Recommit for updates in build 9
This commit is contained in:
19
.vscode/settings.json
vendored
19
.vscode/settings.json
vendored
@@ -1,19 +0,0 @@
|
||||
{
|
||||
"cSpell.words": [
|
||||
"allowdupe",
|
||||
"dontlognull",
|
||||
"dport",
|
||||
"forwardfor",
|
||||
"httplog",
|
||||
"managehome",
|
||||
"maxconn",
|
||||
"nologin",
|
||||
"pidfile",
|
||||
"redispatch",
|
||||
"roundrobin",
|
||||
"sess",
|
||||
"setsebool",
|
||||
"tcplog",
|
||||
"userlist"
|
||||
]
|
||||
}
|
||||
127
Jenkinsfile
vendored
127
Jenkinsfile
vendored
@@ -1,127 +0,0 @@
|
||||
pipeline {
|
||||
agent {
|
||||
label 'puppet'
|
||||
}
|
||||
|
||||
post {
|
||||
always {
|
||||
deleteDir() /* clean up our workspace */
|
||||
}
|
||||
success {
|
||||
updateGitlabCommitStatus state: 'success'
|
||||
}
|
||||
failure {
|
||||
updateGitlabCommitStatus state: 'failed'
|
||||
step([$class: 'Mailer', notifyEveryUnstableBuild: true, recipients: 'support@confdroid.com', sendToIndividuals: true])
|
||||
}
|
||||
}
|
||||
|
||||
options {
|
||||
gitLabConnection('gitlab.confdroid.com')
|
||||
}
|
||||
|
||||
stages {
|
||||
|
||||
stage('pull master') {
|
||||
steps {
|
||||
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
|
||||
sh '''
|
||||
git config user.name "Jenkins Server"
|
||||
git config user.email jenkins@confdroid.com
|
||||
# Ensure we're on the development branch (triggered by push)
|
||||
git checkout development
|
||||
# Create jenkins branch from development
|
||||
git checkout -b jenkins-build-$BUILD_NUMBER
|
||||
# Optionally merge master into jenkins to ensure compatibility
|
||||
git merge origin/master --no-ff || { echo "Merge conflict detected"; exit 1; }
|
||||
'''
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
stage('puppet parser') {
|
||||
steps {
|
||||
sh '''for file in $(find . -iname \'*.pp\'); do
|
||||
/opt/puppetlabs/bin/puppet parser validate --color false --render-as s --modulepath=modules $file || exit 1;
|
||||
done;'''
|
||||
}
|
||||
}
|
||||
|
||||
stage('check templates') {
|
||||
steps{
|
||||
sh '''for file in $(find . -iname \'*.erb\');
|
||||
do erb -P -x -T "-" $file | ruby -c || exit 1;
|
||||
done;'''
|
||||
}
|
||||
}
|
||||
|
||||
stage('puppet-lint') {
|
||||
steps {
|
||||
sh '''/usr/local/bin/puppet-lint . \\
|
||||
--no-variable_scope-check \\
|
||||
|| { echo "Puppet lint failed"; exit 1; }
|
||||
'''
|
||||
}
|
||||
}
|
||||
|
||||
stage('SonarScan') {
|
||||
steps {
|
||||
withCredentials([string(credentialsId: 'sonar-token', variable: 'SONAR_TOKEN')]) {
|
||||
sh '''
|
||||
/opt/sonar-scanner/bin/sonar-scanner \
|
||||
-Dsonar.projectKey=confdroid_haproxy \
|
||||
-Dsonar.sources=. \
|
||||
-Dsonar.host.url=https://sonarqube.confdroid.com \
|
||||
-Dsonar.token=$SONAR_TOKEN
|
||||
'''
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
stage('create Puppet documentation') {
|
||||
steps {
|
||||
sh '/opt/puppetlabs/bin/puppet strings'
|
||||
}
|
||||
}
|
||||
|
||||
stage('update repo') {
|
||||
steps {
|
||||
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
|
||||
sh '''
|
||||
git config user.name "Jenkins Server"
|
||||
git config user.email jenkins@confdroid.com
|
||||
git rm -r --cached .vscode || echo "No .vscode to remove from git"
|
||||
git add -A && git commit -am "Recommit for updates in build $BUILD_NUMBER" || echo "No changes to commit"
|
||||
git push origin HEAD:master
|
||||
'''
|
||||
}
|
||||
}
|
||||
}
|
||||
stage('Mirror to Gitea') {
|
||||
steps {
|
||||
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
|
||||
withCredentials([usernamePassword(
|
||||
credentialsId: 'Jenkins-gitea',
|
||||
usernameVariable: 'GITEA_USER',
|
||||
passwordVariable: 'GITEA_TOKEN')]) {
|
||||
script {
|
||||
// Checkout from GitLab (already done implicitly)
|
||||
sh '''
|
||||
git checkout master
|
||||
git pull origin master
|
||||
git branch -D development
|
||||
git branch -D jenkins-build-$BUILD_NUMBER
|
||||
git rm -f Jenkinsfile
|
||||
git rm -r --cached .vscode || echo "No .vscode to remove from git"
|
||||
git commit --amend --no-edit --allow-empty
|
||||
git remote add master https://sourcecode.confdroid.com/confdroid/confdroid_haproxy.git
|
||||
git -c credential.helper="!f() { echo username=${GITEA_USER}; echo password=${GITEA_TOKEN}; }; f" \
|
||||
push master --mirror
|
||||
'''
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -78,6 +78,8 @@
|
||||
</li><li>
|
||||
<p><a href="#proxy-configuration">Proxy Configuration</a></p>
|
||||
</li><li>
|
||||
<p><a href="#tls">TLS</a></p>
|
||||
</li><li>
|
||||
<p><a href="#selinux">SELINUX</a></p>
|
||||
</li><li>
|
||||
<p><a href="#known-problems">Known Problems</a></p>
|
||||
@@ -126,7 +128,7 @@
|
||||
</li><li>
|
||||
<p>ACL options</p>
|
||||
</li><li>
|
||||
<p>manage fail2ban integration (optional, requires fail2ban_cd module)</p>
|
||||
<p>manage fail2ban integration (optional, requires <code>confdroid_fail2ban</code> module)</p>
|
||||
</li></ul>
|
||||
|
||||
<p>SERVICE</p>
|
||||
@@ -140,8 +142,6 @@
|
||||
|
||||
<p>All dependencies must be included in the catalogue.</p>
|
||||
<ul><li>
|
||||
<p><a href="https://gitlab.confdroid.com/puppet/cd_resources">cd_resources</a> for managing yum base repos</p>
|
||||
</li><li>
|
||||
<p><a href="https://github.com/puppetlabs/puppetlabs-concat">concat</a> for managing file fragments</p>
|
||||
</li></ul>
|
||||
|
||||
@@ -172,6 +172,8 @@
|
||||
|
||||
<p>The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:</p>
|
||||
|
||||
<p>ACL rule:</p>
|
||||
|
||||
<pre class="code ruby"><code class="ruby">confdroid_haproxy::server::proxy { 'testing':
|
||||
haproxy_fqdn => 'node.example.net',
|
||||
frontend_name => 'test01-frontend',
|
||||
@@ -182,8 +184,34 @@
|
||||
}
|
||||
</code></pre>
|
||||
|
||||
<p>real Proxy for https:</p>
|
||||
|
||||
<pre class="code ruby"><code class="ruby">haproxy_cd::server::proxy { 'https-in':
|
||||
haproxy_fqdn => 'node.example.net',
|
||||
frontend_name => 'https-in',
|
||||
frontend_mode => 'http',
|
||||
fe_bind_mode => '*:443 ssl crt /etc/haproxy/certs/',
|
||||
fe_option => 'forwardfor',
|
||||
fe_http_request => 'add-header X-Forwarded-Proto https',
|
||||
acl_rule_front => 'host_grafana hdr(host) -i grafana.example.net',
|
||||
fe_use_backend => 'grafana_backend if host_grafana',
|
||||
backend_configs => [
|
||||
{
|
||||
'backend_name' => 'grafana_backend',
|
||||
'be_mode' => 'http',
|
||||
'be_balance' => 'roundrobin',
|
||||
'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
|
||||
}
|
||||
]
|
||||
default_backend => 'error_backend',
|
||||
</code></pre>
|
||||
|
||||
<p>This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. <code>haproxy_fqdn</code> <strong>must</strong>- contain the fqdn of the haproxy <strong>server</strong>- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.</p>
|
||||
|
||||
<h2 id="label-TLS">TLS</h2>
|
||||
|
||||
<p>Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. <strong>This module is NOT managing certificates</strong>, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.</p>
|
||||
|
||||
<h2 id="label-SELINUX">SELINUX</h2>
|
||||
|
||||
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p>
|
||||
|
||||
@@ -78,6 +78,8 @@
|
||||
</li><li>
|
||||
<p><a href="#proxy-configuration">Proxy Configuration</a></p>
|
||||
</li><li>
|
||||
<p><a href="#tls">TLS</a></p>
|
||||
</li><li>
|
||||
<p><a href="#selinux">SELINUX</a></p>
|
||||
</li><li>
|
||||
<p><a href="#known-problems">Known Problems</a></p>
|
||||
@@ -126,7 +128,7 @@
|
||||
</li><li>
|
||||
<p>ACL options</p>
|
||||
</li><li>
|
||||
<p>manage fail2ban integration (optional, requires fail2ban_cd module)</p>
|
||||
<p>manage fail2ban integration (optional, requires <code>confdroid_fail2ban</code> module)</p>
|
||||
</li></ul>
|
||||
|
||||
<p>SERVICE</p>
|
||||
@@ -140,8 +142,6 @@
|
||||
|
||||
<p>All dependencies must be included in the catalogue.</p>
|
||||
<ul><li>
|
||||
<p><a href="https://gitlab.confdroid.com/puppet/cd_resources">cd_resources</a> for managing yum base repos</p>
|
||||
</li><li>
|
||||
<p><a href="https://github.com/puppetlabs/puppetlabs-concat">concat</a> for managing file fragments</p>
|
||||
</li></ul>
|
||||
|
||||
@@ -172,6 +172,8 @@
|
||||
|
||||
<p>The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:</p>
|
||||
|
||||
<p>ACL rule:</p>
|
||||
|
||||
<pre class="code ruby"><code class="ruby">confdroid_haproxy::server::proxy { 'testing':
|
||||
haproxy_fqdn => 'node.example.net',
|
||||
frontend_name => 'test01-frontend',
|
||||
@@ -182,8 +184,34 @@
|
||||
}
|
||||
</code></pre>
|
||||
|
||||
<p>real Proxy for https:</p>
|
||||
|
||||
<pre class="code ruby"><code class="ruby">haproxy_cd::server::proxy { 'https-in':
|
||||
haproxy_fqdn => 'node.example.net',
|
||||
frontend_name => 'https-in',
|
||||
frontend_mode => 'http',
|
||||
fe_bind_mode => '*:443 ssl crt /etc/haproxy/certs/',
|
||||
fe_option => 'forwardfor',
|
||||
fe_http_request => 'add-header X-Forwarded-Proto https',
|
||||
acl_rule_front => 'host_grafana hdr(host) -i grafana.example.net',
|
||||
fe_use_backend => 'grafana_backend if host_grafana',
|
||||
backend_configs => [
|
||||
{
|
||||
'backend_name' => 'grafana_backend',
|
||||
'be_mode' => 'http',
|
||||
'be_balance' => 'roundrobin',
|
||||
'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
|
||||
}
|
||||
]
|
||||
default_backend => 'error_backend',
|
||||
</code></pre>
|
||||
|
||||
<p>This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. <code>haproxy_fqdn</code> <strong>must</strong>- contain the fqdn of the haproxy <strong>server</strong>- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.</p>
|
||||
|
||||
<h2 id="label-TLS">TLS</h2>
|
||||
|
||||
<p>Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. <strong>This module is NOT managing certificates</strong>, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.</p>
|
||||
|
||||
<h2 id="label-SELINUX">SELINUX</h2>
|
||||
|
||||
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p>
|
||||
|
||||
Reference in New Issue
Block a user