diff --git a/values/headscale/values/values.yaml b/values/headscale/values/values.yaml index f3c2ef49..a942b06b 100644 --- a/values/headscale/values/values.yaml +++ b/values/headscale/values/values.yaml @@ -3,7 +3,7 @@ image: pullPolicy: IfNotPresent tag: v0.26.1 -args: [ "serve" ] +args: ["serve"] env: HEADSCALE_DNS_BASE_DOMAIN: "ts.obx" @@ -132,6 +132,7 @@ configMaps: "tag:k8s": [ "group:admin" ], "tag:hpc": [ "group:admin" ], "tag:mumindalen": [ "group:admin" ], + "tag:hel1": [ "group:admin" ], }, // hosts should be defined using its IP addresses and a subnet mask. // to define a single host, use a /32 mask. You cannot use DNS entries here, @@ -154,29 +155,32 @@ configMaps: "mgmt.tos.net": "10.255.240.0/24", "dc.vtn.net": "172.16.239.0/24", "mgmt.vtn.net": "172.16.238.0/24", + "dc.hel1.net": "10.0.1.0/24", }, "acls": [ { "action": "accept", "src": [ - "group:admin", - "tag:mumindalen", + "group:admin", + "tag:mumindalen", ], "dst": [ - "tag:hpc:*", - "tag:mumindalen:*", - "dc.tos.net:*", - "mgmt.tos.net:*", - "office.tos.net:*", - "dc.vtn.net:*", - "mgmt.vtn.net:*", - "100.64.0.0/10:*", + "tag:hpc:*", + "tag:hel1:*", + "tag:mumindalen:*", + "dc.tos.net:*", + "mgmt.tos.net:*", + "office.tos.net:*", + "dc.vtn.net:*", + "mgmt.vtn.net:*", + "dc.hel1.net:*", + "100.64.0.0/10:*", ] }, { "action": "accept", "src": [ - "tag:hpc", + "tag:hpc", ], "dst": [ "tag:hpc:22", @@ -188,24 +192,27 @@ configMaps: "action": "accept", "src": [ "group:devops" ], "dst": [ - "k8s.oceanbox.tos:6443", - "k8s.ekman.tos:6443", - "tag:hpc:*", - "tag:mumindalen:*", - "dc.tos.net:*", + "k8s.oceanbox.tos:6443", + "k8s.ekman.tos:6443", + "tag:hpc:*", + "tag:hel1:*", + "tag:mumindalen:*", + "dc.tos.net:*", + "dc.hel1.net:*", ] }, { "action": "accept", "src": [ - "group:oceanographer", - "group:manager", - "group:marketing", + "group:oceanographer", + "group:manager", + "group:marketing", ], "dst": [ - "tag:mumindalen:0", - "tag:hpc:22,80,443", - "dc.tos.net:22,80,443", + "tag:mumindalen:0", + "tag:hpc:22,80,443", + "dc.tos.net:22,80,443", + "dc.hel1.net:443", ] }, {