Compare commits

...

4 Commits

Author SHA1 Message Date
Jenkins Server
3012a7195a Recommit for updates in build 8 2026-09-05 13:11:14 +02:00
Jenkins Server
711d817cfb Merge remote-tracking branch 'origin/master' into jenkins-build-8 2026-09-05 13:10:12 +02:00
a399dde784 OP#669 set hy_selinux_allow_status to true by default 2026-09-05 13:09:55 +02:00
Jenkins Server
1467a2d6a3 Recommit for updates in build 7 2026-09-05 13:09:34 +02:00
8 changed files with 14 additions and 181 deletions

16
.vscode/settings.json vendored
View File

@@ -1,16 +0,0 @@
{
"cSpell.words": [
"dontlognull",
"dport",
"forwardfor",
"httplog",
"maxconn",
"nologin",
"pidfile",
"redispatch",
"sess",
"setsebool",
"tcplog",
"userlist"
]
}

127
Jenkinsfile vendored
View File

@@ -1,127 +0,0 @@
pipeline {
agent {
label 'puppet'
}
post {
always {
deleteDir() /* clean up our workspace */
}
success {
updateGitlabCommitStatus state: 'success'
}
failure {
updateGitlabCommitStatus state: 'failed'
step([$class: 'Mailer', notifyEveryUnstableBuild: true, recipients: 'support@confdroid.com', sendToIndividuals: true])
}
}
options {
gitLabConnection('gitlab.confdroid.com')
}
stages {
stage('pull master') {
steps {
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
sh '''
git config user.name "Jenkins Server"
git config user.email jenkins@confdroid.com
# Ensure we're on the development branch (triggered by push)
git checkout development
# Create jenkins branch from development
git checkout -b jenkins-build-$BUILD_NUMBER
# Optionally merge master into jenkins to ensure compatibility
git merge origin/master --no-ff || { echo "Merge conflict detected"; exit 1; }
'''
}
}
}
stage('puppet parser') {
steps {
sh '''for file in $(find . -iname \'*.pp\'); do
/opt/puppetlabs/bin/puppet parser validate --color false --render-as s --modulepath=modules $file || exit 1;
done;'''
}
}
stage('check templates') {
steps{
sh '''for file in $(find . -iname \'*.erb\');
do erb -P -x -T "-" $file | ruby -c || exit 1;
done;'''
}
}
stage('puppet-lint') {
steps {
sh '''/usr/local/bin/puppet-lint . \\
--no-variable_scope-check \\
|| { echo "Puppet lint failed"; exit 1; }
'''
}
}
stage('SonarScan') {
steps {
withCredentials([string(credentialsId: 'sonar-token', variable: 'SONAR_TOKEN')]) {
sh '''
/opt/sonar-scanner/bin/sonar-scanner \
-Dsonar.projectKey=confdroid_haproxy \
-Dsonar.sources=. \
-Dsonar.host.url=https://sonarqube.confdroid.com \
-Dsonar.token=$SONAR_TOKEN
'''
}
}
}
stage('create Puppet documentation') {
steps {
sh '/opt/puppetlabs/bin/puppet strings'
}
}
stage('update repo') {
steps {
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
sh '''
git config user.name "Jenkins Server"
git config user.email jenkins@confdroid.com
git rm -r --cached .vscode || echo "No .vscode to remove from git"
git add -A && git commit -am "Recommit for updates in build $BUILD_NUMBER" || echo "No changes to commit"
git push origin HEAD:master
'''
}
}
}
stage('Mirror to Gitea') {
steps {
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
withCredentials([usernamePassword(
credentialsId: 'Jenkins-gitea',
usernameVariable: 'GITEA_USER',
passwordVariable: 'GITEA_TOKEN')]) {
script {
// Checkout from GitLab (already done implicitly)
sh '''
git checkout master
git pull origin master
git branch -D development
git branch -D jenkins-build-$BUILD_NUMBER
git rm -f Jenkinsfile
git rm -r --cached .vscode || echo "No .vscode to remove from git"
git commit --amend --no-edit --allow-empty
git remote add master https://sourcecode.confdroid.com/confdroid/confdroid_haproxy.git
git -c credential.helper="!f() { echo username=${GITEA_USER}; echo password=${GITEA_TOKEN}; }; f" \
push master --mirror
'''
}
}
}
}
}
}
}

View File

@@ -101,7 +101,7 @@ Multiple ACLs need to be added as array, and will create one line each.
## SELINUX ## SELINUX
All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.
If selinux is set to `enforce` (not controlled within this module), the parameter `hy_selinux_allow_stats` must also be set to `true`, else the haproxy service will not start as selinux will not allow it. If selinux is set to `enforce` (not controlled within this module), the parameter `hy_selinux_allow_stats` must also be set to `true`, else the haproxy service will not start as selinux will not allow it. This is the default setting.
## Known Problems ## Known Problems

View File

@@ -186,7 +186,7 @@
<h2 id="label-SELINUX">SELINUX</h2> <h2 id="label-SELINUX">SELINUX</h2>
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module) and <code>hy_show_stats</code>is set to <code>true</code>, the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it.</p> <p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p>
<h2 id="label-Known+Problems">Known Problems</h2> <h2 id="label-Known+Problems">Known Problems</h2>

View File

@@ -186,7 +186,7 @@
<h2 id="label-SELINUX">SELINUX</h2> <h2 id="label-SELINUX">SELINUX</h2>
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module) and <code>hy_show_stats</code>is set to <code>true</code>, the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it.</p> <p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored. If selinux is set to <code>enforce</code> (not controlled within this module), the parameter <code>hy_selinux_allow_stats</code> must also be set to <code>true</code>, else the haproxy service will not start as selinux will not allow it. This is the default setting.</p>
<h2 id="label-Known+Problems">Known Problems</h2> <h2 id="label-Known+Problems">Known Problems</h2>

View File

@@ -123,9 +123,7 @@
25 25
26 26
27 27
28 28</pre>
29
30</pre>
</td> </td>
<td> <td>
<pre class="code"><span class="info file"># File 'manifests/firewall/iptables.pp', line 6</span> <pre class="code"><span class="info file"># File 'manifests/firewall/iptables.pp', line 6</span>
@@ -146,14 +144,12 @@ class confdroid_haproxy::firewall::iptables (
jump =&gt; &#39;accept&#39;, jump =&gt; &#39;accept&#39;,
} }
if $hy_show_stats == true {
firewall { &quot;${hy_fw_order_no}${hy_stats_port} tcp port ${hy_stats_port}&quot;: firewall { &quot;${hy_fw_order_no}${hy_stats_port} tcp port ${hy_stats_port}&quot;:
proto =&gt; &#39;tcp&#39;, proto =&gt; &#39;tcp&#39;,
dport =&gt; $hy_stats_port, dport =&gt; $hy_stats_port,
jump =&gt; &#39;accept&#39;, jump =&gt; &#39;accept&#39;,
} }
} }
}
}</pre> }</pre>
</td> </td>
</tr> </tr>

View File

@@ -397,24 +397,6 @@
</li> </li>
<li>
<span class='name'>hy_show_stats</span>
<span class='type'>(<tt>Boolean</tt>)</span>
<em class="default">(defaults to: <tt>false</tt>)</em>
&mdash;
<div class='inline'>
<p>whether we want to display the statistics page</p>
</div>
</li>
<li> <li>
<span class='name'>hy_stats_socket</span> <span class='name'>hy_stats_socket</span>
@@ -873,7 +855,7 @@
<span class='type'>(<tt>Boolean</tt>)</span> <span class='type'>(<tt>Boolean</tt>)</span>
<em class="default">(defaults to: <tt>false</tt>)</em> <em class="default">(defaults to: <tt>true</tt>)</em>
&mdash; &mdash;
@@ -912,6 +894,7 @@
<pre class="lines"> <pre class="lines">
59
60 60
61 61
62 62
@@ -1002,12 +985,10 @@
147 147
148 148
149 149
150 150</pre>
151
152</pre>
</td> </td>
<td> <td>
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 60</span> <pre class="code"><span class="info file"># File 'manifests/params.pp', line 59</span>
class confdroid_haproxy::params ( class confdroid_haproxy::params (
@@ -1024,7 +1005,7 @@ class confdroid_haproxy::params (
Boolean $hy_manage_fail2ban = false, Boolean $hy_manage_fail2ban = false,
# selinux # selinux
Boolean $hy_selinux_allow_stats = false, Boolean $hy_selinux_allow_stats = true,
# main config # main config
String $hy_http_port = &#39;80&#39;, String $hy_http_port = &#39;80&#39;,
@@ -1033,7 +1014,6 @@ class confdroid_haproxy::params (
String $hy_chroot = &#39;/var/lib/haproxy&#39;, String $hy_chroot = &#39;/var/lib/haproxy&#39;,
String $hy_pid = &#39;/var/run/haproxy.pid&#39;, String $hy_pid = &#39;/var/run/haproxy.pid&#39;,
String $hy_maxconn = &#39;4000&#39;, String $hy_maxconn = &#39;4000&#39;,
Boolean $hy_show_stats = false,
String $hy_stats_socket = &#39;/var/lib/haproxy/stats&#39;, String $hy_stats_socket = &#39;/var/lib/haproxy/stats&#39;,
String $hy_default_mode = &#39;tcp&#39;, String $hy_default_mode = &#39;tcp&#39;,
Boolean $hy_use_http_server_close = false, Boolean $hy_use_http_server_close = false,

View File

@@ -71,7 +71,7 @@ class confdroid_haproxy::params (
Boolean $hy_manage_fail2ban = false, Boolean $hy_manage_fail2ban = false,
# selinux # selinux
Boolean $hy_selinux_allow_stats = false, Boolean $hy_selinux_allow_stats = true,
# main config # main config
String $hy_http_port = '80', String $hy_http_port = '80',