From 7b457b232e5d562d3c03500e0cbaab2c77f902bb Mon Sep 17 00:00:00 2001 From: Arne Teuke Date: Sun, 2 Mar 2025 17:26:09 +0100 Subject: [PATCH] lint pproxy params --- manifests/firewall/iptables.pp | 12 +- manifests/main/config.pp | 6 +- manifests/main/dirs.pp | 33 +++-- manifests/main/files.pp | 213 +++++++++++++++---------------- manifests/main/install.pp | 6 +- manifests/main/user.pp | 23 ++-- manifests/monitoring/fail2ban.pp | 44 +++---- manifests/params.pp | 2 + manifests/server/proxy.pp | 107 ++++++++-------- manifests/server/service.pp | 11 +- 10 files changed, 223 insertions(+), 234 deletions(-) diff --git a/manifests/firewall/iptables.pp b/manifests/firewall/iptables.pp index 32fc677..d5e41cc 100644 --- a/manifests/firewall/iptables.pp +++ b/manifests/firewall/iptables.pp @@ -6,20 +6,16 @@ class haproxy_cd::firewall::iptables ( ) inherits haproxy_cd::params { - if ($fqdn == $hy_host_fqdn) and ($hy_manage_fw == true) { - - require haproxy_cd::main::files - firewall { "${hy_fw_order_no}${hy_http_port} tcp port ${hy_http_port}": - proto => 'tcp', - dport => $hy_http_port, + proto => 'tcp', + dport => $hy_http_port, jump => 'accept', } firewall { "${hy_fw_order_no}${hy_https_port} tcp port ${hy_https_port}": - proto => 'tcp', - dport => $hy_https_port, + proto => 'tcp', + dport => $hy_https_port, jump => 'accept', } } diff --git a/manifests/main/config.pp b/manifests/main/config.pp index 314ca34..51eb74d 100644 --- a/manifests/main/config.pp +++ b/manifests/main/config.pp @@ -1,18 +1,14 @@ ## haproxy_cd::main::config.pp # Module name: haproxy_cd # Author: Arne Teuke (arne_teuke@confdroid.com) -# @summary Class manages all aspects of configuring the module logic for -# haproxy_cd. +# @summary Class manages module logic for haproxy_cd. ############################################################################## class haproxy_cd::main::config ( ) inherits haproxy_cd::params { - include haproxy_cd::server::service if $hy_manage_fail2ban == true { - include haproxy_cd::monitoring::fail2ban - } } diff --git a/manifests/main/dirs.pp b/manifests/main/dirs.pp index 3b441e6..23bb789 100644 --- a/manifests/main/dirs.pp +++ b/manifests/main/dirs.pp @@ -6,32 +6,31 @@ class haproxy_cd::main::dirs ( ) inherits haproxy_cd::params { - if $fqdn == $hy_host_fqdn { require haproxy_cd::main::user # main dir file { $hy_main_dir: - ensure => directory, - owner => 'root', - group => 'root', - mode => '0755', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, + ensure => directory, + owner => 'root', + group => 'root', + mode => '0755', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, } # errors dir file { $hy_errors_dir: - ensure => directory, - owner => 'root', - group => 'root', - mode => '0755', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, + ensure => directory, + owner => 'root', + group => 'root', + mode => '0755', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, } } } diff --git a/manifests/main/files.pp b/manifests/main/files.pp index 2b5dd55..01fe18d 100644 --- a/manifests/main/files.pp +++ b/manifests/main/files.pp @@ -6,156 +6,153 @@ class haproxy_cd::main::files ( ) inherits haproxy_cd::params { - if $fqdn == $hy_host_fqdn { require haproxy_cd::main::dirs # create the concat target - concat {$hy_main_config: - ensure => present, - owner => 'root', - group => 'root', - mode => '0640', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - notify => Service[$hy_service], + concat { $hy_main_config: + ensure => present, + owner => 'root', + group => 'root', + mode => '0640', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + notify => Service[$hy_service], } # create the header concat::fragment { 'header': - target => $hy_main_config, - content => template($hy_config_head_erb), - order => '001', + target => $hy_main_config, + content => template($hy_config_head_erb), + order => '001', } - # create the header concat::fragment { 'tail': - target => $hy_main_config, - content => template($hy_config_tail_erb), - order => '100', + target => $hy_main_config, + content => template($hy_config_tail_erb), + order => '100', } - # pid file file { $hy_pid: - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => haproxy_var_run_t, - seluser => system_u, + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => haproxy_var_run_t, + seluser => system_u, } # error files file { $hy_400_file: - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - content => template($hy_400_erb), - notify => Service[$hy_service], + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template($hy_400_erb), + notify => Service[$hy_service], } file { $hy_403_file: - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - content => template($hy_403_erb), - notify => Service[$hy_service], + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template($hy_403_erb), + notify => Service[$hy_service], } file { $hy_408_file: - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - content => template($hy_408_erb), - notify => Service[$hy_service], + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template($hy_408_erb), + notify => Service[$hy_service], } file { $hy_500_file: - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - content => template($hy_500_erb), - notify => Service[$hy_service], + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template($hy_500_erb), + notify => Service[$hy_service], } file { $hy_502_file: - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - content => template($hy_502_erb), - notify => Service[$hy_service], + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template($hy_502_erb), + notify => Service[$hy_service], } file { $hy_503_file: - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - content => template($hy_503_erb), - notify => Service[$hy_service], + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template($hy_503_erb), + notify => Service[$hy_service], } file { $hy_504_file: - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - content => template($hy_504_erb), - notify => Service[$hy_service], + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template($hy_504_erb), + notify => Service[$hy_service], } - # make sure rsyslog is logging haproxy logs + # make sure syslog is logging haproxy logs file { '/etc/rsyslog.d/10-haproxy.conf': - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => syslog_conf_t, - seluser => system_u, - content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'), -# notify => Service['rsyslog'], # only if using cd_rsyslog + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => syslog_conf_t, + seluser => system_u, + content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'), +# notify => Service['rsyslog'], # only if using rsyslog_cd module } } } diff --git a/manifests/main/install.pp b/manifests/main/install.pp index 673c4b7..cd00d88 100644 --- a/manifests/main/install.pp +++ b/manifests/main/install.pp @@ -1,15 +1,13 @@ ## haproxy_cd::main::install.pp # Module name: haproxy_cd # Author: Arne Teuke (arne_teuke@confdroid.com) -# @summary Class manage all aspects of installing binaries required for -# haproxy_cd +# @summary Class installs binaries required for haproxy_cd ############################################################################### class haproxy_cd::main::install ( ) inherits haproxy_cd::params { - if $fqdn == $hy_host_fqdn { - package {$reqpackages: + package { $reqpackages: ensure => $pkg_ensure, } } diff --git a/manifests/main/user.pp b/manifests/main/user.pp index 4b6b189..6943273 100644 --- a/manifests/main/user.pp +++ b/manifests/main/user.pp @@ -6,26 +6,25 @@ class haproxy_cd::main::user ( ) inherits haproxy_cd::params { - if $fqdn == $hy_host_fqdn { require haproxy_cd::main::install # manage user user { $hy_user_name: - ensure => present, - name => $hy_user_name, - allowdupe => false, - comment => $hy_user_comment, - gid => $hy_user_name, - managehome => true, - home => $hy_user_home, - shell => $hy_user_shell, + ensure => present, + name => $hy_user_name, + allowdupe => false, + comment => $hy_user_comment, + gid => $hy_user_name, + managehome => true, + home => $hy_user_home, + shell => $hy_user_shell, } group { $hy_user_name: - ensure => present, - name => $hy_user_name, - allowdupe => false, + ensure => present, + name => $hy_user_name, + allowdupe => false, } } } diff --git a/manifests/monitoring/fail2ban.pp b/manifests/monitoring/fail2ban.pp index 460985b..6a9df6f 100644 --- a/manifests/monitoring/fail2ban.pp +++ b/manifests/monitoring/fail2ban.pp @@ -5,37 +5,35 @@ class haproxy_cd::monitoring::fail2ban ( ) inherits haproxy_cd::params { - if $hy_manage_fail2ban == true { - - require cd_fail2ban + require fail2ban_cd # (external module) # configure filter file { '/etc/fail2ban/filter.d/haproxy.conf': - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'), - notify => Service['fail2ban'], + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'), + notify => Service['fail2ban'], } file { '/etc/fail2ban/jail.d/010-haproxy.conf': - ensure => file, - owner => 'root', - group => 'root', - mode => '0644', - selrange => s0, - selrole => object_r, - seltype => etc_t, - seluser => system_u, - content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'), - notify => Service['fail2ban'], + ensure => file, + owner => 'root', + group => 'root', + mode => '0644', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'), + notify => Service['fail2ban'], } } } diff --git a/manifests/params.pp b/manifests/params.pp index 0f8e120..5eb2f09 100644 --- a/manifests/params.pp +++ b/manifests/params.pp @@ -130,6 +130,8 @@ class haproxy_cd::params ( String $hy_be_userlist = '####', ) { + $fqdn = $facts['networking']['fqdn'] + # service $hy_service = 'haproxy' diff --git a/manifests/server/proxy.pp b/manifests/server/proxy.pp index 689cc70..910eac4 100644 --- a/manifests/server/proxy.pp +++ b/manifests/server/proxy.pp @@ -2,62 +2,69 @@ # Module name: haproxy_cd # Author: Arne Teuke (arne_teuke@ConfDroid.com) # @summary Define manages the proxies for haproxy_cd. -# @param [string] haproxy_fqdn the fqdn of the haproxy server in question. +# @param [string] haproxy_fqdn the fqdn of the haproxy server in question. # @param [string] frontend_name the name for the frontend section rule. -# @param [string] frontend_order the order where the concat should appear -# in the file. -# @param [string] frontend_mode mode for the loadbalancer instance: http or tcp -# @param [string] fe_use_backend which backend to use. if left empty, the +# @param [string] frontend_order where the concat should appear in the file. +# @param [string] frontend_mode mode for the loadbalancer instance: http or tcp +# @param [string] fe_use_backend which backend to use. if left empty, the # default backend will be used. -# @param [string] fe_bind_mode which bind mode to use, i.e. to which interface -# and poort to bind. -# @param [string] acl_rule an ACL rule to be inserted if required. Empty values -# will not be populated. -# @param [string] acl_order the order where the acl rule should be inserted, -# so it will be within the correct lb instance configuration. -# @param [string] backend_name the backend name to be used for the rule. -# @param [string] backend_order the order for the backend name, so it will be +# @param [string] fe_bind_mode which bind mode to use, i.e. to which interface +# and port to bind. +# @param [string] backend_name the backend name to be used for the rule. +# @param [string] backend_order the order for the backend name, so it will be # within the correct lb instance configuration. -# @param [string] fe_maxconn the maximum connections for the lb instance. +# @param [string] fe_maxconn the maximum connections for the lb instance. # @param [string] be_server_name set the name for the backend server +# @param [string] be_balance what kind of balance should be used +# @param [string] be_mode which backend mode should be used +# @param [string] default_backend value for the default backend +# @param [string] be_option value for a backend option +# @param [string] fe_tcp_request value for a frontend tcp request +# @param [string] fe_http_request value for a frontend http request +# @param [string] fe_option value for a frontend option +# @param [string] acl_rule_front value for a frontend acl rule +# @param [string] acl_rule_back value for a backend acl rule +# @param [array] backend_configs array of values for the backend +# @param [string] be_stick_table value for the backend stickiness +# @param [string] be_stick_on value for th backend stickiness +# @param [string] be_http_check value for backend http check +# @param [string] be_http_request value for a backend http request +# @param [string] be_acl_rule value for a backend acl rule ############################################################################### define haproxy_cd::server::proxy ( - $haproxy_fqdn = undef, - $frontend_name = undef, - $frontend_mode = undef, - $fe_use_backend = '', - $fe_bind_mode = undef, - $fe_option = '', - $frontend_order = '010', - $acl_rule_front = '', - $acl_rule_back = '', - $backend_name = '', - $backend_order = '030', - $fe_maxconn = '', - $be_server_name = '', - $be_balance = '', - $be_mode = '', - $default_backend = '', - $be_option = '', - $fe_tcp_request = '', - $fe_http_request = '', - $backend_configs = [], - $be_stick_table = '', - $be_stick_on = '', - $be_http_check = '', - $be_http_request = '', - $be_acl_rule = '', + String $haproxy_fqdn = undef, + String $frontend_name = undef, + String $frontend_mode = undef, + String $fe_use_backend = '', + String $fe_bind_mode = undef, + String $fe_option = '', + String $frontend_order = '010', + String $acl_rule_front = '', + String $acl_rule_back = '', + String $backend_name = '', + String $backend_order = '030', + String $fe_maxconn = '', + String $be_server_name = '', + String $be_balance = '', + String $be_mode = '', + String $default_backend = '', + String $be_option = '', + String $fe_tcp_request = '', + String $fe_http_request = '', + Array $backend_configs = [], + String $be_stick_table = '', + String $be_stick_on = '', + String $be_http_check = '', + String $be_http_request = '', + String $be_acl_rule = '', ) { - $hy_main_config = '/etc/haproxy/haproxy.cfg' $hy_frontendrule = 'haproxy_cd/haproxy_frontend_rule.erb' $hy_backendrule = 'haproxy_cd/haproxy_backend_rule.erb' $hy_acl_rule = 'haproxy_cd/haproxy_acl_rule.erb' - - # Ensure acl_rule_front and acl_rule_back are arrays $acl_rule_front_array = split($acl_rule_front, ';') $acl_rule_back_array = split($acl_rule_back, ';') @@ -71,19 +78,17 @@ define haproxy_cd::server::proxy ( # create frontend section concat::fragment { "frontend_${name}": - target => $hy_main_config, - content => template($hy_frontendrule), - order => $frontend_order, + target => $hy_main_config, + content => template($hy_frontendrule), + order => $frontend_order, } # Ensure backends are only created once ensure_resource('concat::fragment', "backends_${name}", { - 'target' => $hy_main_config, - 'content' => template($hy_backendrule), - 'order' => $backend_order, + 'target' => $hy_main_config, + 'content' => template($hy_backendrule), + 'order' => $backend_order, }) - # open sepcific firewall ports - - + # open specific firewall ports } diff --git a/manifests/server/service.pp b/manifests/server/service.pp index c5551f7..4776750 100644 --- a/manifests/server/service.pp +++ b/manifests/server/service.pp @@ -6,16 +6,15 @@ class haproxy_cd::server::service ( ) inherits haproxy_cd::params { - if $fqdn == $hy_host_fqdn { - require haproxy_cd::firewall::iptables + require haproxy_cd::main::files service { $hy_service: - ensure => running, - hasstatus => true, - hasrestart => true, - enable => true, + ensure => running, + hasstatus => true, + hasrestart => true, + enable => true, } } }