From 266e2cdeb7e162f6ba78aa84c780028da7ed88f3 Mon Sep 17 00:00:00 2001 From: "noussair.hamrit" Date: Thu, 24 Apr 2025 14:52:34 +0200 Subject: [PATCH] add TLS config --- ConfigMap-ingress-nginx.yaml | 4 +-- ConfigMap.yaml | 16 +++++++--- deployment.yaml | 12 ++++++-- ingress.yaml | 22 -------------- mosquitto-internal-tls.yaml | 58 ++++++++++++++++++++++++++++++++++++ svc.yaml | 16 +++++----- 6 files changed, 89 insertions(+), 39 deletions(-) delete mode 100644 ingress.yaml create mode 100644 mosquitto-internal-tls.yaml diff --git a/ConfigMap-ingress-nginx.yaml b/ConfigMap-ingress-nginx.yaml index a091fa5..d696ad9 100644 --- a/ConfigMap-ingress-nginx.yaml +++ b/ConfigMap-ingress-nginx.yaml @@ -4,5 +4,5 @@ metadata: name: tcp-services namespace: nginx data: - "1883": "mosquitto/mosquitto-mqtt:1883" - "9001": "mosquitto/mosquitto-ws:9001" + "8883": "mosquitto/mosquitto-mqtts:8883" + "9443": "mosquitto/mosquitto-wss:9443" diff --git a/ConfigMap.yaml b/ConfigMap.yaml index 9a84b93..dc3dd20 100644 --- a/ConfigMap.yaml +++ b/ConfigMap.yaml @@ -16,12 +16,20 @@ data: password_file /mosquitto/secrets/passwd allow_anonymous false - # MQTTS listener - listener 1883 + # MQTT over TLS + listener 8883 protocol mqtt + cafile /mosquitto/certs/ca.crt + certfile /mosquitto/certs/tls.crt + keyfile /mosquitto/certs/tls.key + require_certificate false - # WS Listener - listener 9001 + # WebSocket over TLS + listener 9443 protocol websockets + cafile /mosquitto/certs/ca.crt + certfile /mosquitto/certs/tls.crt + keyfile /mosquitto/certs/tls.key + require_certificate false \ No newline at end of file diff --git a/deployment.yaml b/deployment.yaml index 3693bab..6626403 100644 --- a/deployment.yaml +++ b/deployment.yaml @@ -17,8 +17,8 @@ spec: - name: mosquitto image: eclipse-mosquitto ports: - - containerPort: 1883 - - containerPort: 9001 + - containerPort: 8883 + - containerPort: 9443 volumeMounts: - mountPath: /mosquitto/config/mosquitto.conf subPath: mosquitto.conf @@ -27,6 +27,9 @@ spec: name: passwd - mountPath: /mosquitto/data/ name: data + - mountPath: /mosquitto/certs + name: tls-certs + readOnly: true volumes: - name: config configMap: @@ -36,4 +39,7 @@ spec: secretName: mosquitto-passwd - name: data persistentVolumeClaim: - claimName: mosquitto-data \ No newline at end of file + claimName: mosquitto-data + - name: tls-certs + secret: + secretName: mosquitto-tls \ No newline at end of file diff --git a/ingress.yaml b/ingress.yaml deleted file mode 100644 index e7dea37..0000000 --- a/ingress.yaml +++ /dev/null @@ -1,22 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: mosquitto-ws - namespace: mosquitto - annotations: - nginx.ingress.kubernetes.io/backend-protocol: "HTTP" # Required for WebSocket - nginx.ingress.kubernetes.io/proxy-read-timeout: "3600" # Keep connections alive - nginx.ingress.kubernetes.io/proxy-send-timeout: "3600" -spec: - ingressClassName: nginx - rules: - - host: mosquitto.infrastructure.helmholz.cloud - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: mosquitto-ws - port: - number: 9001 \ No newline at end of file diff --git a/mosquitto-internal-tls.yaml b/mosquitto-internal-tls.yaml new file mode 100644 index 0000000..1a691ae --- /dev/null +++ b/mosquitto-internal-tls.yaml @@ -0,0 +1,58 @@ +--- +apiVersion: cert-manager.io/v1 +kind: Issuer +metadata: + name: mosquitto-selfsigned + namespace: mosquitto +spec: + selfSigned: {} +--- +apiVersion: cert-manager.io/v1 +kind: Certificate +metadata: + name: mosquitto-ca + namespace: mosquitto +spec: + isCA: true + commonName: mosquitto-ca + secretName: mosquitto-ca-secret + issuerRef: + name: mosquitto-selfsigned + kind: Issuer +--- +apiVersion: cert-manager.io/v1 +kind: Issuer +metadata: + name: mosquitto-ca-issuer + namespace: mosquitto +spec: + ca: + secretName: mosquitto-ca-secret +--- +apiVersion: cert-manager.io/v1 +kind: Certificate +metadata: + name: mosquitto-internal-cert + namespace: mosquitto +spec: + secretName: mosquitto-tls + duration: 8760h # 1 year + renewBefore: 720h # 30 days before expiration + subject: + organizations: + - internal + commonName: mosquitto.mosquitto.svc + dnsNames: + - mosquitto.infrastructure.helmholz.cloud + - mosquitto + - mosquitto.mosquitto + - mosquitto.mosquitto.svc + - mosquitto-mqtts + - mosquitto-mqtts.mosquitto + - mosquitto-mqtts.mosquitto.svc + - mosquitto-wss + - mosquitto-wss.mosquitto + - mosquitto-wss.mosquitto.svc + issuerRef: + name: mosquitto-ca-issuer + kind: Issuer diff --git a/svc.yaml b/svc.yaml index 25f846f..5782b82 100644 --- a/svc.yaml +++ b/svc.yaml @@ -1,30 +1,30 @@ apiVersion: v1 kind: Service metadata: - name: mosquitto-mqtt + name: mosquitto-mqtts namespace: mosquitto spec: type: ClusterIP selector: app: mosquitto ports: - - name: mqtt - port: 1883 - targetPort: 1883 + - name: mqtts + port: 8883 + targetPort: 8883 protocol: TCP --- apiVersion: v1 kind: Service metadata: - name: mosquitto-ws + name: mosquitto-wss namespace: mosquitto spec: type: ClusterIP selector: app: mosquitto ports: - - name: mqttws - port: 9001 - targetPort: 9001 + - name: mqttwss + port: 9443 + targetPort: 9443 protocol: TCP \ No newline at end of file