|
@@ -56,58 +56,39 @@ openvpn:
|
|
|
-----BEGIN X509 CRL-----
|
|
|
-----END X509 CRL-----
|
|
|
|
|
|
-
|
|
|
- scripts:
|
|
|
-
|
|
|
- initscript: |-
|
|
|
-
|
|
|
- iptables -I FORWARD 1 -m state --state NEW -s 10.100.10.0/24 -i openvpn-tun -j DROP
|
|
|
- iptables -I FORWARD 1 -m state --state NEW -s 10.100.10.0/24 -d 192.168.205.10 -i openvpn-tun -j ACCEPT
|
|
|
- iptables -I INPUT 1 -m state --state NEW -s 10.100.10.0/24 -i openvpn-tun -j DROP
|
|
|
- iptables -I INPUT 1 -m state --state NEW -s 10.100.10.0/24 -d 217.74.42.72 -i openvpn-tun -j ACCEPT
|
|
|
-
|
|
|
- startscript: |-
|
|
|
-
|
|
|
- mkdir /dev/net
|
|
|
- mknod /dev/net/tun c 10 200
|
|
|
- exec "/usr/sbin/openvpn" "--config" "/etc/openvpn/configuration/openvpn.conf"
|
|
|
-
|
|
|
- stopscript: |-
|
|
|
-
|
|
|
- iptables -D FORWARD -m state --state NEW -s 10.100.10.0/24 -i openvpn-tun -j DROP
|
|
|
- iptables -D FORWARD -m state --state NEW -s 10.100.10.0/24 -d 192.168.205.10 -i openvpn-tun -j ACCEPT
|
|
|
- iptables -D INPUT -m state --state NEW -s 10.100.10.0/24 -i openvpn-tun -j DROP
|
|
|
- iptables -D INPUT -m state --state NEW -s 10.100.10.0/24 -d 217.74.42.72 -i openvpn-tun -j ACCEPT
|
|
|
-
|
|
|
- healthcheck: |-
|
|
|
-
|
|
|
-
|
|
|
-
|
|
|
+
|
|
|
+
|
|
|
+
|
|
|
+
|
|
|
|
|
|
|
|
|
|
|
|
-inbound_IP: 10.1.2.3
|
|
|
+inbound_IP: 192.168.21.75
|
|
|
|
|
|
inbound_port: 1194
|
|
|
|
|
|
inbound_proto: UDP
|
|
|
|
|
|
-# Openvpn settings, musb be the same, as in config, used in router daemonset
|
|
|
-dev_name: openvpn-tun
|
|
|
-net: 10.100.0.0
|
|
|
-mask: 255.255.0.0
|
|
|
+# Virtual flow ip for openvpn service
|
|
|
+virtIP_addr: 192.168.21.71
|
|
|
+virtIP_dev: team0
|
|
|
+
|
|
|
+# Networks CIDR which has to be routed through openvpn
|
|
|
+netOpenvpn:
|
|
|
+ - 10.10.0.0/16
|
|
|
+ - 10.1.200.0/24
|
|
|
|
|
|
|
|
|
ccd:
|
|
|
- client: ifconfig-push 10.100.10.2 255.255.0.0
|
|
|
- someclient: |-
|
|
|
- ifconfig-push 10.100.10.3 255.255.0.0
|
|
|
- iroute 192.168.250.0 255.255.255.0
|
|
|
+ test: |-
|
|
|
+ ifconfig-push 10.10.10.10 255.255.0.0
|
|
|
+ iroute 10.1.200.0 255.255.255.0
|
|
|
+# push "route 192.168.200.0 255.255.248.0"
|
|
|
|
|
|
|
|
|
router:
|
|
|
- image: "jcr.infoclinica.ru/sys/kubectl"
|
|
|
- tag: "1.18.9-3"
|
|
|
+ image: "images.sdsys.ru/sys/ovpn-rsa"
|
|
|
+ tag: "200207025"
|
|
|
pullPolicy: IfNotPresent
|
|
|
resources:
|
|
|
limits:
|
|
@@ -115,5 +96,4 @@ router:
|
|
|
memory: 50Mi
|
|
|
requests:
|
|
|
cpu: 50m
|
|
|
- memory: 50Mi
|
|
|
-
|
|
|
+ memory: 50Mi
|