")) }}
|
||||
externalTrafficPolicy: {{ .Values.service.externalTrafficPolicy | quote }}
|
||||
{{- end }}
|
||||
ipFamilyPolicy: {{ .Values.service.ipFamilyPolicy }}
|
||||
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerClass)) }}
|
||||
loadBalancerClass: {{ .Values.service.loadBalancerClass }}
|
||||
{{- end }}
|
||||
{{- if (and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerIP))) }}
|
||||
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
|
||||
{{- end }}
|
||||
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerSourceRanges)) }}
|
||||
loadBalancerSourceRanges: {{ .Values.service.loadBalancerSourceRanges }}
|
||||
{{- end }}
|
||||
{{- if .Values.service.sessionAffinity }}
|
||||
sessionAffinity: {{ .Values.service.sessionAffinity }}
|
||||
{{- end }}
|
||||
{{- if .Values.service.sessionAffinityConfig }}
|
||||
sessionAffinityConfig: {{- include "st-common.tplvalues.render" (dict "value" .Values.service.sessionAffinityConfig "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: udp-auth
|
||||
port: {{ .Values.service.ports.auth }}
|
||||
protocol: UDP
|
||||
targetPort: {{ .Values.containerPorts.auth }}
|
||||
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.auth) }}
|
||||
nodePort: {{ coalesce .Values.service.nodePorts.auth .Values.service.nodePort }}
|
||||
{{- else if eq .Values.service.type "ClusterIP" }}
|
||||
nodePort: null
|
||||
{{- end }}
|
||||
- name: udp-acct
|
||||
port: {{ .Values.service.ports.acct }}
|
||||
protocol: UDP
|
||||
targetPort: {{ .Values.containerPorts.acct }}
|
||||
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.acct) }}
|
||||
nodePort: {{ .Values.service.nodePorts.acct }}
|
||||
{{- else if eq .Values.service.type "ClusterIP" }}
|
||||
nodePort: null
|
||||
{{- end }}
|
||||
{{- if .Values.sitesEnabled.coa.enabled }}
|
||||
- name: udp-coa
|
||||
port: {{ .Values.service.ports.coa }}
|
||||
protocol: UDP
|
||||
targetPort: {{ .Values.containerPorts.coa }}
|
||||
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.coa) }}
|
||||
nodePort: {{ .Values.service.nodePorts.coa }}
|
||||
{{- else if eq .Values.service.type "ClusterIP" }}
|
||||
nodePort: null
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.tls.enabled }}
|
||||
- name: tcp-radsec
|
||||
port: {{ .Values.service.ports.radsec }}
|
||||
protocol: TCP
|
||||
targetPort: {{ .Values.containerPorts.radsec }}
|
||||
{{- if (and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) .Values.service.nodePorts.radsec) }}
|
||||
nodePort: {{ .Values.service.nodePorts.radsec }}
|
||||
{{- else if eq .Values.service.type "ClusterIP" }}
|
||||
nodePort: null
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
selector: {{ include "st-common.labels.matchLabels" . | nindent 4 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
---
|
||||
@@ -0,0 +1,27 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{- if .Values.serviceAccount.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ include "freeradius.serviceAccountName" . }}
|
||||
namespace: {{ include "st-common.names.namespace" . | quote }}
|
||||
labels: {{- include "st-common.labels.standard" . | nindent 4 }}
|
||||
app.kubernetes.io/component: freeradius
|
||||
{{- if .Values.commonLabels }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonLabels "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.serviceAccount.annotations .Values.commonAnnotations }}
|
||||
annotations:
|
||||
{{- if .Values.commonAnnotations }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.commonAnnotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.serviceAccount.annotations }}
|
||||
{{- include "st-common.tplvalues.render" (dict "value" .Values.serviceAccount.annotations "context" $) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,95 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{/* Create a default fully qualified app name. We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). */}}
|
||||
{{- define "freeradius.mariadb.fullname" -}}
|
||||
{{- include "st-common.names.dependency.fullname" (dict "chartName" "mariadb" "chartValues" .Values.mariadb "context" $) -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the Database hostname */}}
|
||||
{{- define "freeradius.database.host" -}}
|
||||
{{- if eq .Values.mariadb.architecture "replication" }}
|
||||
{{- ternary (include "freeradius.mariadb.fullname" .) .Values.externalDatabase.host .Values.mariadb.enabled -}}-primary
|
||||
{{- else -}}
|
||||
{{- ternary (include "freeradius.mariadb.fullname" .) .Values.externalDatabase.host .Values.mariadb.enabled -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the Database port */}}
|
||||
{{- define "freeradius.database.port" -}}
|
||||
{{- ternary "3306" .Values.externalDatabase.port .Values.mariadb.enabled | quote -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the Database database name */}}
|
||||
{{- define "freeradius.database.name" -}}
|
||||
{{- if .Values.mariadb.enabled }}
|
||||
{{- if .Values.global.mariadb }}
|
||||
{{- if .Values.global.mariadb.auth }}
|
||||
{{- coalesce .Values.global.mariadb.auth.database .Values.mariadb.auth.database -}}
|
||||
{{- else -}}
|
||||
{{- .Values.mariadb.auth.database -}}
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
{{- .Values.mariadb.auth.database -}}
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
{{- .Values.externalDatabase.database -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the Database user */}}
|
||||
{{- define "freeradius.database.user" -}}
|
||||
{{- if .Values.mariadb.enabled }}
|
||||
{{- if .Values.global.mariadb }}
|
||||
{{- if .Values.global.mariadb.auth }}
|
||||
{{- coalesce .Values.global.mariadb.auth.username .Values.mariadb.auth.username -}}
|
||||
{{- else -}}
|
||||
{{- .Values.mariadb.auth.username -}}
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
{{- .Values.mariadb.auth.username -}}
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
{{- .Values.externalDatabase.user -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the Database encrypted password */}}
|
||||
{{- define "freeradius.database.secretName" -}}
|
||||
{{- if .Values.mariadb.enabled }}
|
||||
{{- if .Values.global.mariadb }}
|
||||
{{- if .Values.global.mariadb.auth }}
|
||||
{{- if .Values.global.mariadb.auth.existingSecret }}
|
||||
{{- tpl .Values.global.mariadb.auth.existingSecret $ -}}
|
||||
{{- else -}}
|
||||
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
{{- default (include "freeradius.mariadb.fullname" .) (tpl .Values.mariadb.auth.existingSecret $) -}}
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
{{- default (include "st-common.secrets.name" (dict "existingSecret" .Values.mariadb.auth.existingSecret "context" $)) (tpl .Values.externalDatabase.existingSecret $) -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Add environment variables to configure database values */}}
|
||||
{{- define "freeradius.database.secretKey" -}}
|
||||
{{- if .Values.mariadb.enabled -}}
|
||||
{{- print "mariadb-password" -}}
|
||||
{{- else -}}
|
||||
{{- if .Values.externalDatabase.existingSecret -}}
|
||||
{{- if .Values.externalDatabase.existingSecretPasswordKey -}}
|
||||
{{- printf "%s" .Values.externalDatabase.existingSecretPasswordKey -}}
|
||||
{{- else -}}
|
||||
{{- print "database-password" -}}
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
{{- print "database-password" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,140 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{/* Create the name of the service account to use */}}
|
||||
{{- define "freeradius.serviceAccountName" -}}
|
||||
{{- if .Values.serviceAccount.create }}
|
||||
{{- default (include "st-common.names.fullname" .) .Values.serviceAccount.name }}
|
||||
{{- else }}
|
||||
{{- default "default" .Values.serviceAccount.name }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Return the path to the cert file. */}}
|
||||
{{- define "freeradius.tlsCert" -}}
|
||||
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/tls.crt" -}}
|
||||
{{- else -}}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certFilename -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the path to the cert key file. */}}
|
||||
{{- define "freeradius.tlsCertKey" -}}
|
||||
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/tls.key" -}}
|
||||
{{- else -}}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certKeyFilename -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the path to the CA cert file. */}}
|
||||
{{- define "freeradius.tlsCACert" -}}
|
||||
{{- if and .Values.tls.enabled .Values.tls.autoGenerated }}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/ca.crt" -}}
|
||||
{{- else -}}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.tls.certCAFilename -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Create the name of the SSL certificate to use */}}
|
||||
{{- define "freeradius.tlsSecretName" -}}
|
||||
{{- if .Values.tls.certificatesSecret }}
|
||||
{{ .Values.tls.certificatesSecret }}
|
||||
{{- else }}
|
||||
{{- default (printf "%s-tls" (include "st-common.names.fullname" .)) }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return true if a TLS secret object should be created */}}
|
||||
{{- define "freeradius.createTlsSecret" -}}
|
||||
{{- if and .Values.tls.enabled .Values.tls.autoGenerated (not .Values.tls.certificatesSecret) }}
|
||||
{{- true }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Validate values of FreeRADIUS - Auth TLS enabled */}}
|
||||
{{- define "freeradius.validateValues.tls" -}}
|
||||
{{- if and .Values.tls.enabled (not .Values.tls.autoGenerated) (not .Values.tls.certificatesSecret) }}
|
||||
freeradius: tls.enabled
|
||||
In order to enable TLS, you also need to provide
|
||||
an existing secret containing the Keystore and Truststore or
|
||||
enable auto-generated certificates.
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the path to the SQL cert file. */}}
|
||||
{{- define "freeradius.sqlTlsCert" -}}
|
||||
{{- if and .Values.modsEnabled.sql.tls.enabled }}
|
||||
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/sql-tls.crt" -}}
|
||||
{{- else if not (empty .Values.modsEnabled.sql.tls.certFilename) }}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certFilename -}}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
{{- printf "" -}}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the path to the SQL cert key file. */}}
|
||||
{{- define "freeradius.sqlTlsCertKey" -}}
|
||||
{{- if and .Values.modsEnabled.sql.tls.enabled }}
|
||||
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/sql-tls.key" -}}
|
||||
{{- else if not (empty .Values.modsEnabled.sql.tls.certKeyFilename) }}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certKeyFilename -}}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
{{- printf "" -}}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the path to the SQL CA cert file. */}}
|
||||
{{- define "freeradius.sqlTlsCACert" -}}
|
||||
{{- if and .Values.modsEnabled.sql.tls.enabled }}
|
||||
{{- if .Values.modsEnabled.sql.tls.autoGenerated }}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/sql-ca.crt" -}}
|
||||
{{- else if not (empty .Values.modsEnabled.sql.tls.certCAFilename)}}
|
||||
{{- printf "/opt/startechnica/freeradius/certs/%s" .Values.modsEnabled.sql.tls.certCAFilename -}}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
{{- printf "" -}}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Create the name of the secret for SQL SSL certificate to use */}}
|
||||
{{- define "freeradius.sqlTlsSecretName" -}}
|
||||
{{- if .Values.modsEnabled.sql.tls.certificatesSecret }}
|
||||
{{ .Values.modsEnabled.sql.tls.certificatesSecret }}
|
||||
{{- else }}
|
||||
{{- default (printf "%s-sql-tls" (include "st-common.names.fullname" .)) }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return true if a TLS secret object should be created */}}
|
||||
{{- define "freeradius.createSqlTlsSecret" -}}
|
||||
{{- if and .Values.modsEnabled.sql.tls.enabled .Values.modsEnabled.sql.tls.autoGenerated (not .Values.modsEnabled.sql.tls.certificatesSecret) }}
|
||||
{{- true }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Get the configuration ConfigMap name. */}}
|
||||
{{- define "freeradius.configurationCM" -}}
|
||||
{{- if .Values.configurationConfigMap -}}
|
||||
{{- printf "%s" (tpl .Values.configurationConfigMap $) -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s-configuration" (include "st-common.names.fullname" .) -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Get the initialization scripts ConfigMap name. */}}
|
||||
{{- define "freeradius.initdbScriptsCM" -}}
|
||||
{{- if .Values.initdbScriptsConfigMap -}}
|
||||
{{- printf "%s" .Values.initdbScriptsConfigMap -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s-init-scripts" (include "st-common.names.fullname" .) -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{/* Return the proper FreeRADIUS image name */}}
|
||||
{{- define "freeradius.image" -}}
|
||||
{{ include "st-common.images.image" (dict "imageRoot" .Values.image "global" .Values.global) }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the proper Docker Image Registry Secret Names */}}
|
||||
{{- define "freeradius.imagePullSecrets" -}}
|
||||
{{- include "st-common.images.pullSecrets" (dict "images" (list .Values.image .Values.volumePermissions.image .Values.metrics.image) "global" .Values.global) -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,10 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
|
||||
{{- define "freeradius.names.envvars" -}}
|
||||
{{- printf "%s-envvars" (include "st-common.names.fullname" .) -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,18 @@
|
||||
{{- /*
|
||||
Copyright (c) 2025 Firmansyah Nainggolan. All Rights Reserved.
|
||||
SPDX-License-Identifier: APACHE-2.0
|
||||
*/}}
|
||||
|
||||
{{/* Return the FreeRADIUS PVC name. */}}
|
||||
{{- define "freeradius.claimName" -}}
|
||||
{{- if .Values.persistence.existingClaim }}
|
||||
{{- printf "%s" (tpl .Values.persistence.existingClaim $) -}}
|
||||
{{- else }}
|
||||
{{- printf "%s" (include "st-common.names.fullname" .) -}}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Return the proper image name (for the init container volume-permissions image) */}}
|
||||
{{- define "freeradius.volumePermissions.image" -}}
|
||||
{{ include "st-common.images.image" (dict "imageRoot" .Values.volumePermissions.image "global" .Values.global) }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,44 @@
|
||||
persistence:
|
||||
enabled: true
|
||||
# storageClass:
|
||||
|
||||
service:
|
||||
type: LoadBalancer
|
||||
externalTrafficPolicy: Local
|
||||
ipFamilyPolicy: PreferDualStack
|
||||
|
||||
modsEnabled:
|
||||
sql:
|
||||
enabled: true
|
||||
dialect: mysql
|
||||
|
||||
externalDatabase:
|
||||
# host: mariadb-infra-mariadb-galera.mariadb-infra.svc
|
||||
host: mariadb-primary.mariadb.svc
|
||||
port: 3306
|
||||
user: radius_user
|
||||
database: radiusdb
|
||||
password: "aserfdertg"
|
||||
|
||||
sitesEnabled:
|
||||
coa:
|
||||
enabled: true
|
||||
tls:
|
||||
enabled: true
|
||||
|
||||
tls:
|
||||
enabled: true
|
||||
autoGenerated: true
|
||||
|
||||
# updateStrategy:
|
||||
# type: Recreate
|
||||
|
||||
volumePermissions:
|
||||
enabled: true
|
||||
|
||||
gateway:
|
||||
enabled: true
|
||||
dedicated: false
|
||||
gatewayApi: false
|
||||
name: "freeradius"
|
||||
namespace: "istio-ingress"
|
||||
+985
@@ -0,0 +1,985 @@
|
||||
## @section Global parameters
|
||||
|
||||
## Global Docker image parameters
|
||||
## Please, note that this will override the image parameters, including dependencies, configured to use the global value
|
||||
## Current available global Docker image parameters: imageRegistry, imagePullSecrets and storageClass
|
||||
|
||||
## @param global.imageRegistry Global Docker image registry
|
||||
## @param global.imagePullSecrets Global Docker registry secret names as an array
|
||||
## @param global.storageClass Global StorageClass for Persistent Volume(s)
|
||||
##
|
||||
global:
|
||||
imageRegistry: ""
|
||||
## E.g.
|
||||
## imagePullSecrets:
|
||||
## - myRegistryKeySecretName
|
||||
##
|
||||
imagePullSecrets: []
|
||||
storageClass: ""
|
||||
|
||||
## @section Common parameters
|
||||
|
||||
## @param kubeVersion Force target Kubernetes version (using Helm capabilities if not set)
|
||||
##
|
||||
kubeVersion: ""
|
||||
## @param nameOverride String to partially override freeradius.fullname
|
||||
##
|
||||
nameOverride: ""
|
||||
## @param namespaceOverride String to partially override freeradius.namespace
|
||||
##
|
||||
namespaceOverride: ""
|
||||
## @param fullnameOverride String to fully override adminer.fullname
|
||||
##
|
||||
fullnameOverride: ""
|
||||
## @param commonLabels Labels to add to all deployed objects
|
||||
##
|
||||
commonLabels: {}
|
||||
## @param commonAnnotations Annotations to add to all deployed objects
|
||||
##
|
||||
commonAnnotations: {}
|
||||
## @param clusterDomain Default Kubernetes cluster domain
|
||||
##
|
||||
clusterDomain: cluster.local
|
||||
## @param extraDeploy Array of extra objects to deploy with the release
|
||||
##
|
||||
extraDeploy: []
|
||||
## Enable diagnostic mode in the deployment
|
||||
##
|
||||
diagnosticMode:
|
||||
## @param diagnosticMode.enabled Enable diagnostic mode (all probes will be disabled and the command will be overridden)
|
||||
##
|
||||
enabled: false
|
||||
## @param diagnosticMode.command Command to override all containers in the deployment
|
||||
##
|
||||
command:
|
||||
- sleep
|
||||
## @param diagnosticMode.args Args to override all containers in the deployment
|
||||
##
|
||||
args:
|
||||
- infinity
|
||||
|
||||
## @section FreeRADIUS Image parameters
|
||||
|
||||
## FreeRADIUS image
|
||||
## ref: https://hub.docker.com/r/freeradius/freeradius-server/tags
|
||||
## @param image.registry FreeRADIUS image registry
|
||||
## @param image.repository FreeRADIUS image repository
|
||||
## @param image.tag FreeRADIUS image tag (immutable tags are recommended)
|
||||
## @param image.pullPolicy FreeRADIUS image pull policy
|
||||
## @param image.pullSecrets Specify docker-registry secret names as an array
|
||||
## @param image.debug Specify if debug logs should be enabled
|
||||
##
|
||||
image:
|
||||
registry: docker.io
|
||||
repository: freeradius/freeradius-server
|
||||
tag: "3.2.7"
|
||||
## Specify a imagePullPolicy
|
||||
## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent'
|
||||
## ref: https://kubernetes.io/docs/user-guide/images/#pre-pulling-images
|
||||
##
|
||||
pullPolicy: IfNotPresent
|
||||
## Optionally specify an array of imagePullSecrets (secrets must be manually created in the namespace)
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||
## Example:
|
||||
## pullSecrets:
|
||||
## - myRegistryKeySecretName
|
||||
##
|
||||
pullSecrets: []
|
||||
## Set to true if you would like to see extra information on logs
|
||||
## It turns BASH and/or NAMI debugging in the image
|
||||
##
|
||||
debug: false
|
||||
|
||||
## @param architecture FreeRADIUS architecture (`standalone` or `replication`)
|
||||
##
|
||||
architecture: standalone
|
||||
|
||||
auth:
|
||||
## @param auth.createClientUser Create client user on boot
|
||||
##
|
||||
createClientUser: true
|
||||
## @param auth.clientUser FreeRADIUS administrator user
|
||||
##
|
||||
clientUser: user
|
||||
## @param auth.clientPassword FreeRADIUS administrator password for the new user
|
||||
##
|
||||
clientUserPassword: ""
|
||||
## @param auth.existingSecret An already existing secret containing auth info
|
||||
## e.g:
|
||||
## existingSecret:
|
||||
## name: mySecret
|
||||
## keyMapping:
|
||||
## client-user-password: myPasswordKey
|
||||
##
|
||||
existingSecret: ""
|
||||
## @param auth.existingSecretPerPassword Override `existingSecret` and other secret values
|
||||
## e.g:
|
||||
## existingSecretPerPassword:
|
||||
## keyMapping:
|
||||
## clientUserPassword: FREERADIUS_ADMIN_PASSWORD
|
||||
## databasePassword: password
|
||||
## databasePassword:
|
||||
## name: freeradius.pocwatt-freeradius-cluster.credentials
|
||||
##
|
||||
existingSecretPerPassword: {}
|
||||
|
||||
## @param configuration FreeRADIUS Configuration. Auto-generated based on other parameters when not specified
|
||||
## Specify content for keycloak.conf
|
||||
## NOTE: This will override configuring FreeRADIUS based on environment variables (including those set by the chart)
|
||||
## The radiusd.conf is auto-generated based on other parameters when this parameter is not specified
|
||||
##
|
||||
## Example:
|
||||
## configuration: |-
|
||||
## foo: bar
|
||||
## baz:
|
||||
##
|
||||
configuration: ""
|
||||
## @param configurationConfigMap ConfigMap with the FreeRADIUS configuration files (Note: Overrides `radiusdConfiguration`). The value is evaluated as a template.
|
||||
##
|
||||
configurationConfigMap: ""
|
||||
## @param existingConfigmap Name of existing ConfigMap with FreeRADIUS configuration
|
||||
## NOTE: When it's set the configuration parameter is ignored
|
||||
##
|
||||
existingConfigmap: ""
|
||||
## @param extraStartupArgs Extra default startup args
|
||||
##
|
||||
extraStartupArgs: ""
|
||||
## initdb scripts
|
||||
## @param initdbScripts Specify dictionary of scripts to be run at first boot
|
||||
## Alternatively, you can put your scripts under the files/docker-entrypoint-initdb.d directory
|
||||
## e.g:
|
||||
## initdbScripts:
|
||||
## my_init_script.sh: |
|
||||
## #!/bin/sh
|
||||
## echo "Do something."
|
||||
##
|
||||
initdbScripts: {}
|
||||
## @param initdbScriptsConfigMap ConfigMap with the initdb scripts (Note: Overrides `initdbScripts`)
|
||||
##
|
||||
initdbScriptsConfigMap: ""
|
||||
## @param primary.command Override default container command on FreeRADIUS container(s) (useful when using custom images)
|
||||
##
|
||||
command: []
|
||||
## @param primary.args Override default container args on FreeRADIUS container(s) (useful when using custom images)
|
||||
##
|
||||
args: []
|
||||
## @param primary.lifecycleHooks for the FreeRADIUS container(s) to automate configuration before or after startup
|
||||
##
|
||||
lifecycleHooks: {}
|
||||
## @param primary.hostAliases Add deployment host aliases
|
||||
## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/
|
||||
##
|
||||
hostAliases: []
|
||||
## @param primary.configuration [string] FreeRADIUS configuration to be injected as ConfigMap
|
||||
## ref: https://mysql.com/kb/en/mysql/configuring-mysql-with-mycnf/#example-of-configuration-file
|
||||
##
|
||||
|
||||
## @section FreeRADIUS Deployment parameters
|
||||
|
||||
## @param replicaCount Desired number of cluster nodes
|
||||
##
|
||||
replicaCount: 1
|
||||
## @param updateStrategy.type updateStrategy for FreeRADIUS Master StatefulSet
|
||||
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies
|
||||
##
|
||||
updateStrategy:
|
||||
type: RollingUpdate
|
||||
## @param podLabels Extra labels for FreeRADIUS pods
|
||||
## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
|
||||
##
|
||||
podLabels: {}
|
||||
## @param podAnnotations Annotations for FreeRADIUS pods
|
||||
## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/
|
||||
##
|
||||
podAnnotations: {}
|
||||
## @param podAffinityPreset Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard`
|
||||
## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity
|
||||
##
|
||||
podAffinityPreset: ""
|
||||
## @param podAntiAffinityPreset Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard`
|
||||
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity
|
||||
##
|
||||
podAntiAffinityPreset: soft
|
||||
## Node affinity preset
|
||||
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity
|
||||
##
|
||||
nodeAffinityPreset:
|
||||
## @param nodeAffinityPreset.type Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard`
|
||||
##
|
||||
type: ""
|
||||
## @param nodeAffinityPreset.key Node label key to match. Ignored if `affinity` is set.
|
||||
## E.g.
|
||||
## key: "kubernetes.io/e2e-az-name"
|
||||
##
|
||||
key: ""
|
||||
## @param nodeAffinityPreset.values Node label values to match. Ignored if `affinity` is set.
|
||||
## E.g.
|
||||
## values:
|
||||
## - e2e-az1
|
||||
## - e2e-az2
|
||||
##
|
||||
values: []
|
||||
|
||||
## @param affinity Affinity for FreeRADIUS pods assignment
|
||||
## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
|
||||
## Note: podAffinityPreset, podAntiAffinityPreset, and nodeAffinityPreset will be ignored when it's set
|
||||
##
|
||||
affinity: {}
|
||||
## @param nodeSelector Node labels for FreeRADIUS pods assignment
|
||||
## Ref: https://kubernetes.io/docs/user-guide/node-selection/
|
||||
##
|
||||
nodeSelector: {}
|
||||
## @param tolerations Tolerations for FreeRADIUS pods assignment
|
||||
## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
|
||||
##
|
||||
tolerations: []
|
||||
## @param topologySpreadConstraints Topology Spread Constraints for FreeRADIUS pods assignment
|
||||
## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
|
||||
## E.g.
|
||||
## topologySpreadConstraints:
|
||||
## - maxSkew: 1
|
||||
## topologyKey: topology.kubernetes.io/zone
|
||||
## whenUnsatisfiable: DoNotSchedule
|
||||
##
|
||||
topologySpreadConstraints: {}
|
||||
|
||||
## @param priorityClassName Priority class for FreeRADIUS pods assignment
|
||||
## Ref: https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/
|
||||
##
|
||||
priorityClassName: ""
|
||||
## @param schedulerName Name of the k8s scheduler (other than default)
|
||||
## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/
|
||||
##
|
||||
schedulerName: ""
|
||||
## @param podManagementPolicy podManagementPolicy to manage scaling operation of FreeRADIUS pods
|
||||
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#pod-management-policies
|
||||
##
|
||||
podManagementPolicy: ""
|
||||
|
||||
## @param containerPorts.auth FreeRADIUS Auth container port
|
||||
## @param containerPorts.acct FreeRADIUS Accounting container port
|
||||
## @param containerPorts.status FreeRADIUS Status HTTP container port
|
||||
##
|
||||
containerPorts:
|
||||
auth: 1812
|
||||
acct: 1813
|
||||
coa: 3799
|
||||
radsec: 2083
|
||||
status: 18121
|
||||
## FreeRADIUS Pod security context
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod
|
||||
## @param podSecurityContext.enabled Enable security context for FreeRADIUS pods
|
||||
## @param podSecurityContext.fsGroup Group ID for the mounted volumes' filesystem
|
||||
##
|
||||
podSecurityContext:
|
||||
enabled: false
|
||||
fsGroup: 101
|
||||
runAsUser: 101
|
||||
## FreeRADIUS container security context
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
|
||||
## @param containerSecurityContext.enabled FreeRADIUS container securityContext
|
||||
## @param containerSecurityContext.runAsUser User ID for the FreeRADIUS container
|
||||
## @param containerSecurityContext.runAsNonRoot Set Controller container's Security Context runAsNonRoot
|
||||
##
|
||||
containerSecurityContext:
|
||||
enabled: true
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
add:
|
||||
- SYS_PTRACE
|
||||
drop:
|
||||
- ALL
|
||||
privileged: false
|
||||
readOnlyRootFilesystem: true
|
||||
runAsUser: 101
|
||||
runAsNonRoot: true
|
||||
|
||||
## Resource requests and limits
|
||||
## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/
|
||||
## We usually recommend not to specify default resources and to leave this as a conscious
|
||||
## choice for the user. This also increases chances charts run on environments with little
|
||||
## resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||
## lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||
## @param resourcesPreset Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if resources is set (resources is recommended for production).
|
||||
## More information: https://github.com/startechnica/apps/blob/main/charts/common/templates/_resources.tpl#L15
|
||||
##
|
||||
resourcesPreset: "nano"
|
||||
## @param resources Set container requests and limits for different resources like CPU or memory (essential for production workloads)
|
||||
## Example:
|
||||
## resources:
|
||||
## requests:
|
||||
## cpu: 2
|
||||
## memory: 512Mi
|
||||
## limits:
|
||||
## cpu: 3
|
||||
## memory: 1024Mi
|
||||
##
|
||||
resources: {}
|
||||
|
||||
## Configure extra options for FreeRADIUS containers' liveness, readiness and startup probes
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes)
|
||||
## @param startupProbe.enabled Enable startupProbe
|
||||
## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe
|
||||
## @param startupProbe.periodSeconds Period seconds for startupProbe
|
||||
## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe
|
||||
## @param startupProbe.failureThreshold Failure threshold for startupProbe
|
||||
## @param startupProbe.successThreshold Success threshold for startupProbe
|
||||
##
|
||||
startupProbe:
|
||||
enabled: false
|
||||
initialDelaySeconds: 120
|
||||
periodSeconds: 15
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 10
|
||||
successThreshold: 1
|
||||
## Configure extra options for liveness probe
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes
|
||||
## @param livenessProbe.enabled Enable livenessProbe
|
||||
## @param livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe
|
||||
## @param livenessProbe.periodSeconds Period seconds for livenessProbe
|
||||
## @param livenessProbe.timeoutSeconds Timeout seconds for livenessProbe
|
||||
## @param livenessProbe.failureThreshold Failure threshold for livenessProbe
|
||||
## @param livenessProbe.successThreshold Success threshold for livenessProbe
|
||||
##
|
||||
livenessProbe:
|
||||
enabled: true
|
||||
initialDelaySeconds: 120
|
||||
periodSeconds: 60
|
||||
timeoutSeconds: 2
|
||||
failureThreshold: 3
|
||||
successThreshold: 1
|
||||
## @param readinessProbe.enabled Enable readinessProbe
|
||||
## @param readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe
|
||||
## @param readinessProbe.periodSeconds Period seconds for readinessProbe
|
||||
## @param readinessProbe.timeoutSeconds Timeout seconds for readinessProbe
|
||||
## @param readinessProbe.failureThreshold Failure threshold for readinessProbe
|
||||
## @param readinessProbe.successThreshold Success threshold for readinessProbe
|
||||
##
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 1
|
||||
failureThreshold: 3
|
||||
successThreshold: 1
|
||||
## @param customStartupProbe Override default startup probe for FreeRADIUS containers
|
||||
##
|
||||
customStartupProbe: {}
|
||||
## @param customLivenessProbe Override default liveness probe for FreeRADIUS containers
|
||||
##
|
||||
customLivenessProbe: {}
|
||||
## @param customReadinessProbe Override default readiness probe for FreeRADIUS containers
|
||||
##
|
||||
customReadinessProbe: {}
|
||||
## @param startupWaitOptions Override default builtin startup wait check options for FreeRADIUS containers
|
||||
## `bitnami/mariadb` Docker image has built-in startup check mechanism,
|
||||
## which periodically checks if FreeRADIUS service has started up and stops it
|
||||
## if all checks have failed after X tries. Use these to control these checks.
|
||||
## ref: https://github.com/bitnami/bitnami-docker-mariadb/pull/240
|
||||
## Example (with default options):
|
||||
## startupWaitOptions:
|
||||
## retries: 300
|
||||
## waitTime: 2
|
||||
##
|
||||
startupWaitOptions: {}
|
||||
## @param extraFlags FreeRADIUS additional command line flags
|
||||
## Can be used to specify command line flags, for example:
|
||||
## E.g.
|
||||
## extraFlags: "--max-connect-errors=1000 --max_connections=155"
|
||||
##
|
||||
extraFlags: ""
|
||||
## @param extraEnvVars Extra environment variables to be set on FreeRADIUS containers
|
||||
## E.g.
|
||||
## extraEnvVars:
|
||||
## - name: TZ
|
||||
## value: "Europe/Paris"
|
||||
##
|
||||
extraEnvVars: []
|
||||
## @param extraEnvVarsCM Name of existing ConfigMap containing extra env vars for FreeRADIUS containers
|
||||
##
|
||||
extraEnvVarsCM: ""
|
||||
## @param extraEnvVarsSecret Name of existing Secret containing extra env vars for FreeRADIUS containers
|
||||
##
|
||||
extraEnvVarsSecret: ""
|
||||
|
||||
## @section Persistence Parameters
|
||||
|
||||
## Persistence Parameters
|
||||
## ref: https://kubernetes.io/docs/user-guide/persistent-volumes/
|
||||
##
|
||||
persistence:
|
||||
## @param persistence.enabled Enable persistence on FreeRADIUS replicas using a `PersistentVolumeClaim`
|
||||
##
|
||||
enabled: false
|
||||
## @param persistence.existingClaim Name of an existing `PersistentVolumeClaim` for FreeRADIUS primary replicas
|
||||
## NOTE: When it's set the rest of persistence parameters are ignored
|
||||
##
|
||||
existingClaim: ""
|
||||
## @param persistence.subPath Subdirectory of the volume to mount at
|
||||
##
|
||||
subPath: ""
|
||||
## @param persistence.mountPath Path to mount the volume at
|
||||
##
|
||||
mountPath: /startechnica/freeradius
|
||||
## @param persistence.storageClass FreeRADIUS persistent volume storage Class
|
||||
## If defined, storageClassName: <storageClass>
|
||||
## If set to "-", storageClassName: "", which disables dynamic provisioning
|
||||
## If undefined (the default) or set to null, no storageClassName spec is
|
||||
## set, choosing the default provisioner. (gp2 on AWS, standard on
|
||||
## GKE, AWS & OpenStack)
|
||||
##
|
||||
storageClass: ""
|
||||
## @param persistence.annotations FreeRADIUS persistent volume claim annotations
|
||||
##
|
||||
annotations: {}
|
||||
## @param persistence.accessModes FreeRADIUS persistent volume access Modes
|
||||
##
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
## @param persistence.size FreeRADIUS persistent volume size
|
||||
##
|
||||
size: 8Gi
|
||||
## @param persistence.selector Selector to match an existing Persistent Volume
|
||||
## selector:
|
||||
## matchLabels:
|
||||
## app: my-app
|
||||
##
|
||||
selector: {}
|
||||
|
||||
## 'volumePermissions' init container parameters
|
||||
## Changes the owner and group of the persistent volume mount point to runAsUser:fsGroup values
|
||||
## based on the podSecurityContext/containerSecurityContext parameters
|
||||
##
|
||||
volumePermissions:
|
||||
## @param volumePermissions.enabled Enable init container that changes the owner/group of the PV mount point to `runAsUser:fsGroup`
|
||||
##
|
||||
enabled: false
|
||||
## Bitnami Shell image
|
||||
## ref: https://hub.docker.com/r/bitnami/bitnami-shell/tags/
|
||||
## @param volumePermissions.image.registry Bitnami Shell image registry
|
||||
## @param volumePermissions.image.repository Bitnami Shell image repository
|
||||
## @param volumePermissions.image.tag Bitnami Shell image tag (immutable tags are recommended)
|
||||
## @param volumePermissions.image.pullPolicy Bitnami Shell image pull policy
|
||||
## @param volumePermissions.image.pullSecrets Bitnami Shell image pull secrets
|
||||
##
|
||||
image:
|
||||
registry: docker.io
|
||||
repository: bitnami/os-shell
|
||||
tag: "11"
|
||||
digest: ""
|
||||
pullPolicy: IfNotPresent
|
||||
## Optionally specify an array of imagePullSecrets.
|
||||
## Secrets must be manually created in the namespace.
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||
## e.g:
|
||||
## pullSecrets:
|
||||
## - myRegistryKeySecretName
|
||||
##
|
||||
pullSecrets: []
|
||||
## Init container's resource requests and limits
|
||||
## ref: https://kubernetes.io/docs/user-guide/compute-resources/
|
||||
## @param volumePermissions.resources.limits The resources limits for the init container
|
||||
## @param volumePermissions.resources.requests The requested resources for the init container
|
||||
##
|
||||
resources:
|
||||
limits: {}
|
||||
requests: {}
|
||||
## Init container Container Security Context
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
|
||||
## @param volumePermissions.securityContext.runAsUser Set init container's Security Context runAsUser
|
||||
## NOTE: when runAsUser is set to special value "auto", init container will try to chown the
|
||||
## data folder to auto-determined user&group, using commands: `id -u`:`id -G | cut -d" " -f2`
|
||||
## "auto" is especially useful for OpenShift which has scc with dynamic user ids (and 0 is not allowed)
|
||||
##
|
||||
securityContext:
|
||||
runAsUser: 0
|
||||
|
||||
## @param extraVolumes Optionally specify extra list of additional volumes to the FreeRADIUS pod(s)
|
||||
##
|
||||
extraVolumes: []
|
||||
## @param extraVolumeMounts Optionally specify extra list of additional volumeMounts for the FreeRADIUS container(s)
|
||||
##
|
||||
extraVolumeMounts: []
|
||||
## @param initContainers Add additional init containers for the FreeRADIUS pod(s)
|
||||
##
|
||||
initContainers: []
|
||||
## @param sidecars Add additional sidecar containers for the FreeRADIUS pod(s)
|
||||
##
|
||||
sidecars: []
|
||||
|
||||
## @section Traffic Exposure Parameters
|
||||
|
||||
## FreeRADIUS service parameters
|
||||
##
|
||||
service:
|
||||
## @param service.type FreeRADIUS Kubernetes service type
|
||||
##
|
||||
type: ClusterIP
|
||||
## @param service.ports.auth FreeRADIUS Kubernetes service port
|
||||
##
|
||||
ports:
|
||||
auth: 1812
|
||||
acct: 1813
|
||||
coa: 3799
|
||||
radsec: 2083
|
||||
status: 18121
|
||||
## @param service.nodePorts.mysql FreeRADIUS Kubernetes service node port
|
||||
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
|
||||
##
|
||||
nodePorts:
|
||||
auth: ""
|
||||
acct: ""
|
||||
coa: ""
|
||||
radsec: ""
|
||||
status: ""
|
||||
## @param service.clusterIP FreeRADIUS Kubernetes service clusterIP IP
|
||||
##
|
||||
clusterIP: ""
|
||||
## @param service.loadBalancerIP FreeRADIUS loadBalancerIP if service type is `LoadBalancer`
|
||||
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer
|
||||
##
|
||||
loadBalancerIP: ""
|
||||
## @param service.ipFamilyPolicy FreeRADIUS Kubernetes service ipFamilyPolicy policy
|
||||
##
|
||||
ipFamilyPolicy: SingleStack
|
||||
## @param service.externalTrafficPolicy Enable client source IP preservation
|
||||
## ref https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
|
||||
##
|
||||
externalTrafficPolicy: Cluster
|
||||
## @param service.allocateLoadBalancerNodePorts Allow users to disable node ports for Service Type=LoadBalancer. This is useful for
|
||||
## bare metal / on-prem environments that rely on VIP based LB implementations.
|
||||
## ref https://kubernetes.io/docs/concepts/services-networking/service/#load-balancer-nodeport-allocation
|
||||
##
|
||||
allocateLoadBalancerNodePorts: "false"
|
||||
## @param service.loadBalancerClass Enables to use a load balancer implementation other than the cloud provider default.
|
||||
## https://kubernetes.io/docs/concepts/services-networking/service/#load-balancer-class
|
||||
##
|
||||
loadBalancerClass: ""
|
||||
## @param service.loadBalancerSourceRanges Address that are allowed when FreeRADIUS service is LoadBalancer
|
||||
## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service
|
||||
## E.g.
|
||||
## loadBalancerSourceRanges:
|
||||
## - 10.10.10.0/24
|
||||
##
|
||||
loadBalancerSourceRanges: []
|
||||
## @param service.extraPorts Extra ports to expose (normally used with the `sidecar` value)
|
||||
##
|
||||
extraPorts: []
|
||||
## @param service.annotations Provide any additional annotations which may be required
|
||||
##
|
||||
annotations: {}
|
||||
## @param service.sessionAffinity Session Affinity for Kubernetes service, can be "None" or "ClientIP"
|
||||
## If "ClientIP", consecutive client requests will be directed to the same Pod
|
||||
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
|
||||
##
|
||||
sessionAffinity: None
|
||||
## @param service.sessionAffinityConfig Additional settings for the sessionAffinity
|
||||
## sessionAffinityConfig:
|
||||
## clientIP:
|
||||
## timeoutSeconds: 300
|
||||
sessionAffinityConfig: {}
|
||||
## Configure the ingress resource that allows you to access the FreeRADIUS installation
|
||||
## ref: https://kubernetes.io/docs/user-guide/ingress/
|
||||
##
|
||||
ingress:
|
||||
## @param ingress.enabled Enable ingress record generation for FreeRADIUS
|
||||
##
|
||||
enabled: false
|
||||
## @param ingress.pathType Ingress path type
|
||||
##
|
||||
pathType: ImplementationSpecific
|
||||
## @param ingress.apiVersion Force Ingress API version (automatically detected if not set)
|
||||
##
|
||||
apiVersion: ""
|
||||
## @param ingress.hostname Default host for the ingress record
|
||||
##
|
||||
hostname: freeradius.local
|
||||
## @param ingress.path Default path for the ingress record
|
||||
## NOTE: You may need to set this to '/*' in order to use this with ALB ingress controllers
|
||||
##
|
||||
path: /
|
||||
## @param ingress.annotations Additional annotations for the Ingress resource. To enable certificate autogeneration, place here your cert-manager annotations.
|
||||
## For a full list of possible ingress annotations, please see
|
||||
## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/user-guide/nginx-configuration/annotations.md
|
||||
## Use this parameter to set the required annotations for cert-manager, see
|
||||
## ref: https://cert-manager.io/docs/usage/ingress/#supported-annotations
|
||||
##
|
||||
## e.g:
|
||||
## annotations:
|
||||
## kubernetes.io/ingress.class: nginx
|
||||
## cert-manager.io/cluster-issuer: cluster-issuer-name
|
||||
##
|
||||
annotations: {}
|
||||
## @param ingress.tls Enable TLS configuration for the host defined at `ingress.hostname` parameter
|
||||
## TLS certificates will be retrieved from a TLS secret with name: `{{- printf "%s-tls" .Values.ingress.hostname }}`
|
||||
## You can:
|
||||
## - Use the `ingress.secrets` parameter to create this TLS secret
|
||||
## - Rely on cert-manager to create it by setting the corresponding annotations
|
||||
## - Rely on Helm to create self-signed certificates by setting `ingress.selfSigned=true`
|
||||
##
|
||||
tls: false
|
||||
## DEPRECATED: Use ingress.annotations instead of ingress.certManager
|
||||
## certManager: false
|
||||
##
|
||||
|
||||
## @param ingress.selfSigned Create a TLS secret for this ingress record using self-signed certificates generated by Helm
|
||||
##
|
||||
selfSigned: false
|
||||
## @param ingress.extraHosts An array with additional hostname(s) to be covered with the ingress record
|
||||
## e.g:
|
||||
## extraHosts:
|
||||
## - name: freeradius.local
|
||||
## path: /
|
||||
##
|
||||
extraHosts: []
|
||||
## @param ingress.extraPaths An array with additional arbitrary paths that may need to be added to the ingress under the main host
|
||||
## e.g:
|
||||
## extraPaths:
|
||||
## - path: /*
|
||||
## backend:
|
||||
## serviceName: ssl-redirect
|
||||
## servicePort: use-annotation
|
||||
##
|
||||
extraPaths: []
|
||||
## @param ingress.extraTls TLS configuration for additional hostname(s) to be covered with this ingress record
|
||||
## ref: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls
|
||||
## e.g:
|
||||
## extraTls:
|
||||
## - hosts:
|
||||
## - freeradius.local
|
||||
## secretName: freeradius.local-tls
|
||||
##
|
||||
extraTls: []
|
||||
## @param ingress.secrets Custom TLS certificates as secrets
|
||||
## NOTE: 'key' and 'certificate' are expected in PEM format
|
||||
## NOTE: 'name' should line up with a 'secretName' set further up
|
||||
## If it is not set and you're using cert-manager, this is unneeded, as it will create a secret for you with valid certificates
|
||||
## If it is not set and you're NOT using cert-manager either, self-signed certificates will be created valid for 365 days
|
||||
## It is also possible to create and manage the certificates outside of this helm chart
|
||||
## Please see README.md for more information
|
||||
## e.g:
|
||||
## secrets:
|
||||
## - name: freeradius.local-tls
|
||||
## key: |-
|
||||
## -----BEGIN RSA PRIVATE KEY-----
|
||||
## ...
|
||||
## -----END RSA PRIVATE KEY-----
|
||||
## certificate: |-
|
||||
## -----BEGIN CERTIFICATE-----
|
||||
## ...
|
||||
## -----END CERTIFICATE-----
|
||||
##
|
||||
secrets: []
|
||||
## @param ingress.ingressClassName IngressClass that will be be used to implement the Ingress (Kubernetes 1.18+)
|
||||
## This is supported in Kubernetes 1.18+ and required if you have more than one IngressClass marked as the default for your cluster .
|
||||
## ref: https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/
|
||||
##
|
||||
ingressClassName: ""
|
||||
## @param ingress.extraRules Additional rules to be covered with this ingress record
|
||||
## ref: https://kubernetes.io/docs/concepts/services-networking/ingress/#ingress-rules
|
||||
## e.g:
|
||||
## extraRules:
|
||||
## - host: example.local
|
||||
## http:
|
||||
## path: /
|
||||
## backend:
|
||||
## service:
|
||||
## name: example-svc
|
||||
## port:
|
||||
## name: http
|
||||
##
|
||||
extraRules: []
|
||||
|
||||
## @param revisionHistoryLimit Maximum number of revisions that will be maintained in the Deployment
|
||||
##
|
||||
revisionHistoryLimit: 3
|
||||
|
||||
## @section RBAC parameter
|
||||
#
|
||||
|
||||
## Specifies whether a ServiceAccount should be created
|
||||
##
|
||||
serviceAccount:
|
||||
## @param serviceAccount.create Enable the creation of a ServiceAccount for Adminer pods
|
||||
##
|
||||
create: true
|
||||
## @param serviceAccount.name Name of the created ServiceAccount
|
||||
## If not set and create is true, a name is generated using the fullname template
|
||||
##
|
||||
name: ""
|
||||
## @param serviceAccount.automountServiceAccountToken Auto-mount the service account token in the pod
|
||||
##
|
||||
automountServiceAccountToken: false
|
||||
## @param serviceAccount.annotations Additional custom annotations for the ServiceAccount
|
||||
##
|
||||
annotations: {}
|
||||
## Role Based Access
|
||||
## Ref: https://kubernetes.io/docs/admin/authorization/rbac/
|
||||
##
|
||||
rbac:
|
||||
## @param rbac.create Specify whether RBAC resources should be created and used
|
||||
##
|
||||
create: false
|
||||
## @param rbac.rules Custom RBAC rules
|
||||
## Example:
|
||||
## rules:
|
||||
## - apiGroups:
|
||||
## - ""
|
||||
## resources:
|
||||
## - pods
|
||||
## verbs:
|
||||
## - get
|
||||
## - list
|
||||
##
|
||||
rules: []
|
||||
|
||||
## Network Policy configuration
|
||||
## ref: https://kubernetes.io/docs/concepts/services-networking/network-policies/
|
||||
##
|
||||
networkPolicy:
|
||||
## @param networkPolicy.enabled Enable the default NetworkPolicy policy
|
||||
##
|
||||
enabled: false
|
||||
## @param networkPolicy.allowExternal Don't require client label for connections
|
||||
## The Policy model to apply. When set to false, only pods with the correct
|
||||
## client label will have network access to the ports Keycloak is listening
|
||||
## on. When true, Keycloak will accept connections from any source
|
||||
## (with the correct destination port).
|
||||
##
|
||||
allowExternal: true
|
||||
## @param networkPolicy.additionalRules Additional NetworkPolicy rules
|
||||
## Note that all rules are OR-ed.
|
||||
## Example:
|
||||
## additionalRules:
|
||||
## - matchLabels:
|
||||
## - role: frontend
|
||||
## - matchExpressions:
|
||||
## - key: role
|
||||
## operator: In
|
||||
## values:
|
||||
## - frontend
|
||||
##
|
||||
additionalRules: {}
|
||||
|
||||
## Pod disruption budget configuration
|
||||
##
|
||||
podDisruptionBudget:
|
||||
## @param podDisruptionBudget.create Specifies whether a Pod disruption budget should be created
|
||||
##
|
||||
create: false
|
||||
## @param podDisruptionBudget.minAvailable Minimum number / percentage of pods that should remain scheduled
|
||||
##
|
||||
minAvailable: 1
|
||||
## @param podDisruptionBudget.maxUnavailable Maximum number / percentage of pods that may be made unavailable
|
||||
##
|
||||
maxUnavailable: ""
|
||||
|
||||
## MariaDB chart configuration
|
||||
## ref: https://github.com/bitnami/charts/blob/master/bitnami/mariadb/values.yaml
|
||||
## @param mariadb.enabled Switch to enable or disable the MariaDB helm chart
|
||||
## @param mariadb.auth.username Name for a custom user to create
|
||||
## @param mariadb.auth.password Password for the custom user to create
|
||||
## @param mariadb.auth.database Name for a custom database to create
|
||||
## @param mariadb.auth.existingSecret Name of existing secret to use for MariaDB credentials
|
||||
## @param mariadb.architecture MariaDB architecture (`standalone` or `replication`)
|
||||
##
|
||||
mariadb:
|
||||
enabled: false
|
||||
auth:
|
||||
username: freeradius_user
|
||||
password: ""
|
||||
database: freeradius_db
|
||||
existingSecret: ""
|
||||
architecture: standalone
|
||||
|
||||
## External Database configuration
|
||||
## All of these values are only used when mariadb.enabled is set to false
|
||||
## @param externalDatabase.host Database host
|
||||
## @param externalDatabase.port Database port number
|
||||
## @param externalDatabase.user Non-root username for FreeRADIUS
|
||||
## @param externalDatabase.password Password for the non-root username for FreeRADIUS
|
||||
## @param externalDatabase.database FreeRADIUS database name
|
||||
## @param externalDatabase.existingSecret Name of an existing secret resource containing the database credentials
|
||||
## @param externalDatabase.existingSecretPasswordKey Name of an existing secret key containing the database credentials
|
||||
##
|
||||
externalDatabase:
|
||||
host: ""
|
||||
port: 3306
|
||||
user: freeradius_user
|
||||
database: freeradius_db
|
||||
password: ""
|
||||
existingSecret: ""
|
||||
existingSecretPasswordKey: ""
|
||||
|
||||
modsEnabled:
|
||||
sql:
|
||||
enabled: true
|
||||
dialect: mysql
|
||||
table:
|
||||
acct1: radacct
|
||||
acct2: radacct
|
||||
authcheck: radcheck
|
||||
authreply: radreply
|
||||
client: nas
|
||||
groupcheck: radgroupcheck
|
||||
groupreply: radgroupreply
|
||||
postauth: radpostauth
|
||||
usergroup: radusergroup
|
||||
## @param modsEnabled.sql.groupAttribute The group attribute specific to this instance of rlm_sql
|
||||
##
|
||||
groupAttribute: SQL-Group
|
||||
## @param modsEnabled.sql.readClients Set to 'true' to read radius clients from the database ('nas' table)
|
||||
##
|
||||
readClients: true
|
||||
## @param modsEnabled.sql.tls.enabled
|
||||
## @param modsEnabled.sql.tls.autoGenerated Generate automatically self-signed SQL TLS certificates
|
||||
## @param modsEnabled.sql.tls.certificatesSecret
|
||||
## @param modsEnabled.sql.tls.certFilename
|
||||
## @param modsEnabled.sql.tls.certKeyFilename
|
||||
## @param modsEnabled.sql.tls.certCAFilename
|
||||
## @param modsEnabled.sql.tls.existingTlsSecret
|
||||
## @param modsEnabled.sql.tls.privateKeyPassword
|
||||
##
|
||||
tls:
|
||||
enabled: false
|
||||
ciphers: ""
|
||||
autoGenerated: true
|
||||
certificatesSecret: ""
|
||||
certFilename: ""
|
||||
certKeyFilename: ""
|
||||
certCAFilename: ""
|
||||
existingTlsSecret: ""
|
||||
privateKeyPassword: whatever
|
||||
|
||||
## @param modsEnabled.sql.sqllite.filename
|
||||
## @param modsEnabled.sql.sqllite.busyTimeout
|
||||
##
|
||||
sqlite:
|
||||
filename: /startechnica/freeradius/freeradius.db
|
||||
busyTimeout: "200"
|
||||
|
||||
sitesEnabled:
|
||||
coa:
|
||||
enabled: false
|
||||
status:
|
||||
enabled: true
|
||||
listen: 127.0.0.1
|
||||
secret: adminsecret
|
||||
tls:
|
||||
## @param sitesEnabled.tls.enabled Enable TLS support for radsec traffic
|
||||
##
|
||||
enabled: false
|
||||
privateKeyPassword: ""
|
||||
cipher: "DEFAULT"
|
||||
|
||||
clients:
|
||||
localhost:
|
||||
ipv4addr: "127.0.0.1"
|
||||
ipv6addr: ""
|
||||
proto: udp
|
||||
secret: password
|
||||
nasType: other
|
||||
virtualServer: default
|
||||
coaServer: coa
|
||||
limit:
|
||||
maxConnections: 16
|
||||
lifetime: 0
|
||||
idleTimeout: 30
|
||||
existingConfigMapName: ""
|
||||
|
||||
tls:
|
||||
## @param tls.enabled Enable TLS support for FreeRADIUS
|
||||
##
|
||||
enabled: false
|
||||
## @param tls.autoGenerated Generate automatically self-signed TLS certificates
|
||||
##
|
||||
autoGenerated: true
|
||||
autoGenerator:
|
||||
certmanager:
|
||||
enabled: false
|
||||
issuerKind: ClusterIssuer
|
||||
issuerName: selfsigned-issuer
|
||||
## @param tls.certificatesSecret Name of the secret that contains the certificates
|
||||
##
|
||||
certificatesSecret: ""
|
||||
## @param tls.certFilename Certificate filename
|
||||
##
|
||||
certFilename: ""
|
||||
## @param tls.certKeyFilename Certificate key filename
|
||||
##
|
||||
certKeyFilename: ""
|
||||
## @param tls.certCAFilename CA Certificate filename
|
||||
##
|
||||
certCAFilename: ""
|
||||
|
||||
secretName: ~
|
||||
existingSecret: ""
|
||||
|
||||
gateway:
|
||||
enabled: false
|
||||
dedicated: false
|
||||
gatewayApi: false
|
||||
name: ""
|
||||
namespace: ""
|
||||
gatewayClassName: istio
|
||||
## @param gateway.listeners
|
||||
##
|
||||
listeners: []
|
||||
existingGateway: ~
|
||||
existingVirtualService: ~
|
||||
## @param gateway.extraRoute Array of extra Kubernetes Gateway API Route to deploy with the release
|
||||
##
|
||||
extraRoute: []
|
||||
|
||||
## Prometheus exporter configuration
|
||||
##
|
||||
metrics:
|
||||
## @param metrics.enabled Start a side-car prometheus exporter
|
||||
##
|
||||
enabled: false
|
||||
## Bitnami FreeRADIUS Prometheus exporter image
|
||||
## ref:
|
||||
## @param metrics.image.registry FreeRADIUS Prometheus exporter image registry
|
||||
## @param metrics.image.repository FreeRADIUS Prometheus exporter image repository
|
||||
## @param metrics.image.tag FreeRADIUS Prometheus exporter image tag (immutable tags are recommended)
|
||||
## @param metrics.image.pullPolicy FreeRADIUS Prometheus exporter image pull policy
|
||||
## @param metrics.image.pullSecrets FreeRADIUS Prometheus exporter image pull secrets
|
||||
##
|
||||
image:
|
||||
registry: docker.io
|
||||
repository:
|
||||
tag:
|
||||
pullPolicy: IfNotPresent
|
||||
## Optionally specify an array of imagePullSecrets (secrets must be manually created in the namespace)
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||
## Example:
|
||||
## pullSecrets:
|
||||
## - myRegistryKeySecretName
|
||||
##
|
||||
pullSecrets: []
|
||||
|
||||
## Prometheus Operator PrometheusRule configuration
|
||||
##
|
||||
prometheusRules:
|
||||
## @param metrics.prometheusRules.enabled if `true`, creates a Prometheus Operator PrometheusRule (also requires `metrics.enabled` to be `true`, and makes little sense without ServiceMonitor)
|
||||
##
|
||||
enabled: false
|
||||
## @param metrics.prometheusRules.additionalLabels [object] Additional labels to add to the PrometheusRule so it is picked up by the operator
|
||||
## If using the [Helm Chart](https://github.com/helm/charts/tree/master/stable/prometheus-operator) this is the name of the Helm release and 'app: prometheus-operator'
|
||||
##
|
||||
additionalLabels:
|
||||
app: prometheus-operator
|
||||
release: prometheus
|
||||
## @param metrics.prometheusRules.rules PrometheusRule rules to configure
|
||||
## e.g:
|
||||
## - alert: FreeRADIUS-Down
|
||||
## annotations:
|
||||
## message: 'FreeRADIUS instance {{ $labels.instance }} is down'
|
||||
## summary: FreeRADIUS instance is down
|
||||
## expr: absent(up{job="freeradius"} == 1)
|
||||
## labels:
|
||||
## severity: warning
|
||||
## service: freeradius
|
||||
## for: 5m
|
||||
##
|
||||
rules: {}
|
||||
Reference in New Issue
Block a user