Compare commits

..

1 Commits

Author SHA1 Message Date
Jenkins Server
3012a7195a Recommit for updates in build 8 2026-09-05 13:11:14 +02:00
3 changed files with 8 additions and 93 deletions

View File

@@ -10,7 +10,6 @@
- [Deployment](#deployment) - [Deployment](#deployment)
- [Parameters](#parameters) - [Parameters](#parameters)
- [Proxy Configuration](#proxy-configuration) - [Proxy Configuration](#proxy-configuration)
- [TLS](#tls)
- [SELINUX](#selinux) - [SELINUX](#selinux)
- [Known Problems](#known-problems) - [Known Problems](#known-problems)
- [Support](#support) - [Support](#support)
@@ -43,7 +42,7 @@ CONFIGURATION
- front-end options - front-end options
- back-end options - back-end options
- ACL options - ACL options
- manage fail2ban integration (optional, requires `confdroid_fail2ban` module) - manage fail2ban integration (optional, requires fail2ban_cd module)
SERVICE SERVICE
@@ -54,6 +53,7 @@ SERVICE
All dependencies must be included in the catalogue. All dependencies must be included in the catalogue.
- [cd_resources](https://gitlab.confdroid.com/puppet/cd_resources) for managing yum base repos
- [concat](https://github.com/puppetlabs/puppetlabs-concat) for managing file fragments - [concat](https://github.com/puppetlabs/puppetlabs-concat) for managing file fragments
## Deployment ## Deployment
@@ -83,8 +83,6 @@ The parameters are documented via puppet strings and [listed here](/docs/index.h
The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module.
In order to create proxy instances, you will need an external class, which addresses the define, like so: In order to create proxy instances, you will need an external class, which addresses the define, like so:
ACL rule:
```bash ```bash
confdroid_haproxy::server::proxy { 'testing': confdroid_haproxy::server::proxy { 'testing':
haproxy_fqdn => 'node.example.net', haproxy_fqdn => 'node.example.net',
@@ -96,37 +94,10 @@ ACL rule:
} }
``` ```
real Proxy for https:
```bash
haproxy_cd::server::proxy { 'https-in':
haproxy_fqdn => 'node.example.net',
frontend_name => 'https-in',
frontend_mode => 'http',
fe_bind_mode => '*:443 ssl crt /etc/haproxy/certs/',
fe_option => 'forwardfor',
fe_http_request => 'add-header X-Forwarded-Proto https',
acl_rule_front => 'host_grafana hdr(host) -i grafana.example.net',
fe_use_backend => 'grafana_backend if host_grafana',
backend_configs => [
{
'backend_name' => 'grafana_backend',
'be_mode' => 'http',
'be_balance' => 'roundrobin',
'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
}
]
default_backend => 'error_backend',
```
This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made.
`haproxy_fqdn` **must**- contain the fqdn of the haproxy **server**- where this should be configured, otherwise the templates are not being populated. `haproxy_fqdn` **must**- contain the fqdn of the haproxy **server**- where this should be configured, otherwise the templates are not being populated.
Multiple ACLs need to be added as array, and will create one line each. Multiple ACLs need to be added as array, and will create one line each.
## TLS
Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. **This module is NOT managing certificates**, as there are many ways to manage this, including Kubernetes cert-manager, Let's encrypt or other ways.
## SELINUX ## SELINUX
All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.

View File

@@ -78,8 +78,6 @@
</li><li> </li><li>
<p><a href="#proxy-configuration">Proxy Configuration</a></p> <p><a href="#proxy-configuration">Proxy Configuration</a></p>
</li><li> </li><li>
<p><a href="#tls">TLS</a></p>
</li><li>
<p><a href="#selinux">SELINUX</a></p> <p><a href="#selinux">SELINUX</a></p>
</li><li> </li><li>
<p><a href="#known-problems">Known Problems</a></p> <p><a href="#known-problems">Known Problems</a></p>
@@ -128,7 +126,7 @@
</li><li> </li><li>
<p>ACL options</p> <p>ACL options</p>
</li><li> </li><li>
<p>manage fail2ban integration (optional, requires <code>confdroid_fail2ban</code> module)</p> <p>manage fail2ban integration (optional, requires fail2ban_cd module)</p>
</li></ul> </li></ul>
<p>SERVICE</p> <p>SERVICE</p>
@@ -142,6 +140,8 @@
<p>All dependencies must be included in the catalogue.</p> <p>All dependencies must be included in the catalogue.</p>
<ul><li> <ul><li>
<p><a href="https://gitlab.confdroid.com/puppet/cd_resources">cd_resources</a> for managing yum base repos</p>
</li><li>
<p><a href="https://github.com/puppetlabs/puppetlabs-concat">concat</a> for managing file fragments</p> <p><a href="https://github.com/puppetlabs/puppetlabs-concat">concat</a> for managing file fragments</p>
</li></ul> </li></ul>
@@ -172,8 +172,6 @@
<p>The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:</p> <p>The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:</p>
<p>ACL rule:</p>
<pre class="code ruby"><code class="ruby">confdroid_haproxy::server::proxy { &#39;testing&#39;: <pre class="code ruby"><code class="ruby">confdroid_haproxy::server::proxy { &#39;testing&#39;:
haproxy_fqdn =&gt; &#39;node.example.net&#39;, haproxy_fqdn =&gt; &#39;node.example.net&#39;,
frontend_name =&gt; &#39;test01-frontend&#39;, frontend_name =&gt; &#39;test01-frontend&#39;,
@@ -184,34 +182,8 @@
} }
</code></pre> </code></pre>
<p>real Proxy for https:</p>
<pre class="code ruby"><code class="ruby">haproxy_cd::server::proxy { &#39;https-in&#39;:
haproxy_fqdn =&gt; &#39;node.example.net&#39;,
frontend_name =&gt; &#39;https-in&#39;,
frontend_mode =&gt; &#39;http&#39;,
fe_bind_mode =&gt; &#39;*:443 ssl crt /etc/haproxy/certs/&#39;,
fe_option =&gt; &#39;forwardfor&#39;,
fe_http_request =&gt; &#39;add-header X-Forwarded-Proto https&#39;,
acl_rule_front =&gt; &#39;host_grafana hdr(host) -i grafana.example.net&#39;,
fe_use_backend =&gt; &#39;grafana_backend if host_grafana&#39;,
backend_configs =&gt; [
{
&#39;backend_name&#39; =&gt; &#39;grafana_backend&#39;,
&#39;be_mode&#39; =&gt; &#39;http&#39;,
&#39;be_balance&#39; =&gt; &#39;roundrobin&#39;,
&#39;be_server_name_array&#39; =&gt; [&#39;node1 10.0.1.1:8080 check&#39;],
}
]
default_backend =&gt; &#39;error_backend&#39;,
</code></pre>
<p>This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. <code>haproxy_fqdn</code> <strong>must</strong>- contain the fqdn of the haproxy <strong>server</strong>- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.</p> <p>This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. <code>haproxy_fqdn</code> <strong>must</strong>- contain the fqdn of the haproxy <strong>server</strong>- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.</p>
<h2 id="label-TLS">TLS</h2>
<p>Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. <strong>This module is NOT managing certificates</strong>, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.</p>
<h2 id="label-SELINUX">SELINUX</h2> <h2 id="label-SELINUX">SELINUX</h2>
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p> <p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p>

View File

@@ -78,8 +78,6 @@
</li><li> </li><li>
<p><a href="#proxy-configuration">Proxy Configuration</a></p> <p><a href="#proxy-configuration">Proxy Configuration</a></p>
</li><li> </li><li>
<p><a href="#tls">TLS</a></p>
</li><li>
<p><a href="#selinux">SELINUX</a></p> <p><a href="#selinux">SELINUX</a></p>
</li><li> </li><li>
<p><a href="#known-problems">Known Problems</a></p> <p><a href="#known-problems">Known Problems</a></p>
@@ -128,7 +126,7 @@
</li><li> </li><li>
<p>ACL options</p> <p>ACL options</p>
</li><li> </li><li>
<p>manage fail2ban integration (optional, requires <code>confdroid_fail2ban</code> module)</p> <p>manage fail2ban integration (optional, requires fail2ban_cd module)</p>
</li></ul> </li></ul>
<p>SERVICE</p> <p>SERVICE</p>
@@ -142,6 +140,8 @@
<p>All dependencies must be included in the catalogue.</p> <p>All dependencies must be included in the catalogue.</p>
<ul><li> <ul><li>
<p><a href="https://gitlab.confdroid.com/puppet/cd_resources">cd_resources</a> for managing yum base repos</p>
</li><li>
<p><a href="https://github.com/puppetlabs/puppetlabs-concat">concat</a> for managing file fragments</p> <p><a href="https://github.com/puppetlabs/puppetlabs-concat">concat</a> for managing file fragments</p>
</li></ul> </li></ul>
@@ -172,8 +172,6 @@
<p>The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:</p> <p>The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module. In order to create proxy instances, you will need an external class, which addresses the define, like so:</p>
<p>ACL rule:</p>
<pre class="code ruby"><code class="ruby">confdroid_haproxy::server::proxy { &#39;testing&#39;: <pre class="code ruby"><code class="ruby">confdroid_haproxy::server::proxy { &#39;testing&#39;:
haproxy_fqdn =&gt; &#39;node.example.net&#39;, haproxy_fqdn =&gt; &#39;node.example.net&#39;,
frontend_name =&gt; &#39;test01-frontend&#39;, frontend_name =&gt; &#39;test01-frontend&#39;,
@@ -184,34 +182,8 @@
} }
</code></pre> </code></pre>
<p>real Proxy for https:</p>
<pre class="code ruby"><code class="ruby">haproxy_cd::server::proxy { &#39;https-in&#39;:
haproxy_fqdn =&gt; &#39;node.example.net&#39;,
frontend_name =&gt; &#39;https-in&#39;,
frontend_mode =&gt; &#39;http&#39;,
fe_bind_mode =&gt; &#39;*:443 ssl crt /etc/haproxy/certs/&#39;,
fe_option =&gt; &#39;forwardfor&#39;,
fe_http_request =&gt; &#39;add-header X-Forwarded-Proto https&#39;,
acl_rule_front =&gt; &#39;host_grafana hdr(host) -i grafana.example.net&#39;,
fe_use_backend =&gt; &#39;grafana_backend if host_grafana&#39;,
backend_configs =&gt; [
{
&#39;backend_name&#39; =&gt; &#39;grafana_backend&#39;,
&#39;be_mode&#39; =&gt; &#39;http&#39;,
&#39;be_balance&#39; =&gt; &#39;roundrobin&#39;,
&#39;be_server_name_array&#39; =&gt; [&#39;node1 10.0.1.1:8080 check&#39;],
}
]
default_backend =&gt; &#39;error_backend&#39;,
</code></pre>
<p>This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. <code>haproxy_fqdn</code> <strong>must</strong>- contain the fqdn of the haproxy <strong>server</strong>- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.</p> <p>This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made. <code>haproxy_fqdn</code> <strong>must</strong>- contain the fqdn of the haproxy <strong>server</strong>- where this should be configured, otherwise the templates are not being populated. Multiple ACLs need to be added as array, and will create one line each.</p>
<h2 id="label-TLS">TLS</h2>
<p>Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. <strong>This module is NOT managing certificates</strong>, as there are many ways to manage this, including Kubernetes cert-manager, Let’s encrypt or other ways.</p>
<h2 id="label-SELINUX">SELINUX</h2> <h2 id="label-SELINUX">SELINUX</h2>
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p> <p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p>