Add ssl-check
This commit is contained in:
parent
173a31ea80
commit
6e367174d4
7 changed files with 35 additions and 17 deletions
|
|
@ -117,7 +117,7 @@ class HaproxyConfigGenerator:
|
|||
if port not in easymapping:
|
||||
easymapping[port] = {
|
||||
"mode": mode,
|
||||
"health-check": "",
|
||||
"ssl-check": "",
|
||||
"port": port,
|
||||
"hosts": dict(),
|
||||
"redirect": dict(),
|
||||
|
|
@ -129,8 +129,8 @@ class HaproxyConfigGenerator:
|
|||
"80"
|
||||
)
|
||||
|
||||
easymapping[port]["health-check"] = self.label.get(
|
||||
self.label.create([definition, "health-check"]),
|
||||
easymapping[port]["ssl-check"] = self.label.get(
|
||||
self.label.create([definition, "ssl-check"]),
|
||||
""
|
||||
)
|
||||
|
||||
|
|
@ -145,6 +145,10 @@ class HaproxyConfigGenerator:
|
|||
easymapping[port]["hosts"][hostname]["redirect_ssl"] = self.label.get_bool(
|
||||
self.label.create([definition, "redirect_ssl"])
|
||||
)
|
||||
easymapping[port]["hosts"][hostname]["balance"] = self.label.get(
|
||||
self.label.create([definition, "balance"]),
|
||||
"roundrobin"
|
||||
)
|
||||
|
||||
easymapping[port]["redirect"] = self.label.get_json(
|
||||
self.label.create([definition, "redirect"])
|
||||
|
|
@ -154,7 +158,7 @@ class HaproxyConfigGenerator:
|
|||
if "443" not in easymapping:
|
||||
easymapping["443"] = {
|
||||
"mode": "http",
|
||||
"health-check": "ssl",
|
||||
"ssl-check": "ssl",
|
||||
"port": "443",
|
||||
"hosts": dict(),
|
||||
"redirect": dict(),
|
||||
|
|
|
|||
|
|
@ -188,9 +188,9 @@ class Kubernetes(ProcessorInterface):
|
|||
self.cert_cache = {}
|
||||
super().__init__()
|
||||
|
||||
def _check_annotation(self, annotations, key):
|
||||
def _check_annotation(self, annotations, key, default = None):
|
||||
if key not in annotations:
|
||||
return None
|
||||
return default
|
||||
return annotations[key]
|
||||
|
||||
def inspect_network(self):
|
||||
|
|
@ -258,6 +258,8 @@ class Kubernetes(ProcessorInterface):
|
|||
rule_data["%s.redirect" % (definition)] = redirect
|
||||
if mode is not None:
|
||||
rule_data["%s.mode" % (definition)] = mode
|
||||
rule_data["%s.balance" % (definition)] = self._check_annotation(ingress.metadata.annotations, "easyhaproxy.balance", "roundrobin")
|
||||
|
||||
|
||||
service_name = rule.http.paths[0].backend.service.name
|
||||
try:
|
||||
|
|
|
|||
|
|
@ -59,7 +59,7 @@ frontend {{ mode }}_in_{{ o["port"] }}
|
|||
{% for k in o["hosts"] -%}
|
||||
{% set host = k.replace(".", "_") + "_{0}".format(o["port"]) %}
|
||||
backend srv_{{ host }}
|
||||
balance roundrobin
|
||||
balance {{ o["balance"] | default("roundrobin") }}
|
||||
mode {{ mode }}
|
||||
{% if mode == "http" %}
|
||||
option forwardfor
|
||||
|
|
@ -67,10 +67,10 @@ backend srv_{{ host }}
|
|||
http-request add-header X-Forwarded-Proto https if { ssl_fc }
|
||||
{% elif mode == "tcp" %}
|
||||
option tcp-check
|
||||
tcp-check connect{{ " ssl" if o["health-check"] == "ssl" }}
|
||||
tcp-check connect{{ " ssl" if o["ssl-check"] == "ssl" }}
|
||||
{% endif %}
|
||||
{% for c in o["hosts"][k]["containers"] %}
|
||||
server srv-{{ loop.index0 }} {{ c }} check weight 1{{ " verify none" if o["health-check"] == "ssl" }}
|
||||
server srv-{{ loop.index0 }} {{ c }} check weight 1{{ " verify none" if o["ssl-check"] == "ssl" }}
|
||||
{% endfor %}
|
||||
{% endfor %}
|
||||
{% endfor %}
|
||||
|
|
|
|||
2
src/tests/fixtures/services-tcp
vendored
2
src/tests/fixtures/services-tcp
vendored
|
|
@ -1,2 +1,2 @@
|
|||
{"test_agent": {"easyhaproxy.agent.host":"agent.quantum.local","easyhaproxy.agent.localport":"9001","easyhaproxy.agent.mode":"tcp","easyhaproxy.agent.port":"31339","com.docker.stack.image":"portainer/agent:1.5.1","com.docker.stack.namespace":"test", "easyhaproxy.agent.health-check":"ssl"},
|
||||
{"test_agent": {"easyhaproxy.agent.host":"agent.quantum.local","easyhaproxy.agent.localport":"9001","easyhaproxy.agent.mode":"tcp","easyhaproxy.agent.port":"31339","com.docker.stack.image":"portainer/agent:1.5.1","com.docker.stack.namespace":"test", "easyhaproxy.agent.ssl-check":"ssl"},
|
||||
"test_proxy": {"com.docker.stack.image":"byjg/easy-haproxy:local","com.docker.stack.namespace":"test"}}
|
||||
|
|
@ -110,10 +110,11 @@ def test_parser_finds_services_raw():
|
|||
parsed_object = [
|
||||
{
|
||||
"mode":"tcp",
|
||||
"health-check":"",
|
||||
"ssl-check":"",
|
||||
"port":"31339",
|
||||
"hosts":{
|
||||
"agent.quantum.example.org": {
|
||||
"balance": "roundrobin",
|
||||
"containers": [
|
||||
"my-stack_agent:9001"
|
||||
],
|
||||
|
|
@ -127,10 +128,11 @@ def test_parser_finds_services_raw():
|
|||
},
|
||||
{
|
||||
"mode":"http",
|
||||
"health-check":"",
|
||||
"ssl-check":"",
|
||||
"port":"31337",
|
||||
"hosts":{
|
||||
"cadvisor.quantum.example.org":{
|
||||
"balance": "roundrobin",
|
||||
"containers": [
|
||||
"my-stack_cadvisor:8080"
|
||||
],
|
||||
|
|
@ -138,6 +140,7 @@ def test_parser_finds_services_raw():
|
|||
"redirect_ssl": False
|
||||
},
|
||||
"node-exporter.quantum.example.org":{
|
||||
"balance": "roundrobin",
|
||||
"containers": [
|
||||
"my-stack_node-exporter:9100"
|
||||
],
|
||||
|
|
@ -151,10 +154,11 @@ def test_parser_finds_services_raw():
|
|||
},
|
||||
{
|
||||
"mode":"http",
|
||||
"health-check":"",
|
||||
"ssl-check":"",
|
||||
"port":"443",
|
||||
"hosts":{
|
||||
"node-exporter.quantum.example.org": {
|
||||
"balance": "roundrobin",
|
||||
"containers": [
|
||||
"my-stack_node-exporter:9100"
|
||||
],
|
||||
|
|
@ -162,6 +166,7 @@ def test_parser_finds_services_raw():
|
|||
"redirect_ssl": False
|
||||
},
|
||||
"www.somehost.com.br":{
|
||||
"balance": "roundrobin",
|
||||
"containers": [
|
||||
"some-service:80"
|
||||
],
|
||||
|
|
@ -180,10 +185,11 @@ def test_parser_finds_services_raw():
|
|||
},
|
||||
{
|
||||
"mode":"http",
|
||||
"health-check":"",
|
||||
"ssl-check":"",
|
||||
"port":"80",
|
||||
"hosts":{
|
||||
"www.somehost.com.br":{
|
||||
"balance": "roundrobin",
|
||||
"containers": [
|
||||
"some-service:80"
|
||||
],
|
||||
|
|
@ -444,9 +450,10 @@ def test_parser_finds_services_clone_to_ssl_raw():
|
|||
|
||||
parsed_object = [
|
||||
{
|
||||
"health-check":"",
|
||||
"ssl-check":"",
|
||||
"hosts":{
|
||||
"host2.local":{
|
||||
"balance":"roundrobin",
|
||||
"containers":[
|
||||
"10.152.183.215:8080"
|
||||
],
|
||||
|
|
@ -454,6 +461,7 @@ def test_parser_finds_services_clone_to_ssl_raw():
|
|||
"redirect_ssl": False
|
||||
},
|
||||
"valida.me":{
|
||||
"balance":"roundrobin",
|
||||
"containers":[
|
||||
"10.152.183.62:8080"
|
||||
],
|
||||
|
|
@ -461,6 +469,7 @@ def test_parser_finds_services_clone_to_ssl_raw():
|
|||
"redirect_ssl": False
|
||||
},
|
||||
"www.valida.me":{
|
||||
"balance":"roundrobin",
|
||||
"containers":[
|
||||
"10.152.183.62:8080"
|
||||
],
|
||||
|
|
@ -475,9 +484,10 @@ def test_parser_finds_services_clone_to_ssl_raw():
|
|||
}
|
||||
},
|
||||
{
|
||||
"health-check":"ssl",
|
||||
"ssl-check":"ssl",
|
||||
"hosts":{
|
||||
"host2.local":{
|
||||
"balance":"roundrobin",
|
||||
"containers":[
|
||||
"10.152.183.215:8080"
|
||||
],
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue