This commit is contained in:
@@ -65,7 +65,7 @@ The database stores all client data needed to restore configs:
|
||||
- created/updated timestamps
|
||||
|
||||
The Kubernetes Secret is derived from the database. Active clients are rendered
|
||||
into `peers.conf`; exact same-owner/same-group IPv4 pairs are rendered into
|
||||
into `peers.conf`; exact same-group IPv4 pairs are rendered into
|
||||
`policy.conf`. Clients without a group are isolated from other VPN clients.
|
||||
|
||||
## Kubernetes Sync
|
||||
|
||||
+6
-4
@@ -242,7 +242,7 @@ pub fn render_peer_secret(clients: &[VpnClient]) -> String {
|
||||
pub fn render_client_policy(clients: &[VpnClient], cidr: &str) -> Result<String, String> {
|
||||
parse_ipv4_cidr(cidr)?;
|
||||
|
||||
let mut groups = BTreeMap::<(i64, String), Vec<Ipv4Addr>>::new();
|
||||
let mut groups = BTreeMap::<String, Vec<Ipv4Addr>>::new();
|
||||
for client in clients.iter().filter(|client| client.enabled()) {
|
||||
let Some(group_name) = client.group_name_str() else {
|
||||
continue;
|
||||
@@ -262,7 +262,7 @@ pub fn render_client_policy(clients: &[VpnClient], cidr: &str) -> Result<String,
|
||||
));
|
||||
}
|
||||
groups
|
||||
.entry((client.owner_user_id(), group_name.to_owned()))
|
||||
.entry(group_name.to_owned())
|
||||
.or_default()
|
||||
.push(address);
|
||||
}
|
||||
@@ -1257,7 +1257,7 @@ mod tests {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn client_policy_allows_only_exact_pairs_with_same_owner_and_group() {
|
||||
fn client_policy_allows_only_exact_pairs_with_same_group() {
|
||||
let clients = vec![
|
||||
test_client(1, 10, "10.8.0.2", Some("home")),
|
||||
test_client(2, 10, "10.8.0.3", Some("home")),
|
||||
@@ -1269,9 +1269,11 @@ mod tests {
|
||||
let policy = render_client_policy(&clients, "10.8.0.0/16").unwrap();
|
||||
assert!(policy.contains("10.8.0.2/32 10.8.0.3/32\n"));
|
||||
assert!(policy.contains("10.8.0.3/32 10.8.0.2/32\n"));
|
||||
assert!(policy.contains("10.8.0.2/32 10.8.0.5/32\n"));
|
||||
assert!(policy.contains("10.8.0.5/32 10.8.0.2/32\n"));
|
||||
assert_eq!(
|
||||
policy.lines().filter(|line| !line.starts_with('#')).count(),
|
||||
2
|
||||
6
|
||||
);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user