From 3ba353aef47d8555dacedaa459a1dda9e4a9d0c3 Mon Sep 17 00:00:00 2001 From: Jenkins Server Date: Sat, 5 Sep 2026 13:32:27 +0200 Subject: [PATCH] Recommit for updates in build 9 --- doc/file.README.html | 34 +++++++++++++++++++++++++++++++--- doc/index.html | 34 +++++++++++++++++++++++++++++++--- 2 files changed, 62 insertions(+), 6 deletions(-) diff --git a/doc/file.README.html b/doc/file.README.html index e9f2bbf..e991a83 100644 --- a/doc/file.README.html +++ b/doc/file.README.html @@ -78,6 +78,8 @@
  • Proxy Configuration

  • +

    TLS

    +
  • SELINUX

  • Known Problems

    @@ -126,7 +128,7 @@
  • ACL options

  • -

    manage fail2ban integration (optional, requires fail2ban_cd module)

    +

    manage fail2ban integration (optional, requires confdroid_fail2ban module)

  • SERVICE

    @@ -140,8 +142,6 @@

    All dependencies must be included in the catalogue.

    @@ -172,6 +172,8 @@

    The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:

    +

    ACL rule:

    +
    confdroid_haproxy::server::proxy { 'testing':
         haproxy_fqdn    =>  'node.example.net',
         frontend_name   =>  'test01-frontend',
    @@ -182,8 +184,34 @@
       }
     
    +

    real Proxy for https:

    + +
    haproxy_cd::server::proxy { 'https-in':
    +    haproxy_fqdn    => 'node.example.net',
    +    frontend_name   => 'https-in',
    +    frontend_mode   => 'http',
    +    fe_bind_mode    => '*:443 ssl crt /etc/haproxy/certs/',
    +    fe_option       => 'forwardfor',
    +    fe_http_request => 'add-header X-Forwarded-Proto https',
    +    acl_rule_front  => 'host_grafana hdr(host) -i grafana.example.net',
    +    fe_use_backend  => 'grafana_backend if host_grafana',
    +    backend_configs => [
    +      {
    +        'backend_name'         => 'grafana_backend',
    +        'be_mode'              => 'http',
    +        'be_balance'           => 'roundrobin',
    +        'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
    +      }
    +    ]
    +  default_backend => 'error_backend',
    +
    +

    This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. haproxy_fqdn must- contain the fqdn of the haproxy server- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.

    +

    TLS

    + +

    Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. This module is NOT managing certificates, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.

    +

    SELINUX

    All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to enforce (not controlled within this module), the parameter hy_selinux_allow_stats must also be set to true, else the haproxy service will not start as selinux will not allow it. This is the default setting.

    diff --git a/doc/index.html b/doc/index.html index 16616b5..79f4334 100644 --- a/doc/index.html +++ b/doc/index.html @@ -78,6 +78,8 @@
  • Proxy Configuration

  • +

    TLS

    +
  • SELINUX

  • Known Problems

    @@ -126,7 +128,7 @@
  • ACL options

  • -

    manage fail2ban integration (optional, requires fail2ban_cd module)

    +

    manage fail2ban integration (optional, requires confdroid_fail2ban module)

  • SERVICE

    @@ -140,8 +142,6 @@

    All dependencies must be included in the catalogue.

    @@ -172,6 +172,8 @@

    The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:

    +

    ACL rule:

    +
    confdroid_haproxy::server::proxy { 'testing':
         haproxy_fqdn    =>  'node.example.net',
         frontend_name   =>  'test01-frontend',
    @@ -182,8 +184,34 @@
       }
     
    +

    real Proxy for https:

    + +
    haproxy_cd::server::proxy { 'https-in':
    +    haproxy_fqdn    => 'node.example.net',
    +    frontend_name   => 'https-in',
    +    frontend_mode   => 'http',
    +    fe_bind_mode    => '*:443 ssl crt /etc/haproxy/certs/',
    +    fe_option       => 'forwardfor',
    +    fe_http_request => 'add-header X-Forwarded-Proto https',
    +    acl_rule_front  => 'host_grafana hdr(host) -i grafana.example.net',
    +    fe_use_backend  => 'grafana_backend if host_grafana',
    +    backend_configs => [
    +      {
    +        'backend_name'         => 'grafana_backend',
    +        'be_mode'              => 'http',
    +        'be_balance'           => 'roundrobin',
    +        'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
    +      }
    +    ]
    +  default_backend => 'error_backend',
    +
    +

    This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. haproxy_fqdn must- contain the fqdn of the haproxy server- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.

    +

    TLS

    + +

    Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. This module is NOT managing certificates, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.

    +

    SELINUX

    All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to enforce (not controlled within this module), the parameter hy_selinux_allow_stats must also be set to true, else the haproxy service will not start as selinux will not allow it. This is the default setting.