Compare commits

...

7 Commits

Author SHA1 Message Date
014c663e30 OP#672 update Readme 2026-09-07 16:02:54 +02:00
541e3672b7 OP#672 add service target for haproxy 2026-09-07 15:44:39 +02:00
ad2428456a OP#706 extend exec to run only if found off 2026-09-07 14:54:48 +02:00
7df6938b04 OP#669 add badges 2026-09-05 14:48:16 +02:00
6fef250c0d OP#669 update Readme 2026-09-05 14:42:31 +02:00
06dbd0fbd0 OP#669 update Readme 2026-09-05 13:31:04 +02:00
a399dde784 OP#669 set hy_selinux_allow_status to true by default 2026-09-05 13:09:55 +02:00
5 changed files with 83 additions and 5 deletions

View File

@@ -1,13 +1,20 @@
{
"cSpell.words": [
"allowdupe",
"dontlognull",
"dport",
"forwardfor",
"getsebool",
"httplog",
"managehome",
"maxconn",
"nagiosadmin",
"nologin",
"onlyif",
"pidfile",
"procs",
"redispatch",
"roundrobin",
"sess",
"setsebool",
"tcplog",

View File

@@ -1,6 +1,8 @@
# Readme
[![Build Status](https://jenkins.confdroid.com/buildStatus/icon?job=confdroid_haproxy&style=plastic)](https://jenkins.confdroid.com/job/confdroid_haproxy/)
[![Security Hotspots](https://sonarqube.confdroid.com/api/project_badges/measure?project=confdroid_haproxy&metric=security_hotspots&token=sqb_0205ee61c907f77ebdc1c717b8f4ff568c3724cf)](https://sonarqube.confdroid.com/dashboard?id=confdroid_haproxy)
[![Ask DeepWiki](https://deepwiki.com/badge.svg)](https://deepwiki.com/grizzlycoda/puppet_collection)
- [Readme](#readme)
- [Synopsis](#synopsis)
@@ -10,6 +12,7 @@
- [Deployment](#deployment)
- [Parameters](#parameters)
- [Proxy Configuration](#proxy-configuration)
- [TLS](#tls)
- [SELINUX](#selinux)
- [Known Problems](#known-problems)
- [Support](#support)
@@ -42,18 +45,20 @@ CONFIGURATION
- front-end options
- back-end options
- ACL options
- manage fail2ban integration (optional, requires fail2ban_cd module)
- adds haproxy logs to rsyslog for remote logging where used
- manage fail2ban integration (optional, requires `confdroid_fail2ban` module)
- manage nagios integration (optional, requires `confdroid-nagios` module)
SERVICE
- manage haproxy service
- restart service after changes in the configuration
- stats are enabled on port 8404 with uri /haproxy?stats and strict private mode, set `hy_stats_auth` to something meaningful.
## Dependencies
All dependencies must be included in the catalogue.
- [cd_resources](https://gitlab.confdroid.com/puppet/cd_resources) for managing yum base repos
- [concat](https://github.com/puppetlabs/puppetlabs-concat) for managing file fragments
## Deployment
@@ -83,6 +88,8 @@ The parameters are documented via puppet strings and [listed here](/docs/index.h
The proxy instances are configured in /etc/haproxy/haproxy.cfg, which is concatenated from various templates through a define in this puppet module.
In order to create proxy instances, you will need an external class, which addresses the define, like so:
ACL rule:
```bash
confdroid_haproxy::server::proxy { 'testing':
haproxy_fqdn => 'node.example.net',
@@ -94,14 +101,41 @@ In order to create proxy instances, you will need an external class, which addre
}
```
real Proxy for https:
```bash
haproxy_cd::server::proxy { 'https-in':
haproxy_fqdn => 'node.example.net',
frontend_name => 'https-in',
frontend_mode => 'http',
fe_bind_mode => '*:443 ssl crt /etc/haproxy/certs/',
fe_option => 'forwardfor',
fe_http_request => 'add-header X-Forwarded-Proto https',
acl_rule_front => 'host_grafana hdr(host) -i grafana.example.net',
fe_use_backend => 'grafana_backend if host_grafana',
backend_configs => [
{
'backend_name' => 'grafana_backend',
'be_mode' => 'http',
'be_balance' => 'roundrobin',
'be_server_name_array' => ['node1 10.0.1.1:8080 check'],
}
]
default_backend => 'error_backend',
```
This allows the puppet module to create the sections in the configuration file as required. The haproxy service will be restarted after the changes in the configuration file are made.
`haproxy_fqdn` **must**- contain the fqdn of the haproxy **server**- where this should be configured, otherwise the templates are not being populated.
Multiple ACLs need to be added as array, and will create one line each.
## TLS
Haproxy can manage all sorts of proxies including http and https. It also can terminate https requests and send the requests within a private network unencrypted, which is quite common. **This module is NOT managing certificates**, as there are many ways to manage this, including Kubernetes cert-manager, Let's encrypt or other ways.
## SELINUX
All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.
If selinux is set to `enforce` (not controlled within this module), the parameter `hy_selinux_allow_stats` must also be set to `true`, else the haproxy service will not start as selinux will not allow it.
If selinux is set to `enforce` (not controlled within this module), the parameter `hy_selinux_allow_stats` must also be set to `true`, else the haproxy service will not start as selinux will not allow it. This is the default setting.
## Known Problems

View File

@@ -12,9 +12,14 @@ class confdroid_haproxy::main::config (
include confdroid_haproxy::monitoring::fail2ban
}
if $hy_manage_nagios == true {
include confdroid_haproxy::monitoring::target
}
if $hy_selinux_allow_stats == true {
exec { 'setsebool haproxy_connect_any on':
path => ['/bin', '/usr/bin', '/sbin', '/usr/sbin'],
onlyif => '/usr/sbin/getsebool haproxy_connect_any | /usr/bin/grep -q " --> off$"',
}
}
}

View File

@@ -0,0 +1,23 @@
## confdroid_haproxy::monitoring::target.pp
# Module name: confdroid_haproxy
# Author: 12ww1160 (12ww1160@puppetsoft.com)
# @summary class manages exports for nagios monitoring
##############################################################################
class confdroid_haproxy::monitoring::target (
) inherits confdroid_haproxy::params {
if $hy_manage_nagios == true {
@@nagios_service { "check_haproxy_${fqdn}":
check_command => "check_nrpe!check_haproxy!${hy_procs_allowed}!haproxy",
use => 'generic-service',
host_name => $fqdn,
notification_period => '24x7',
service_description => "${fqdn}_check_haproxy",
target => $hy_target_service,
owner => 'nagios',
group => 'nagios',
mode => '0640',
contacts => $hy_target_contacts,
}
}
}

View File

@@ -55,6 +55,9 @@
# @param [Boolean] hy_manage_be_users whether to manage backend users
# @param [Boolean] hy_selinux_allow_stats whether to allow stats in selinux
# @param [String] hy_stats_port the port to use for stats. used in firewall settings
# @param [Boolean] hy_manage_nagios whether to manage nagios service checks
# @param [String] hy_target_service the path to the nagios service check file
# @param [Array] hy_target_contacts the contacts to use for nagios service checks
###############################################################################
class confdroid_haproxy::params (
@@ -71,7 +74,7 @@ class confdroid_haproxy::params (
Boolean $hy_manage_fail2ban = false,
# selinux
Boolean $hy_selinux_allow_stats = false,
Boolean $hy_selinux_allow_stats = true,
# main config
String $hy_http_port = '80',
@@ -115,6 +118,12 @@ class confdroid_haproxy::params (
Boolean $hy_manage_be_users = false,
String $hy_be_userlist = '####',
# nagios
Boolean $hy_manage_nagios = false,
String $hy_target_service = '/etc/nagios/conf.d/haproxy_service.cfg',
Array $hy_target_contacts = ['nagiosadmin'],
String $hy_procs_allowed = '1:1'
) {
$fqdn = $facts['networking']['fqdn']