add fail2ban class
This commit is contained in:
@@ -1,23 +1,6 @@
|
|||||||
## cd_haproxy::firewall::iptables.pp
|
## cd_haproxy::firewall::iptables.pp
|
||||||
# Module name: cd_haproxy
|
# Module name: cd_haproxy
|
||||||
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
||||||
# License:
|
|
||||||
# This file is part of cd_haproxy.
|
|
||||||
#
|
|
||||||
# cd_haproxy is used for providing automatic configuration of HA proxy.
|
|
||||||
# Copyright (C) 2017 confdroid (copyright@confdroid.com)
|
|
||||||
# This program is free software: you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation, either version 3 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# This program is distributed in the hope that it will be useful,
|
|
||||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
# GNU General Public License for more details.
|
|
||||||
#
|
|
||||||
# You should have received a copy of the GNU General Public License
|
|
||||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
# @summary manage firewall settings through cd_firewall or puppetlabs-firewall
|
# @summary manage firewall settings through cd_firewall or puppetlabs-firewall
|
||||||
###############################################################################
|
###############################################################################
|
||||||
class cd_haproxy::firewall::iptables (
|
class cd_haproxy::firewall::iptables (
|
||||||
|
|||||||
@@ -1,23 +1,6 @@
|
|||||||
## cd_haproxy::main::config.pp
|
## cd_haproxy::main::config.pp
|
||||||
# Module name: cd_haproxy
|
# Module name: cd_haproxy
|
||||||
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
||||||
# License:
|
|
||||||
# This file is part of cd_haproxy.
|
|
||||||
#
|
|
||||||
# cd_haproxy is used for providing automatic configuration of HA proxy.
|
|
||||||
# Copyright (C) 2017 confdroid (copyright@confdroid.com)
|
|
||||||
# This program is free software: you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation, either version 3 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# This program is distributed in the hope that it will be useful,
|
|
||||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
# GNU General Public License for more details.
|
|
||||||
#
|
|
||||||
# You should have received a copy of the GNU General Public License
|
|
||||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
# @summary Class manages all aspects of configuring the module logic for
|
# @summary Class manages all aspects of configuring the module logic for
|
||||||
# cd_haproxy.
|
# cd_haproxy.
|
||||||
##############################################################################
|
##############################################################################
|
||||||
|
|||||||
@@ -1,23 +1,6 @@
|
|||||||
## cd_haproxy::main::dirs.pp
|
## cd_haproxy::main::dirs.pp
|
||||||
# Module name: cd_haproxy
|
# Module name: cd_haproxy
|
||||||
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
||||||
# License:
|
|
||||||
# This file is part of cd_haproxy.
|
|
||||||
#
|
|
||||||
# cd_haproxy is used for providing automatic configuration of HA proxy.
|
|
||||||
# Copyright (C) 2017 confdroid (copyright@confdroid.com)
|
|
||||||
# This program is free software: you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation, either version 3 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# This program is distributed in the hope that it will be useful,
|
|
||||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
# GNU General Public License for more details.
|
|
||||||
#
|
|
||||||
# You should have received a copy of the GNU General Public License
|
|
||||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
# @summary Class manages all directories required for cd_haproxy.
|
# @summary Class manages all directories required for cd_haproxy.
|
||||||
###############################################################################
|
###############################################################################
|
||||||
class cd_haproxy::main::dirs (
|
class cd_haproxy::main::dirs (
|
||||||
|
|||||||
@@ -1,23 +1,6 @@
|
|||||||
## cd_haproxy::main::files.pp
|
## cd_haproxy::main::files.pp
|
||||||
# Module name: cd_haproxy
|
# Module name: cd_haproxy
|
||||||
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
||||||
# License:
|
|
||||||
# This file is part of cd_haproxy.
|
|
||||||
#
|
|
||||||
# cd_haproxy is used for providing automatic configuration of HA proxy.
|
|
||||||
# Copyright (C) 2017 confdroid (copyright@confdroid.com)
|
|
||||||
# This program is free software: you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation, either version 3 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# This program is distributed in the hope that it will be useful,
|
|
||||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
# GNU General Public License for more details.
|
|
||||||
#
|
|
||||||
# You should have received a copy of the GNU General Public License
|
|
||||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
# @summary Class manages all configuration files required for cd_haproxy.
|
# @summary Class manages all configuration files required for cd_haproxy.
|
||||||
##############################################################################
|
##############################################################################
|
||||||
class cd_haproxy::main::files (
|
class cd_haproxy::main::files (
|
||||||
|
|||||||
@@ -1,23 +1,6 @@
|
|||||||
## cd_haproxy::main::install.pp
|
## cd_haproxy::main::install.pp
|
||||||
# Module name: cd_haproxy
|
# Module name: cd_haproxy
|
||||||
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
||||||
# License:
|
|
||||||
# This file is part of cd_haproxy.
|
|
||||||
#
|
|
||||||
# cd_haproxy is used for providing automatic configuration of HA proxy.
|
|
||||||
# Copyright (C) 2017 confdroid (copyright@confdroid.com)
|
|
||||||
# This program is free software: you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation, either version 3 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# This program is distributed in the hope that it will be useful,
|
|
||||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
# GNU General Public License for more details.
|
|
||||||
#
|
|
||||||
# You should have received a copy of the GNU General Public License
|
|
||||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
# @summary Class manage all aspects of installing binaries required for
|
# @summary Class manage all aspects of installing binaries required for
|
||||||
# cd_haproxy
|
# cd_haproxy
|
||||||
###############################################################################
|
###############################################################################
|
||||||
|
|||||||
@@ -1,23 +1,6 @@
|
|||||||
## cd_haproxy::main::user.pp
|
## cd_haproxy::main::user.pp
|
||||||
# Module name: cd_haproxy
|
# Module name: cd_haproxy
|
||||||
# Author: Arne Teuke (arne_teuke@ConfDroid.com)
|
# Author: Arne Teuke (arne_teuke@ConfDroid.com)
|
||||||
# # License:
|
|
||||||
# This file is part of cd_haproxy.
|
|
||||||
#
|
|
||||||
# cd_haproxy is used for providing automatic configuration of HAproxy
|
|
||||||
# Copyright (C) 2016 ConfDroid (copyright@ConfDroid.com)
|
|
||||||
# This program is free software: you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation, either version 3 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# This program is distributed in the hope that it will be useful,
|
|
||||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
# GNU General Public License for more details.
|
|
||||||
#
|
|
||||||
# You should have received a copy of the GNU General Public License
|
|
||||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
# @summary Class manages service users for cd_haproxy.
|
# @summary Class manages service users for cd_haproxy.
|
||||||
#############################################################################
|
#############################################################################
|
||||||
class cd_haproxy::main::user (
|
class cd_haproxy::main::user (
|
||||||
|
|||||||
28
manifests/monitoring/fail2ban.pp
Normal file
28
manifests/monitoring/fail2ban.pp
Normal file
@@ -0,0 +1,28 @@
|
|||||||
|
# Module name: cd_haproxy
|
||||||
|
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
||||||
|
# @summary Class manages fail2ban settings
|
||||||
|
##############################################################################
|
||||||
|
class cd_haproxy::monitoring::fail2ban (
|
||||||
|
|
||||||
|
) inherits cd_haproxy::params {
|
||||||
|
|
||||||
|
require cd_fail2ban
|
||||||
|
|
||||||
|
if $hy_manage_fail2ban == true {
|
||||||
|
|
||||||
|
# configure filter
|
||||||
|
|
||||||
|
file { '/etc/fail2ban/filter.d/haproxy.conf':
|
||||||
|
ensure => file,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0644',
|
||||||
|
selrange => s0,
|
||||||
|
selrole => object_r,
|
||||||
|
seltype => etc_t,
|
||||||
|
seluser => system_u,
|
||||||
|
content => template('cd_haproxy/fail2ban/f2b_haproxy.conf.erb'),
|
||||||
|
notify => Service[$fn_service],
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -66,6 +66,9 @@ $hy_host_fqdn = undef,
|
|||||||
$hy_manage_fw = true,
|
$hy_manage_fw = true,
|
||||||
$hy_fw_order_no = '50',
|
$hy_fw_order_no = '50',
|
||||||
|
|
||||||
|
# fail2ban
|
||||||
|
$hy_manage_fail2ban = false,
|
||||||
|
|
||||||
# main config
|
# main config
|
||||||
$hy_http_port = '80',
|
$hy_http_port = '80',
|
||||||
$hy_https_port = '443',
|
$hy_https_port = '443',
|
||||||
|
|||||||
@@ -1,23 +1,6 @@
|
|||||||
## cd_haproxy::server::service.pp
|
## cd_haproxy::server::service.pp
|
||||||
# Module name: cd_haproxy
|
# Module name: cd_haproxy
|
||||||
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
||||||
# License:
|
|
||||||
# This file is part of cd_haproxy.
|
|
||||||
#
|
|
||||||
# cd_haproxy is used for providing automatic configuration of HA proxy.
|
|
||||||
# Copyright (C) 2017 confdroid (copyright@confdroid.com)
|
|
||||||
# This program is free software: you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation, either version 3 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# This program is distributed in the hope that it will be useful,
|
|
||||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
# GNU General Public License for more details.
|
|
||||||
#
|
|
||||||
# You should have received a copy of the GNU General Public License
|
|
||||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
# @summary Class manages the service(s) for cd_haproxy.
|
# @summary Class manages the service(s) for cd_haproxy.
|
||||||
#############################################################################
|
#############################################################################
|
||||||
class cd_haproxy::server::service (
|
class cd_haproxy::server::service (
|
||||||
|
|||||||
7
templates/fail2ban/f2b_haproxy.conf.erb
Normal file
7
templates/fail2ban/f2b_haproxy.conf.erb
Normal file
@@ -0,0 +1,7 @@
|
|||||||
|
################################################################################
|
||||||
|
##### fail2ban for haproxy.conf created by Puppet #####
|
||||||
|
################################################################################
|
||||||
|
|
||||||
|
[Definition]
|
||||||
|
failregex = ^<HOST> -.*"(GET|POST|HEAD|PUT|DELETE|OPTIONS) .*(/login|/admin|/api/login).*HTTP/1\.[01]" 401
|
||||||
|
ignoreregex =
|
||||||
Reference in New Issue
Block a user