commit dfec133745551bc6046552792a5b0fb1f07e703d
parent 21b851f39ff76bafbcd894fb53a061615ba6dd66
Author: Joris Hartog <jorishartog@hotmail.com>
Date: Tue, 25 Aug 2026 10:53:42 +0200
Keep admin IP allowlist outside version control
Diffstat:
3 files changed, 28 insertions(+), 1 deletion(-)
diff --git a/.gitignore b/.gitignore
@@ -8,5 +8,6 @@
/src-tauri/binaries/iuna-sidecar-*
/downloads/*
!/downloads/.gitkeep
+/config/admin-ip-allowlist.local
__pycache__/
*.py[cod]
diff --git a/config/deployment.yml b/config/deployment.yml
@@ -144,6 +144,7 @@ metadata:
spec:
ipAllowList:
sourceRange:
+${IUNA_ADMIN_IP_ALLOWLIST_LOCAL}
---
apiVersion: apps/v1
kind: Deployment
diff --git a/deployment.sh b/deployment.sh
@@ -380,16 +380,41 @@ render_manifest() {
local www_image="$1"
local node_image="$2"
local output="$3"
+ local local_allowlist_file="config/admin-ip-allowlist.local"
+ local allowlist_entry
+ local allowlist_entry_count=0
local escaped_www_image
local escaped_node_image
escaped_www_image="$(escape_sed_replacement "$www_image")"
escaped_node_image="$(escape_sed_replacement "$node_image")"
+ [ -f "$local_allowlist_file" ] || die "missing local admin allowlist: ${local_allowlist_file}"
+ while IFS= read -r allowlist_entry || [ -n "$allowlist_entry" ]; do
+ allowlist_entry="${allowlist_entry%%#*}"
+ allowlist_entry="${allowlist_entry//[[:space:]]/}"
+ [ -z "$allowlist_entry" ] && continue
+ [[ "$allowlist_entry" =~ ^([0-9]{1,3}\.){3}[0-9]{1,3}/(3[0-2]|[12]?[0-9])$ ]] || \
+ die "invalid CIDR in ${local_allowlist_file}: ${allowlist_entry}"
+ allowlist_entry_count=$((allowlist_entry_count + 1))
+ done < "$local_allowlist_file"
+ [ "$allowlist_entry_count" -gt 0 ] || die "local admin allowlist is empty: ${local_allowlist_file}"
+
sed \
-e "s|\${IUNA_WWW_IMAGE}|${escaped_www_image}|g" \
-e "s|\${IUNA_NODE_IMAGE}|${escaped_node_image}|g" \
- config/deployment.yml > "$output"
+ config/deployment.yml | awk -v local_allowlist_file="$local_allowlist_file" '
+ $0 == "${IUNA_ADMIN_IP_ALLOWLIST_LOCAL}" {
+ while ((getline entry < local_allowlist_file) > 0) {
+ sub(/#.*/, "", entry)
+ gsub(/[[:space:]]/, "", entry)
+ if (entry != "") print " - " entry
+ }
+ close(local_allowlist_file)
+ next
+ }
+ { print }
+ ' > "$output"
}
deploy_docker_image() {