Compare commits

..

5 Commits

Author SHA1 Message Date
Jenkins Server
19df6fdca0 Recommit for updates in build 4 2026-09-05 12:54:06 +02:00
Jenkins Server
2004d2b7e7 Merge remote-tracking branch 'origin/master' into jenkins-build-4 2026-09-05 12:53:02 +02:00
5b20bf27ac OP#669 add config section to execute haproxy_connect_any 2026-09-05 12:52:42 +02:00
04e35b6d1d OP#669 remove unwanted onio-api fw rule 2026-09-05 12:50:53 +02:00
Jenkins Server
2ebe772103 Recommit for updates in build 3 2026-09-05 12:02:06 +02:00
8 changed files with 57 additions and 11 deletions

View File

@@ -101,6 +101,7 @@ Multiple ACLs need to be added as array, and will create one line each.
## SELINUX ## SELINUX
All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.
If selinux is set to `enforce` (not controlled within this module) and `hy_show_stats`is set to `true`, the parameter `hy_selinux_allow_stats` must also be set to `true`, else the haproxy service will not start as selinux will not allow it.
## Known Problems ## Known Problems

View File

@@ -186,7 +186,7 @@
<h2 id="label-SELINUX">SELINUX</h2> <h2 id="label-SELINUX">SELINUX</h2>
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.</p> <p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module) and <code>hy_show_stats</code>is set to <code>true</code>, the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it.</p>
<h2 id="label-Known+Problems">Known Problems</h2> <h2 id="label-Known+Problems">Known Problems</h2>

View File

@@ -186,7 +186,7 @@
<h2 id="label-SELINUX">SELINUX</h2> <h2 id="label-SELINUX">SELINUX</h2>
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.</p> <p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module) and <code>hy_show_stats</code>is set to <code>true</code>, the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it.</p>
<h2 id="label-Known+Problems">Known Problems</h2> <h2 id="label-Known+Problems">Known Problems</h2>

View File

@@ -109,7 +109,13 @@
11 11
12 12
13 13
14</pre> 14
15
16
17
18
19
20</pre>
</td> </td>
<td> <td>
<pre class="code"><span class="info file"># File 'manifests/main/config.pp', line 6</span> <pre class="code"><span class="info file"># File 'manifests/main/config.pp', line 6</span>
@@ -122,6 +128,12 @@ class confdroid_haproxy::main::config (
if $hy_manage_fail2ban == true { if $hy_manage_fail2ban == true {
include confdroid_haproxy::monitoring::fail2ban include confdroid_haproxy::monitoring::fail2ban
} }
if $hy_selinux_allow_stats == true {
exec { &#39;setsebool haproxy_connect_any on&#39;:
path =&gt; [&#39;/bin&#39;, &#39;/usr/bin&#39;, &#39;/sbin&#39;, &#39;/usr/sbin&#39;],
}
}
}</pre> }</pre>
</td> </td>
</tr> </tr>

View File

@@ -861,6 +861,24 @@
&mdash; &mdash;
<div class='inline'> <div class='inline'>
<p>whether to manage backend users</p> <p>whether to manage backend users</p>
</div>
</li>
<li>
<span class='name'>hy_selinux_allow_stats</span>
<span class='type'>(<tt>Boolean</tt>)</span>
<em class="default">(defaults to: <tt>false</tt>)</em>
&mdash;
<div class='inline'>
<p>whether to allow stats in selinux</p>
</div> </div>
</li> </li>
@@ -876,7 +894,6 @@
<pre class="lines"> <pre class="lines">
58
59 59
60 60
61 61
@@ -964,10 +981,14 @@
143 143
144 144
145 145
146</pre> 146
147
148
149
150</pre>
</td> </td>
<td> <td>
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 58</span> <pre class="code"><span class="info file"># File 'manifests/params.pp', line 59</span>
class confdroid_haproxy::params ( class confdroid_haproxy::params (
@@ -983,6 +1004,9 @@ class confdroid_haproxy::params (
# fail2ban # fail2ban
Boolean $hy_manage_fail2ban = false, Boolean $hy_manage_fail2ban = false,
# selinux
Boolean $hy_selinux_allow_stats = false,
# main config # main config
String $hy_http_port = &#39;80&#39;, String $hy_http_port = &#39;80&#39;,
String $hy_https_port = &#39;443&#39;, String $hy_https_port = &#39;443&#39;,

View File

@@ -11,4 +11,10 @@ class confdroid_haproxy::main::config (
if $hy_manage_fail2ban == true { if $hy_manage_fail2ban == true {
include confdroid_haproxy::monitoring::fail2ban include confdroid_haproxy::monitoring::fail2ban
} }
if $hy_selinux_allow_stats == true {
exec { 'setsebool haproxy_connect_any on':
path => ['/bin', '/usr/bin', '/sbin', '/usr/sbin'],
}
}
} }

View File

@@ -54,6 +54,7 @@
# @param [Boolean] hy_use_dontlognull whether to use dontlognull as default # @param [Boolean] hy_use_dontlognull whether to use dontlognull as default
# @param [String] hy_be_userlist backend userlist comment # @param [String] hy_be_userlist backend userlist comment
# @param [Boolean] hy_manage_be_users whether to manage backend users # @param [Boolean] hy_manage_be_users whether to manage backend users
# @param [Boolean] hy_selinux_allow_stats whether to allow stats in selinux
############################################################################### ###############################################################################
class confdroid_haproxy::params ( class confdroid_haproxy::params (
@@ -69,6 +70,9 @@ class confdroid_haproxy::params (
# fail2ban # fail2ban
Boolean $hy_manage_fail2ban = false, Boolean $hy_manage_fail2ban = false,
# selinux
Boolean $hy_selinux_allow_stats = false,
# main config # main config
String $hy_http_port = '80', String $hy_http_port = '80',
String $hy_https_port = '443', String $hy_https_port = '443',

View File

@@ -7,10 +7,6 @@ global
log <%= @hy_log_local1 %> log <%= @hy_log_local1 %>
<% if @hy_hard_stop == true -%> <% if @hy_hard_stop == true -%>
hard-stop-after <%= @hy_hard_stop_value %> hard-stop-after <%= @hy_hard_stop_value %>
<% end -%>
<% if @hy_show_stats == true -%>
stats socket /var/lib/haproxy/stats
stats timeout 30s
<% end -%> <% end -%>
chroot <%= @hy_chroot %> chroot <%= @hy_chroot %>
pidfile <%= @hy_pid %> pidfile <%= @hy_pid %>
@@ -54,8 +50,9 @@ defaults
timeout check <%= @hy_timeout_check %> timeout check <%= @hy_timeout_check %>
maxconn <%= @hy_maxconn %> maxconn <%= @hy_maxconn %>
<% if @hy_show_stats == true -%>
listen stats listen stats
bind 127.0.0.1:8404 # Bind to localhost if only local access is needed # bind *:8404
mode http mode http
stats enable stats enable
stats uri /haproxy?stats stats uri /haproxy?stats
@@ -63,6 +60,8 @@ listen stats
stats auth <%= @hy_stats_auth %> stats auth <%= @hy_stats_auth %>
stats refresh 30s stats refresh 30s
stats admin if TRUE # Allow admin actions if logged in stats admin if TRUE # Allow admin actions if logged in
<% end -%>
listen stats
<% if @hy_manage_be_users == true -%> <% if @hy_manage_be_users == true -%>
<%= @hy_be_userlist %> <%= @hy_be_userlist %>