From 4132353fd78599c295fa015d8496c1310089d6f9 Mon Sep 17 00:00:00 2001
From: Jenkins ConfDroid
# File 'manifests/firewall/iptables.pp', line 6 @@ -129,20 +125,16 @@ Teuke (arne_teuke@confdroid.com) class haproxy_cd::firewall::iptables ( ) inherits haproxy_cd::params { - if ($fqdn == $hy_host_fqdn) and ($hy_manage_fw == true) { - - require haproxy_cd::main::files - firewall { "${hy_fw_order_no}${hy_http_port} tcp port ${hy_http_port}": - proto => 'tcp', - dport => $hy_http_port, + proto => 'tcp', + dport => $hy_http_port, jump => 'accept', } firewall { "${hy_fw_order_no}${hy_https_port} tcp port ${hy_https_port}": - proto => 'tcp', - dport => $hy_https_port, + proto => 'tcp', + dport => $hy_https_port, jump => 'accept', } } diff --git a/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Aconfig.html b/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Aconfig.html index 2c0dd49..34fbb10 100644 --- a/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Aconfig.html +++ b/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Aconfig.html @@ -77,8 +77,7 @@Summary
- Class manages all aspects of configuring the module logic for -haproxy_cd. + Class manages module logic for haproxy_cd.Overview
@@ -102,6 +101,7 @@ haproxy_cd.+6 7 8 9 @@ -109,25 +109,18 @@ haproxy_cd. 11 12 13 -14 -15 -16 -17 -18+14
# File 'manifests/main/config.pp', line 7
+ # File 'manifests/main/config.pp', line 6
class haproxy_cd::main::config (
) inherits haproxy_cd::params {
-
include haproxy_cd::server::service
if $hy_manage_fail2ban == true {
-
include haproxy_cd::monitoring::fail2ban
-
}
}
# File 'manifests/main/dirs.pp', line 6
@@ -140,32 +139,31 @@
class haproxy_cd::main::dirs (
) inherits haproxy_cd::params {
-
if $fqdn == $hy_host_fqdn {
require haproxy_cd::main::user
# main dir
file { $hy_main_dir:
- ensure => directory,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
+ ensure => directory,
+ owner => 'root',
+ group => 'root',
+ mode => '0755',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
}
# errors dir
file { $hy_errors_dir:
- ensure => directory,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
+ ensure => directory,
+ owner => 'root',
+ group => 'root',
+ mode => '0755',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
}
}
}
diff --git a/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Afiles.html b/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Afiles.html
index 023eaaa..8f89146 100644
--- a/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Afiles.html
+++ b/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Afiles.html
@@ -253,10 +253,7 @@
155
156
157
-158
-159
-160
-161
+158
# File 'manifests/main/files.pp', line 6
@@ -264,156 +261,153 @@
class haproxy_cd::main::files (
) inherits haproxy_cd::params {
-
if $fqdn == $hy_host_fqdn {
require haproxy_cd::main::dirs
# create the concat target
- concat {$hy_main_config:
- ensure => present,
- owner => 'root',
- group => 'root',
- mode => '0640',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- notify => Service[$hy_service],
+ concat { $hy_main_config:
+ ensure => present,
+ owner => 'root',
+ group => 'root',
+ mode => '0640',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ notify => Service[$hy_service],
}
# create the header
concat::fragment { 'header':
- target => $hy_main_config,
- content => template($hy_config_head_erb),
- order => '001',
+ target => $hy_main_config,
+ content => template($hy_config_head_erb),
+ order => '001',
}
-
# create the header
concat::fragment { 'tail':
- target => $hy_main_config,
- content => template($hy_config_tail_erb),
- order => '100',
+ target => $hy_main_config,
+ content => template($hy_config_tail_erb),
+ order => '100',
}
-
# pid file
file { $hy_pid:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => haproxy_var_run_t,
- seluser => system_u,
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => haproxy_var_run_t,
+ seluser => system_u,
}
# error files
file { $hy_400_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_400_erb),
- notify => Service[$hy_service],
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_400_erb),
+ notify => Service[$hy_service],
}
file { $hy_403_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_403_erb),
- notify => Service[$hy_service],
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_403_erb),
+ notify => Service[$hy_service],
}
file { $hy_408_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_408_erb),
- notify => Service[$hy_service],
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_408_erb),
+ notify => Service[$hy_service],
}
file { $hy_500_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_500_erb),
- notify => Service[$hy_service],
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_500_erb),
+ notify => Service[$hy_service],
}
file { $hy_502_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_502_erb),
- notify => Service[$hy_service],
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_502_erb),
+ notify => Service[$hy_service],
}
file { $hy_503_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_503_erb),
- notify => Service[$hy_service],
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_503_erb),
+ notify => Service[$hy_service],
}
file { $hy_504_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_504_erb),
- notify => Service[$hy_service],
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_504_erb),
+ notify => Service[$hy_service],
}
- # make sure rsyslog is logging haproxy logs
+ # make sure syslog is logging haproxy logs
file { '/etc/rsyslog.d/10-haproxy.conf':
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => syslog_conf_t,
- seluser => system_u,
- content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'),
-# notify => Service['rsyslog'], # only if using cd_rsyslog
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => syslog_conf_t,
+ seluser => system_u,
+ content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'),
+# notify => Service['rsyslog'], # only if using rsyslog_cd module
}
}
}
diff --git a/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Ainstall.html b/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Ainstall.html
index 1692eb0..ef4ba50 100644
--- a/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Ainstall.html
+++ b/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Ainstall.html
@@ -77,8 +77,7 @@
+6 7 8 9 @@ -109,19 +109,16 @@ haproxy_cd 11 12 13 -14 -15 -16+14
# File 'manifests/main/install.pp', line 7
+ # File 'manifests/main/install.pp', line 6
class haproxy_cd::main::install (
) inherits haproxy_cd::params {
-
if $fqdn == $hy_host_fqdn {
- package {$reqpackages:
+ package { $reqpackages:
ensure => $pkg_ensure,
}
}
diff --git a/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Auser.html b/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Auser.html
index 65502c9..281f429 100644
--- a/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Auser.html
+++ b/doc/puppet_classes/haproxy_cd_3A_3Amain_3A_3Auser.html
@@ -125,8 +125,7 @@
27
28
29
-30
-31
+30
# File 'manifests/main/user.pp', line 6
@@ -134,26 +133,25 @@
class haproxy_cd::main::user (
) inherits haproxy_cd::params {
-
if $fqdn == $hy_host_fqdn {
require haproxy_cd::main::install
# manage user
user { $hy_user_name:
- ensure => present,
- name => $hy_user_name,
- allowdupe => false,
- comment => $hy_user_comment,
- gid => $hy_user_name,
- managehome => true,
- home => $hy_user_home,
- shell => $hy_user_shell,
+ ensure => present,
+ name => $hy_user_name,
+ allowdupe => false,
+ comment => $hy_user_comment,
+ gid => $hy_user_name,
+ managehome => true,
+ home => $hy_user_home,
+ shell => $hy_user_shell,
}
group { $hy_user_name:
- ensure => present,
- name => $hy_user_name,
- allowdupe => false,
+ ensure => present,
+ name => $hy_user_name,
+ allowdupe => false,
}
}
}
diff --git a/doc/puppet_classes/haproxy_cd_3A_3Amonitoring_3A_3Afail2ban.html b/doc/puppet_classes/haproxy_cd_3A_3Amonitoring_3A_3Afail2ban.html
index fa47e0e..c8942f3 100644
--- a/doc/puppet_classes/haproxy_cd_3A_3Amonitoring_3A_3Afail2ban.html
+++ b/doc/puppet_classes/haproxy_cd_3A_3Amonitoring_3A_3Afail2ban.html
@@ -134,9 +134,7 @@
36
37
38
-39
-40
-41
+39
# File 'manifests/monitoring/fail2ban.pp', line 5
@@ -144,37 +142,35 @@
class haproxy_cd::monitoring::fail2ban (
) inherits haproxy_cd::params {
-
if $hy_manage_fail2ban == true {
-
- require cd_fail2ban
+ require fail2ban_cd # (external module)
# configure filter
file { '/etc/fail2ban/filter.d/haproxy.conf':
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'),
- notify => Service['fail2ban'],
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'),
+ notify => Service['fail2ban'],
}
file { '/etc/fail2ban/jail.d/010-haproxy.conf':
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'),
- notify => Service['fail2ban'],
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'),
+ notify => Service['fail2ban'],
}
}
}
diff --git a/doc/puppet_classes/haproxy_cd_3A_3Aparams.html b/doc/puppet_classes/haproxy_cd_3A_3Aparams.html
index 8285983..8106452 100644
--- a/doc/puppet_classes/haproxy_cd_3A_3Aparams.html
+++ b/doc/puppet_classes/haproxy_cd_3A_3Aparams.html
@@ -1131,7 +1131,9 @@ succeed.
158
159
160
-161
+161
+162
+163
# File 'manifests/params.pp', line 76
@@ -1193,6 +1195,8 @@ class haproxy_cd::params (
String $hy_be_userlist = '####',
) {
+ $fqdn = $facts['networking']['fqdn']
+
# service
$hy_service = 'haproxy'
diff --git a/doc/puppet_classes/haproxy_cd_3A_3Aserver_3A_3Aservice.html b/doc/puppet_classes/haproxy_cd_3A_3Aserver_3A_3Aservice.html
index d26cb9c..c1c0419 100644
--- a/doc/puppet_classes/haproxy_cd_3A_3Aserver_3A_3Aservice.html
+++ b/doc/puppet_classes/haproxy_cd_3A_3Aserver_3A_3Aservice.html
@@ -115,8 +115,7 @@
17
18
19
-20
-21
+20
# File 'manifests/server/service.pp', line 6
@@ -124,16 +123,15 @@
class haproxy_cd::server::service (
) inherits haproxy_cd::params {
-
if $fqdn == $hy_host_fqdn {
-
require haproxy_cd::firewall::iptables
+ require haproxy_cd::main::files
service { $hy_service:
- ensure => running,
- hasstatus => true,
- hasrestart => true,
- enable => true,
+ ensure => running,
+ hasstatus => true,
+ hasrestart => true,
+ enable => true,
}
}
}
diff --git a/doc/puppet_defined_types/haproxy_cd_3A_3Aserver_3A_3Aproxy.html b/doc/puppet_defined_types/haproxy_cd_3A_3Aserver_3A_3Aproxy.html
index a2d9640..90823c6 100644
--- a/doc/puppet_defined_types/haproxy_cd_3A_3Aserver_3A_3Aproxy.html
+++ b/doc/puppet_defined_types/haproxy_cd_3A_3Aserver_3A_3Aproxy.html
@@ -92,7 +92,7 @@
haproxy_fqdn
- (string)
+ (String)
(defaults to: undef)
@@ -110,7 +110,7 @@
frontend_name
- (string)
+ (String)
(defaults to: undef)
@@ -128,7 +128,7 @@
frontend_order
- (string)
+ (String)
(defaults to: '010')
@@ -136,7 +136,7 @@
—
the order where the concat should appear in the file.
+where the concat should appear in the file.
which bind mode to use, i.e. to which interface and poort to bind.
-an ACL rule to be inserted if required. Empty values will not be populated.
-the order where the acl rule should be inserted, so it will be within the -correct lb instance configuration.
+which bind mode to use, i.e. to which interface and port to bind.
set the name for the backend server
- - -what kind of balance should be used
+which backend mode should be used
+value for the default backend
+value for a backend option
+value for a frontend tcp request
+value for a frontend http request
+value for a frontend option
+value for a frontend acl rule
+value for a backend acl rule
+array of values for the backend
+value for the backend stickiness
+value for th backend stickiness
+value for backend http check
+value for a backend http request
+value for a backend acl rule
+-24 -25 -26 -27 -28 -29 -30 -31 -32 -33 34 35 36 @@ -572,48 +604,50 @@ instance configuration. 86 87 88 -89+89 +90 +91 +92 +93 +94
# File 'manifests/server/proxy.pp', line 24
+ # File 'manifests/server/proxy.pp', line 34
define haproxy_cd::server::proxy (
- $haproxy_fqdn = undef,
- $frontend_name = undef,
- $frontend_mode = undef,
- $fe_use_backend = '',
- $fe_bind_mode = undef,
- $fe_option = '',
- $frontend_order = '010',
- $acl_rule_front = '',
- $acl_rule_back = '',
- $backend_name = '',
- $backend_order = '030',
- $fe_maxconn = '',
- $be_server_name = '',
- $be_balance = '',
- $be_mode = '',
- $default_backend = '',
- $be_option = '',
- $fe_tcp_request = '',
- $fe_http_request = '',
- $backend_configs = [],
- $be_stick_table = '',
- $be_stick_on = '',
- $be_http_check = '',
- $be_http_request = '',
- $be_acl_rule = '',
+ String $haproxy_fqdn = undef,
+ String $frontend_name = undef,
+ String $frontend_mode = undef,
+ String $fe_use_backend = '',
+ String $fe_bind_mode = undef,
+ String $fe_option = '',
+ String $frontend_order = '010',
+ String $acl_rule_front = '',
+ String $acl_rule_back = '',
+ String $backend_name = '',
+ String $backend_order = '030',
+ String $fe_maxconn = '',
+ String $be_server_name = '',
+ String $be_balance = '',
+ String $be_mode = '',
+ String $default_backend = '',
+ String $be_option = '',
+ String $fe_tcp_request = '',
+ String $fe_http_request = '',
+ Array $backend_configs = [],
+ String $be_stick_table = '',
+ String $be_stick_on = '',
+ String $be_http_check = '',
+ String $be_http_request = '',
+ String $be_acl_rule = '',
) {
-
$hy_main_config = '/etc/haproxy/haproxy.cfg'
$hy_frontendrule = 'haproxy_cd/haproxy_frontend_rule.erb'
$hy_backendrule = 'haproxy_cd/haproxy_backend_rule.erb'
$hy_acl_rule = 'haproxy_cd/haproxy_acl_rule.erb'
-
-
# Ensure acl_rule_front and acl_rule_back are arrays
$acl_rule_front_array = split($acl_rule_front, ';')
$acl_rule_back_array = split($acl_rule_back, ';')
@@ -627,21 +661,19 @@ define haproxy_cd::server::proxy (
# create frontend section
concat::fragment { "frontend_${name}":
- target => $hy_main_config,
- content => template($hy_frontendrule),
- order => $frontend_order,
+ target => $hy_main_config,
+ content => template($hy_frontendrule),
+ order => $frontend_order,
}
# Ensure backends are only created once
ensure_resource('concat::fragment', "backends_${name}", {
- 'target' => $hy_main_config,
- 'content' => template($hy_backendrule),
- 'order' => $backend_order,
+ 'target' => $hy_main_config,
+ 'content' => template($hy_backendrule),
+ 'order' => $backend_order,
})
- # open sepcific firewall ports
-
-
+ # open specific firewall ports
}