Documentation by YARD 0.9.36
-Alphabetic Index
- -Puppet Class Listing A-Z
- - -
-
-
-
|
-
Defined Type Listing A-Z
- - -
-
-
-
|
-
File Listing
--
-
-
-
- README - - -
diff --git a/.puppet-lint.rc b/.puppet-lint.rc new file mode 100644 index 0000000..24728eb --- /dev/null +++ b/.puppet-lint.rc @@ -0,0 +1,2 @@ +--no-variable_scope-check +--no-top_scope_facts \ No newline at end of file diff --git a/Jenkinsfile b/Jenkinsfile index 6f7af1a..5498b66 100644 --- a/Jenkinsfile +++ b/Jenkinsfile @@ -69,7 +69,7 @@ pipeline { withCredentials([string(credentialsId: 'sonar-token', variable: 'SONAR_TOKEN')]) { sh ''' /opt/sonar-scanner/bin/sonar-scanner \ - -Dsonar.projectKey=haproxy_cd \ + -Dsonar.projectKey=confdroid_haproxy \ -Dsonar.sources=. \ -Dsonar.host.url=https://sonarqube.confdroid.com \ -Dsonar.token=$SONAR_TOKEN @@ -90,16 +90,36 @@ pipeline { sh ''' git config user.name "Jenkins Server" git config user.email jenkins@confdroid.com + git rm -r --cached .vscode || echo "No .vscode to remove from git" git add -A && git commit -am "Recommit for updates in build $BUILD_NUMBER" || echo "No changes to commit" - git push -o merge_request.create \ - -o merge_request.target=master \ - -o merge_request.title="Auto-merge for build $BUILD_NUMBER" \ - -o merge_request.description="Automated changes from Jenkins build $BUILD_NUMBER" \ - -o merge_request.merge_when_pipeline_succeeds=true \ - origin jenkins-build-$BUILD_NUMBER + git push origin HEAD:master ''' } } } + stage('Mirror to Gitea') { + steps { + sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { + withCredentials([usernamePassword( + credentialsId: 'Jenkins-gitea', + usernameVariable: 'GITEA_USER', + passwordVariable: 'GITEA_TOKEN')]) { + script { + // Checkout from GitLab (already done implicitly) + sh ''' + git checkout master + git pull origin master + git branch -D development + git branch -D jenkins-build-$BUILD_NUMBER + git rm -f Jenkinsfile + git rm -r --cached .vscode || echo "No .vscode to remove from git" + git commit --amend --no-edit --allow-empty + git remote add master https://sourcecode.confdroid.com/confdroid/confdroid_haproxy.git + git -c credential.helper="!f() { echo username=${GITEA_USER}; echo password=${GITEA_TOKEN}; }; f" \ + push master --mirror + ''' + } + } + } } \ No newline at end of file diff --git a/README.md b/README.md index 2299b7e..01c1d4b 100644 --- a/README.md +++ b/README.md @@ -1,14 +1,27 @@ # Readme -[](https://jenkins.confdroid.com/job/haproxy_cd/)| +[](https://jenkins.confdroid.com/job/confdroid_haproxy/) -[[_TOC_]] +- [Readme](#readme) + - [Synopsis](#synopsis) + - [WARNING](#warning) + - [Features](#features) + - [Dependencies](#dependencies) + - [Deployment](#deployment) + - [Parameters](#parameters) + - [Proxy Configuration](#proxy-configuration) + - [SELINUX](#selinux) + - [Known Problems](#known-problems) + - [Support](#support) + - [Tests](#tests) + - [Contact Us](#contact-us) + - [Disclaimer](#disclaimer) ## Synopsis `HA Proxy` is a very powerful and popular open source load balancer to balance incoming requests between multiple instances of web-, application- or database servers etc. -`haproxy_cd` automates installation and configuration of `HA proxy` including self-healing, monitoring and firewall etc. +`confdroid_haproxy` automates installation and configuration of `HA proxy` including self-healing, monitoring and firewall etc. ## WARNING @@ -18,46 +31,46 @@ INSTALLATION -* install rpm binaries +- install rpm binaries CONFIGURATION -* manage haproxy user -* manage directories (file system permissions, selinux context) -* manage files (file system permissions, content, selinux context) -* manage proxy instances through a define - * front-end options - * back-end options - * ACL options -* manage fail2ban integration (optional, requires fail2ban_cd module) +- manage haproxy user +- manage directories (file system permissions, selinux context) +- manage files (file system permissions, content, selinux context) +- manage proxy instances through a define + - front-end options + - back-end options + - ACL options +- manage fail2ban integration (optional, requires fail2ban_cd module) SERVICE -* manage haproxy service -* restart service after changes in the configuration +- manage haproxy service +- restart service after changes in the configuration ## Dependencies All dependencies must be included in the catalogue. -* [cd_resources](https://gitlab.confdroid.com/puppet/cd_resources) for managing yum base repos -* [concat](https://github.com/puppetlabs/puppetlabs-concat) for managing file fragments +- [cd_resources](https://gitlab.confdroid.com/puppet/cd_resources) for managing yum base repos +- [concat](https://github.com/puppetlabs/puppetlabs-concat) for managing file fragments ## Deployment -* native Puppet deployment +- native Puppet deployment via site.pp or nodes.pp ```bash node 'example.example.net' { - include haproxy_cd + include confdroid_haproxy } ``` -* through Foreman: +- through Foreman: -In order to apply parameters through Foreman, **__haproxy_cd::params__** must be added to the host or host group in question. +In order to apply parameters through Foreman, **confdroid_haproxy::params**- must be added to the host or host group in question. See [more details about class deployment on Confdroid.com](https://confdroid.com/2017/05/deploying-our-puppet-modules/). @@ -71,7 +84,7 @@ The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concate In order to create proxy instances, you will need an external class, which addresses the define, like so: ```bash - haproxy_cd::server::proxy { 'testing': + confdroid_haproxy::server::proxy { 'testing': haproxy_fqdn => 'node.example.net', frontend_name => 'test01-frontend', frontend_mode => 'http', @@ -82,7 +95,7 @@ In order to create proxy instances, you will need an external class, which addre ``` This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. -`haproxy_fqdn` **__must__** contain the fqdn of the haproxy **__server__** where this should be configured, otherwise the templates are not being populated. +`haproxy_fqdn` **must**- contain the fqdn of the haproxy **server**- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each. ## SELINUX @@ -93,22 +106,22 @@ All files and directories are configured with correct selinux context. If selinu ## Support -* OS: Rocky 9 -* Puppet 8 +- OS: Rocky 9 +- Puppet 8 ## Tests -* Puppet Lint - * excluded tests: - * `--no-variable_scope-check`: not applicable as we are inheriting parameters from params class. the lint check does not distinguish between facts and inherited parameters. -* Puppet Parser -* ERB Template Parser -* Sonar Quality Gate +- Puppet Lint + - excluded tests: + - `--no-variable_scope-check`: not applicable as we are inheriting parameters from params class. the lint check does not distinguish between facts and inherited parameters. +- Puppet Parser +- ERB Template Parser +- Sonar Quality Gate ## Contact Us -[contact Us](https://confdroid.com/contact/) -[Feedback Portal](https://feedback.confdroid.com/) +- [contact Us](https://confdroid.com/contact/) +- [Feedback Portal](https://feedback.confdroid.com/) ## Disclaimer diff --git a/doc/_index.html b/doc/_index.html deleted file mode 100644 index e2689b0..0000000 --- a/doc/_index.html +++ /dev/null @@ -1,182 +0,0 @@ - - -
- - -
-
-
-
|
-
-
-
-
|
-
| t |
- - - -6 -7 -8- |
-
- # File 'manifests/init.pp', line 6
-
-class haproxy_cd {
- include haproxy_cd::params
-}
- |
-
haproxy_cd::firewall::iptables.pp Module name: haproxy_cd Author: Arne Teuke (arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14 -15 -16 -17 -18 -19 -20 -21 -22 -23 -24 -25 -26 -27 -28- |
-
- # File 'manifests/firewall/iptables.pp', line 6
-
-class haproxy_cd::firewall::iptables (
-
-) inherits haproxy_cd::params {
- if ($fqdn == $hy_host_fqdn) and ($hy_manage_fw == true) {
- firewall { "${hy_fw_order_no}${hy_http_port} tcp port ${hy_http_port}":
- proto => 'tcp',
- dport => $hy_http_port,
- jump => 'accept',
- }
-
- firewall { "${hy_fw_order_no}${hy_https_port} tcp port ${hy_https_port}":
- proto => 'tcp',
- dport => $hy_https_port,
- jump => 'accept',
- }
-
- firewall { "${hy_fw_order_no}9000 tcp port minio-api":
- proto => 'tcp',
- dport => '9000',
- jump => 'accept',
- }
- }
-}
- |
-
haproxy_cd::main::config.pp Module name: haproxy_cd Author: Arne Teuke (arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14- |
-
- # File 'manifests/main/config.pp', line 6
-
-class haproxy_cd::main::config (
-
-) inherits haproxy_cd::params {
- include haproxy_cd::server::service
-
- if $hy_manage_fail2ban == true {
- include haproxy_cd::monitoring::fail2ban
- }
-}
- |
-
haproxy_cd::main::dirs.pp Module name: haproxy_cd Author: Arne Teuke (arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14 -15 -16 -17 -18 -19 -20 -21 -22 -23 -24 -25 -26 -27 -28 -29 -30 -31 -32 -33 -34 -35 -36 -37 -38 -39 -40 -41 -42 -43 -44 -45 -46 -47 -48- |
-
- # File 'manifests/main/dirs.pp', line 6
-
-class haproxy_cd::main::dirs (
-
-) inherits haproxy_cd::params {
- if $fqdn == $hy_host_fqdn {
- require haproxy_cd::main::user
-
- # main dir
- file { $hy_main_dir:
- ensure => directory,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- }
-
- # errors dir
- file { $hy_errors_dir:
- ensure => directory,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- }
-
- # certs dir
- file { $hy_certs_dir:
- ensure => directory,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- }
- }
-}
- |
-
haproxy_cd::main::files.pp Module name: haproxy_cd Author: Arne Teuke (arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14 -15 -16 -17 -18 -19 -20 -21 -22 -23 -24 -25 -26 -27 -28 -29 -30 -31 -32 -33 -34 -35 -36 -37 -38 -39 -40 -41 -42 -43 -44 -45 -46 -47 -48 -49 -50 -51 -52 -53 -54 -55 -56 -57 -58 -59 -60 -61 -62 -63 -64 -65 -66 -67 -68 -69 -70 -71 -72 -73 -74 -75 -76 -77 -78 -79 -80 -81 -82 -83 -84 -85 -86 -87 -88 -89 -90 -91 -92 -93 -94 -95 -96 -97 -98 -99 -100 -101 -102 -103 -104 -105 -106 -107 -108 -109 -110 -111 -112 -113 -114 -115 -116 -117 -118 -119 -120 -121 -122 -123 -124 -125 -126 -127 -128 -129 -130 -131 -132 -133 -134 -135 -136 -137 -138 -139 -140 -141 -142 -143 -144 -145 -146 -147 -148 -149 -150 -151 -152 -153 -154 -155 -156 -157 -158- |
-
- # File 'manifests/main/files.pp', line 6
-
-class haproxy_cd::main::files (
-
-) inherits haproxy_cd::params {
- if $fqdn == $hy_host_fqdn {
- require haproxy_cd::main::dirs
-
- # create the concat target
- concat { $hy_main_config:
- ensure => present,
- owner => 'root',
- group => 'root',
- mode => '0640',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- notify => Service[$hy_service],
- }
-
- # create the header
- concat::fragment { 'header':
- target => $hy_main_config,
- content => template($hy_config_head_erb),
- order => '001',
- }
-
- # create the header
- concat::fragment { 'tail':
- target => $hy_main_config,
- content => template($hy_config_tail_erb),
- order => '100',
- }
-
- # pid file
- file { $hy_pid:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => haproxy_var_run_t,
- seluser => system_u,
- }
-
- # error files
- file { $hy_400_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_400_erb),
- notify => Service[$hy_service],
- }
-
- file { $hy_403_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_403_erb),
- notify => Service[$hy_service],
- }
-
- file { $hy_408_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_408_erb),
- notify => Service[$hy_service],
- }
-
- file { $hy_500_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_500_erb),
- notify => Service[$hy_service],
- }
-
- file { $hy_502_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_502_erb),
- notify => Service[$hy_service],
- }
-
- file { $hy_503_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_503_erb),
- notify => Service[$hy_service],
- }
-
- file { $hy_504_file:
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($hy_504_erb),
- notify => Service[$hy_service],
- }
-
- # make sure syslog is logging haproxy logs
-
- file { '/etc/rsyslog.d/10-haproxy.conf':
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => syslog_conf_t,
- seluser => system_u,
- content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'),
-# notify => Service['rsyslog'], # only if using rsyslog_cd module
- }
- }
-}
- |
-
haproxy_cd::main::install.pp Module name: haproxy_cd Author: Arne Teuke (arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14- |
-
- # File 'manifests/main/install.pp', line 6
-
-class haproxy_cd::main::install (
-
-) inherits haproxy_cd::params {
- if $fqdn == $hy_host_fqdn {
- package { $reqpackages:
- ensure => $pkg_ensure,
- }
- }
-}
- |
-
haproxy_cd::main::user.pp Module name: haproxy_cd Author: Arne Teuke (arne_teuke@ConfDroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14 -15 -16 -17 -18 -19 -20 -21 -22 -23 -24 -25 -26 -27 -28 -29 -30- |
-
- # File 'manifests/main/user.pp', line 6
-
-class haproxy_cd::main::user (
-
-) inherits haproxy_cd::params {
- if $fqdn == $hy_host_fqdn {
- require haproxy_cd::main::install
-
- # manage user
- user { $hy_user_name:
- ensure => present,
- name => $hy_user_name,
- allowdupe => false,
- comment => $hy_user_comment,
- gid => $hy_user_name,
- managehome => true,
- home => $hy_user_home,
- shell => $hy_user_shell,
- }
-
- group { $hy_user_name:
- ensure => present,
- name => $hy_user_name,
- allowdupe => false,
- }
- }
-}
- |
-
Module name: haproxy_cd Author: Arne Teuke (arne_teuke@confdroid.com)
- -
- - - -5 -6 -7 -8 -9 -10 -11 -12 -13 -14 -15 -16 -17 -18 -19 -20 -21 -22 -23 -24 -25 -26 -27 -28 -29 -30 -31 -32 -33 -34 -35 -36 -37 -38 -39- |
-
- # File 'manifests/monitoring/fail2ban.pp', line 5
-
-class haproxy_cd::monitoring::fail2ban (
-
-) inherits haproxy_cd::params {
- if $hy_manage_fail2ban == true {
- require confdroid_fail2ban # (external module)
-
- # configure filter
-
- file { '/etc/fail2ban/filter.d/haproxy.conf':
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'),
- notify => Service['fail2ban'],
- }
-
- file { '/etc/fail2ban/jail.d/010-haproxy.conf':
- ensure => file,
- owner => 'root',
- group => 'root',
- mode => '0644',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'),
- notify => Service['fail2ban'],
- }
- }
-}
- |
-
haproxy_cd::params.pp Module name: haproxy_cd Author: Arne Teuke (arne_teuke@confdroid.com)
- -
- - - -58 -59 -60 -61 -62 -63 -64 -65 -66 -67 -68 -69 -70 -71 -72 -73 -74 -75 -76 -77 -78 -79 -80 -81 -82 -83 -84 -85 -86 -87 -88 -89 -90 -91 -92 -93 -94 -95 -96 -97 -98 -99 -100 -101 -102 -103 -104 -105 -106 -107 -108 -109 -110 -111 -112 -113 -114 -115 -116 -117 -118 -119 -120 -121 -122 -123 -124 -125 -126 -127 -128 -129 -130 -131 -132 -133 -134 -135 -136 -137 -138 -139 -140 -141 -142 -143 -144 -145 -146- |
-
- # File 'manifests/params.pp', line 58
-
-class haproxy_cd::params (
-
- String $pkg_ensure = 'latest',
- Array $reqpackages = ['haproxy','httpd-tools'],
-
- String $hy_host_fqdn = undef,
-
-# firewall
- Boolean $hy_manage_fw = true,
- String $hy_fw_order_no = '50',
-
-# fail2ban
- Boolean $hy_manage_fail2ban = false,
-
-# main config
- String $hy_http_port = '80',
- String $hy_https_port = '443',
- String $hy_chroot = '/var/lib/haproxy',
- String $hy_pid = '/var/run/haproxy.pid',
- String $hy_maxconn = '4000',
- Boolean $hy_show_stats = false,
- String $hy_stats_socket = '/var/lib/haproxy/stats',
- String $hy_default_mode = 'tcp',
- Boolean $hy_use_http_server_close = false,
- Boolean $hy_use_forward_for = false,
- Boolean $hy_use_redispatch = true,
- String $hy_max_retries = '3',
- String $hy_timeout_http_request = '10s',
- String $hy_timeout_queue = '1m',
- String $hy_timeout_connect = '10s',
- String $hy_timeout_client = '1m',
- String $hy_timeout_server = '1m',
- String $hy_timeout_http_keep_alive = '10s',
- String $hy_timeout_check = '10s',
- Boolean $hy_hard_stop = true,
- String $hy_hard_stop_value = '60s',
- String $hy_stats_auth = 'admin:password',
-
-# user
- String $hy_user_name = 'haproxy',
- String $hy_user_comment = 'haproxy user',
- String $hy_user_home = '/var/lib/haproxy',
- String $hy_user_shell = '/sbin/nologin',
-
-# logging
- String $hy_log_local0 = '127.0.0.1:514 local0',
- String $hy_log_local1 = '127.0.0.1:514 local1 notice',
- String $hy_log_target = '127.0.0.1',
- String $hy_log_facility = 'local2',
- String $hy_log_default = 'global',
- Boolean $hy_use_tcplog = true,
- Boolean $hy_use_httplog = false,
- Boolean $hy_use_dontlognull = true,
- Boolean $hy_manage_be_users = false,
- String $hy_be_userlist = '####',
-
-) {
- $fqdn = $facts['networking']['fqdn']
-
- # service
- $hy_service = 'haproxy'
-
- # directories
- $hy_main_dir = '/etc/haproxy'
- $hy_errors_dir = "${hy_main_dir}/errors"
- $hy_certs_dir = "${hy_main_dir}/certs"
-
- # files
- $hy_main_config = "${hy_main_dir}/haproxy.cfg"
- $hy_config_head_erb = 'haproxy_cd/haproxy_head.erb'
- $hy_config_tail_erb = 'haproxy_cd/haproxy_tail.erb'
- $hy_400_file = "${hy_errors_dir}/400.http"
- $hy_400_erb = 'haproxy_cd/errors/400_http.erb'
- $hy_403_file = "${hy_errors_dir}/403.http"
- $hy_403_erb = 'haproxy_cd/errors/403_http.erb'
- $hy_408_file = "${hy_errors_dir}/408.http"
- $hy_408_erb = 'haproxy_cd/errors/408_http.erb'
- $hy_500_file = "${hy_errors_dir}/500.http"
- $hy_500_erb = 'haproxy_cd/errors/500_http.erb'
- $hy_502_file = "${hy_errors_dir}/502.http"
- $hy_502_erb = 'haproxy_cd/errors/502_http.erb'
- $hy_503_file = "${hy_errors_dir}/503.http"
- $hy_503_erb = 'haproxy_cd/errors/503_http.erb'
- $hy_504_file = "${hy_errors_dir}/504.http"
- $hy_504_erb = 'haproxy_cd/errors/504_http.erb'
-
- # includes must be last
- include haproxy_cd::main::config
-}
- |
-
haproxy_cd::server::service.pp Module name: haproxy_cd Author: Arne Teuke (arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14 -15 -16 -17 -18 -19 -20- |
-
- # File 'manifests/server/service.pp', line 6
-
-class haproxy_cd::server::service (
-
-) inherits haproxy_cd::params {
- if $fqdn == $hy_host_fqdn {
- require haproxy_cd::firewall::iptables
- require haproxy_cd::main::files
-
- service { $hy_service:
- ensure => running,
- hasstatus => true,
- hasrestart => true,
- enable => true,
- }
- }
-}
- |
-
haproxy_cd::server::proxy.pp Module name: haproxy_cd Author: Arne Teuke (arne_teuke@ConfDroid.com)
- -
- - - -34 -35 -36 -37 -38 -39 -40 -41 -42 -43 -44 -45 -46 -47 -48 -49 -50 -51 -52 -53 -54 -55 -56 -57 -58 -59 -60 -61 -62 -63 -64 -65 -66 -67 -68 -69 -70 -71 -72 -73 -74 -75 -76 -77 -78 -79 -80 -81 -82 -83 -84 -85 -86 -87 -88 -89 -90 -91 -92 -93 -94 -95 -96- |
-
- # File 'manifests/server/proxy.pp', line 34
-
-define haproxy_cd::server::proxy (
-
- String $haproxy_fqdn = undef,
- String $frontend_name = undef,
- String $frontend_mode = undef,
- String $fe_use_backend = '',
- String $fe_bind_mode = undef,
- String $fe_option = '',
- String $frontend_order = '010',
- String $acl_rule_front = '',
- String $acl_rule_back = '',
- String $backend_name = '',
- String $backend_order = '030',
- String $fe_maxconn = '',
- String $be_server_name = '',
- String $be_balance = '',
- String $be_mode = '',
- String $default_backend = '',
- String $be_option = '',
- String $fe_tcp_request = '',
- String $fe_http_request = '',
- Array $backend_configs = [],
- String $be_stick_table = '',
- String $be_stick_on = '',
- String $be_http_check = '',
- String $be_http_request = '',
- String $be_acl_rule = '',
-
-) {
- $fqdn = $facts['networking']['fqdn']
-
- $hy_main_config = '/etc/haproxy/haproxy.cfg'
- $hy_frontendrule = 'haproxy_cd/haproxy_frontend_rule.erb'
- $hy_backendrule = 'haproxy_cd/haproxy_backend_rule.erb'
- $hy_acl_rule = 'haproxy_cd/haproxy_acl_rule.erb'
-
- # Ensure acl_rule_front and acl_rule_back are arrays
- $acl_rule_front_array = split($acl_rule_front, ';')
- $acl_rule_back_array = split($acl_rule_back, ';')
- $fe_use_backend_array = split($fe_use_backend,';')
- $backend_name_array = split($backend_name, ';')
- $be_server_name_array = split($be_server_name, ';')
- $be_option_array = split($be_option, ';')
- $fe_tcp_request_array = split($fe_tcp_request, ';')
- $fe_option_array = split($fe_option, ';')
- $fe_http_request_array = split($fe_http_request, ';')
-
- # create frontend section
- concat::fragment { "frontend_${name}":
- target => $hy_main_config,
- content => template($hy_frontendrule),
- order => $frontend_order,
- }
-
- # Ensure backends are only created once
- ensure_resource('concat::fragment', "backends_${name}", {
- 'target' => $hy_main_config,
- 'content' => template($hy_backendrule),
- 'order' => $backend_order,
- })
-
- # open specific firewall ports
-}
- |
-