From f22e45146f602dbda7b2f9937bf6490c6aea1d5a Mon Sep 17 00:00:00 2001 From: Xstar97TheNoob <9399967+xstar97@users.noreply.github.com> Date: Fri, 16 Jun 2023 03:01:34 -0400 Subject: [PATCH] feat(firezone) add firezone (#9402) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit **Description** Add FireZone ⚒️ Fixes # **⚙️ Type of change** - [X] ⚙️ Feature/App addition - [ ] 🪛 Bugfix - [ ] ⚠️ Breaking change (fix or feature that would cause existing functionality to not work as expected) - [ ] 🔃 Refactor of current code **🧪 How Has This Been Tested?** **📃 Notes:** **✔️ Checklist:** - [X] ⚖️ My code follows the style guidelines of this project - [X] 👀 I have performed a self-review of my own code - [ ] #️⃣ I have commented my code, particularly in hard-to-understand areas - [ ] 📄 I have made corresponding changes to the documentation - [ ] ⚠️ My changes generate no new warnings - [ ] 🧪 I have added tests to this description that prove my fix is effective or that my feature works - [ ] ⬆️ I increased versions for any altered app according to semantic versioning **➕ App addition** If this PR is an app addition please make sure you have done the following. - [X] 🪞 I have opened a PR on [truecharts/containers](https://github.com/truecharts/containers) adding the container to TrueCharts mirror repo. - [X] 🖼️ I have added an icon in the Chart's root directory called `icon.png` --- _Please don't blindly check all the boxes. Read them and only check those that apply. Those checkboxes are there for the reviewer to see what is this all about and the status of this PR with a quick glance._ --------- Signed-off-by: Stavros Kois <47820033+stavros-k@users.noreply.github.com> Co-authored-by: Stavros Kois <47820033+stavros-k@users.noreply.github.com> --- charts/incubator/firezone/.helmignore | 30 ++ charts/incubator/firezone/CHANGELOG.md | 1 + charts/incubator/firezone/Chart.yaml | 30 ++ charts/incubator/firezone/README.md | 1 + charts/incubator/firezone/logo.png | Bin 0 -> 12240 bytes charts/incubator/firezone/questions.yaml | 341 ++++++++++++++++++ charts/incubator/firezone/templates/NOTES.txt | 1 + .../incubator/firezone/templates/_secrets.tpl | 26 ++ .../incubator/firezone/templates/common.yaml | 11 + charts/incubator/firezone/values.yaml | 140 +++++++ 10 files changed, 581 insertions(+) create mode 100644 charts/incubator/firezone/.helmignore create mode 100644 charts/incubator/firezone/CHANGELOG.md create mode 100644 charts/incubator/firezone/Chart.yaml create mode 100644 charts/incubator/firezone/README.md create mode 100644 charts/incubator/firezone/logo.png create mode 100644 charts/incubator/firezone/questions.yaml create mode 100644 charts/incubator/firezone/templates/NOTES.txt create mode 100644 charts/incubator/firezone/templates/_secrets.tpl create mode 100644 charts/incubator/firezone/templates/common.yaml create mode 100644 charts/incubator/firezone/values.yaml diff --git a/charts/incubator/firezone/.helmignore b/charts/incubator/firezone/.helmignore new file mode 100644 index 00000000000..77ca5567b26 --- /dev/null +++ b/charts/incubator/firezone/.helmignore @@ -0,0 +1,30 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +# OWNERS file for Kubernetes +OWNERS +# helm-docs templates +*.gotmpl +# docs folder +/docs +# icon +icon.png diff --git a/charts/incubator/firezone/CHANGELOG.md b/charts/incubator/firezone/CHANGELOG.md new file mode 100644 index 00000000000..825c32f0d03 --- /dev/null +++ b/charts/incubator/firezone/CHANGELOG.md @@ -0,0 +1 @@ +# Changelog diff --git a/charts/incubator/firezone/Chart.yaml b/charts/incubator/firezone/Chart.yaml new file mode 100644 index 00000000000..33329e5feac --- /dev/null +++ b/charts/incubator/firezone/Chart.yaml @@ -0,0 +1,30 @@ +apiVersion: v2 +appVersion: "0.7.30" +dependencies: + - name: common + repository: https://library-charts.truecharts.org + version: 12.14.2 +deprecated: false +description: WireGuard-based VPN server and egress firewall +home: https://truecharts.org/charts/incubator/firezone +icon: https://truecharts.org/img/hotlink-ok/chart-icons/firezone.png +keywords: + - firezone + - wireguard + - vpn +kubeVersion: ">=1.16.0-0" +maintainers: + - email: info@truecharts.org + name: TrueCharts + url: https://truecharts.org +name: firezone +sources: + - https://github.com/truecharts/charts/tree/master/charts/incubator/firezone + - https://github.com/firezone/firezone +type: application +version: 0.0.1 +annotations: + truecharts.org/catagories: | + - vpn + - security + truecharts.org/SCALE-support: "true" diff --git a/charts/incubator/firezone/README.md b/charts/incubator/firezone/README.md new file mode 100644 index 00000000000..7e59600739c --- /dev/null +++ b/charts/incubator/firezone/README.md @@ -0,0 +1 @@ +# README diff --git a/charts/incubator/firezone/logo.png b/charts/incubator/firezone/logo.png new file mode 100644 index 0000000000000000000000000000000000000000..7983abea3a488580a3614e7f687b39c86e429a8c GIT binary patch literal 12240 zcmch7hd-O&7k}ChwMVJa+G?xa21Qlvy*IT-Y(i{Wv#1qf@7jB>7*(qXO6}Pep$H`v zjTpc5`}+O0Kh}8f1f*Q`kcS32;dNM!|oCX!HbzW?p}@c-_p&T?#jd1zQ(zgm00SDGFo6Tk1zsmIYX zQ}_+Q`x2lS@DV=C)?dV*qa(ul_TJ^vEqMC&Js#Enuj_3yX8%N838#Y}@NE^#b?=|w zvk?L?0sw&Ru8PQMsGx+Sx@$_faSt1wfc-uv`?OxS)23!3)WVSa4&aq3f!Y_%_GWhT zgF&JWF|}-bKXz))`@fZ5{_2(X_`D@EQCl}MguO@>S2BGmPUN>0G)KAwt&7`lvPN#hC|0X;EZ)@JdrG($Z_ldMW2!J=qLXDhur6EPTVFMTEoeC#dVpDPyhfB zHdVWN8%W#!c2m$Gr4Tvh6CD)>nNfF3+2mC1fW2`fXcJAhBX zNKTAT-*o?)tnNRpSP`flfj`NpCI0J6OwBo~Gw{R10v2iw0DKyLqFTyhJ$ZJ=T1fU1 zu5X5KQvBDn5#b{JU7#DUL7US1oU`d6ZMTt(lRi78c--;Isfs#-{c9YIMC%T@KRf^c zZbo^UYrfb{ymli9)c)+^d~b^z^L}_3d;JFx86<{Es@i{AN_@sc1hDbNbIUR&noc7R z+_Dd31iV#KN>#Kz{+>|AYpssgCN~Y9RZx@wG#M&&2LParXN&KD5#q_JsiyZ28;7c0 zs=SffnobKZ9@NzUw#K;b4e-=4o?7#9 zB%TStj$IWm9NWW4PRfch2BcF1kJdlw@KZwG%WJ3M**iaxuIP_6!D1qP3X& zKm+jFYJibVbYB|QLfr-e_9R#GY0NCF8WOt_Tb*Y%9{@g;JQU-$p}GFyT&|=tK0+!`Mz^`uGH%ZcF)yk@@Hji;Esc?pfYbWx7$b>BWM{2lxtty z5O$KjT{vHqS41bI*#Gx7rM=gHJm9}iKZd^oFTt8h8gX3(P9}MJU9By?KdPaO>W3iM z;&a;&=Z`_VUFbXrsE`u;>geXSNW0r)Duk63@cpap0`T%1G&F`xq1EV1`vQz{BF#cC zu2E%Baa{niYy|+sQOeWED!D2*RH-^~F-#Ql&m-VyF=Zy7iMs$vKVs;9B?Bh5KU0`6 zC(zv6D_j3`*(iaT3;cio9LJ=7@CHBBcd)tsww5)eiy?fZVopa0@ZQHSL4&UfVr6_P zETsDF#+(CXfv#>9Fx4-d4F;k^vE6=QPnbs*v}o@Kj;#yrXJstGv?eO>JZSd~U^upap`7Ql`J#=jY;kd!`^tKpX>@v)MWW z8yE#?m+Gj!Yxb<z+U&CS=XkUb^o1syTRwi8iscZz2aA ztqPDls#3LMHBbr_cfaGVOQi|T zs2M8!K%;P-8>zPUVZ2p_gMug)H_ZNUX4P2JOI_ViO z_&jx8D;?Mv{%bkRGIYI5CZV_12t!}MKs-7 zl=-cDga()J#bxg|PcpoH8GV3fNFdNLq+b%Ji=(jBG11ZZ=M7Bl7Jv}2=KeQ!uY)+I zRpaY{%B45#Z|K?L+}%FP(Uq08Jz$0#m2YV4AO4(P<1Ggs`Q6=GvgSuggsS8^&loHB zN2PBheOZIH=*MI+t8`Y@eHcGU{(U5R894EQ6N{8I(w_C1Kb#P9Ir8*hwPkg~NxJ#4 z@NZn6HN9M{t!;<)2~!65Lr#dS%`dDU+l@8q1^xd1E)<87;5tQM#Xs9O$bb+PUmprp z3x@ir%3KEVIed5kx5LdN2AvV1EqEL_z(T^xNctPFZ8%nK>Vo12N~+fcZB+%N&KH}0}7`(#t+KeV^seY z+gQL=xp3(KjOrWpC=S%;we(}Q!h|uhZErMU0s@$--O%vK#l^piEa){_T;DW!}| z%zV9Gtl)YhzGJlXerYMf{y3yaF~~}W7$0(IzHc*146*f+Lnn@Y+8%2_EY3u-t>}Pl zwX`P)nuV*xc3)-x_bc(X zB#**J{otW~@>r|pK9I%<(Pk;{Ct|`o`r`|bVl4rp<F@NTmmINSffZw8Fnh_B`9?N_ba`03+6Z(Eb~=Okr1tf@yvE@4}iIQ9JU z&t<{F1E%P)7?jAw|_9Zm4pW63q84S z=vv~wcb(Cr-plLqO_NxJZ9VO}Xz7+)9m5qY>>^g@H~K=B3_ZOfQa84`CVL;Oo97Q? zvBlGKgL(0U4$SNl@l6bi}HtYGV<`2H3SNY2svDMBP08J}`e9mP)@3cqX> za7g2|@aeelXb|#6j0{~?3UnU%@IJ9AYJDPufnjlt6?EMG_1uT&mudzvSFhcTL|EPZ z&m?SzIOS=CC4cDDy{R4Ri0h+}navhx$|C&oikf3eO>gvlnCMnM|BisEDYs_u>ugPE zeTH<*QLU$KcIisY6klbgKi6u*@bn-UNSv-l1zuZN4p7uy`I-qIvm769vW4O`<`<2+ zUqr#O+E7T+zxBy`^~_QEZN`R~+4v9%AN0GDOqKSp-q?1~X9qF&_lSscOTvY@rvm9x zJ#rb$$PV-~t~(tx*bRxTe8V8}G%NOhc;Bfk=>O%Z%^XFvkB%1S1%-Fn9H{Rz`@S_j zA}f(13w^rnRO2ns$&*80A&c6yn|26=NUp`IJ|aQ}K7);0h~*f{uUk_vmPP$=2gS9m z>ohmp`c7aM0sJr&s>EavVZtqdvkLTdQ3nzWDpp2?oBmrE~GlZUJa4A@xvm&G_Y@wLzogg5yoOJ`AI?L*)wNrHShiBL2Vrj^$xcm^A z-{;r1yT$b2r!-nLaqtg|N?&7aPm{4DeA(p$QeExY5q)|ZSCrL|^F2UnKB?#nqId*o z;yf~qB@sVrZf+W_K}9KUq^ue%mln={Zb3UBs8z~b&E{}ajr9#KYFao#bNVZtdxTA0 z@-5|k>H}f5aTJvsfS|fv>qHAK^Hy*P$IH@#BV$hLfzptS4sR`z`&J zIAi#+Fjt}JQ20mcqcs`4cY`%$-o8_O5WVE^dgpvwaNzOtwjvNwTKSA?JJiJ6lft4J zJ={#@#SeW19$ZT3r-JNZt*kAo7ig>c6ERGTUtTls$v@X0SE0#k$RQgZNCqW>z2Z&xodzQ?+yqM?|uhYF&aois>_lnU5r>xO>dYH-jJd9BZQ3S! z5ABok99-DzSo>DZ5UW%0!ZCTEnlMC8U1oyLc?q4z7O#r9BkQfgXsyJXC%_M7NP`fb z%;&U%yQ}g?DCtS!R1cFR5KE^95OoOa!Wiuye9qOW{Mna&~^dZ)zT_%NpkNnw5L} zORTj&rt>Blw5c>NlY{K4TF^IWTdrJyYOa}QML&^e`Z)Rz>+wr2%pXY$`@8FmoxHET0mb;mCKH0IK>QFl&* z>HDk2SD#Iw>z8r)d6n;lSpM`C$%MP7bhapVW@89X#?$GfYAO!Q4R<1^r?DmY>2bf} zT*vJ593n-r<7nK}m)kV-zP*kIxaC$+%qFr7$d%_9Z~L{$+BlMKWT+EcP0qZNA*3P0 zsM2wz$>Ih7%MCG_TOR<`ZF+))+g;20OfNU%X)!+a8srt<{}$oG>R0L}XCoEEJsDT8 zrfvzRsQ=OX3sGMU0w&KrvP35n<_wLaT9=S&W9kprx0~RvQ zU-G!p+MzUl>R1*F(|PUldtel4{by9*azUABs?M_VVS#5{KdF0t=O@Kp9~N!)%N&uS zE~dG@IX_!gQvNA*xjuQt@#O*KaUQ@T^F1O)rS#jQj54{Do8fq`9k>dl1}30(hA7w< zFfyb$f7H;AIKcL8hVhIJ{*rvb@QzcpbV@>J@lHtVum5u6);i>n)%qE~fi;JSG)0IE zisyxlQ>`I#Gp22 zC1y^7#wE(z@%!DV$Ds>*!Pikm9ynT1A;I;NwB~0>v#Durk)3KIQM=?}z#yrIk9{Y$ z`C2M{Ro)RN&0qQ8(3WKu*fQu{N!$0jvQ0g-c}lV+>C2LYM4}kX9VV`WIA!`EDWXDi zM{amAPJW?D5i%`*a(8ZX~T6UZvn4a6l?gV>Kl&k&Vq7l^1q#jQ?b$pUza3Np(TX%$yruPHT@3 zMX3bZF7!neVitc2hPQvPIjBmoupO)1phP z+mWUAR$3xb={nL%ucm1H&w|;C$U>wr?8!x_b^kMywDW`Dm-J5Gy+Kri9DIkh0<3QF zaw+T=qNE-fiC((nlORU`^f}{VXr(r}E$~&oE<}%NBiU65dQxGhHuvqg8 zXol}sJ`?V#LXMM-#!NIarP3CKtc`*MqtDRMWWimSq`X!6V@|68?&r zo!A4*s%-1?9Go0wsg1I?Eup4)&lV1UG(aeA>k{R{>Iys zu)M(3HXcVtrl=bObM>3TFs*dby_yZz3WnY-5YR0=v-f(axWy@IA`Fc_EPRqQYGNot zl!M(PhRyN z)OT~r8@}$NgW|}Q2k^70EUp=tW27T1q|l*A*M)ybcJEhPMn)-6;wyCO`u3vL*VgO3 z<$mm!r81Xf3i$U*7a_%m$KkL6*=(P`9=WtrqEfwn*`Cx2`*mOYxqLtyGMi_@YRP=4 zhmM9WT6AjyjiEf&vhDI`zdLS!B`|YJ550p7epagY9T2N#xB~BdhBQ4}P~V-Lg5M67 zCJ52?981>(r2fJE5d*hL-Q(#0+VzOsBj9nF*F{?E&m;g|u9&{3w?b zyG%lgwQUkZWy<>O)~>Wo9LG+}&097syTDA=Z9|9sPsr|m$aWogsVr@~=9>HQ018gV z96}=@c}4rUR{@||)?DhGU!?=Z!L(1*UL*%wDYIcVzvoulzwBFI67f@nj|+YTp2gWq?*-+*l(oi*LIu3Bq*V9Q!t zl_(BM*mV;&Q5QR86TZPybh{ZnNg{$yRNgKoln7}rRFfJ#O7W{rLltHUo4@5XJGy5g zEj*Xs)_AYTSl_YX>Debp{?|0&I#^-YNod0!rkpDWCt zD`E1JY`kD-cL)wM3Z9)+Van)nF5HTEVqfZ&dh}GetNEg4CK?{w9g(ROQ{$sp)_-&E z&9kk&;N^U_Nw*q)<=S+%MyZrF6$iA*|^XH!n0)0n87eIIQd2Z~Jp1}8RTMy$qUjJRB+N~i; zqne7_wJ|lHER~YCJ}VqY&<|u86h#P{AmRgk@JDTqxYw%*#n(AV>yfKg`2o9rKP%^@ z6p?HL&jgi`CxVJ)l>oK%E4hv_tHbH;!u~^ey`=X9C7c#ekSmId5)PBO^wQ;-G=nxY1gvD z&Y_R>%Hi72X{3CIjcZB`8b02db1PO(=?G#Bd88}-CU0LUYp!&AHQ&euS&Own;Ks@D z$D7~6kM}T+xoKr&Y7Fr^DwxLUlBRv23v^KbWU)XmXDyM>%X1gi9NZM~#rUyWvyI2Muj z&N?An9Y_-^-Jj1f4ZtfHC65y)YPJc{S_zo26xiyQl5AK_4iBNTgF?Gm5I&bQd`!pJ z;Z+~ON5wv;|8vZ`OKSHGjC}c14HF&sGP6NvwRa<`_jHu;=L1q7;RlnQ9*%+J1axZR zik9sQDpHC)C1;6^yAC3i`p#ncpu9ri)n9kEWsaDg0^xLW)Z8qb=QlwHQ?*6?fxWON z8}#2_2(+iEyg-atP$la}gk;x3Au*5uvUN#(Scu=>|BUO5_UI@p*$!yPzIAWUy!7Kh zy)cUBn_$Al`&@PP+5eOoFp`&I9cS?7{xSR*QGL~iSmQ6}qmRgzhn?LKwNQ(^Ga9zDkYM~}&u8=ikZ<^UL z?`rH?ik6Nu;D9p3xkIwDkIQ~a2=OTHl@xj=>2jKxRMTdy9UdtaG_vV2s8L0~-w%;n zyio#f*owxsr&%O#yP!gD`A@UiMJ|>=1@6ZiaGr^^npK-U?62$m2DY#7Lo|Mhy+a00 zPI|OroD1jU7&a+|m=+PK1DsWG{_yPXDoT%q;FfFB6ecMt z&yBRA-kOjxNK7 zB-ku=9&}-_anTp>w1sbVZxfLHX-ek_a*I{j)DFiJ% zE~W7(49FwANaQREKz{xTQOsUh4LxH-{|Mb9Dp<|;<%nC1r-E7)Y-Z#Tsyl{=KyZ4< zXSy#`Mkoadg}+RYKr=`%61{~y9agi4qdoW zOW0)fv54OTh$`IV`J6E`{V{<7-A=s;KAW@UxlArZ!>Ll*%g{B^N9WVHIFgA8W>Har zxs&IPwe^?_fHrV@IqAu=peYRkWB^In7Ck9@GSN&JuigsiF`?JKy$uA|mtI~^{Zv?Z zhKWz|wj%b}v-nUDC7ds9Qmuj=V37%AV`SXQVA|>y^PY|A)3JDCcl`*(R3BFIoW|-R zG{T{=2qKIUzi<4$apO%xuE2YT*eaBLNttKSMMsMLKtkPy;D{I9Ws_-QWf^R(g}; z#(@$}GqGzYd2CXjEE;ptD@Zcb#VmpfYF}Zi%yTpM1|d1$TDU5mZp!aRQ`2&ym@1Y% zr0%LeK6r0fbN<@|86hV?Z<$tzuGAEfU7@Ie2-Wx%@v0-yZFyR{<2ecUV`)kb@kgeV zid@c zuK3s%rk%z0Y(ui+`IT;q2U;9Kin0{3^~9`W(`~)ph!4f7OdY;ex3?!^Jf2TZ6cbbu zbTu#kIwo;+@K=ornpwclvAH@yBm1U7aL>np(5~0bBm`g>Mz=b&=HF zwjGHh*`PJchDti3}&PlBGJy5o-;OsddnW-8_~j|5tv7Z)6c zbQ#3j{oS*gVg1_oHXAs$?RS@+3TaUlvvM&l$mI6~sT$k%u^anZ8NT}f4(8p$>UH4i zj-R8q7?+L`%c=>cJtFkEI&gZk(L-^pIX_(CZ!5Nv9y;x|bQgr(KfsoGGp%^i&25;# zqZU>f1mwc6O!I7O2OdEvt#k&*HDHlsgt%}H9&sbQQLrPDms7E*ck;l5I_lw?P0-1O zkLDgmJMFz5c$1-mtfHcmvA=q22Pd{E+(up#@PD0%{#F~+LqN^>qz4Bxygq_VG$T@@ zpCKPx;&QYGq^i$w{?xi#ek`h+GEryC<5A3DwL8A(4wBK zHmGzs_!}Q1TB9tmb%E19WLKpuVdNEG?CKpd$Snry0Q&wlSI*|GLXN>mbKK)&0!z2e&#%)ig&kni;9Ey~v zqZM@pkD$sk%N$NcZh;fqIZL*eVqQWN|KlQNduBe0<`JjL5WoG{>=N6VhzXqW!h4Acyd7;Q`_n!B5yjZhoC5y~QdI8K6OLi%N|O~>yvYZp?aj}6>L zVb`smx?bycUKLFj$__~GR}hRxqw?i)es~8|yqh!TMy(wLe=Q#ndSbVB&wooI0(aa& z!@UCpp2=wvMB^hcIw{mRg+X($04uw~lHsHr9g;K3#XXzc{9uR6G<$nW9Hx&{tQdRq zv>#K17%9bs=f>@IcB}S6>UIat-;~q13KGbRaRGJj4Q;GU7a@9ISDT-ee0baFXsd$u zSzB-KLLW|yFHy>WYC3ZDq!nYSss6|V+Y6ISpiO2zAT>TLEWq&zK)yY9tBtVO9M>aE zEdJ^KxsK#P<#a6hgZDE+P0|};g!c{77Ke^USn?Y3L@cDhp2tJHVYVbtzE->%S&uu! zNHZ3;2opV9DAT7R%)Msf$ZtAi*SJ={dtPYMf2V#CcG=c@IN3f;z5n{5{6|LqY(f-Co+1P6M+h>(^(afK59@RZUi?k=X+pHj+7K3U>^UC`?6jVwb@Bs^)*J+ zWeu&qft%5VHTJPK;_J+njJ$hV#g>1V%v9~^(4TWHYYQ_$8!PG3j#FU@t0B1!{0sK1 zp5LjPd6+;ceuk_vRYn82kIT&ZM@&CjIMtWhPpsvR)e2sTzUc7j4r+A?h?`x_k!bV* zkDq)fJw&$qj~lXiotdT>UtsIq+OhsK`7@S$Ze!hbky8XvTVaNbkC_Oii7Ck+K0I7s z)`>eTLgg#zd9||ZDwwzfJSzV#rtH{*S&z*H@yQv8`a1w^MeCG>sN}Er2Ec7CFXfk~ z%Lf%75Bm26BWBXM?ka_^=>AGHfM{0Do2#o=tHQIFNh`4tj|+q9bbg!eZ8q$69`<_` z){gMboD|Qwck0Zy)D26}lh3Ihi1Mf=t2VK=d6=Xl!WU-CAK*dcpG1$Ba=Hb)zbYa5 zDa)S%A=7~4QUR$%R4iXQx55p4L&fci9alY7Om(LxF>ZpW2sa%7aw|3$I(qaJ%rdsp zXYLW)`t=xn=#SCsOlc3xhj;pTr1Gk!k6n5%W3M)`*=wB}W3q{3`D{{lK;7J^@0ld8 za!!nCMc(OSebL7eoD!8^k8?b-Yd9fKEeGX5QYHj{ zwPwF{#g|B~JW)k{{j#S6DHl2FGvTpO4>-0L_PW&-%9fD8G)!+QjbH6q&q~t(-aft0 z34Tg6v|*)%KFO`zNq;I3esYy#Rq)Wzd6H-&8MX=le7Gm?OTNRaYwnNs;;YvM#Wj%; z^2Ly(T0x}MW83hES>$~+35GUam^%2Hoeg2iYSto>zg%yHJ!yu#k(3o2*)!0m%sonY zH2TtoIE3oqG5{d*f?!-UJrA26mTl_1B`iiU+bp8m-Rk7}_f=C*1+Oy^r_L-2rdXTfFW%Y9n== zB8}w$fSv#3&r-jvMCQ*^bKpTzMeeZM|5rXYcs1U_B!;h71DwUM1*xvEpG;FqIZ6=_ zr{TL$;k!)Y_)l~**8c!^Ny*&sWn}b`JJC(==9(AAMRQd^7DPE)=W}}lS@JPGPiEqyC$VLNypaUinz1)O?!_e#bWt_x$)%H42}Q;p^J~Y`6Hb=p$m-N!}|H z#K)VFxGKbsn}PI#iVlzwjzUtj(I|FW68 ZidYY5vr5&alKD5fnv%9+!)u$!{{un6z(@c9 literal 0 HcmV?d00001 diff --git a/charts/incubator/firezone/questions.yaml b/charts/incubator/firezone/questions.yaml new file mode 100644 index 00000000000..beda409b783 --- /dev/null +++ b/charts/incubator/firezone/questions.yaml @@ -0,0 +1,341 @@ +# Include{groups} +portals: + open: +# Include{portalLink} +questions: +# Include{global} +# Include{workload} +# Include{workloadDeployment} + +# Include{replicas1} +# Include{podSpec} +# Include{containerMain} + + - variable: env + label: Image Environment + schema: + additional_attrs: true + type: dict + attrs: + - variable: EXTERNAL_URL + label: External Url + description: Must be a valid and public FQDN for ACME SSL issuance to function. + schema: + type: string + required: true + default: "" + - variable: DEFAULT_ADMIN_EMAIL + label: Default Admin Email + description: Primary administrator email. + schema: + type: string + required: true + default: "" + - variable: DEFAULT_ADMIN_PASSWORD + label: Default Admin Password + description: Primary administrator password. + schema: + type: string + required: true + private: true + default: "" + - variable: RESET_ADMIN_ON_BOOT + label: Reset Admin On Boot + description: to create or reset the admin password every time FireZone starts. + schema: + type: boolean + default: false + - variable: TELEMETRY_ENABLED + label: Telemetry Enabled + description: Enable or disable the FireZone telemetry collection. + schema: + type: boolean + default: false + - variable: devices + label: Devices Settings + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: ALLOW_UNPRIVILEGED_DEVICE_MANAGEMENT + label: Allow Unprivileged Devices + description: Enable or disable management of devices on unprivileged accounts. + schema: + type: boolean + default: true + - variable: ALLOW_UNPRIVILEGED_DEVICE_CONFIGURATION + label: Allow Unprivileged Device Configuration + description: Enable or disable configuration of device network settings for unprivileged users. + schema: + type: boolean + default: true + - variable: VPN_SESSION_DURATION + label: VPN Session Duration + description: Optionally require users to periodically authenticate to the FireZone, Interval for WireGuard persistent keepalive. + schema: + type: int + default: 0 + - variable: DEFAULT_CLIENT_PERSISTENT_KEEPALIVE + label: Default Client Persistent KeepAlive + description: send a keepalive packet every 25 seconds. Otherwise, keep it disabled with a 0 default value. + schema: + type: int + default: 25 + - variable: DEFAULT_CLIENT_MTU + label: Default Client MTU + description: WireGuard interface MTU for devices. + schema: + type: int + default: 1280 + - variable: DEFAULT_CLIENT_ENDPOINT + label: Default Client EndPoint + description: IPv4, IPv6 address, or FQDN that devices will be configured to connect to. Defaults to this server's FQDN. + schema: + type: string + default: "" + - variable: DEFAULT_CLIENT_DNS + label: Default Client DNS + description: Comma-separated list of DNS servers to use for devices. + schema: + type: string + default: "1.1.1.1,1.0.0.1" + - variable: DEFAULT_CLIENT_ALLOWED_IPS + label: Default Client Allowed IPs + description: AllowedIPs determines which destination IPs get routed through FireZone. + schema: + type: string + default: "0.0.0.0/0,::/0" + - variable: MAX_DEVICES_PER_USER + label: Max Devices Per User + description: Changes how many devices a user can have at a time. + schema: + type: int + default: 10 + - variable: authorization + label: Authorization Settings + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: LOCAL_AUTH_ENABLED + label: Local Auth Enabled + description: Enable or disable the local authentication method for all users. + schema: + type: boolean + default: true + - variable: DISABLE_VPN_ON_OIDC_ERROR + label: Disable VPN On OIDC Error + description: Enable or disable auto disabling VPN connection on OIDC refresh error. + schema: + type: boolean + default: false + - variable: wireguard + label: Wireguard Settings + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: WIREGUARD_IPV4_ENABLED + label: WireGuard IPV4 Enabled + description: Enable or disable IPv4 support for WireGuard. + schema: + type: boolean + default: true + - variable: WIREGUARD_IPV6_ENABLED + label: WireGuard IPV6 Enabled + description: Enable or disable IPv6 support for WireGuard. + schema: + type: boolean + default: false + - variable: outbound + label: OutBound Email Settings + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: OUTBOUND_EMAIL_FROM + label: Outbound Email From + description: From address to use for sending outbound emails. + schema: + type: string + default: "" + - variable: OUTBOUND_EMAIL_ADAPTER + label: Outbound Email Adapter + description: Method to use for sending outbound email. + schema: + type: string + default: "Elixir.FzHttpWeb.Mailer.NoopAdapter" + enum: + - value: "Elixir.FzHttpWeb.Mailer.AmazonSES" + description: "AmazonSES" + - value: "Elixir.FzHttpWeb.Mailer.CustomerIO" + description: CustomerIO" + - value: "Elixir.FzHttpWeb.Mailer.Dyn" + description: Dyn + - value: "Elixir.FzHttpWeb.Mailer.ExAwsAmazonSES" + description: ExAwsAmazonSES" + - value: "Elixir.FzHttpWeb.Mailer.Gmail" + description: Gmail" + - value: "Elixir.FzHttpWeb.Mailer.MailPace" + description: MailPace" + - value: "Elixir.FzHttpWeb.Mailer.Mailgun" + description: Mailgun" + - value: "Elixir.FzHttpWeb.Mailer.Mailjet" + description: MailJet" + - value: "Elixir.FzHttpWeb.Mailer.Mandrill" + description: Mandrill" + - value: "Elixir.FzHttpWeb.Mailer.Postmark" + description: Postmark" + - value: "Elixir.FzHttpWeb.Mailer.ProtonBridge" + description: ProtonBridge" + - value: "Elixir.FzHttpWeb.Mailer.SMTP" + description: SMTP" + - value: "Elixir.FzHttpWeb.Mailer.SMTP2GO" + description: SMTP2GO" + - value: "Elixir.FzHttpWeb.Mailer.Sendgrid" + description: SendGrid" + - value: "Elixir.FzHttpWeb.Mailer.Sendinblue" + description: "SendInBlue" + - value: "Elixir.FzHttpWeb.Mailer.Sendmail" + description: "Sendmail" + - value: "Elixir.FzHttpWeb.Mailer.SocketLabs" + description: "SocketLabs" + - value: "Elixir.FzHttpWeb.Mailer.SparkPost" + description: "SparkPost" + - value: "Elixir.FzHttpWeb.Mailer.NoopAdapter" + description: "NoopAdapter" + - variable: OUTBOUND_EMAIL_ADAPTER_OPTS + label: Outbound Email Adapter OPTS + description: Adapter configuration, see https://github.com/swoosh/swoosh#adapters. + schema: + type: string + default: "" + - variable: connectivity + label: Connectivity Settings + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: CONNECTIVITY_CHECKS_ENABLED + label: Connectivity Checks Enabled + description: Enable / disable periodic checking for egress connectivity. Determines the instance's public IP to populate Endpoint fields. + schema: + type: boolean + default: true + - variable: CONNECTIVITY_CHECKS_INTERVAL + label: Connectivity Checks Interval + description: Periodicity in seconds to check for egress connectivity. + schema: + type: int + default: 43200 + +# Include{containerBasic} +# Include{containerAdvanced} + +# Include{containerConfig} +# Include{podOptions} +# Include{serviceRoot} + - variable: main + label: Main Service + description: The Primary service on which the healthcheck runs, often the webUI + schema: + additional_attrs: true + type: dict + attrs: +# Include{serviceSelectorLoadBalancer} +# Include{serviceSelectorExtras} + - variable: main + label: Main Service Port Configuration + schema: + additional_attrs: true + type: dict + attrs: + - variable: port + label: Port + description: This port exposes the container port on the service + schema: + type: int + default: 13000 + required: true + - variable: wireguard + label: Wireguard Service + description: The Wireguard service + schema: + additional_attrs: true + type: dict + attrs: +# Include{serviceSelectorLoadBalancer} +# Include{serviceSelectorExtras} + - variable: wireguard + label: Wireguard Service Port Configuration + schema: + additional_attrs: true + type: dict + attrs: + - variable: port + label: Port + description: This port exposes the container port on the service + schema: + type: int + default: 51820 + required: true +# Include{serviceExpertRoot} +# Include{serviceExpert} +# Include{serviceList} +# Include{persistenceRoot} + - variable: config + label: App Config Storage + description: Stores the Application Config. + schema: + additional_attrs: true + type: dict + attrs: +# Include{persistenceBasic} +# Include{persistenceList} +# Include{ingressRoot} + - variable: main + label: Main Ingress + schema: + additional_attrs: true + type: dict + attrs: +# Include{ingressDefault} +# Include{ingressTLS} +# Include{ingressTraefik} +# Include{ingressList} +# Include{securityContextRoot} + - variable: runAsUser + label: runAsUser + description: The UserID of the user running the application + schema: + type: int + default: 0 + - variable: runAsGroup + label: runAsGroup + description: The groupID of the user running the application + schema: + type: int + default: 0 +# Include{securityContextContainer} +# Include{securityContextAdvanced} +# Include{securityContextPod} + - variable: fsGroup + label: fsGroup + description: The group that should own ALL storage. + schema: + type: int + default: 568 +# Include{resources} +# Include{metrics} +# Include{prometheusRule} +# Include{advanced} +# Include{addons} +# Include{codeserver} +# Include{netshoot} +# Include{vpn} +# Include{documentation} diff --git a/charts/incubator/firezone/templates/NOTES.txt b/charts/incubator/firezone/templates/NOTES.txt new file mode 100644 index 00000000000..efcb74cb772 --- /dev/null +++ b/charts/incubator/firezone/templates/NOTES.txt @@ -0,0 +1 @@ +{{- include "tc.v1.common.lib.chart.notes" $ -}} diff --git a/charts/incubator/firezone/templates/_secrets.tpl b/charts/incubator/firezone/templates/_secrets.tpl new file mode 100644 index 00000000000..8390618aad5 --- /dev/null +++ b/charts/incubator/firezone/templates/_secrets.tpl @@ -0,0 +1,26 @@ +{{/* Define the secrets */}} +{{- define "firezone.secrets" -}} +{{- $secretName := (printf "%s-firezone-secrets" (include "tc.v1.common.lib.chart.names.fullname" $)) -}} +{{- $keyGuardian := randAlphaNum 32 -}} +{{- $keyDatabase := randAlphaNum 32 -}} +{{- $keySecret := randAlphaNum 32 -}} +{{- $keyLive := randAlphaNum 32 -}} +{{- $keyCookieSigning := randAlphaNum 32 -}} +{{- $keyCookieEncrypt := randAlphaNum 32 -}} +{{- with (lookup "v1" "Secret" .Release.Namespace $secretName) -}} + {{- $keyGuardian = index .data "GUARDIAN_SECRET_KEY" | b64dec -}} + {{- $keyDatabase = index .data "DATABASE_ENCRYPTION_KEY" | b64dec -}} + {{- $keySecret = index .data "SECRET_KEY_BASE" | b64dec -}} + {{- $keyLive = index .data "LIVE_VIEW_SIGNING_SALT" | b64dec -}} + {{- $keyCookieSigning = index .data "COOKIE_SIGNING_SALT" | b64dec -}} + {{- $keyCookieEncrypt = index .data "COOKIE_ENCRYPTION_SALT" | b64dec -}} +{{- end }} +enabled: true +data: + GUARDIAN_SECRET_KEY: {{ $keyGuardian }} + DATABASE_ENCRYPTION_KEY: {{ $keyDatabase }} + SECRET_KEY_BASE: {{ $keySecret }} + LIVE_VIEW_SIGNING_SALT: {{ $keyLive }} + COOKIE_SIGNING_SALT: {{ $keyCookieSigning }} + COOKIE_ENCRYPTION_SALT: {{ $keyCookieEncrypt }} +{{- end -}} diff --git a/charts/incubator/firezone/templates/common.yaml b/charts/incubator/firezone/templates/common.yaml new file mode 100644 index 00000000000..3a972e62863 --- /dev/null +++ b/charts/incubator/firezone/templates/common.yaml @@ -0,0 +1,11 @@ +{{/* Make sure all variables are set properly */}} +{{- include "tc.v1.common.loader.init" . }} + +{{/* Render secrets for firezone */}} +{{- $secrets := include "firezone.secrets" . | fromYaml -}} +{{- if $secrets -}} + {{- $_ := set .Values.secret "secrets" $secrets -}} +{{- end -}} + +{{/* Render the templates */}} +{{ include "tc.v1.common.loader.apply" . }} diff --git a/charts/incubator/firezone/values.yaml b/charts/incubator/firezone/values.yaml new file mode 100644 index 00000000000..822722ffcac --- /dev/null +++ b/charts/incubator/firezone/values.yaml @@ -0,0 +1,140 @@ +image: + repository: tccr.io/truecharts/firezone + pullPolicy: IfNotPresent + tag: v0.7.30@sha256:e22dc7a9be93a804bbe0e3d301c883625463a3649d856c8b41f80a2257214667 + +securityContext: + container: + readOnlyRootFilesystem: false + runAsNonRoot: false + PUID: 0 + runAsUser: 0 + runAsGroup: 0 + capabilities: + add: + - NET_ADMIN + - SYS_MODULE + +workload: + main: + podSpec: + containers: + main: + probes: + liveness: + enabled: false + readiness: + enabled: false + startup: + enabled: false + env: + # web + PHOENIX_HTTP_PORT: "{{ .Values.service.main.ports.main.port }}" + EXTERNAL_URL: "https://app.mydomain.com" + # PHOENIX_SECURE_COOKIES: true + # PHOENIX_HTTP_PROTOCOL_OPTIONS: "{}" + # PHOENIX_EXTERNAL_TRUSTED_PROXIES: "[]" + # PHOENIX_PRIVATE_CLIENTS: "[]" + # DB + DATABASE_HOST: + secretKeyRef: + name: cnpg-main-urls + key: host + DATABASE_PORT: 5432 + DATABASE_NAME: "{{ .Values.cnpg.main.database }}" + DATABASE_USER: "{{ .Values.cnpg.main.user }}" + DATABASE_PASSWORD: + secretKeyRef: + name: cnpg-main-user + key: password + # DATABASE_POOL_SIZE + DATABASE_SSL_ENABLED: false + # DATABASE_SSL_OPTS: "{}" + # Admin + RESET_ADMIN_ON_BOOT: false + DEFAULT_ADMIN_EMAIL: "admin@email.com" + DEFAULT_ADMIN_PASSWORD: "1234567890" + # Secrets and Encryption + GUARDIAN_SECRET_KEY: + secretKeyRef: + name: secrets + key: GUARDIAN_SECRET_KEY + DATABASE_ENCRYPTION_KEY: + secretKeyRef: + name: secrets + key: DATABASE_ENCRYPTION_KEY + SECRET_KEY_BASE: + secretKeyRef: + name: secrets + key: SECRET_KEY_BASE + LIVE_VIEW_SIGNING_SALT: + secretKeyRef: + name: secrets + key: LIVE_VIEW_SIGNING_SALT + COOKIE_SIGNING_SALT: + secretKeyRef: + name: secrets + key: COOKIE_SIGNING_SALT + COOKIE_ENCRYPTION_SALT: + secretKeyRef: + name: secrets + key: COOKIE_ENCRYPTION_SALT + # Devices + ALLOW_UNPRIVILEGED_DEVICE_MANAGEMENT: true + ALLOW_UNPRIVILEGED_DEVICE_CONFIGURATION: true + VPN_SESSION_DURATION: 0 + DEFAULT_CLIENT_PERSISTENT_KEEPALIVE: 25 + DEFAULT_CLIENT_MTU: 1280 + # DEFAULT_CLIENT_ENDPOINT: "" + DEFAULT_CLIENT_DNS: "1.1.1.1,1.0.0.1" + DEFAULT_CLIENT_ALLOWED_IPS: "0.0.0.0/0, ::/0" + # Limits + MAX_DEVICES_PER_USER: 10 + # Authorization + LOCAL_AUTH_ENABLED: true + DISABLE_VPN_ON_OIDC_ERROR: false + SAML_ENTITY_ID: "urn:firezone.dev:firezone-app" + # SAML_KEYFILE_PATH: "/var/firezone/saml.key" + # SAML_CERTFILE_PATH: "/var/firezone/saml.crt" + # OPENID_CONNECT_PROVIDERS: "[]" + # SAML_IDENTITY_PROVIDERS: "[]" + # WireGuard + WIREGUARD_PORT: "{{ .Values.service.wireguard.ports.wireguard.port }}" + WIREGUARD_IPV4_ENABLED: true + WIREGUARD_IPV6_ENABLED: false + # Outbound Emails + OUTBOUND_EMAIL_FROM: "" + OUTBOUND_EMAIL_ADAPTER: "Elixir.FzHttpWeb.Mailer.NoopAdapter" + # OUTBOUND_EMAIL_ADAPTER_OPTS: "{}" + # Connectivity Checks + CONNECTIVITY_CHECKS_ENABLED: true + CONNECTIVITY_CHECKS_INTERVAL: 43200 + # Telemetry + TELEMETRY_ENABLED: false + +service: + main: + ports: + main: + protocol: http + port: 13000 + wireguard: + ports: + wireguard: + protocol: udp + port: 51820 + +persistence: + config: + enabled: true + mountPath: "/var/firezone" + +cnpg: + main: + enabled: true + user: firezone + database: firezone + +portal: + open: + enabled: true