From 04e35b6d1d2e53de97a088ac3e7ff5bc281e9302 Mon Sep 17 00:00:00 2001 From: 12ww1160 <12ww1160@confdroid.com> Date: Sat, 5 Sep 2026 12:50:53 +0200 Subject: [PATCH] OP#669 remove unwanted onio-api fw rule --- .vscode/settings.json | 2 ++ README.md | 1 + manifests/params.pp | 4 ++++ templates/haproxy_head.erb | 9 ++++----- 4 files changed, 11 insertions(+), 5 deletions(-) diff --git a/.vscode/settings.json b/.vscode/settings.json index 28884c3..85a82f4 100644 --- a/.vscode/settings.json +++ b/.vscode/settings.json @@ -2,9 +2,11 @@ "cSpell.words": [ "dontlognull", "dport", + "forwardfor", "httplog", "maxconn", "nologin", + "pidfile", "redispatch", "sess", "tcplog", diff --git a/README.md b/README.md index 01c1d4b..e952172 100644 --- a/README.md +++ b/README.md @@ -101,6 +101,7 @@ Multiple ACLs need to be added as array, and will create one line each. ## SELINUX All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. +If selinux is set to `enforce` (not controlled within this module) and `hy_show_stats`is set to `true`, the parameter `hy_selinux_allow_stats` must also be set to `true`, else the haproxy service will not start as selinux will not allow it. ## Known Problems diff --git a/manifests/params.pp b/manifests/params.pp index d486690..deb58c6 100644 --- a/manifests/params.pp +++ b/manifests/params.pp @@ -54,6 +54,7 @@ # @param [Boolean] hy_use_dontlognull whether to use dontlognull as default # @param [String] hy_be_userlist backend userlist comment # @param [Boolean] hy_manage_be_users whether to manage backend users +# @param [Boolean] hy_selinux_allow_stats whether to allow stats in selinux ############################################################################### class confdroid_haproxy::params ( @@ -69,6 +70,9 @@ class confdroid_haproxy::params ( # fail2ban Boolean $hy_manage_fail2ban = false, +# selinux + Boolean $hy_selinux_allow_stats = false, + # main config String $hy_http_port = '80', String $hy_https_port = '443', diff --git a/templates/haproxy_head.erb b/templates/haproxy_head.erb index 8dd99b1..4b23052 100644 --- a/templates/haproxy_head.erb +++ b/templates/haproxy_head.erb @@ -7,10 +7,6 @@ global log <%= @hy_log_local1 %> <% if @hy_hard_stop == true -%> hard-stop-after <%= @hy_hard_stop_value %> -<% end -%> -<% if @hy_show_stats == true -%> - stats socket /var/lib/haproxy/stats - stats timeout 30s <% end -%> chroot <%= @hy_chroot %> pidfile <%= @hy_pid %> @@ -54,8 +50,9 @@ defaults timeout check <%= @hy_timeout_check %> maxconn <%= @hy_maxconn %> +<% if @hy_show_stats == true -%> listen stats - bind 127.0.0.1:8404 # Bind to localhost if only local access is needed # + bind *:8404 mode http stats enable stats uri /haproxy?stats @@ -63,6 +60,8 @@ listen stats stats auth <%= @hy_stats_auth %> stats refresh 30s stats admin if TRUE # Allow admin actions if logged in +<% end -%> +listen stats <% if @hy_manage_be_users == true -%> <%= @hy_be_userlist %>