add TLS config

This commit is contained in:
2025-04-24 16:19:58 +02:00
parent 9baca6a5cf
commit 266e2cdeb7
6 changed files with 89 additions and 39 deletions
+2 -2
View File
@@ -4,5 +4,5 @@ metadata:
name: tcp-services
namespace: nginx
data:
"1883": "mosquitto/mosquitto-mqtt:1883"
"9001": "mosquitto/mosquitto-ws:9001"
"8883": "mosquitto/mosquitto-mqtts:8883"
"9443": "mosquitto/mosquitto-wss:9443"
+12 -4
View File
@@ -16,12 +16,20 @@ data:
password_file /mosquitto/secrets/passwd
allow_anonymous false
# MQTTS listener
listener 1883
# MQTT over TLS
listener 8883
protocol mqtt
cafile /mosquitto/certs/ca.crt
certfile /mosquitto/certs/tls.crt
keyfile /mosquitto/certs/tls.key
require_certificate false
# WS Listener
listener 9001
# WebSocket over TLS
listener 9443
protocol websockets
cafile /mosquitto/certs/ca.crt
certfile /mosquitto/certs/tls.crt
keyfile /mosquitto/certs/tls.key
require_certificate false
+9 -3
View File
@@ -17,8 +17,8 @@ spec:
- name: mosquitto
image: eclipse-mosquitto
ports:
- containerPort: 1883
- containerPort: 9001
- containerPort: 8883
- containerPort: 9443
volumeMounts:
- mountPath: /mosquitto/config/mosquitto.conf
subPath: mosquitto.conf
@@ -27,6 +27,9 @@ spec:
name: passwd
- mountPath: /mosquitto/data/
name: data
- mountPath: /mosquitto/certs
name: tls-certs
readOnly: true
volumes:
- name: config
configMap:
@@ -36,4 +39,7 @@ spec:
secretName: mosquitto-passwd
- name: data
persistentVolumeClaim:
claimName: mosquitto-data
claimName: mosquitto-data
- name: tls-certs
secret:
secretName: mosquitto-tls
-22
View File
@@ -1,22 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: mosquitto-ws
namespace: mosquitto
annotations:
nginx.ingress.kubernetes.io/backend-protocol: "HTTP" # Required for WebSocket
nginx.ingress.kubernetes.io/proxy-read-timeout: "3600" # Keep connections alive
nginx.ingress.kubernetes.io/proxy-send-timeout: "3600"
spec:
ingressClassName: nginx
rules:
- host: mosquitto.infrastructure.helmholz.cloud
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: mosquitto-ws
port:
number: 9001
+58
View File
@@ -0,0 +1,58 @@
---
apiVersion: cert-manager.io/v1
kind: Issuer
metadata:
name: mosquitto-selfsigned
namespace: mosquitto
spec:
selfSigned: {}
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: mosquitto-ca
namespace: mosquitto
spec:
isCA: true
commonName: mosquitto-ca
secretName: mosquitto-ca-secret
issuerRef:
name: mosquitto-selfsigned
kind: Issuer
---
apiVersion: cert-manager.io/v1
kind: Issuer
metadata:
name: mosquitto-ca-issuer
namespace: mosquitto
spec:
ca:
secretName: mosquitto-ca-secret
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: mosquitto-internal-cert
namespace: mosquitto
spec:
secretName: mosquitto-tls
duration: 8760h # 1 year
renewBefore: 720h # 30 days before expiration
subject:
organizations:
- internal
commonName: mosquitto.mosquitto.svc
dnsNames:
- mosquitto.infrastructure.helmholz.cloud
- mosquitto
- mosquitto.mosquitto
- mosquitto.mosquitto.svc
- mosquitto-mqtts
- mosquitto-mqtts.mosquitto
- mosquitto-mqtts.mosquitto.svc
- mosquitto-wss
- mosquitto-wss.mosquitto
- mosquitto-wss.mosquitto.svc
issuerRef:
name: mosquitto-ca-issuer
kind: Issuer
+8 -8
View File
@@ -1,30 +1,30 @@
apiVersion: v1
kind: Service
metadata:
name: mosquitto-mqtt
name: mosquitto-mqtts
namespace: mosquitto
spec:
type: ClusterIP
selector:
app: mosquitto
ports:
- name: mqtt
port: 1883
targetPort: 1883
- name: mqtts
port: 8883
targetPort: 8883
protocol: TCP
---
apiVersion: v1
kind: Service
metadata:
name: mosquitto-ws
name: mosquitto-wss
namespace: mosquitto
spec:
type: ClusterIP
selector:
app: mosquitto
ports:
- name: mqttws
port: 9001
targetPort: 9001
- name: mqttwss
port: 9443
targetPort: 9443
protocol: TCP