From 3ed73f6cb6dfe9d67b27bf96e45468e26f013991 Mon Sep 17 00:00:00 2001 From: Arne Teuke Date: Fri, 14 Feb 2025 11:36:23 +0100 Subject: [PATCH] add fail2ban class --- manifests/firewall/iptables.pp | 17 --------------- manifests/main/config.pp | 17 --------------- manifests/main/dirs.pp | 17 --------------- manifests/main/files.pp | 17 --------------- manifests/main/install.pp | 17 --------------- manifests/main/user.pp | 17 --------------- manifests/monitoring/fail2ban.pp | 28 +++++++++++++++++++++++++ manifests/params.pp | 3 +++ manifests/server/service.pp | 17 --------------- templates/fail2ban/f2b_haproxy.conf.erb | 7 +++++++ 10 files changed, 38 insertions(+), 119 deletions(-) create mode 100644 manifests/monitoring/fail2ban.pp create mode 100644 templates/fail2ban/f2b_haproxy.conf.erb diff --git a/manifests/firewall/iptables.pp b/manifests/firewall/iptables.pp index 8789de7..7f7ea09 100644 --- a/manifests/firewall/iptables.pp +++ b/manifests/firewall/iptables.pp @@ -1,23 +1,6 @@ ## cd_haproxy::firewall::iptables.pp # Module name: cd_haproxy # Author: Arne Teuke (arne_teuke@confdroid.com) -# License: -# This file is part of cd_haproxy. -# -# cd_haproxy is used for providing automatic configuration of HA proxy. -# Copyright (C) 2017 confdroid (copyright@confdroid.com) -# This program is free software: you can redistribute it and/or modify -# it under the terms of the GNU General Public License as published by -# the Free Software Foundation, either version 3 of the License, or -# (at your option) any later version. -# -# This program is distributed in the hope that it will be useful, -# but WITHOUT ANY WARRANTY; without even the implied warranty of -# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -# GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public License -# along with this program. If not, see . # @summary manage firewall settings through cd_firewall or puppetlabs-firewall ############################################################################### class cd_haproxy::firewall::iptables ( diff --git a/manifests/main/config.pp b/manifests/main/config.pp index 64ee58a..8131b90 100644 --- a/manifests/main/config.pp +++ b/manifests/main/config.pp @@ -1,23 +1,6 @@ ## cd_haproxy::main::config.pp # Module name: cd_haproxy # Author: Arne Teuke (arne_teuke@confdroid.com) -# License: -# This file is part of cd_haproxy. -# -# cd_haproxy is used for providing automatic configuration of HA proxy. -# Copyright (C) 2017 confdroid (copyright@confdroid.com) -# This program is free software: you can redistribute it and/or modify -# it under the terms of the GNU General Public License as published by -# the Free Software Foundation, either version 3 of the License, or -# (at your option) any later version. -# -# This program is distributed in the hope that it will be useful, -# but WITHOUT ANY WARRANTY; without even the implied warranty of -# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -# GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public License -# along with this program. If not, see . # @summary Class manages all aspects of configuring the module logic for # cd_haproxy. ############################################################################## diff --git a/manifests/main/dirs.pp b/manifests/main/dirs.pp index 2409bf6..839186d 100644 --- a/manifests/main/dirs.pp +++ b/manifests/main/dirs.pp @@ -1,23 +1,6 @@ ## cd_haproxy::main::dirs.pp # Module name: cd_haproxy # Author: Arne Teuke (arne_teuke@confdroid.com) -# License: -# This file is part of cd_haproxy. -# -# cd_haproxy is used for providing automatic configuration of HA proxy. -# Copyright (C) 2017 confdroid (copyright@confdroid.com) -# This program is free software: you can redistribute it and/or modify -# it under the terms of the GNU General Public License as published by -# the Free Software Foundation, either version 3 of the License, or -# (at your option) any later version. -# -# This program is distributed in the hope that it will be useful, -# but WITHOUT ANY WARRANTY; without even the implied warranty of -# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -# GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public License -# along with this program. If not, see . # @summary Class manages all directories required for cd_haproxy. ############################################################################### class cd_haproxy::main::dirs ( diff --git a/manifests/main/files.pp b/manifests/main/files.pp index 11a0ec1..9d54db5 100644 --- a/manifests/main/files.pp +++ b/manifests/main/files.pp @@ -1,23 +1,6 @@ ## cd_haproxy::main::files.pp # Module name: cd_haproxy # Author: Arne Teuke (arne_teuke@confdroid.com) -# License: -# This file is part of cd_haproxy. -# -# cd_haproxy is used for providing automatic configuration of HA proxy. -# Copyright (C) 2017 confdroid (copyright@confdroid.com) -# This program is free software: you can redistribute it and/or modify -# it under the terms of the GNU General Public License as published by -# the Free Software Foundation, either version 3 of the License, or -# (at your option) any later version. -# -# This program is distributed in the hope that it will be useful, -# but WITHOUT ANY WARRANTY; without even the implied warranty of -# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -# GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public License -# along with this program. If not, see . # @summary Class manages all configuration files required for cd_haproxy. ############################################################################## class cd_haproxy::main::files ( diff --git a/manifests/main/install.pp b/manifests/main/install.pp index 6101927..0bf1198 100644 --- a/manifests/main/install.pp +++ b/manifests/main/install.pp @@ -1,23 +1,6 @@ ## cd_haproxy::main::install.pp # Module name: cd_haproxy # Author: Arne Teuke (arne_teuke@confdroid.com) -# License: -# This file is part of cd_haproxy. -# -# cd_haproxy is used for providing automatic configuration of HA proxy. -# Copyright (C) 2017 confdroid (copyright@confdroid.com) -# This program is free software: you can redistribute it and/or modify -# it under the terms of the GNU General Public License as published by -# the Free Software Foundation, either version 3 of the License, or -# (at your option) any later version. -# -# This program is distributed in the hope that it will be useful, -# but WITHOUT ANY WARRANTY; without even the implied warranty of -# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -# GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public License -# along with this program. If not, see . # @summary Class manage all aspects of installing binaries required for # cd_haproxy ############################################################################### diff --git a/manifests/main/user.pp b/manifests/main/user.pp index b5159ab..c818eec 100644 --- a/manifests/main/user.pp +++ b/manifests/main/user.pp @@ -1,23 +1,6 @@ ## cd_haproxy::main::user.pp # Module name: cd_haproxy # Author: Arne Teuke (arne_teuke@ConfDroid.com) -# # License: -# This file is part of cd_haproxy. -# -# cd_haproxy is used for providing automatic configuration of HAproxy -# Copyright (C) 2016 ConfDroid (copyright@ConfDroid.com) -# This program is free software: you can redistribute it and/or modify -# it under the terms of the GNU General Public License as published by -# the Free Software Foundation, either version 3 of the License, or -# (at your option) any later version. -# -# This program is distributed in the hope that it will be useful, -# but WITHOUT ANY WARRANTY; without even the implied warranty of -# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -# GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public License -# along with this program. If not, see . # @summary Class manages service users for cd_haproxy. ############################################################################# class cd_haproxy::main::user ( diff --git a/manifests/monitoring/fail2ban.pp b/manifests/monitoring/fail2ban.pp new file mode 100644 index 0000000..4662b20 --- /dev/null +++ b/manifests/monitoring/fail2ban.pp @@ -0,0 +1,28 @@ +# Module name: cd_haproxy +# Author: Arne Teuke (arne_teuke@confdroid.com) +# @summary Class manages fail2ban settings +############################################################################## +class cd_haproxy::monitoring::fail2ban ( + +) inherits cd_haproxy::params { + + require cd_fail2ban + + if $hy_manage_fail2ban == true { + + # configure filter + + file { '/etc/fail2ban/filter.d/haproxy.conf': + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template('cd_haproxy/fail2ban/f2b_haproxy.conf.erb'), + notify => Service[$fn_service], + } + } +} diff --git a/manifests/params.pp b/manifests/params.pp index 35a4d67..dfdf0f7 100644 --- a/manifests/params.pp +++ b/manifests/params.pp @@ -66,6 +66,9 @@ $hy_host_fqdn = undef, $hy_manage_fw = true, $hy_fw_order_no = '50', +# fail2ban +$hy_manage_fail2ban = false, + # main config $hy_http_port = '80', $hy_https_port = '443', diff --git a/manifests/server/service.pp b/manifests/server/service.pp index a6e6c3f..ce9b450 100644 --- a/manifests/server/service.pp +++ b/manifests/server/service.pp @@ -1,23 +1,6 @@ ## cd_haproxy::server::service.pp # Module name: cd_haproxy # Author: Arne Teuke (arne_teuke@confdroid.com) -# License: -# This file is part of cd_haproxy. -# -# cd_haproxy is used for providing automatic configuration of HA proxy. -# Copyright (C) 2017 confdroid (copyright@confdroid.com) -# This program is free software: you can redistribute it and/or modify -# it under the terms of the GNU General Public License as published by -# the Free Software Foundation, either version 3 of the License, or -# (at your option) any later version. -# -# This program is distributed in the hope that it will be useful, -# but WITHOUT ANY WARRANTY; without even the implied warranty of -# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -# GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public License -# along with this program. If not, see . # @summary Class manages the service(s) for cd_haproxy. ############################################################################# class cd_haproxy::server::service ( diff --git a/templates/fail2ban/f2b_haproxy.conf.erb b/templates/fail2ban/f2b_haproxy.conf.erb new file mode 100644 index 0000000..2d91380 --- /dev/null +++ b/templates/fail2ban/f2b_haproxy.conf.erb @@ -0,0 +1,7 @@ +################################################################################ +##### fail2ban for haproxy.conf created by Puppet ##### +################################################################################ + +[Definition] +failregex = ^ -.*"(GET|POST|HEAD|PUT|DELETE|OPTIONS) .*(/login|/admin|/api/login).*HTTP/1\.[01]" 401 +ignoreregex =