recommit for updates in build 3
This commit is contained in:
@@ -117,11 +117,7 @@ Teuke (arne_teuke@confdroid.com)</p>
|
||||
19
|
||||
20
|
||||
21
|
||||
22
|
||||
23
|
||||
24
|
||||
25
|
||||
26</pre>
|
||||
22</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/firewall/iptables.pp', line 6</span>
|
||||
@@ -129,20 +125,16 @@ Teuke (arne_teuke@confdroid.com)</p>
|
||||
class haproxy_cd::firewall::iptables (
|
||||
|
||||
) inherits haproxy_cd::params {
|
||||
|
||||
if ($fqdn == $hy_host_fqdn) and ($hy_manage_fw == true) {
|
||||
|
||||
require haproxy_cd::main::files
|
||||
|
||||
firewall { "${hy_fw_order_no}${hy_http_port} tcp port ${hy_http_port}":
|
||||
proto => 'tcp',
|
||||
dport => $hy_http_port,
|
||||
proto => 'tcp',
|
||||
dport => $hy_http_port,
|
||||
jump => 'accept',
|
||||
}
|
||||
|
||||
firewall { "${hy_fw_order_no}${hy_https_port} tcp port ${hy_https_port}":
|
||||
proto => 'tcp',
|
||||
dport => $hy_https_port,
|
||||
proto => 'tcp',
|
||||
dport => $hy_https_port,
|
||||
jump => 'accept',
|
||||
}
|
||||
}
|
||||
|
||||
@@ -77,8 +77,7 @@
|
||||
</div>
|
||||
|
||||
<h2>Summary</h2>
|
||||
Class manages all aspects of configuring the module logic for
|
||||
haproxy_cd.
|
||||
Class manages module logic for haproxy_cd.
|
||||
|
||||
<h2>Overview</h2>
|
||||
<div class="docstring">
|
||||
@@ -102,6 +101,7 @@ haproxy_cd.
|
||||
<pre class="lines">
|
||||
|
||||
|
||||
6
|
||||
7
|
||||
8
|
||||
9
|
||||
@@ -109,25 +109,18 @@ haproxy_cd.
|
||||
11
|
||||
12
|
||||
13
|
||||
14
|
||||
15
|
||||
16
|
||||
17
|
||||
18</pre>
|
||||
14</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/main/config.pp', line 7</span>
|
||||
<pre class="code"><span class="info file"># File 'manifests/main/config.pp', line 6</span>
|
||||
|
||||
class haproxy_cd::main::config (
|
||||
|
||||
) inherits haproxy_cd::params {
|
||||
|
||||
include haproxy_cd::server::service
|
||||
|
||||
if $hy_manage_fail2ban == true {
|
||||
|
||||
include haproxy_cd::monitoring::fail2ban
|
||||
|
||||
}
|
||||
}</pre>
|
||||
</td>
|
||||
|
||||
@@ -131,8 +131,7 @@
|
||||
33
|
||||
34
|
||||
35
|
||||
36
|
||||
37</pre>
|
||||
36</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/main/dirs.pp', line 6</span>
|
||||
@@ -140,32 +139,31 @@
|
||||
class haproxy_cd::main::dirs (
|
||||
|
||||
) inherits haproxy_cd::params {
|
||||
|
||||
if $fqdn == $hy_host_fqdn {
|
||||
require haproxy_cd::main::user
|
||||
|
||||
# main dir
|
||||
file { $hy_main_dir:
|
||||
ensure => directory,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0755',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
ensure => directory,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0755',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
}
|
||||
|
||||
# errors dir
|
||||
file { $hy_errors_dir:
|
||||
ensure => directory,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0755',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
ensure => directory,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0755',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
}
|
||||
}
|
||||
}</pre>
|
||||
|
||||
@@ -253,10 +253,7 @@
|
||||
155
|
||||
156
|
||||
157
|
||||
158
|
||||
159
|
||||
160
|
||||
161</pre>
|
||||
158</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/main/files.pp', line 6</span>
|
||||
@@ -264,156 +261,153 @@
|
||||
class haproxy_cd::main::files (
|
||||
|
||||
) inherits haproxy_cd::params {
|
||||
|
||||
if $fqdn == $hy_host_fqdn {
|
||||
require haproxy_cd::main::dirs
|
||||
|
||||
# create the concat target
|
||||
concat {$hy_main_config:
|
||||
ensure => present,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0640',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
notify => Service[$hy_service],
|
||||
concat { $hy_main_config:
|
||||
ensure => present,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0640',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
notify => Service[$hy_service],
|
||||
}
|
||||
|
||||
# create the header
|
||||
concat::fragment { 'header':
|
||||
target => $hy_main_config,
|
||||
content => template($hy_config_head_erb),
|
||||
order => '001',
|
||||
target => $hy_main_config,
|
||||
content => template($hy_config_head_erb),
|
||||
order => '001',
|
||||
}
|
||||
|
||||
|
||||
# create the header
|
||||
concat::fragment { 'tail':
|
||||
target => $hy_main_config,
|
||||
content => template($hy_config_tail_erb),
|
||||
order => '100',
|
||||
target => $hy_main_config,
|
||||
content => template($hy_config_tail_erb),
|
||||
order => '100',
|
||||
}
|
||||
|
||||
|
||||
# pid file
|
||||
file { $hy_pid:
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => haproxy_var_run_t,
|
||||
seluser => system_u,
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => haproxy_var_run_t,
|
||||
seluser => system_u,
|
||||
}
|
||||
|
||||
# error files
|
||||
file { $hy_400_file:
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_400_erb),
|
||||
notify => Service[$hy_service],
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_400_erb),
|
||||
notify => Service[$hy_service],
|
||||
}
|
||||
|
||||
file { $hy_403_file:
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_403_erb),
|
||||
notify => Service[$hy_service],
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_403_erb),
|
||||
notify => Service[$hy_service],
|
||||
}
|
||||
|
||||
file { $hy_408_file:
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_408_erb),
|
||||
notify => Service[$hy_service],
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_408_erb),
|
||||
notify => Service[$hy_service],
|
||||
}
|
||||
|
||||
file { $hy_500_file:
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_500_erb),
|
||||
notify => Service[$hy_service],
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_500_erb),
|
||||
notify => Service[$hy_service],
|
||||
}
|
||||
|
||||
file { $hy_502_file:
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_502_erb),
|
||||
notify => Service[$hy_service],
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_502_erb),
|
||||
notify => Service[$hy_service],
|
||||
}
|
||||
|
||||
file { $hy_503_file:
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_503_erb),
|
||||
notify => Service[$hy_service],
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_503_erb),
|
||||
notify => Service[$hy_service],
|
||||
}
|
||||
|
||||
file { $hy_504_file:
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_504_erb),
|
||||
notify => Service[$hy_service],
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template($hy_504_erb),
|
||||
notify => Service[$hy_service],
|
||||
}
|
||||
|
||||
# make sure rsyslog is logging haproxy logs
|
||||
# make sure syslog is logging haproxy logs
|
||||
|
||||
file { '/etc/rsyslog.d/10-haproxy.conf':
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => syslog_conf_t,
|
||||
seluser => system_u,
|
||||
content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'),
|
||||
# notify => Service['rsyslog'], # only if using cd_rsyslog
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => syslog_conf_t,
|
||||
seluser => system_u,
|
||||
content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'),
|
||||
# notify => Service['rsyslog'], # only if using rsyslog_cd module
|
||||
}
|
||||
}
|
||||
}</pre>
|
||||
|
||||
@@ -77,8 +77,7 @@
|
||||
</div>
|
||||
|
||||
<h2>Summary</h2>
|
||||
Class manage all aspects of installing binaries required for
|
||||
haproxy_cd
|
||||
Class installs binaries required for haproxy_cd
|
||||
|
||||
<h2>Overview</h2>
|
||||
<div class="docstring">
|
||||
@@ -102,6 +101,7 @@ haproxy_cd
|
||||
<pre class="lines">
|
||||
|
||||
|
||||
6
|
||||
7
|
||||
8
|
||||
9
|
||||
@@ -109,19 +109,16 @@ haproxy_cd
|
||||
11
|
||||
12
|
||||
13
|
||||
14
|
||||
15
|
||||
16</pre>
|
||||
14</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/main/install.pp', line 7</span>
|
||||
<pre class="code"><span class="info file"># File 'manifests/main/install.pp', line 6</span>
|
||||
|
||||
class haproxy_cd::main::install (
|
||||
|
||||
) inherits haproxy_cd::params {
|
||||
|
||||
if $fqdn == $hy_host_fqdn {
|
||||
package {$reqpackages:
|
||||
package { $reqpackages:
|
||||
ensure => $pkg_ensure,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -125,8 +125,7 @@
|
||||
27
|
||||
28
|
||||
29
|
||||
30
|
||||
31</pre>
|
||||
30</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/main/user.pp', line 6</span>
|
||||
@@ -134,26 +133,25 @@
|
||||
class haproxy_cd::main::user (
|
||||
|
||||
) inherits haproxy_cd::params {
|
||||
|
||||
if $fqdn == $hy_host_fqdn {
|
||||
require haproxy_cd::main::install
|
||||
|
||||
# manage user
|
||||
user { $hy_user_name:
|
||||
ensure => present,
|
||||
name => $hy_user_name,
|
||||
allowdupe => false,
|
||||
comment => $hy_user_comment,
|
||||
gid => $hy_user_name,
|
||||
managehome => true,
|
||||
home => $hy_user_home,
|
||||
shell => $hy_user_shell,
|
||||
ensure => present,
|
||||
name => $hy_user_name,
|
||||
allowdupe => false,
|
||||
comment => $hy_user_comment,
|
||||
gid => $hy_user_name,
|
||||
managehome => true,
|
||||
home => $hy_user_home,
|
||||
shell => $hy_user_shell,
|
||||
}
|
||||
|
||||
group { $hy_user_name:
|
||||
ensure => present,
|
||||
name => $hy_user_name,
|
||||
allowdupe => false,
|
||||
ensure => present,
|
||||
name => $hy_user_name,
|
||||
allowdupe => false,
|
||||
}
|
||||
}
|
||||
}</pre>
|
||||
|
||||
@@ -134,9 +134,7 @@
|
||||
36
|
||||
37
|
||||
38
|
||||
39
|
||||
40
|
||||
41</pre>
|
||||
39</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/monitoring/fail2ban.pp', line 5</span>
|
||||
@@ -144,37 +142,35 @@
|
||||
class haproxy_cd::monitoring::fail2ban (
|
||||
|
||||
) inherits haproxy_cd::params {
|
||||
|
||||
if $hy_manage_fail2ban == true {
|
||||
|
||||
require cd_fail2ban
|
||||
require fail2ban_cd # (external module)
|
||||
|
||||
# configure filter
|
||||
|
||||
file { '/etc/fail2ban/filter.d/haproxy.conf':
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'),
|
||||
notify => Service['fail2ban'],
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'),
|
||||
notify => Service['fail2ban'],
|
||||
}
|
||||
|
||||
file { '/etc/fail2ban/jail.d/010-haproxy.conf':
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'),
|
||||
notify => Service['fail2ban'],
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
selrange => s0,
|
||||
selrole => object_r,
|
||||
seltype => etc_t,
|
||||
seluser => system_u,
|
||||
content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'),
|
||||
notify => Service['fail2ban'],
|
||||
}
|
||||
}
|
||||
}</pre>
|
||||
|
||||
@@ -1131,7 +1131,9 @@ succeed.</p>
|
||||
158
|
||||
159
|
||||
160
|
||||
161</pre>
|
||||
161
|
||||
162
|
||||
163</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 76</span>
|
||||
@@ -1193,6 +1195,8 @@ class haproxy_cd::params (
|
||||
String $hy_be_userlist = '####',
|
||||
|
||||
) {
|
||||
$fqdn = $facts['networking']['fqdn']
|
||||
|
||||
# service
|
||||
$hy_service = 'haproxy'
|
||||
|
||||
|
||||
@@ -115,8 +115,7 @@
|
||||
17
|
||||
18
|
||||
19
|
||||
20
|
||||
21</pre>
|
||||
20</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/server/service.pp', line 6</span>
|
||||
@@ -124,16 +123,15 @@
|
||||
class haproxy_cd::server::service (
|
||||
|
||||
) inherits haproxy_cd::params {
|
||||
|
||||
if $fqdn == $hy_host_fqdn {
|
||||
|
||||
require haproxy_cd::firewall::iptables
|
||||
require haproxy_cd::main::files
|
||||
|
||||
service { $hy_service:
|
||||
ensure => running,
|
||||
hasstatus => true,
|
||||
hasrestart => true,
|
||||
enable => true,
|
||||
ensure => running,
|
||||
hasstatus => true,
|
||||
hasrestart => true,
|
||||
enable => true,
|
||||
}
|
||||
}
|
||||
}</pre>
|
||||
|
||||
Reference in New Issue
Block a user