diff --git a/.vscode/settings.json b/.vscode/settings.json index 3e3b918..1e87f6f 100644 --- a/.vscode/settings.json +++ b/.vscode/settings.json @@ -1,13 +1,16 @@ { "cSpell.words": [ + "allowdupe", "dontlognull", "dport", "forwardfor", "httplog", + "managehome", "maxconn", "nologin", "pidfile", "redispatch", + "roundrobin", "sess", "setsebool", "tcplog", diff --git a/README.md b/README.md index f0c5161..6306c31 100644 --- a/README.md +++ b/README.md @@ -10,6 +10,7 @@ - [Deployment](#deployment) - [Parameters](#parameters) - [Proxy Configuration](#proxy-configuration) + - [TLS](#tls) - [SELINUX](#selinux) - [Known Problems](#known-problems) - [Support](#support) @@ -42,7 +43,7 @@ CONFIGURATION - front-end options - back-end options - ACL options -- manage fail2ban integration (optional, requires fail2ban_cd module) +- manage fail2ban integration (optional, requires `confdroid_fail2ban` module) SERVICE @@ -53,7 +54,6 @@ SERVICE All dependencies must be included in the catalogue. -- [cd_resources](https://gitlab.confdroid.com/puppet/cd_resources) for managing yum base repos - [concat](https://github.com/puppetlabs/puppetlabs-concat) for managing file fragments ## Deployment @@ -83,6 +83,8 @@ The parameters are documented via puppet strings and [listed here](/docs/index.h The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so: +ACL rule: + ```bash confdroid_haproxy::server::proxy { 'testing': haproxy_fqdn => 'node.example.net', @@ -94,10 +96,37 @@ In order to create proxy instances, you will need an external class, which addre } ``` +real Proxy for https: + +```bash + haproxy_cd::server::proxy { 'https-in': + haproxy_fqdn => 'node.example.net', + frontend_name => 'https-in', + frontend_mode => 'http', + fe_bind_mode => '*:443 ssl crt /etc/haproxy/certs/', + fe_option => 'forwardfor', + fe_http_request => 'add-header X-Forwarded-Proto https', + acl_rule_front => 'host_grafana hdr(host) -i grafana.example.net', + fe_use_backend => 'grafana_backend if host_grafana', + backend_configs => [ + { + 'backend_name' => 'grafana_backend', + 'be_mode' => 'http', + 'be_balance' => 'roundrobin', + 'be_server_name_array' => ['node1 10.0.1.1:8080 check'], + } + ] + default_backend => 'error_backend', +``` + This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. `haproxy_fqdn` **must**- contain the fqdn of the haproxy **server**- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each. +## TLS + +Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. **This module is NOT managing certificates**, as there are many ways to manage this, including Kubernetes cert-manager, Let's encrypt or other ways. + ## SELINUX All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.