Puppet Class: confdroid_haproxy::params

Overview

confdroid_haproxy::params.pp Module name: confdroid_haproxy Author: Arne Teuke (arne_teuke@confdroid.com)

Parameters:

  • pkg_ensure (String) (defaults to: 'latest')

    which package type to choose, i.e. latest or present.

  • reqpackages (Array) (defaults to: ['haproxy','httpd-tools'])

    specify the packages to be installed

  • hy_host_fqdn (String) (defaults to: undef)

    the fqdn of the ha proxy host. must be fqdn, not cname. specify multiple fqdns via array.

  • hy_manage_fw (Boolean) (defaults to: true)

    whether to manage the firewall.

  • hy_fw_order_no (String) (defaults to: '50')

    the rule number to control the order of the firewall rules.

  • hy_http_port (String) (defaults to: '80')

    the http port. used in firewall settings

  • hy_https_port (String) (defaults to: '443')

    the https port. used in firewall settings

  • hy_user_name (String) (defaults to: 'haproxy')

    the name of the haproxy service user.

  • hy_user_comment (String) (defaults to: 'haproxy user')

    the comment of the haproxy user, shows up in emails sent from haproxy.

  • hy_user_home (String) (defaults to: '/var/lib/haproxy')

    the home directory for the haproxy user.

  • hy_user_shell (String) (defaults to: '/sbin/nologin')

    the shell for the haproxy user.

  • hy_log_target (String) (defaults to: '127.0.0.1')

    Where to send the logs for this haproxy. Currently only local logging / rsyslog forwarding supported.

  • hy_log_facility (String) (defaults to: 'local2')

    which logging facility to use.

  • hy_chroot (String) (defaults to: '/var/lib/haproxy')

    where the chroot should be

  • hy_pid (String) (defaults to: '/var/run/haproxy.pid')

    the pid file to use.

  • hy_maxconn (String) (defaults to: '4000')

    how many connections should we max allow.

  • hy_show_stats (Boolean) (defaults to: false)

    whether we want to display the statistics page

  • hy_stats_socket (String) (defaults to: '/var/lib/haproxy/stats')

    name and path of the stats socket

  • hy_default_mode (String) (defaults to: 'tcp')

    which mode to use in the defaults block

  • hy_log_default (String) (defaults to: 'global')

    should be used when the instance’s logging parameters are the same as the global ones.

  • hy_timeout_http_request (String) (defaults to: '10s')

    Set the maximum allowed time to wait for a complete HTTP request.

  • hy_timeout_queue (String) (defaults to: '1m')

    Set the maximum time to wait in the queue for a connection slot to be free.

  • hy_timeout_http_keep_alive (String) (defaults to: '10s')

    set the timeout value for keeping https connections alive

  • hy_timeout_check (String) (defaults to: '10s')

    set the timeout value for how long to check if the timeout has occurred

  • hy_manage_fail2ban (Boolean) (defaults to: false)

    whether to integrate fail2ban

  • hy_use_http_server_close (Boolean) (defaults to: false)

    whether to use this in global mode

  • hy_use_forward_for (Boolean) (defaults to: false)

    whether to use this in global mode

  • hy_use_redispatch (Boolean) (defaults to: true)

    whether to use this in global mode

  • hy_max_retries (String) (defaults to: '3')

    max retries value

  • hy_timeout_connect (String) (defaults to: '10s')

    timeout for connections

  • hy_timeout_client (String) (defaults to: '1m')

    timeout for client connections

  • hy_timeout_server (String) (defaults to: '1m')

    timeout for server response

  • hy_hard_stop (Boolean) (defaults to: true)

    whether to use hard stop for service restart

  • hy_hard_stop_value (String) (defaults to: '60s')

    which value to use for hard stop

  • hy_stats_auth (String) (defaults to: 'admin:password')

    credentials to use for stats authentication

  • hy_log_local0 (String) (defaults to: '127.0.0.1:514 local0')

    settings for logging to local0

  • hy_log_local1 (String) (defaults to: '127.0.0.1:514 local1 notice')

    settings for logging to local1

  • hy_use_tcplog (Boolean) (defaults to: true)

    whether to use tcplog as default

  • hy_use_httplog (Boolean) (defaults to: false)

    whether to use httplog as default

  • hy_use_dontlognull (Boolean) (defaults to: true)

    whether to use dontlognull as default

  • hy_be_userlist (String) (defaults to: '####')

    backend userlist comment

  • hy_manage_be_users (Boolean) (defaults to: false)

    whether to manage backend users



58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
# File 'manifests/params.pp', line 58

class confdroid_haproxy::params (

  String $pkg_ensure                  = 'latest',
  Array $reqpackages                  = ['haproxy','httpd-tools'],

  String $hy_host_fqdn                = undef,

# firewall
  Boolean $hy_manage_fw               = true,
  String $hy_fw_order_no              = '50',

# fail2ban
  Boolean $hy_manage_fail2ban         = false,

# main config
  String $hy_http_port                = '80',
  String $hy_https_port               = '443',
  String $hy_chroot                   = '/var/lib/haproxy',
  String $hy_pid                      = '/var/run/haproxy.pid',
  String $hy_maxconn                  = '4000',
  Boolean $hy_show_stats              = false,
  String $hy_stats_socket             = '/var/lib/haproxy/stats',
  String $hy_default_mode             = 'tcp',
  Boolean $hy_use_http_server_close   = false,
  Boolean $hy_use_forward_for         = false,
  Boolean $hy_use_redispatch          = true,
  String $hy_max_retries              = '3',
  String $hy_timeout_http_request     = '10s',
  String $hy_timeout_queue            = '1m',
  String $hy_timeout_connect          = '10s',
  String $hy_timeout_client           = '1m',
  String $hy_timeout_server           = '1m',
  String $hy_timeout_http_keep_alive  = '10s',
  String $hy_timeout_check            = '10s',
  Boolean $hy_hard_stop               = true,
  String $hy_hard_stop_value          = '60s',
  String $hy_stats_auth               = 'admin:password',

# user
  String $hy_user_name                = 'haproxy',
  String $hy_user_comment             = 'haproxy user',
  String $hy_user_home                = '/var/lib/haproxy',
  String $hy_user_shell               = '/sbin/nologin',

# logging
  String $hy_log_local0               = '127.0.0.1:514 local0',
  String $hy_log_local1               = '127.0.0.1:514 local1 notice',
  String $hy_log_target               = '127.0.0.1',
  String $hy_log_facility             = 'local2',
  String $hy_log_default              = 'global',
  Boolean $hy_use_tcplog              = true,
  Boolean $hy_use_httplog             = false,
  Boolean $hy_use_dontlognull         = true,
  Boolean $hy_manage_be_users         = false,
  String $hy_be_userlist              = '####',

) {
  $fqdn                               = $facts['networking']['fqdn']

  # service
  $hy_service                         = 'haproxy'

  # directories
  $hy_main_dir                        = '/etc/haproxy'
  $hy_errors_dir                      = "${hy_main_dir}/errors"
  $hy_certs_dir                       = "${hy_main_dir}/certs"

  # files
  $hy_main_config                     = "${hy_main_dir}/haproxy.cfg"
  $hy_config_head_erb                 = 'confdroid_haproxy/haproxy_head.erb'
  $hy_config_tail_erb                 = 'confdroid_haproxy/haproxy_tail.erb'
  $hy_400_file                        = "${hy_errors_dir}/400.http"
  $hy_400_erb                         = 'confdroid_haproxy/errors/400_http.erb'
  $hy_403_file                        = "${hy_errors_dir}/403.http"
  $hy_403_erb                         = 'confdroid_haproxy/errors/403_http.erb'
  $hy_408_file                        = "${hy_errors_dir}/408.http"
  $hy_408_erb                         = 'confdroid_haproxy/errors/408_http.erb'
  $hy_500_file                        = "${hy_errors_dir}/500.http"
  $hy_500_erb                         = 'confdroid_haproxy/errors/500_http.erb'
  $hy_502_file                        = "${hy_errors_dir}/502.http"
  $hy_502_erb                         = 'confdroid_haproxy/errors/502_http.erb'
  $hy_503_file                        = "${hy_errors_dir}/503.http"
  $hy_503_erb                         = 'confdroid_haproxy/errors/503_http.erb'
  $hy_504_file                        = "${hy_errors_dir}/504.http"
  $hy_504_erb                         = 'confdroid_haproxy/errors/504_http.erb'

  # includes must be last
  include confdroid_haproxy::main::config
}