lint pproxy params

This commit is contained in:
Arne Teuke
2025-03-02 17:26:09 +01:00
parent f09b452830
commit 7b457b232e
10 changed files with 223 additions and 234 deletions

View File

@@ -6,20 +6,16 @@
class haproxy_cd::firewall::iptables ( class haproxy_cd::firewall::iptables (
) inherits haproxy_cd::params { ) inherits haproxy_cd::params {
if ($fqdn == $hy_host_fqdn) and ($hy_manage_fw == true) { if ($fqdn == $hy_host_fqdn) and ($hy_manage_fw == true) {
require haproxy_cd::main::files
firewall { "${hy_fw_order_no}${hy_http_port} tcp port ${hy_http_port}": firewall { "${hy_fw_order_no}${hy_http_port} tcp port ${hy_http_port}":
proto => 'tcp', proto => 'tcp',
dport => $hy_http_port, dport => $hy_http_port,
jump => 'accept', jump => 'accept',
} }
firewall { "${hy_fw_order_no}${hy_https_port} tcp port ${hy_https_port}": firewall { "${hy_fw_order_no}${hy_https_port} tcp port ${hy_https_port}":
proto => 'tcp', proto => 'tcp',
dport => $hy_https_port, dport => $hy_https_port,
jump => 'accept', jump => 'accept',
} }
} }

View File

@@ -1,18 +1,14 @@
## haproxy_cd::main::config.pp ## haproxy_cd::main::config.pp
# Module name: haproxy_cd # Module name: haproxy_cd
# Author: Arne Teuke (arne_teuke@confdroid.com) # Author: Arne Teuke (arne_teuke@confdroid.com)
# @summary Class manages all aspects of configuring the module logic for # @summary Class manages module logic for haproxy_cd.
# haproxy_cd.
############################################################################## ##############################################################################
class haproxy_cd::main::config ( class haproxy_cd::main::config (
) inherits haproxy_cd::params { ) inherits haproxy_cd::params {
include haproxy_cd::server::service include haproxy_cd::server::service
if $hy_manage_fail2ban == true { if $hy_manage_fail2ban == true {
include haproxy_cd::monitoring::fail2ban include haproxy_cd::monitoring::fail2ban
} }
} }

View File

@@ -6,32 +6,31 @@
class haproxy_cd::main::dirs ( class haproxy_cd::main::dirs (
) inherits haproxy_cd::params { ) inherits haproxy_cd::params {
if $fqdn == $hy_host_fqdn { if $fqdn == $hy_host_fqdn {
require haproxy_cd::main::user require haproxy_cd::main::user
# main dir # main dir
file { $hy_main_dir: file { $hy_main_dir:
ensure => directory, ensure => directory,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0755', mode => '0755',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
} }
# errors dir # errors dir
file { $hy_errors_dir: file { $hy_errors_dir:
ensure => directory, ensure => directory,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0755', mode => '0755',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
} }
} }
} }

View File

@@ -6,156 +6,153 @@
class haproxy_cd::main::files ( class haproxy_cd::main::files (
) inherits haproxy_cd::params { ) inherits haproxy_cd::params {
if $fqdn == $hy_host_fqdn { if $fqdn == $hy_host_fqdn {
require haproxy_cd::main::dirs require haproxy_cd::main::dirs
# create the concat target # create the concat target
concat {$hy_main_config: concat { $hy_main_config:
ensure => present, ensure => present,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0640', mode => '0640',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
notify => Service[$hy_service], notify => Service[$hy_service],
} }
# create the header # create the header
concat::fragment { 'header': concat::fragment { 'header':
target => $hy_main_config, target => $hy_main_config,
content => template($hy_config_head_erb), content => template($hy_config_head_erb),
order => '001', order => '001',
} }
# create the header # create the header
concat::fragment { 'tail': concat::fragment { 'tail':
target => $hy_main_config, target => $hy_main_config,
content => template($hy_config_tail_erb), content => template($hy_config_tail_erb),
order => '100', order => '100',
} }
# pid file # pid file
file { $hy_pid: file { $hy_pid:
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => haproxy_var_run_t, seltype => haproxy_var_run_t,
seluser => system_u, seluser => system_u,
} }
# error files # error files
file { $hy_400_file: file { $hy_400_file:
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($hy_400_erb), content => template($hy_400_erb),
notify => Service[$hy_service], notify => Service[$hy_service],
} }
file { $hy_403_file: file { $hy_403_file:
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($hy_403_erb), content => template($hy_403_erb),
notify => Service[$hy_service], notify => Service[$hy_service],
} }
file { $hy_408_file: file { $hy_408_file:
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($hy_408_erb), content => template($hy_408_erb),
notify => Service[$hy_service], notify => Service[$hy_service],
} }
file { $hy_500_file: file { $hy_500_file:
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($hy_500_erb), content => template($hy_500_erb),
notify => Service[$hy_service], notify => Service[$hy_service],
} }
file { $hy_502_file: file { $hy_502_file:
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($hy_502_erb), content => template($hy_502_erb),
notify => Service[$hy_service], notify => Service[$hy_service],
} }
file { $hy_503_file: file { $hy_503_file:
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($hy_503_erb), content => template($hy_503_erb),
notify => Service[$hy_service], notify => Service[$hy_service],
} }
file { $hy_504_file: file { $hy_504_file:
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($hy_504_erb), content => template($hy_504_erb),
notify => Service[$hy_service], notify => Service[$hy_service],
} }
# make sure rsyslog is logging haproxy logs # make sure syslog is logging haproxy logs
file { '/etc/rsyslog.d/10-haproxy.conf': file { '/etc/rsyslog.d/10-haproxy.conf':
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => syslog_conf_t, seltype => syslog_conf_t,
seluser => system_u, seluser => system_u,
content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'), content => template('haproxy_cd/rsyslog/10_haproxy.conf.erb'),
# notify => Service['rsyslog'], # only if using cd_rsyslog # notify => Service['rsyslog'], # only if using rsyslog_cd module
} }
} }
} }

View File

@@ -1,15 +1,13 @@
## haproxy_cd::main::install.pp ## haproxy_cd::main::install.pp
# Module name: haproxy_cd # Module name: haproxy_cd
# Author: Arne Teuke (arne_teuke@confdroid.com) # Author: Arne Teuke (arne_teuke@confdroid.com)
# @summary Class manage all aspects of installing binaries required for # @summary Class installs binaries required for haproxy_cd
# haproxy_cd
############################################################################### ###############################################################################
class haproxy_cd::main::install ( class haproxy_cd::main::install (
) inherits haproxy_cd::params { ) inherits haproxy_cd::params {
if $fqdn == $hy_host_fqdn { if $fqdn == $hy_host_fqdn {
package {$reqpackages: package { $reqpackages:
ensure => $pkg_ensure, ensure => $pkg_ensure,
} }
} }

View File

@@ -6,26 +6,25 @@
class haproxy_cd::main::user ( class haproxy_cd::main::user (
) inherits haproxy_cd::params { ) inherits haproxy_cd::params {
if $fqdn == $hy_host_fqdn { if $fqdn == $hy_host_fqdn {
require haproxy_cd::main::install require haproxy_cd::main::install
# manage user # manage user
user { $hy_user_name: user { $hy_user_name:
ensure => present, ensure => present,
name => $hy_user_name, name => $hy_user_name,
allowdupe => false, allowdupe => false,
comment => $hy_user_comment, comment => $hy_user_comment,
gid => $hy_user_name, gid => $hy_user_name,
managehome => true, managehome => true,
home => $hy_user_home, home => $hy_user_home,
shell => $hy_user_shell, shell => $hy_user_shell,
} }
group { $hy_user_name: group { $hy_user_name:
ensure => present, ensure => present,
name => $hy_user_name, name => $hy_user_name,
allowdupe => false, allowdupe => false,
} }
} }
} }

View File

@@ -5,37 +5,35 @@
class haproxy_cd::monitoring::fail2ban ( class haproxy_cd::monitoring::fail2ban (
) inherits haproxy_cd::params { ) inherits haproxy_cd::params {
if $hy_manage_fail2ban == true { if $hy_manage_fail2ban == true {
require fail2ban_cd # (external module)
require cd_fail2ban
# configure filter # configure filter
file { '/etc/fail2ban/filter.d/haproxy.conf': file { '/etc/fail2ban/filter.d/haproxy.conf':
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'), content => template('haproxy_cd/fail2ban/f2b_haproxy.conf.erb'),
notify => Service['fail2ban'], notify => Service['fail2ban'],
} }
file { '/etc/fail2ban/jail.d/010-haproxy.conf': file { '/etc/fail2ban/jail.d/010-haproxy.conf':
ensure => file, ensure => file,
owner => 'root', owner => 'root',
group => 'root', group => 'root',
mode => '0644', mode => '0644',
selrange => s0, selrange => s0,
selrole => object_r, selrole => object_r,
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'), content => template('haproxy_cd/fail2ban/010_jail.d_haproxy.conf.erb'),
notify => Service['fail2ban'], notify => Service['fail2ban'],
} }
} }
} }

View File

@@ -130,6 +130,8 @@ class haproxy_cd::params (
String $hy_be_userlist = '####', String $hy_be_userlist = '####',
) { ) {
$fqdn = $facts['networking']['fqdn']
# service # service
$hy_service = 'haproxy' $hy_service = 'haproxy'

View File

@@ -2,62 +2,69 @@
# Module name: haproxy_cd # Module name: haproxy_cd
# Author: Arne Teuke (arne_teuke@ConfDroid.com) # Author: Arne Teuke (arne_teuke@ConfDroid.com)
# @summary Define manages the proxies for haproxy_cd. # @summary Define manages the proxies for haproxy_cd.
# @param [string] haproxy_fqdn the fqdn of the haproxy server in question. # @param [string] haproxy_fqdn the fqdn of the haproxy server in question.
# @param [string] frontend_name the name for the frontend section rule. # @param [string] frontend_name the name for the frontend section rule.
# @param [string] frontend_order the order where the concat should appear # @param [string] frontend_order where the concat should appear in the file.
# in the file. # @param [string] frontend_mode mode for the loadbalancer instance: http or tcp
# @param [string] frontend_mode mode for the loadbalancer instance: http or tcp # @param [string] fe_use_backend which backend to use. if left empty, the
# @param [string] fe_use_backend which backend to use. if left empty, the
# default backend will be used. # default backend will be used.
# @param [string] fe_bind_mode which bind mode to use, i.e. to which interface # @param [string] fe_bind_mode which bind mode to use, i.e. to which interface
# and poort to bind. # and port to bind.
# @param [string] acl_rule an ACL rule to be inserted if required. Empty values # @param [string] backend_name the backend name to be used for the rule.
# will not be populated. # @param [string] backend_order the order for the backend name, so it will be
# @param [string] acl_order the order where the acl rule should be inserted,
# so it will be within the correct lb instance configuration.
# @param [string] backend_name the backend name to be used for the rule.
# @param [string] backend_order the order for the backend name, so it will be
# within the correct lb instance configuration. # within the correct lb instance configuration.
# @param [string] fe_maxconn the maximum connections for the lb instance. # @param [string] fe_maxconn the maximum connections for the lb instance.
# @param [string] be_server_name set the name for the backend server # @param [string] be_server_name set the name for the backend server
# @param [string] be_balance what kind of balance should be used
# @param [string] be_mode which backend mode should be used
# @param [string] default_backend value for the default backend
# @param [string] be_option value for a backend option
# @param [string] fe_tcp_request value for a frontend tcp request
# @param [string] fe_http_request value for a frontend http request
# @param [string] fe_option value for a frontend option
# @param [string] acl_rule_front value for a frontend acl rule
# @param [string] acl_rule_back value for a backend acl rule
# @param [array] backend_configs array of values for the backend
# @param [string] be_stick_table value for the backend stickiness
# @param [string] be_stick_on value for th backend stickiness
# @param [string] be_http_check value for backend http check
# @param [string] be_http_request value for a backend http request
# @param [string] be_acl_rule value for a backend acl rule
############################################################################### ###############################################################################
define haproxy_cd::server::proxy ( define haproxy_cd::server::proxy (
$haproxy_fqdn = undef, String $haproxy_fqdn = undef,
$frontend_name = undef, String $frontend_name = undef,
$frontend_mode = undef, String $frontend_mode = undef,
$fe_use_backend = '', String $fe_use_backend = '',
$fe_bind_mode = undef, String $fe_bind_mode = undef,
$fe_option = '', String $fe_option = '',
$frontend_order = '010', String $frontend_order = '010',
$acl_rule_front = '', String $acl_rule_front = '',
$acl_rule_back = '', String $acl_rule_back = '',
$backend_name = '', String $backend_name = '',
$backend_order = '030', String $backend_order = '030',
$fe_maxconn = '', String $fe_maxconn = '',
$be_server_name = '', String $be_server_name = '',
$be_balance = '', String $be_balance = '',
$be_mode = '', String $be_mode = '',
$default_backend = '', String $default_backend = '',
$be_option = '', String $be_option = '',
$fe_tcp_request = '', String $fe_tcp_request = '',
$fe_http_request = '', String $fe_http_request = '',
$backend_configs = [], Array $backend_configs = [],
$be_stick_table = '', String $be_stick_table = '',
$be_stick_on = '', String $be_stick_on = '',
$be_http_check = '', String $be_http_check = '',
$be_http_request = '', String $be_http_request = '',
$be_acl_rule = '', String $be_acl_rule = '',
) { ) {
$hy_main_config = '/etc/haproxy/haproxy.cfg' $hy_main_config = '/etc/haproxy/haproxy.cfg'
$hy_frontendrule = 'haproxy_cd/haproxy_frontend_rule.erb' $hy_frontendrule = 'haproxy_cd/haproxy_frontend_rule.erb'
$hy_backendrule = 'haproxy_cd/haproxy_backend_rule.erb' $hy_backendrule = 'haproxy_cd/haproxy_backend_rule.erb'
$hy_acl_rule = 'haproxy_cd/haproxy_acl_rule.erb' $hy_acl_rule = 'haproxy_cd/haproxy_acl_rule.erb'
# Ensure acl_rule_front and acl_rule_back are arrays # Ensure acl_rule_front and acl_rule_back are arrays
$acl_rule_front_array = split($acl_rule_front, ';') $acl_rule_front_array = split($acl_rule_front, ';')
$acl_rule_back_array = split($acl_rule_back, ';') $acl_rule_back_array = split($acl_rule_back, ';')
@@ -71,19 +78,17 @@ define haproxy_cd::server::proxy (
# create frontend section # create frontend section
concat::fragment { "frontend_${name}": concat::fragment { "frontend_${name}":
target => $hy_main_config, target => $hy_main_config,
content => template($hy_frontendrule), content => template($hy_frontendrule),
order => $frontend_order, order => $frontend_order,
} }
# Ensure backends are only created once # Ensure backends are only created once
ensure_resource('concat::fragment', "backends_${name}", { ensure_resource('concat::fragment', "backends_${name}", {
'target' => $hy_main_config, 'target' => $hy_main_config,
'content' => template($hy_backendrule), 'content' => template($hy_backendrule),
'order' => $backend_order, 'order' => $backend_order,
}) })
# open sepcific firewall ports # open specific firewall ports
} }

View File

@@ -6,16 +6,15 @@
class haproxy_cd::server::service ( class haproxy_cd::server::service (
) inherits haproxy_cd::params { ) inherits haproxy_cd::params {
if $fqdn == $hy_host_fqdn { if $fqdn == $hy_host_fqdn {
require haproxy_cd::firewall::iptables require haproxy_cd::firewall::iptables
require haproxy_cd::main::files
service { $hy_service: service { $hy_service:
ensure => running, ensure => running,
hasstatus => true, hasstatus => true,
hasrestart => true, hasrestart => true,
enable => true, enable => true,
} }
} }
} }