deploy / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
ci / lint-prettier (pull_request) Successful in 3s
ci / lint-ruff (pull_request) Successful in 1s
ci / lint-yaml (pull_request) Successful in 5s
ci / lint-dockerfiles (pull_request) Successful in 1s
ci / validate (pull_request) Successful in 1s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 10s
161 lines
4.3 KiB
YAML
161 lines
4.3 KiB
YAML
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: netbird-config
|
|
namespace: netbird
|
|
data:
|
|
# Public hostname, rendered into the server config by entrypoint.sh.
|
|
NETBIRD_DOMAIN: "nb.forust.xyz"
|
|
NETBIRD_PROXY_SUBNET: "10.244.0.0/16"
|
|
|
|
NETBIRD_MGMT_API_ENDPOINT: "https://nb.forust.xyz"
|
|
NETBIRD_MGMT_GRPC_API_ENDPOINT: "https://nb.forust.xyz"
|
|
AUTH_AUDIENCE: "netbird-dashboard"
|
|
AUTH_CLIENT_ID: "netbird-dashboard"
|
|
AUTH_CLIENT_SECRET: ""
|
|
AUTH_AUTHORITY: "https://nb.forust.xyz/oauth2"
|
|
AUTH_SUPPORTED_SCOPES: "openid profile email groups"
|
|
AUTH_REDIRECT_URI: "/nb-auth"
|
|
AUTH_SILENT_REDIRECT_URI: "/nb-silent-auth"
|
|
USE_AUTH0: "false"
|
|
LETSENCRYPT_DOMAIN: "none"
|
|
|
|
config.template.yaml: |
|
|
server:
|
|
listenAddress: ":80"
|
|
exposedAddress: "https://__NETBIRD_DOMAIN__:443"
|
|
stunPorts:
|
|
- 3478
|
|
metricsPort: 9090
|
|
healthcheckAddress: ":9000"
|
|
logLevel: info
|
|
logFile: console
|
|
authSecret: "__NETBIRD_AUTH_SECRET__"
|
|
dataDir: "/var/lib/netbird"
|
|
disableAnonymousMetrics: true
|
|
auth:
|
|
issuer: "https://__NETBIRD_DOMAIN__/oauth2"
|
|
signKeyRefreshEnabled: true
|
|
dashboardRedirectURIs:
|
|
- "https://__NETBIRD_DOMAIN__/nb-auth"
|
|
- "https://__NETBIRD_DOMAIN__/nb-silent-auth"
|
|
reverseProxy:
|
|
trustedHTTPProxies:
|
|
- "__NETBIRD_PROXY_SUBNET__"
|
|
trustedPeers:
|
|
- "__NETBIRD_PROXY_SUBNET__"
|
|
store:
|
|
engine: sqlite
|
|
encryptionKey: "__NETBIRD_ENCRYPTION_KEY__"
|
|
|
|
entrypoint.sh: |
|
|
#!/bin/sh
|
|
set -eu
|
|
|
|
umask 077
|
|
|
|
TEMPLATE_PATH=/opt/netbird/config.template.yaml
|
|
RENDERED_PATH=/run/netbird/config.yaml
|
|
RELAY_SECRET_PATH=/run/secrets/relay_auth_secret
|
|
ENCRYPTION_KEY_PATH=/run/secrets/datastore_encryption_key
|
|
|
|
is_valid_proxy_subnet() {
|
|
candidate="$1"
|
|
case "$candidate" in
|
|
0.0.0.0/0)
|
|
return 1
|
|
;;
|
|
*/*)
|
|
address="${candidate%%/*}"
|
|
prefix="${candidate#*/}"
|
|
;;
|
|
*)
|
|
return 1
|
|
;;
|
|
esac
|
|
|
|
case "$prefix" in
|
|
0|[1-9]|[1-2][0-9]|3[0-2]) ;;
|
|
*)
|
|
return 1
|
|
;;
|
|
esac
|
|
|
|
old_ifs="$IFS"
|
|
IFS=.
|
|
# shellcheck disable=SC2086
|
|
set -- $address
|
|
IFS="$old_ifs"
|
|
[ "$#" -eq 4 ] || return 1
|
|
|
|
for octet do
|
|
case "$octet" in
|
|
0|[1-9]|[1-9][0-9]|1[0-9][0-9]|2[0-4][0-9]|25[0-5]) ;;
|
|
*)
|
|
return 1
|
|
;;
|
|
esac
|
|
done
|
|
}
|
|
|
|
read_secret() {
|
|
secret_path="$1"
|
|
|
|
if [ ! -r "$secret_path" ]; then
|
|
echo "Required secret is not readable: $secret_path" >&2
|
|
exit 1
|
|
fi
|
|
|
|
secret_value="$(cat "$secret_path")"
|
|
if [ -z "$secret_value" ]; then
|
|
echo "Required secret is empty: $secret_path" >&2
|
|
exit 1
|
|
fi
|
|
|
|
printf '%s' "$secret_value"
|
|
}
|
|
|
|
if [ -z "${NETBIRD_DOMAIN:-}" ]; then
|
|
echo "NETBIRD_DOMAIN must be set" >&2
|
|
exit 1
|
|
fi
|
|
|
|
case "$NETBIRD_DOMAIN" in
|
|
*[!A-Za-z0-9.-]*)
|
|
echo "NETBIRD_DOMAIN contains unsupported characters" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
|
|
if [ -z "${NETBIRD_PROXY_SUBNET:-}" ] || [ "$NETBIRD_PROXY_SUBNET" = "auto" ]; then
|
|
echo "NETBIRD_PROXY_SUBNET must be an explicit IPv4 CIDR; run netbird/setup.sh first" >&2
|
|
exit 1
|
|
fi
|
|
if ! is_valid_proxy_subnet "$NETBIRD_PROXY_SUBNET"; then
|
|
echo "NETBIRD_PROXY_SUBNET must be a non-default IPv4 CIDR, for example 172.20.0.0/16" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [ "$#" -ne 2 ] || [ "$1" != "--config" ] || [ "$2" != "$RENDERED_PATH" ]; then
|
|
echo "Expected: --config $RENDERED_PATH" >&2
|
|
exit 1
|
|
fi
|
|
|
|
relay_secret="$(read_secret "$RELAY_SECRET_PATH")"
|
|
encryption_key="$(read_secret "$ENCRYPTION_KEY_PATH")"
|
|
|
|
mkdir -p "$(dirname "$RENDERED_PATH")"
|
|
sed \
|
|
-e "s|__NETBIRD_DOMAIN__|${NETBIRD_DOMAIN}|g" \
|
|
-e "s|__NETBIRD_AUTH_SECRET__|${relay_secret}|g" \
|
|
-e "s|__NETBIRD_ENCRYPTION_KEY__|${encryption_key}|g" \
|
|
-e "s|__NETBIRD_PROXY_SUBNET__|${NETBIRD_PROXY_SUBNET}|g" \
|
|
"$TEMPLATE_PATH" >"$RENDERED_PATH"
|
|
|
|
if grep -q '__NETBIRD_' "$RENDERED_PATH"; then
|
|
echo "Rendered NetBird configuration still contains unresolved placeholders" >&2
|
|
exit 1
|
|
fi
|
|
|
|
exec /go/bin/netbird-server "$@"
|