diff --git a/.vscode/settings.json b/.vscode/settings.json deleted file mode 100644 index 3e3b918..0000000 --- a/.vscode/settings.json +++ /dev/null @@ -1,16 +0,0 @@ -{ - "cSpell.words": [ - "dontlognull", - "dport", - "forwardfor", - "httplog", - "maxconn", - "nologin", - "pidfile", - "redispatch", - "sess", - "setsebool", - "tcplog", - "userlist" - ] -} \ No newline at end of file diff --git a/Jenkinsfile b/Jenkinsfile deleted file mode 100644 index 512e8e6..0000000 --- a/Jenkinsfile +++ /dev/null @@ -1,127 +0,0 @@ -pipeline { - agent { - label 'puppet' - } - - post { - always { - deleteDir() /* clean up our workspace */ - } - success { - updateGitlabCommitStatus state: 'success' - } - failure { - updateGitlabCommitStatus state: 'failed' - step([$class: 'Mailer', notifyEveryUnstableBuild: true, recipients: 'support@confdroid.com', sendToIndividuals: true]) - } - } - - options { - gitLabConnection('gitlab.confdroid.com') - } - - stages { - - stage('pull master') { - steps { - sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { - sh ''' - git config user.name "Jenkins Server" - git config user.email jenkins@confdroid.com - # Ensure we're on the development branch (triggered by push) - git checkout development - # Create jenkins branch from development - git checkout -b jenkins-build-$BUILD_NUMBER - # Optionally merge master into jenkins to ensure compatibility - git merge origin/master --no-ff || { echo "Merge conflict detected"; exit 1; } - ''' - } - } - } - - stage('puppet parser') { - steps { - sh '''for file in $(find . -iname \'*.pp\'); do - /opt/puppetlabs/bin/puppet parser validate --color false --render-as s --modulepath=modules $file || exit 1; - done;''' - } - } - - stage('check templates') { - steps{ - sh '''for file in $(find . -iname \'*.erb\'); - do erb -P -x -T "-" $file | ruby -c || exit 1; - done;''' - } - } - - stage('puppet-lint') { - steps { - sh '''/usr/local/bin/puppet-lint . \\ - --no-variable_scope-check \\ - || { echo "Puppet lint failed"; exit 1; } - ''' - } - } - - stage('SonarScan') { - steps { - withCredentials([string(credentialsId: 'sonar-token', variable: 'SONAR_TOKEN')]) { - sh ''' - /opt/sonar-scanner/bin/sonar-scanner \ - -Dsonar.projectKey=confdroid_haproxy \ - -Dsonar.sources=. \ - -Dsonar.host.url=https://sonarqube.confdroid.com \ - -Dsonar.token=$SONAR_TOKEN - ''' - } - } - } - - stage('create Puppet documentation') { - steps { - sh '/opt/puppetlabs/bin/puppet strings' - } - } - - stage('update repo') { - steps { - sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { - sh ''' - git config user.name "Jenkins Server" - git config user.email jenkins@confdroid.com - git rm -r --cached .vscode || echo "No .vscode to remove from git" - git add -A && git commit -am "Recommit for updates in build $BUILD_NUMBER" || echo "No changes to commit" - git push origin HEAD:master - ''' - } - } - } - stage('Mirror to Gitea') { - steps { - sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { - withCredentials([usernamePassword( - credentialsId: 'Jenkins-gitea', - usernameVariable: 'GITEA_USER', - passwordVariable: 'GITEA_TOKEN')]) { - script { - // Checkout from GitLab (already done implicitly) - sh ''' - git checkout master - git pull origin master - git branch -D development - git branch -D jenkins-build-$BUILD_NUMBER - git rm -f Jenkinsfile - git rm -r --cached .vscode || echo "No .vscode to remove from git" - git commit --amend --no-edit --allow-empty - git remote add master https://sourcecode.confdroid.com/confdroid/confdroid_haproxy.git - git -c credential.helper="!f() { echo username=${GITEA_USER}; echo password=${GITEA_TOKEN}; }; f" \ - push master --mirror - ''' - } - } - } - } - } - } -} \ No newline at end of file diff --git a/doc/file.README.html b/doc/file.README.html index 135f5c5..7c5760f 100644 --- a/doc/file.README.html +++ b/doc/file.README.html @@ -186,7 +186,7 @@

SELINUX

-

All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.

+

All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to enforce (not controlled within this module) and hy_show_statsis set to true, the parameter hy_selinux_allow_stats must also be set to true, else the haproxy service will not start as selinux will not allow it.

Known Problems

diff --git a/doc/index.html b/doc/index.html index 015b6c7..48badd7 100644 --- a/doc/index.html +++ b/doc/index.html @@ -186,7 +186,7 @@

SELINUX

-

All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.

+

All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to enforce (not controlled within this module) and hy_show_statsis set to true, the parameter hy_selinux_allow_stats must also be set to true, else the haproxy service will not start as selinux will not allow it.

Known Problems

diff --git a/doc/puppet_classes/confdroid_haproxy_3A_3Amain_3A_3Aconfig.html b/doc/puppet_classes/confdroid_haproxy_3A_3Amain_3A_3Aconfig.html index d789c2a..9ed838a 100644 --- a/doc/puppet_classes/confdroid_haproxy_3A_3Amain_3A_3Aconfig.html +++ b/doc/puppet_classes/confdroid_haproxy_3A_3Amain_3A_3Aconfig.html @@ -109,7 +109,13 @@ 11 12 13 -14 +14 +15 +16 +17 +18 +19 +20
# File 'manifests/main/config.pp', line 6
@@ -122,6 +128,12 @@ class confdroid_haproxy::main::config (
   if $hy_manage_fail2ban == true {
     include confdroid_haproxy::monitoring::fail2ban
   }
+
+  if $hy_selinux_allow_stats == true {
+    exec { 'setsebool haproxy_connect_any on':
+      path => ['/bin', '/usr/bin', '/sbin', '/usr/sbin'],
+    }
+  }
 }
diff --git a/doc/puppet_classes/confdroid_haproxy_3A_3Aparams.html b/doc/puppet_classes/confdroid_haproxy_3A_3Aparams.html index c71ce8b..372d73e 100644 --- a/doc/puppet_classes/confdroid_haproxy_3A_3Aparams.html +++ b/doc/puppet_classes/confdroid_haproxy_3A_3Aparams.html @@ -861,6 +861,24 @@ —

whether to manage backend users

+
+ + + +
  • + + hy_selinux_allow_stats + + + (Boolean) + + + (defaults to: false) + + + — +
    +

    whether to allow stats in selinux

  • @@ -876,7 +894,6 @@
     
     
    -58
     59
     60
     61
    @@ -964,10 +981,14 @@
     143
     144
     145
    -146
    +146 +147 +148 +149 +150 -
    # File 'manifests/params.pp', line 58
    +        
    # File 'manifests/params.pp', line 59
     
     class confdroid_haproxy::params (
     
    @@ -983,6 +1004,9 @@ class confdroid_haproxy::params (
     # fail2ban
       Boolean $hy_manage_fail2ban         = false,
     
    +# selinux
    +  Boolean $hy_selinux_allow_stats     = false,
    +
     # main config
       String $hy_http_port                = '80',
       String $hy_https_port               = '443',