4 Commits
1.0.0 ... 1.1.0

Author SHA1 Message Date
014c663e30 OP#672 update Readme 2026-09-07 16:02:54 +02:00
541e3672b7 OP#672 add service target for haproxy 2026-09-07 15:44:39 +02:00
ad2428456a OP#706 extend exec to run only if found off 2026-09-07 14:54:48 +02:00
7df6938b04 OP#669 add badges 2026-09-05 14:48:16 +02:00
5 changed files with 45 additions and 1 deletions

View File

@@ -4,11 +4,15 @@
"dontlognull",
"dport",
"forwardfor",
"getsebool",
"httplog",
"managehome",
"maxconn",
"nagiosadmin",
"nologin",
"onlyif",
"pidfile",
"procs",
"redispatch",
"roundrobin",
"sess",

View File

@@ -1,6 +1,8 @@
# Readme
[![Build Status](https://jenkins.confdroid.com/buildStatus/icon?job=confdroid_haproxy&style=plastic)](https://jenkins.confdroid.com/job/confdroid_haproxy/)
[![Security Hotspots](https://sonarqube.confdroid.com/api/project_badges/measure?project=confdroid_haproxy&metric=security_hotspots&token=sqb_0205ee61c907f77ebdc1c717b8f4ff568c3724cf)](https://sonarqube.confdroid.com/dashboard?id=confdroid_haproxy)
[![Ask DeepWiki](https://deepwiki.com/badge.svg)](https://deepwiki.com/grizzlycoda/puppet_collection)
- [Readme](#readme)
- [Synopsis](#synopsis)
@@ -45,6 +47,7 @@ CONFIGURATION
- ACL options
- adds haproxy logs to rsyslog for remote logging where used
- manage fail2ban integration (optional, requires `confdroid_fail2ban` module)
- manage nagios integration (optional, requires `confdroid-nagios` module)
SERVICE

View File

@@ -12,9 +12,14 @@ class confdroid_haproxy::main::config (
include confdroid_haproxy::monitoring::fail2ban
}
if $hy_manage_nagios == true {
include confdroid_haproxy::monitoring::target
}
if $hy_selinux_allow_stats == true {
exec { 'setsebool haproxy_connect_any on':
path => ['/bin', '/usr/bin', '/sbin', '/usr/sbin'],
path => ['/bin', '/usr/bin', '/sbin', '/usr/sbin'],
onlyif => '/usr/sbin/getsebool haproxy_connect_any | /usr/bin/grep -q " --> off$"',
}
}
}

View File

@@ -0,0 +1,23 @@
## confdroid_haproxy::monitoring::target.pp
# Module name: confdroid_haproxy
# Author: 12ww1160 (12ww1160@puppetsoft.com)
# @summary class manages exports for nagios monitoring
##############################################################################
class confdroid_haproxy::monitoring::target (
) inherits confdroid_haproxy::params {
if $hy_manage_nagios == true {
@@nagios_service { "check_haproxy_${fqdn}":
check_command => "check_nrpe!check_haproxy!${hy_procs_allowed}!haproxy",
use => 'generic-service',
host_name => $fqdn,
notification_period => '24x7',
service_description => "${fqdn}_check_haproxy",
target => $hy_target_service,
owner => 'nagios',
group => 'nagios',
mode => '0640',
contacts => $hy_target_contacts,
}
}
}

View File

@@ -55,6 +55,9 @@
# @param [Boolean] hy_manage_be_users whether to manage backend users
# @param [Boolean] hy_selinux_allow_stats whether to allow stats in selinux
# @param [String] hy_stats_port the port to use for stats. used in firewall settings
# @param [Boolean] hy_manage_nagios whether to manage nagios service checks
# @param [String] hy_target_service the path to the nagios service check file
# @param [Array] hy_target_contacts the contacts to use for nagios service checks
###############################################################################
class confdroid_haproxy::params (
@@ -115,6 +118,12 @@ class confdroid_haproxy::params (
Boolean $hy_manage_be_users = false,
String $hy_be_userlist = '####',
# nagios
Boolean $hy_manage_nagios = false,
String $hy_target_service = '/etc/nagios/conf.d/haproxy_service.cfg',
Array $hy_target_contacts = ['nagiosadmin'],
String $hy_procs_allowed = '1:1'
) {
$fqdn = $facts['networking']['fqdn']