Files
confdroid_haproxy/manifests/params.pp

153 lines
7.5 KiB
ObjectPascal
Raw Normal View History

## confdroid_haproxy::params.pp
# Module name: confdroid_haproxy
2018-04-24 15:32:11 +02:00
# Author: Arne Teuke (arne_teuke@confdroid.com)
# @param [String] pkg_ensure
2018-04-24 15:32:11 +02:00
# which [package type](https://confdroid.com/2017/05/puppet-type-package/)
# to choose, i.e. `latest` or `present`.
2025-03-02 17:51:51 +01:00
# @param [array] reqpackages specify the packages to be installed
# @param [String] hy_host_fqdn the fqdn of the ha proxy host. must be fqdn,
2018-04-24 15:32:11 +02:00
# not cname. specify multiple fqdns via array.
# @param [Boolean] hy_manage_fw whether to manage the firewall.
# @param [String] hy_fw_order_no the rule number to control the order of the
2018-04-24 15:32:11 +02:00
# firewall rules.
# @param [String] hy_http_port the http port. used in firewall settings
# @param [String] hy_https_port the https port. used in firewall settings
# @param [String] hy_user_name the name of the haproxy service user.
# @param [String] hy_user_comment the comment of the haproxy user, shows up
2018-12-10 16:12:32 +01:00
# in emails sent from haproxy.
# @param [String] hy_user_home the home directory for the haproxy user.
# @param [String] hy_user_shell the shell for the haproxy user.
# @param [String] hy_log_target Where to send the logs for this haproxy.
2018-12-10 16:57:53 +01:00
# Currently only local logging / rsyslog forwarding supported.
# @param [String] hy_log_facility which logging facility to use.
# @param [String] hy_chroot where the chroot should be
# @param [String] hy_pid the pid file to use.
# @param [String] hy_maxconn how many connections should we max allow.
# @param [Boolean] hy_show_stats whether we want to display the statistics page
# @param [String] hy_stats_socket name and path of the stats socket
# @param [String] hy_default_mode which mode to use in the defaults block
# @param [String] hy_log_default should be used when the instance's logging
2018-12-19 16:07:59 +01:00
# parameters are the same as the global ones.
# @param [String] hy_timeout_http_request Set the maximum allowed time to wait
2018-12-24 16:51:00 +01:00
# for a complete HTTP request.
# @param [String] hy_timeout_queue Set the maximum time to wait in the queue
2018-12-24 16:51:00 +01:00
# for a connection slot to be free.
# @param [String] hy_timeout_http_keep_alive set the timeout value for
# keeping https connections alive
# @param [String] hy_timeout_check set the timeout value for how long to check
2025-03-02 16:28:57 +01:00
# if the timeout has occurred
# @param [Boolean] hy_manage_fail2ban whether to integrate fail2ban
# @param [Boolean] hy_use_http_server_close whether to use this in global mode
# @param [Boolean] hy_use_forward_for whether to use this in global mode
# @param [Boolean] hy_use_redispatch whether to use this in global mode
# @param [String] hy_max_retries max retries value
# @param [String] hy_timeout_connect timeout for connections
# @param [String] hy_timeout_client timeout for client connections
# @param [String] hy_timeout_server timeout for server response
# @param [Boolean] hy_hard_stop whether to use hard stop for service restart
# @param [String] hy_hard_stop_value which value to use for hard stop
# @param [String] hy_stats_auth credentials to use for stats authentication
# @param [String] hy_log_local0 settings for logging to local0
# @param [String] hy_log_local1 settings for logging to local1
# @param [Boolean] hy_use_tcplog whether to use tcplog as default
# @param [Boolean] hy_use_httplog whether to use httplog as default
# @param [Boolean] hy_use_dontlognull whether to use dontlognull as default
# @param [String] hy_be_userlist backend userlist comment
# @param [Boolean] hy_manage_be_users whether to manage backend users
# @param [Boolean] hy_selinux_allow_stats whether to allow stats in selinux
2026-09-05 12:56:23 +02:00
# @param [String] hy_stats_port the port to use for stats. used in firewall settings
2018-12-10 16:12:32 +01:00
###############################################################################
class confdroid_haproxy::params (
2018-04-24 15:32:11 +02:00
2025-03-02 16:28:57 +01:00
String $pkg_ensure = 'latest',
2025-05-18 17:56:49 +02:00
Array $reqpackages = ['haproxy','httpd-tools'],
2018-04-24 15:32:11 +02:00
2025-03-02 16:28:57 +01:00
String $hy_host_fqdn = undef,
2018-04-24 15:32:11 +02:00
# firewall
2025-03-02 16:28:57 +01:00
Boolean $hy_manage_fw = true,
String $hy_fw_order_no = '50',
2018-04-24 15:32:11 +02:00
2025-02-14 11:36:23 +01:00
# fail2ban
2025-03-02 16:28:57 +01:00
Boolean $hy_manage_fail2ban = false,
2025-02-14 11:36:23 +01:00
# selinux
Boolean $hy_selinux_allow_stats = false,
2018-04-24 15:32:11 +02:00
# main config
2025-03-02 16:28:57 +01:00
String $hy_http_port = '80',
String $hy_https_port = '443',
2026-09-05 12:56:23 +02:00
String $hy_stats_port = '8404',
2025-03-02 16:28:57 +01:00
String $hy_chroot = '/var/lib/haproxy',
String $hy_pid = '/var/run/haproxy.pid',
String $hy_maxconn = '4000',
Boolean $hy_show_stats = false,
String $hy_stats_socket = '/var/lib/haproxy/stats',
String $hy_default_mode = 'tcp',
Boolean $hy_use_http_server_close = false,
Boolean $hy_use_forward_for = false,
Boolean $hy_use_redispatch = true,
String $hy_max_retries = '3',
String $hy_timeout_http_request = '10s',
String $hy_timeout_queue = '1m',
String $hy_timeout_connect = '10s',
String $hy_timeout_client = '1m',
String $hy_timeout_server = '1m',
String $hy_timeout_http_keep_alive = '10s',
String $hy_timeout_check = '10s',
Boolean $hy_hard_stop = true,
String $hy_hard_stop_value = '60s',
String $hy_stats_auth = 'admin:password',
2018-12-10 14:36:54 +01:00
# user
2025-03-02 16:28:57 +01:00
String $hy_user_name = 'haproxy',
String $hy_user_comment = 'haproxy user',
String $hy_user_home = '/var/lib/haproxy',
String $hy_user_shell = '/sbin/nologin',
2018-04-24 15:32:11 +02:00
2018-12-10 16:57:53 +01:00
# logging
2025-03-02 16:28:57 +01:00
String $hy_log_local0 = '127.0.0.1:514 local0',
String $hy_log_local1 = '127.0.0.1:514 local1 notice',
String $hy_log_target = '127.0.0.1',
String $hy_log_facility = 'local2',
String $hy_log_default = 'global',
Boolean $hy_use_tcplog = true,
Boolean $hy_use_httplog = false,
Boolean $hy_use_dontlognull = true,
Boolean $hy_manage_be_users = false,
String $hy_be_userlist = '####',
2025-02-12 11:45:09 +01:00
2018-04-24 15:32:11 +02:00
) {
2025-03-02 17:26:09 +01:00
$fqdn = $facts['networking']['fqdn']
2025-03-02 16:28:57 +01:00
# service
$hy_service = 'haproxy'
2018-04-24 15:32:11 +02:00
2025-03-02 16:28:57 +01:00
# directories
$hy_main_dir = '/etc/haproxy'
$hy_errors_dir = "${hy_main_dir}/errors"
2025-05-18 16:12:28 +02:00
$hy_certs_dir = "${hy_main_dir}/certs"
2018-12-10 14:36:54 +01:00
2025-03-02 16:28:57 +01:00
# files
$hy_main_config = "${hy_main_dir}/haproxy.cfg"
$hy_config_head_erb = 'confdroid_haproxy/haproxy_head.erb'
$hy_config_tail_erb = 'confdroid_haproxy/haproxy_tail.erb'
2025-03-02 16:28:57 +01:00
$hy_400_file = "${hy_errors_dir}/400.http"
$hy_400_erb = 'confdroid_haproxy/errors/400_http.erb'
2025-03-02 16:28:57 +01:00
$hy_403_file = "${hy_errors_dir}/403.http"
$hy_403_erb = 'confdroid_haproxy/errors/403_http.erb'
2025-03-02 16:28:57 +01:00
$hy_408_file = "${hy_errors_dir}/408.http"
$hy_408_erb = 'confdroid_haproxy/errors/408_http.erb'
2025-03-02 16:28:57 +01:00
$hy_500_file = "${hy_errors_dir}/500.http"
$hy_500_erb = 'confdroid_haproxy/errors/500_http.erb'
2025-03-02 16:28:57 +01:00
$hy_502_file = "${hy_errors_dir}/502.http"
$hy_502_erb = 'confdroid_haproxy/errors/502_http.erb'
2025-03-02 16:28:57 +01:00
$hy_503_file = "${hy_errors_dir}/503.http"
$hy_503_erb = 'confdroid_haproxy/errors/503_http.erb'
2025-03-02 16:28:57 +01:00
$hy_504_file = "${hy_errors_dir}/504.http"
$hy_504_erb = 'confdroid_haproxy/errors/504_http.erb'
2018-04-24 17:07:38 +02:00
2025-03-02 16:28:57 +01:00
# includes must be last
include confdroid_haproxy::main::config
2018-04-24 15:32:11 +02:00
}