Fix remaining VPN addon issues (#1029)

* Fix remaining VPN addon issues

* fix minor common-test issue
This commit is contained in:
Kjeld Schouten-Lebbing
2021-09-25 14:40:14 +02:00
committed by GitHub
parent c0aa278e27
commit 2db56c1e42
8 changed files with 99 additions and 44 deletions
+1 -1
View File
@@ -15,4 +15,4 @@ maintainers:
name: common name: common
sources: null sources: null
type: library type: library
version: 8.0.0 version: 8.0.1
@@ -6,6 +6,8 @@ name: openvpn
image: "{{ .Values.openvpnImage.repository }}:{{ .Values.openvpnImage.tag }}" image: "{{ .Values.openvpnImage.repository }}:{{ .Values.openvpnImage.tag }}"
imagePullPolicy: {{ .Values.openvpnImage.pullPolicy }} imagePullPolicy: {{ .Values.openvpnImage.pullPolicy }}
securityContext: securityContext:
runAsUser: 0
runAsGroup: 0
capabilities: capabilities:
add: add:
- NET_ADMIN - NET_ADMIN
@@ -28,6 +30,28 @@ env:
value: {{ $v | quote }} value: {{ $v | quote }}
{{- end }} {{- end }}
{{- end }} {{- end }}
{{- if .Values.addons.vpn.killSwitch }}
- name: FIREWALL
value: "ON"
- name: ROUTE_1
value: "172.16.0.0/12"
{{- range $index, $value := .Values.addons.vpn.excludedNetworks_IPv4 }}
- name: ROUTE_{{ add $index 2 }}
value: {{ $value | quote }}
{{- end}}
{{- if .Values.addons.vpn.excludedNetworks_IPv6 }}
{{- $excludednetworksv6 := ""}}
{{- range .Values.addons.vpn.excludedNetworks_IPv4 }}
{{- $excludednetworksv6 = ( printf "%v;%v" $excludednetworksv6 . ) }}
{{- end}}
{{- range $index, $value := .Values.addons.vpn.excludedNetworks_IPv6 }}
- name: ROUTE6_{{ add $index 1 }}
value: {{ $value | quote }}
{{- end}}
{{- end }}
{{- end }}
{{- if or .Values.addons.vpn.openvpn.auth }} {{- if or .Values.addons.vpn.openvpn.auth }}
envFrom: envFrom:
- secretRef: - secretRef:
@@ -2,7 +2,6 @@
The OpenVPN credentials secrets to be included. The OpenVPN credentials secrets to be included.
*/}} */}}
{{- define "common.addon.openvpn.secret" -}} {{- define "common.addon.openvpn.secret" -}}
{{- with .Values.addons.vpn.openvpn.auth }}
--- ---
apiVersion: v1 apiVersion: v1
kind: Secret kind: Secret
@@ -11,6 +10,11 @@ metadata:
labels: labels:
{{- include "common.labels" $ | nindent 4 }} {{- include "common.labels" $ | nindent 4 }}
data: data:
VPN_AUTH: {{ . | b64enc }} {{- $vpnauth := "" }}
{{- end -}} {{- if .Values.addons.vpn.openvpn.username }}
{{- $vpnauth = ( printf "%v;%v" .Values.addons.vpn.openvpn.username .Values.addons.vpn.openvpn.password ) }}
{{- else }}
{{- $vpnauth = .Values.addons.vpn.openvpn.password }}
{{- end }}
VPN_AUTH: {{ $vpnauth | b64enc }}
{{- end -}} {{- end -}}
@@ -34,16 +34,22 @@ env:
{{- end }} {{- end }}
{{- end }} {{- end }}
{{- if .Values.addons.vpn.wireguard.KILLSWITCH }} {{- if .Values.addons.vpn.killSwitch }}
- name: KILLSWITCH - name: KILLSWITCH
value: "true" value: "true"
{{- if .Values.addons.vpn.wireguard.KILLSWITCH_EXCLUDEDNETWORKS_IPV4 }} {{- $excludednetworksv4 := "172.16.0.0/12"}}
{{- range .Values.addons.vpn.excludedNetworks_IPv4 }}
{{- $excludednetworksv4 = ( printf "%v;%v" $excludednetworksv4 . ) }}
{{- end}}
- name: KILLSWITCH_EXCLUDEDNETWORKS_IPV4 - name: KILLSWITCH_EXCLUDEDNETWORKS_IPV4
value: {{ .Values.addons.vpn.wireguard.KILLSWITCH_EXCLUDEDNETWORKS_IPV4 | quote }} value: {{ $excludednetworksv4 | quote }}
{{- end }} {{- if .Values.addons.vpn.excludedNetworks_IPv6 }}
{{- if .Values.addons.vpn.wireguard.KILLSWITCH_EXCLUDEDNETWORKS_IPV6 }} {{- $excludednetworksv6 := ""}}
- name: KILLSWITCH_EXCLUDEDNETWORKS_IPV4 {{- range .Values.addons.vpn.excludedNetworks_IPv4 }}
value: {{ .Values.addons.vpn.wireguard.KILLSWITCH_EXCLUDEDNETWORKS_IPV6 | quote }} {{- $excludednetworksv6 = ( printf "%v;%v" $excludednetworksv6 . ) }}
{{- end}}
- name: KILLSWITCH_EXCLUDEDNETWORKS_IPV6
value: {{ .Values.addons.vpn.excludedNetworks_IPv6 | quote }}
{{- end }} {{- end }}
{{- end }} {{- end }}
@@ -27,8 +27,12 @@ before chart installation.
command: command:
- "/bin/sh" - "/bin/sh"
- "-c" - "-c"
- "echo 'Automatically correcting permissions...';{{ range $_, $hpm := $hostPathMounts }}chown -R :{{ $group }} {{ $hpm.mountPath | squote }}; chmod -R g+w {{ $hpm.mountPath | squote }};{{ end }}" - "echo 'Automatically correcting permissions...';{{ if .Values.addons.vpn.configFile }}chown -R 568:568 /vpn/vpn.conf; chmod -R g+w /vpn/vpn.conf;{{ end }}{{ range $_, $hpm := $hostPathMounts }}chown -R :{{ $group }} {{ $hpm.mountPath | squote }}; chmod -R g+w {{ $hpm.mountPath | squote }};{{ end }}"
volumeMounts: volumeMounts:
{{- if .Values.addons.vpn.configFile }}
- name: vpnconfig
mountPath: /vpn/vpn.conf
{{- end }}
{{- range $name, $hpm := $hostPathMounts }} {{- range $name, $hpm := $hostPathMounts }}
- name: {{ $name }} - name: {{ $name }}
mountPath: {{ $hpm.mountPath }} mountPath: {{ $hpm.mountPath }}
@@ -81,7 +81,7 @@ func (suite *PersistenceVolumeClaimTestSuite) TestMetaData() {
"app.kubernetes.io/managed-by": "Helm", "app.kubernetes.io/managed-by": "Helm",
"app.kubernetes.io/name": "common-test", "app.kubernetes.io/name": "common-test",
"app.kubernetes.io/version":"latest", "app.kubernetes.io/version":"latest",
"helm.sh/chart": "common-test-3.1.2", "helm.sh/chart": "common-test-3.1.3",
} }
tests := map[string]struct { tests := map[string]struct {
+8 -9
View File
@@ -698,15 +698,14 @@ addons:
# @default -- See below # @default -- See below
openvpn: openvpn:
# -- Credentials to connect to the VPN Service (used with -a) # -- Credentials to connect to the VPN Service (used with -a)
auth: # "user;password" # Only using password is enough
# -- Optionally specify an existing secret that contains the credentials. username: ""
# Credentials should be stored under the `VPN_AUTH` key password: ""
authSecret: # my-vpn-secret
killSwitch: true
excludedNetworks_IPv4: []
excludedNetworks_IPv6: []
wireguard:
KILLSWITCH: false
KILLSWITCH_EXCLUDEDNETWORKS_IPV4:
- 192.168.0.0.1
# -- Set the VPN container specific securityContext # -- Set the VPN container specific securityContext
# @default -- See values.yaml # @default -- See values.yaml
securityContext: {} securityContext: {}
@@ -725,7 +724,7 @@ addons:
# -- Provide a customized vpn configuration file to be used by the VPN. # -- Provide a customized vpn configuration file to be used by the VPN.
configFile: configFile:
enabled: false enabled: true
type: hostPath type: hostPath
# -- Which path on the host should be mounted. # -- Which path on the host should be mounted.
hostPath: /vpn/vpn.conf hostPath: /vpn/vpn.conf
+40 -22
View File
@@ -28,35 +28,52 @@
type: dict type: dict
show_if: [["type", "=", "openvpn"]] show_if: [["type", "=", "openvpn"]]
attrs: attrs:
- variable: auth - variable: username
label: "authentication credentials" label: "authentication username"
description: "authentication credentials, seperated by ; example: username;password" description: "authentication username, optional"
schema: schema:
type: string type: string
default: "" default: ""
- variable: wireguard - variable: password
label: "Wireguard Settings" label: "authentication password"
description: "authentication credentials"
schema:
type: string
default: ""
required: true
- variable: killSwitch
label: "Enable killswitch"
schema: schema:
type: dict type: boolean
show_if: [["type", "=", "wireguard"]] show_if: [["type", "!=", "disabled"]]
attrs: default: true
- variable: KILLSWITCH - variable: excludedNetworks_IPv4
label: "Enable killswitch" label: "Killswitch Excluded IPv4 networks"
schema: description: "list of killswitch excluded ipv4 addresses"
type: boolean schema:
default: false type: list
- variable: KILLSWITCH_EXCLUDEDNETWORKS_IPV4 show_if: [["type", "!=", "disabled"]]
label: "Killswitch Excluded IPv4 networks" default: []
description: "list of killswitch excluded ipv4 addresses seperated by ;" items:
- variable: networkv4
label: "IPv4 Network"
schema: schema:
type: string type: string
default: "172.16.0.0/12" required: true
- variable: KILLSWITCH_EXCLUDEDNETWORKS_IPV6 - variable: excludedNetworks_IPv6
label: "Killswitch Excluded IPv6 networks" label: "Killswitch Excluded IPv6 networks"
description: "list of killswitch excluded ipv4 addresses seperated by ;" description: "list of killswitch excluded ipv4 addresses"
schema:
type: list
show_if: [["type", "!=", "disabled"]]
default: []
items:
- variable: networkv6
label: "IPv6 Network"
schema: schema:
type: string type: string
default: "" required: true
- variable: configFile - variable: configFile
label: "VPN Config File Location" label: "VPN Config File Location"
schema: schema:
@@ -89,9 +106,10 @@
hidden: true hidden: true
- variable: hostPath - variable: hostPath
label: "Full path to file" label: "Full path to file"
description: "path to your local VPN config file for example: /mnt/tank/vpn.conf or /mnt/tank/vpn.ovpn"
schema: schema:
type: string type: string
default: "/mnt/tank/config/YourVPN-Config.conf" default: ""
required: true required: true
- variable: envList - variable: envList
label: "VPN environment Variables" label: "VPN environment Variables"