Readme
- +[[TOC]]
@@ -72,7 +71,7 @@ src="https://pipelines.confdroid.com/buildStatus/icon?job=cd_haproxy">| balancer to balance incoming requests between multiple instances of web-, application- or database servers etc. -cd_haproxy automates installation and configuration of
+
haproxy_cd automates installation and configuration of
HA proxy including self-healing, monitoring and firewall etc.
WARNING
@@ -107,6 +106,8 @@ productionback-end options
ACL options
+manage fail2ban integration (optional, requires fail2ban_cd module)
SERVICE
@@ -137,7 +138,7 @@ managing file fragmentsvia site.pp or nodes.pp
node 'example.example.net' {
- include cd_haproxy
+ include haproxy_cd
}
- @@ -145,7 +146,7 @@ managing file fragments
In order to apply parameters through Foreman, -cd_haproxy::params must be added to the host or host group +haproxy_cd::params must be added to the host or host group in question.
Support
-
-
OS: CentOS 7, Rocky 9
+OS: Rocky 9
-
-
Puppet 6
+Puppet 8
Tests
@@ -222,12 +223,6 @@ block, not per class.ERB Template Parser
Test for unwanted UTF8 files in the Puppet code (see tests/UTF_Files)
-Markdown-lint
-Spellcheck
-Sonar Quality Gate
Readme
- +[[TOC]]
@@ -72,7 +71,7 @@ src="https://pipelines.confdroid.com/buildStatus/icon?job=cd_haproxy">| balancer to balance incoming requests between multiple instances of web-, application- or database servers etc. -cd_haproxy automates installation and configuration of
+
haproxy_cd automates installation and configuration of
HA proxy including self-healing, monitoring and firewall etc.
WARNING
@@ -107,6 +106,8 @@ productionback-end options
ACL options
+manage fail2ban integration (optional, requires fail2ban_cd module)
SERVICE
@@ -137,7 +138,7 @@ managing file fragmentsvia site.pp or nodes.pp
node 'example.example.net' {
- include cd_haproxy
+ include haproxy_cd
}
- @@ -145,7 +146,7 @@ managing file fragments
In order to apply parameters through Foreman, -cd_haproxy::params must be added to the host or host group +haproxy_cd::params must be added to the host or host group in question.
Support
-
-
OS: CentOS 7, Rocky 9
+OS: Rocky 9
-
-
Puppet 6
+Puppet 8
Tests
@@ -222,12 +223,6 @@ block, not per class.ERB Template Parser
Test for unwanted UTF8 files in the Puppet code (see tests/UTF_Files)
-Markdown-lint
-Spellcheck
-Sonar Quality Gate
-
-
- +
-
- cd_haproxy + haproxy_cd
-
- +
- -
- +
- -
- +
- -
- +
- -
- +
- -
- +
- -
- +
- -
- +
- -
- +
- diff --git a/doc/puppet_classes/haproxy_cd.html b/doc/puppet_classes/haproxy_cd.html new file mode 100644 index 0000000..fc063b8 --- /dev/null +++ b/doc/puppet_classes/haproxy_cd.html @@ -0,0 +1,121 @@ + + + + + +
- Defined in: +
- + manifests/init.pp + +
- Inherits: +
- haproxy_cd::params +
- Defined in: +
- + manifests/firewall/iptables.pp + +
- Inherits: +
- haproxy_cd::params +
- Defined in: +
- + manifests/main/config.pp + +
- Inherits: +
- haproxy_cd::params +
- Defined in: +
- + manifests/main/dirs.pp + +
- Inherits: +
- haproxy_cd::params +
- Defined in: +
- + manifests/main/files.pp + +
- Inherits: +
- haproxy_cd::params +
- Defined in: +
- + manifests/main/install.pp + +
- Inherits: +
- haproxy_cd::params +
- Defined in: +
- + manifests/main/user.pp + +
- Inherits: +
- haproxy_cd::params +
- Defined in: +
- + manifests/monitoring/fail2ban.pp + +
- Inherited by: +
-
+
+ haproxy_cd::main::dirs
+ + haproxy_cd::main::user
+ + haproxy_cd::main::files
+ + haproxy_cd::main::config
+ + haproxy_cd::main::install
+ + haproxy_cd::server::service
+ + haproxy_cd::firewall::iptables
+ + haproxy_cd::monitoring::fail2ban
+ +
+ - Defined in: +
- + manifests/params.pp + +
- Inherits: +
- haproxy_cd::params +
- Defined in: +
- + manifests/server/service.pp + +
- +
- diff --git a/doc/puppet_defined_types/haproxy_cd_3A_3Aserver_3A_3Aproxy.html b/doc/puppet_defined_types/haproxy_cd_3A_3Aserver_3A_3Aproxy.html new file mode 100644 index 0000000..a2d9640 --- /dev/null +++ b/doc/puppet_defined_types/haproxy_cd_3A_3Aserver_3A_3Aproxy.html @@ -0,0 +1,658 @@ + + + + + +
- Defined in: +
- + manifests/server/proxy.pp + +
Puppet Class: haproxy_cd
+-
+
Summary
+ Class initializes the haproxy_cd module. + +Overview
+haproxy_cd::init.pp Module name: haproxy_cd Author: Arne Teuke +(arne_teuke@confdroid.com)
+ +
+ + + +6 +7 +8+ |
+
+ # File 'manifests/init.pp', line 6
+
+class haproxy_cd {
+ include haproxy_cd::params
+}
+ |
+
Puppet Class: haproxy_cd::firewall::iptables
+-
+
-
+
Summary
+ manage firewall settings through cd_firewall or puppetlabs-firewall + +Overview
+haproxy_cd::firewall::iptables.pp Module name: haproxy_cd Author: Arne +Teuke (arne_teuke@confdroid.com)
+ +
+ + + +6 +7 +8 +9 +10 +11 +12 +13 +14 +15 +16 +17 +18 +19 +20 +21 +22 +23 +24 +25 +26+ |
+
+ # File 'manifests/firewall/iptables.pp', line 6
+
+class haproxy_cd::firewall::iptables (
+
+) inherits haproxy_cd::params {
+
+ if ($fqdn == $hy_host_fqdn) and ($hy_manage_fw == true) {
+
+ require haproxy_cd::main::files
+
+ firewall { "${hy_fw_order_no}${hy_http_port} tcp port ${hy_http_port}":
+ proto => 'tcp',
+ dport => $hy_http_port,
+ jump => 'accept',
+ }
+
+ firewall { "${hy_fw_order_no}${hy_https_port} tcp port ${hy_https_port}":
+ proto => 'tcp',
+ dport => $hy_https_port,
+ jump => 'accept',
+ }
+ }
+}
+ |
+
Puppet Class: haproxy_cd::main::config
+-
+
-
+
Summary
+ Class manages all aspects of configuring the module logic for +haproxy_cd. + +Overview
+haproxy_cd::main::config.pp Module name: haproxy_cd Author: Arne Teuke +(arne_teuke@confdroid.com)
+ +
+ + + +7 +8 +9 +10 +11 +12 +13 +14 +15 +16 +17 +18+ |
+
+ # File 'manifests/main/config.pp', line 7
+
+class haproxy_cd::main::config (
+
+) inherits haproxy_cd::params {
+
+ include haproxy_cd::server::service
+
+ if $hy_manage_fail2ban == true {
+
+ include haproxy_cd::monitoring::fail2ban
+
+ }
+}
+ |
+
Puppet Class: haproxy_cd::main::dirs
+-
+
-
+
Summary
+ Class manages all directories required for haproxy_cd. + +Overview
+haproxy_cd::main::dirs.pp Module name: haproxy_cd Author: Arne Teuke +(arne_teuke@confdroid.com)
+ +
+ + + +6 +7 +8 +9 +10 +11 +12 +13 +14 +15 +16 +17 +18 +19 +20 +21 +22 +23 +24 +25 +26 +27 +28 +29 +30 +31 +32 +33 +34 +35 +36 +37+ |
+
+ # File 'manifests/main/dirs.pp', line 6
+
+class haproxy_cd::main::dirs (
+
+) inherits haproxy_cd::params {
+
+ if $fqdn == $hy_host_fqdn {
+ require haproxy_cd::main::user
+
+ # main dir
+ file { $hy_main_dir:
+ ensure => directory,
+ owner => 'root',
+ group => 'root',
+ mode => '0755',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ }
+
+ # errors dir
+ file { $hy_errors_dir:
+ ensure => directory,
+ owner => 'root',
+ group => 'root',
+ mode => '0755',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ }
+ }
+}
+ |
+
Puppet Class: haproxy_cd::main::files
+-
+
-
+
Summary
+ Class manages all configuration files required for haproxy_cd. + +Overview
+haproxy_cd::main::files.pp Module name: haproxy_cd Author: Arne Teuke +(arne_teuke@confdroid.com)
+ +
+ + + +6 +7 +8 +9 +10 +11 +12 +13 +14 +15 +16 +17 +18 +19 +20 +21 +22 +23 +24 +25 +26 +27 +28 +29 +30 +31 +32 +33 +34 +35 +36 +37 +38 +39 +40 +41 +42 +43 +44 +45 +46 +47 +48 +49 +50 +51 +52 +53 +54 +55 +56 +57 +58 +59 +60 +61 +62 +63 +64 +65 +66 +67 +68 +69 +70 +71 +72 +73 +74 +75 +76 +77 +78 +79 +80 +81 +82 +83 +84 +85 +86 +87 +88 +89 +90 +91 +92 +93 +94 +95 +96 +97 +98 +99 +100 +101 +102 +103 +104 +105 +106 +107 +108 +109 +110 +111 +112 +113 +114 +115 +116 +117 +118 +119 +120 +121 +122 +123 +124 +125 +126 +127 +128 +129 +130 +131 +132 +133 +134 +135 +136 +137 +138 +139 +140 +141 +142 +143 +144 +145 +146 +147 +148 +149 +150 +151 +152 +153 +154 +155 +156 +157 +158 +159 +160 +161+ |
+
+ # File 'manifests/main/files.pp', line 6
+
+class haproxy_cd::main::files (
+
+) inherits haproxy_cd::params {
+
+ if $fqdn == $hy_host_fqdn {
+ require haproxy_cd::main::dirs
+
+ # create the concat target
+ concat {$hy_main_config:
+ ensure => present,
+ owner => 'root',
+ group => 'root',
+ mode => '0640',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ notify => Service[$hy_service],
+ }
+
+ # create the header
+ concat::fragment { 'header':
+ target => $hy_main_config,
+ content => template($hy_config_head_erb),
+ order => '001',
+ }
+
+
+ # create the header
+ concat::fragment { 'tail':
+ target => $hy_main_config,
+ content => template($hy_config_tail_erb),
+ order => '100',
+ }
+
+
+ # pid file
+ file { $hy_pid:
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => haproxy_var_run_t,
+ seluser => system_u,
+ }
+
+ # error files
+ file { $hy_400_file:
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_400_erb),
+ notify => Service[$hy_service],
+ }
+
+ file { $hy_403_file:
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_403_erb),
+ notify => Service[$hy_service],
+ }
+
+ file { $hy_408_file:
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_408_erb),
+ notify => Service[$hy_service],
+ }
+
+ file { $hy_500_file:
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_500_erb),
+ notify => Service[$hy_service],
+ }
+
+ file { $hy_502_file:
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_502_erb),
+ notify => Service[$hy_service],
+ }
+
+ file { $hy_503_file:
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_503_erb),
+ notify => Service[$hy_service],
+ }
+
+ file { $hy_504_file:
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template($hy_504_erb),
+ notify => Service[$hy_service],
+ }
+
+ # make sure rsyslog is logging haproxy logs
+
+ file { '/etc/rsyslog.d/10-haproxy.conf':
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => syslog_conf_t,
+ seluser => system_u,
+ content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'),
+# notify => Service['rsyslog'], # only if using cd_rsyslog
+ }
+ }
+}
+ |
+
Puppet Class: haproxy_cd::main::install
+-
+
-
+
Summary
+ Class manage all aspects of installing binaries required for +haproxy_cd + +Overview
+haproxy_cd::main::install.pp Module name: haproxy_cd Author: Arne Teuke +(arne_teuke@confdroid.com)
+ +
+ + + +7 +8 +9 +10 +11 +12 +13 +14 +15 +16+ |
+
+ # File 'manifests/main/install.pp', line 7
+
+class haproxy_cd::main::install (
+
+) inherits haproxy_cd::params {
+
+ if $fqdn == $hy_host_fqdn {
+ package {$reqpackages:
+ ensure => $pkg_ensure,
+ }
+ }
+}
+ |
+
Puppet Class: haproxy_cd::main::user
+-
+
-
+
Summary
+ Class manages service users for haproxy_cd. + +Overview
+haproxy_cd::main::user.pp Module name: haproxy_cd Author: Arne Teuke +(arne_teuke@ConfDroid.com)
+ +
+ + + +6 +7 +8 +9 +10 +11 +12 +13 +14 +15 +16 +17 +18 +19 +20 +21 +22 +23 +24 +25 +26 +27 +28 +29 +30 +31+ |
+
+ # File 'manifests/main/user.pp', line 6
+
+class haproxy_cd::main::user (
+
+) inherits haproxy_cd::params {
+
+ if $fqdn == $hy_host_fqdn {
+ require haproxy_cd::main::install
+
+ # manage user
+ user { $hy_user_name:
+ ensure => present,
+ name => $hy_user_name,
+ allowdupe => false,
+ comment => $hy_user_comment,
+ gid => $hy_user_name,
+ managehome => true,
+ home => $hy_user_home,
+ shell => $hy_user_shell,
+ }
+
+ group { $hy_user_name:
+ ensure => present,
+ name => $hy_user_name,
+ allowdupe => false,
+ }
+ }
+}
+ |
+
Puppet Class: haproxy_cd::monitoring::fail2ban
+-
+
-
+
Summary
+ Class manages fail2ban settings + +Overview
+Module name: haproxy_cd Author: Arne Teuke (arne_teuke@confdroid.com)
+ +
+ + + +5 +6 +7 +8 +9 +10 +11 +12 +13 +14 +15 +16 +17 +18 +19 +20 +21 +22 +23 +24 +25 +26 +27 +28 +29 +30 +31 +32 +33 +34 +35 +36 +37 +38 +39 +40 +41+ |
+
+ # File 'manifests/monitoring/fail2ban.pp', line 5
+
+class haproxy_cd::monitoring::fail2ban (
+
+) inherits haproxy_cd::params {
+
+ if $hy_manage_fail2ban == true {
+
+ require cd_fail2ban
+
+ # configure filter
+
+ file { '/etc/fail2ban/filter.d/haproxy.conf':
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'),
+ notify => Service['fail2ban'],
+ }
+
+ file { '/etc/fail2ban/jail.d/010-haproxy.conf':
+ ensure => file,
+ owner => 'root',
+ group => 'root',
+ mode => '0644',
+ selrange => s0,
+ selrole => object_r,
+ seltype => etc_t,
+ seluser => system_u,
+ content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'),
+ notify => Service['fail2ban'],
+ }
+ }
+}
+ |
+
Puppet Class: haproxy_cd::params
+-
+
-
+
Overview
+haproxy_cd::params.pp Module name: haproxy_cd Author: Arne Teuke +(arne_teuke@confdroid.com)
+ +
+ + + +76 +77 +78 +79 +80 +81 +82 +83 +84 +85 +86 +87 +88 +89 +90 +91 +92 +93 +94 +95 +96 +97 +98 +99 +100 +101 +102 +103 +104 +105 +106 +107 +108 +109 +110 +111 +112 +113 +114 +115 +116 +117 +118 +119 +120 +121 +122 +123 +124 +125 +126 +127 +128 +129 +130 +131 +132 +133 +134 +135 +136 +137 +138 +139 +140 +141 +142 +143 +144 +145 +146 +147 +148 +149 +150 +151 +152 +153 +154 +155 +156 +157 +158 +159 +160 +161+ |
+
+ # File 'manifests/params.pp', line 76
+
+class haproxy_cd::params (
+
+ String $pkg_ensure = 'latest',
+ String $reqpackages = ['haproxy','httpd-tools'],
+
+ String $hy_host_fqdn = undef,
+
+# firewall
+ Boolean $hy_manage_fw = true,
+ String $hy_fw_order_no = '50',
+
+# fail2ban
+ Boolean $hy_manage_fail2ban = false,
+
+# main config
+ String $hy_http_port = '80',
+ String $hy_https_port = '443',
+ String $hy_chroot = '/var/lib/haproxy',
+ String $hy_pid = '/var/run/haproxy.pid',
+ String $hy_maxconn = '4000',
+ Boolean $hy_show_stats = false,
+ String $hy_stats_socket = '/var/lib/haproxy/stats',
+ String $hy_default_mode = 'tcp',
+ Boolean $hy_use_http_server_close = false,
+ Boolean $hy_use_forward_for = false,
+ Boolean $hy_use_redispatch = true,
+ String $hy_max_retries = '3',
+ String $hy_timeout_http_request = '10s',
+ String $hy_timeout_queue = '1m',
+ String $hy_timeout_connect = '10s',
+ String $hy_timeout_client = '1m',
+ String $hy_timeout_server = '1m',
+ String $hy_timeout_http_keep_alive = '10s',
+ String $hy_timeout_check = '10s',
+ Boolean $hy_hard_stop = true,
+ String $hy_hard_stop_value = '60s',
+ String $hy_stats_auth = 'admin:password',
+
+# user
+ String $hy_user_name = 'haproxy',
+ String $hy_user_comment = 'haproxy user',
+ String $hy_user_home = '/var/lib/haproxy',
+ String $hy_user_shell = '/sbin/nologin',
+
+# logging
+ String $hy_log_local0 = '127.0.0.1:514 local0',
+ String $hy_log_local1 = '127.0.0.1:514 local1 notice',
+ String $hy_log_target = '127.0.0.1',
+ String $hy_log_facility = 'local2',
+ String $hy_log_default = 'global',
+ Boolean $hy_use_tcplog = true,
+ Boolean $hy_use_httplog = false,
+ Boolean $hy_use_dontlognull = true,
+ Boolean $hy_manage_be_users = false,
+ String $hy_be_userlist = '####',
+
+) {
+ # service
+ $hy_service = 'haproxy'
+
+ # directories
+ $hy_main_dir = '/etc/haproxy'
+ $hy_errors_dir = "${hy_main_dir}/errors"
+
+ # files
+ $hy_main_config = "${hy_main_dir}/haproxy.cfg"
+ $hy_config_head_erb = 'haproxy_cd/haproxy_head.erb'
+ $hy_config_tail_erb = 'haproxy_cd/haproxy_tail.erb'
+ $hy_400_file = "${hy_errors_dir}/400.http"
+ $hy_400_erb = 'haproxy_cd/errors/400_http.erb'
+ $hy_403_file = "${hy_errors_dir}/403.http"
+ $hy_403_erb = 'haproxy_cd/errors/403_http.erb'
+ $hy_408_file = "${hy_errors_dir}/408.http"
+ $hy_408_erb = 'haproxy_cd/errors/408_http.erb'
+ $hy_500_file = "${hy_errors_dir}/500.http"
+ $hy_500_erb = 'haproxy_cd/errors/500_http.erb'
+ $hy_502_file = "${hy_errors_dir}/502.http"
+ $hy_502_erb = 'haproxy_cd/errors/502_http.erb'
+ $hy_503_file = "${hy_errors_dir}/503.http"
+ $hy_503_erb = 'haproxy_cd/errors/503_http.erb'
+ $hy_504_file = "${hy_errors_dir}/504.http"
+ $hy_504_erb = 'haproxy_cd/errors/504_http.erb'
+
+ # includes must be last
+ include haproxy_cd::main::config
+}
+ |
+
Puppet Class: haproxy_cd::server::service
+-
+
-
+
Summary
+ Class manages the service(s) for haproxy_cd. + +Overview
+haproxy_cd::server::service.pp Module name: haproxy_cd Author: Arne Teuke +(arne_teuke@confdroid.com)
+ +
+ + + +6 +7 +8 +9 +10 +11 +12 +13 +14 +15 +16 +17 +18 +19 +20 +21+ |
+
+ # File 'manifests/server/service.pp', line 6
+
+class haproxy_cd::server::service (
+
+) inherits haproxy_cd::params {
+
+ if $fqdn == $hy_host_fqdn {
+
+ require haproxy_cd::firewall::iptables
+
+ service { $hy_service:
+ ensure => running,
+ hasstatus => true,
+ hasrestart => true,
+ enable => true,
+ }
+ }
+}
+ |
+
-
-
Defined Type: haproxy_cd::server::proxy
+-
+
Summary
+ Define manages the proxies for haproxy_cd. + +Overview
+haproxy_cd::server::proxy.pp Module name: haproxy_cd Author: Arne Teuke +(arne_teuke@ConfDroid.com)
+ +
+ + + +24 +25 +26 +27 +28 +29 +30 +31 +32 +33 +34 +35 +36 +37 +38 +39 +40 +41 +42 +43 +44 +45 +46 +47 +48 +49 +50 +51 +52 +53 +54 +55 +56 +57 +58 +59 +60 +61 +62 +63 +64 +65 +66 +67 +68 +69 +70 +71 +72 +73 +74 +75 +76 +77 +78 +79 +80 +81 +82 +83 +84 +85 +86 +87 +88 +89+ |
+
+ # File 'manifests/server/proxy.pp', line 24
+
+define haproxy_cd::server::proxy (
+
+ $haproxy_fqdn = undef,
+ $frontend_name = undef,
+ $frontend_mode = undef,
+ $fe_use_backend = '',
+ $fe_bind_mode = undef,
+ $fe_option = '',
+ $frontend_order = '010',
+ $acl_rule_front = '',
+ $acl_rule_back = '',
+ $backend_name = '',
+ $backend_order = '030',
+ $fe_maxconn = '',
+ $be_server_name = '',
+ $be_balance = '',
+ $be_mode = '',
+ $default_backend = '',
+ $be_option = '',
+ $fe_tcp_request = '',
+ $fe_http_request = '',
+ $backend_configs = [],
+ $be_stick_table = '',
+ $be_stick_on = '',
+ $be_http_check = '',
+ $be_http_request = '',
+ $be_acl_rule = '',
+
+) {
+
+ $hy_main_config = '/etc/haproxy/haproxy.cfg'
+ $hy_frontendrule = 'haproxy_cd/haproxy_frontend_rule.erb'
+ $hy_backendrule = 'haproxy_cd/haproxy_backend_rule.erb'
+ $hy_acl_rule = 'haproxy_cd/haproxy_acl_rule.erb'
+
+
+
+ # Ensure acl_rule_front and acl_rule_back are arrays
+ $acl_rule_front_array = split($acl_rule_front, ';')
+ $acl_rule_back_array = split($acl_rule_back, ';')
+ $fe_use_backend_array = split($fe_use_backend,';')
+ $backend_name_array = split($backend_name, ';')
+ $be_server_name_array = split($be_server_name, ';')
+ $be_option_array = split($be_option, ';')
+ $fe_tcp_request_array = split($fe_tcp_request, ';')
+ $fe_option_array = split($fe_option, ';')
+ $fe_http_request_array = split($fe_http_request, ';')
+
+ # create frontend section
+ concat::fragment { "frontend_${name}":
+ target => $hy_main_config,
+ content => template($hy_frontendrule),
+ order => $frontend_order,
+ }
+
+ # Ensure backends are only created once
+ ensure_resource('concat::fragment', "backends_${name}", {
+ 'target' => $hy_main_config,
+ 'content' => template($hy_backendrule),
+ 'order' => $backend_order,
+ })
+
+ # open sepcific firewall ports
+
+
+}
+ |
+