Recommit for updates in build 9
This commit is contained in:
@@ -78,6 +78,8 @@
|
||||
</li><li>
|
||||
<p><a href="#proxy-configuration">Proxy Configuration</a></p>
|
||||
</li><li>
|
||||
<p><a href="#tls">TLS</a></p>
|
||||
</li><li>
|
||||
<p><a href="#selinux">SELINUX</a></p>
|
||||
</li><li>
|
||||
<p><a href="#known-problems">Known Problems</a></p>
|
||||
@@ -126,7 +128,7 @@
|
||||
</li><li>
|
||||
<p>ACL options</p>
|
||||
</li><li>
|
||||
<p>manage fail2ban integration (optional, requires fail2ban_cd module)</p>
|
||||
<p>manage fail2ban integration (optional, requires <code>confdroid_fail2ban</code> module)</p>
|
||||
</li></ul>
|
||||
|
||||
<p>SERVICE</p>
|
||||
@@ -140,8 +142,6 @@
|
||||
|
||||
<p>All dependencies must be included in the catalogue.</p>
|
||||
<ul><li>
|
||||
<p><a href="https://gitlab.confdroid.com/puppet/cd_resources">cd_resources</a> for managing yum base repos</p>
|
||||
</li><li>
|
||||
<p><a href="https://github.com/puppetlabs/puppetlabs-concat">concat</a> for managing file fragments</p>
|
||||
</li></ul>
|
||||
|
||||
@@ -172,6 +172,8 @@
|
||||
|
||||
<p>The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:</p>
|
||||
|
||||
<p>ACL rule:</p>
|
||||
|
||||
<pre class="code ruby"><code class="ruby">confdroid_haproxy::server::proxy { 'testing':
|
||||
haproxy_fqdn => 'node.example.net',
|
||||
frontend_name => 'test01-frontend',
|
||||
@@ -182,8 +184,34 @@
|
||||
}
|
||||
</code></pre>
|
||||
|
||||
<p>real Proxy for https:</p>
|
||||
|
||||
<pre class="code ruby"><code class="ruby">haproxy_cd::server::proxy { 'https-in':
|
||||
haproxy_fqdn => 'node.example.net',
|
||||
frontend_name => 'https-in',
|
||||
frontend_mode => 'http',
|
||||
fe_bind_mode => '*:443 ssl crt /etc/haproxy/certs/',
|
||||
fe_option => 'forwardfor',
|
||||
fe_http_request => 'add-header X-Forwarded-Proto https',
|
||||
acl_rule_front => 'host_grafana hdr(host) -i grafana.example.net',
|
||||
fe_use_backend => 'grafana_backend if host_grafana',
|
||||
backend_configs => [
|
||||
{
|
||||
'backend_name' => 'grafana_backend',
|
||||
'be_mode' => 'http',
|
||||
'be_balance' => 'roundrobin',
|
||||
'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
|
||||
}
|
||||
]
|
||||
default_backend => 'error_backend',
|
||||
</code></pre>
|
||||
|
||||
<p>This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. <code>haproxy_fqdn</code> <strong>must</strong>- contain the fqdn of the haproxy <strong>server</strong>- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.</p>
|
||||
|
||||
<h2 id="label-TLS">TLS</h2>
|
||||
|
||||
<p>Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. <strong>This module is NOT managing certificates</strong>, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.</p>
|
||||
|
||||
<h2 id="label-SELINUX">SELINUX</h2>
|
||||
|
||||
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p>
|
||||
|
||||
@@ -78,6 +78,8 @@
|
||||
</li><li>
|
||||
<p><a href="#proxy-configuration">Proxy Configuration</a></p>
|
||||
</li><li>
|
||||
<p><a href="#tls">TLS</a></p>
|
||||
</li><li>
|
||||
<p><a href="#selinux">SELINUX</a></p>
|
||||
</li><li>
|
||||
<p><a href="#known-problems">Known Problems</a></p>
|
||||
@@ -126,7 +128,7 @@
|
||||
</li><li>
|
||||
<p>ACL options</p>
|
||||
</li><li>
|
||||
<p>manage fail2ban integration (optional, requires fail2ban_cd module)</p>
|
||||
<p>manage fail2ban integration (optional, requires <code>confdroid_fail2ban</code> module)</p>
|
||||
</li></ul>
|
||||
|
||||
<p>SERVICE</p>
|
||||
@@ -140,8 +142,6 @@
|
||||
|
||||
<p>All dependencies must be included in the catalogue.</p>
|
||||
<ul><li>
|
||||
<p><a href="https://gitlab.confdroid.com/puppet/cd_resources">cd_resources</a> for managing yum base repos</p>
|
||||
</li><li>
|
||||
<p><a href="https://github.com/puppetlabs/puppetlabs-concat">concat</a> for managing file fragments</p>
|
||||
</li></ul>
|
||||
|
||||
@@ -172,6 +172,8 @@
|
||||
|
||||
<p>The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:</p>
|
||||
|
||||
<p>ACL rule:</p>
|
||||
|
||||
<pre class="code ruby"><code class="ruby">confdroid_haproxy::server::proxy { 'testing':
|
||||
haproxy_fqdn => 'node.example.net',
|
||||
frontend_name => 'test01-frontend',
|
||||
@@ -182,8 +184,34 @@
|
||||
}
|
||||
</code></pre>
|
||||
|
||||
<p>real Proxy for https:</p>
|
||||
|
||||
<pre class="code ruby"><code class="ruby">haproxy_cd::server::proxy { 'https-in':
|
||||
haproxy_fqdn => 'node.example.net',
|
||||
frontend_name => 'https-in',
|
||||
frontend_mode => 'http',
|
||||
fe_bind_mode => '*:443 ssl crt /etc/haproxy/certs/',
|
||||
fe_option => 'forwardfor',
|
||||
fe_http_request => 'add-header X-Forwarded-Proto https',
|
||||
acl_rule_front => 'host_grafana hdr(host) -i grafana.example.net',
|
||||
fe_use_backend => 'grafana_backend if host_grafana',
|
||||
backend_configs => [
|
||||
{
|
||||
'backend_name' => 'grafana_backend',
|
||||
'be_mode' => 'http',
|
||||
'be_balance' => 'roundrobin',
|
||||
'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
|
||||
}
|
||||
]
|
||||
default_backend => 'error_backend',
|
||||
</code></pre>
|
||||
|
||||
<p>This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. <code>haproxy_fqdn</code> <strong>must</strong>- contain the fqdn of the haproxy <strong>server</strong>- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.</p>
|
||||
|
||||
<h2 id="label-TLS">TLS</h2>
|
||||
|
||||
<p>Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. <strong>This module is NOT managing certificates</strong>, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.</p>
|
||||
|
||||
<h2 id="label-SELINUX">SELINUX</h2>
|
||||
|
||||
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p>
|
||||
|
||||
Reference in New Issue
Block a user