1
0
Fork 0

Update: more tests and ssl health-check

- restructure more tests for the "mode http"
 - add tests tests for "mode tcp"
 - add the ability to ssl health check on a backend (in mode tcp)
This commit is contained in:
till 2020-06-05 16:27:02 +02:00
parent 08de132450
commit 75deebc783
No known key found for this signature in database
GPG key ID: B119050E2EBA1DC5
5 changed files with 59 additions and 12 deletions

View file

@ -86,7 +86,7 @@ Important: easyhaproxy needs to be in the same network of the containers or othe
| com.byjg.easyhaproxy.host.[definition] | What is the host that the HAProxy will listen to. | | com.byjg.easyhaproxy.host.[definition] | What is the host that the HAProxy will listen to. |
| com.byjg.easyhaproxy.redirect.[definition] | (Optional) Host redirects from connections in the port defined above. | | com.byjg.easyhaproxy.redirect.[definition] | (Optional) Host redirects from connections in the port defined above. |
| com.byjg.easyhaproxy.sslcert.[definition] | (Optional) Cert PEM Base64 encoded. | | com.byjg.easyhaproxy.sslcert.[definition] | (Optional) Cert PEM Base64 encoded. |
| com.byjg.easyhaproxy.health-check.[definition] | (Optional) `ssl`, enable health check via SSL in `mode tcp` (Defaults to "empty") |
Note: if you are deploying a stack set labels at the `deploy` level: Note: if you are deploying a stack set labels at the `deploy` level:
@ -135,11 +135,14 @@ Used to pass on SSL-termination to a backend:
docker run \ docker run \
-l com.byjg.easyhaproxy.defintions=tcp-service \ -l com.byjg.easyhaproxy.defintions=tcp-service \
-l com.byjg.easyhaproxy.mode.tcp-service=tcp \ -l com.byjg.easyhaproxy.mode.tcp-service=tcp \
-l com.byjg.easyhaproxy.health-check.tcp-service=ssl \
-l com.byjg.easyhaproxy.port.tcp-service=443 -l com.byjg.easyhaproxy.port.tcp-service=443
.... \ .... \
some/tcp-service some/tcp-service
``` ```
- enable health-check via SSL on the backend with the optional `health-check` label
### Redirect Example: ### Redirect Example:
```bash ```bash

View file

@ -101,6 +101,7 @@ class HaproxyConfigGenerator:
if key not in easymapping: if key not in easymapping:
easymapping[key] = { easymapping[key] = {
"mode": mode, "mode": mode,
"health-check": "",
"port": port, "port": port,
"hosts": dict(), "hosts": dict(),
"redirect": dict(), "redirect": dict(),
@ -112,6 +113,11 @@ class HaproxyConfigGenerator:
"80" "80"
) )
easymapping[key]["health-check"] = self.label.get(
self.label.create(["health-check", definition]),
""
)
easymapping[key]["hosts"][d[host_label]] = "{}:{}".format(container, ct_port) easymapping[key]["hosts"][d[host_label]] = "{}:{}".format(container, ct_port)
# handle SSL # handle SSL

View file

@ -60,8 +60,8 @@ backend srv_{{ host }}
http-request add-header X-Forwarded-Proto https if { ssl_fc } http-request add-header X-Forwarded-Proto https if { ssl_fc }
{% elif mode == "tcp" %} {% elif mode == "tcp" %}
option tcp-check option tcp-check
tcp-check connect tcp-check connect{{ " ssl" if o["health-check"] == "ssl" }}
{% endif %} {% endif %}
server srv {{ o["hosts"][k] }} check weight 1 server srv {{ o["hosts"][k] }} check weight 1{{ " verify none" if o["health-check"] == "ssl" }}
{% endfor %} {% endfor %}
{% endfor %} {% endfor %}

View file

@ -1,2 +1,2 @@
test_agent={"com.byjg.easyhaproxy.definitions":"agent","com.byjg.easyhaproxy.host.agent":"agent.quantum.local","com.byjg.easyhaproxy.localport.agent":"9001","com.byjg.easyhaproxy.mode.agent":"tcp","com.byjg.easyhaproxy.port.agent":"31339","com.docker.stack.image":"portainer/agent:1.5.1","com.docker.stack.namespace":"test","com.planetary-quantum":"monitoring"} test_agent={"com.byjg.easyhaproxy.definitions":"agent","com.byjg.easyhaproxy.host.agent":"agent.quantum.local","com.byjg.easyhaproxy.localport.agent":"9001","com.byjg.easyhaproxy.mode.agent":"tcp","com.byjg.easyhaproxy.port.agent":"31339","com.docker.stack.image":"portainer/agent:1.5.1","com.docker.stack.namespace":"test", "com.byjg.easyhaproxy.health-check.agent":"ssl"}
test_proxy={"com.docker.stack.image":"byjg/easy-haproxy:local","com.docker.stack.namespace":"test"} test_proxy={"com.docker.stack.image":"byjg/easy-haproxy:local","com.docker.stack.namespace":"test"}

View file

@ -59,12 +59,50 @@ def test_parser_static():
assert "redirect prefix http://host1.com.br code 301 if { hdr(host) -i www.host1.com.br }" in haproxy_config assert "redirect prefix http://host1.com.br code 301 if { hdr(host) -i www.host1.com.br }" in haproxy_config
# assert that we found the services # assert that we found the services
assert "frontend http_in_80_1" in haproxy_config frontend_http_cfg = "frontend http_in_80_1\n"
assert "bind *:80" frontend_http_cfg += " bind *:80"
assert "frontend http_in_443_2" in haproxy_config assert frontend_http_cfg in haproxy_config
assert "bind *:443"
assert "frontend http_in_8080_3" in haproxy_config
assert "bind :*8080"
# verify ssl config frontend_https_cfg = "frontend http_in_443_2\n"
assert "frontend http_in_443_2\n bind *:443 ssl crt BASE64_PEM_CERTIFICATE" in haproxy_config frontend_https_cfg += " bind *:443"
assert frontend_https_cfg in haproxy_config
# print(haproxy_config)
frontend_http8080_cfg = "frontend http_in_8080_3\n"
frontend_http8080_cfg += " bind *:8080"
assert frontend_http8080_cfg in haproxy_config
# verify ssl config with certificate
frontend_ssl_cfg = "frontend http_in_443_2\n"
frontend_ssl_cfg += " bind *:443 ssl crt BASE64_PEM_CERTIFICATE"
assert frontend_ssl_cfg in haproxy_config
def test_parser_tcp():
lineList = load_fixture("services-tcp")
result = {
"customerrors": False
}
cfg = easymapping.HaproxyConfigGenerator(result)
haproxy_config = cfg.generate(lineList)
# print(haproxy_config)
frontend_cfg = "frontend tcp_in_31339_1\n"
frontend_cfg += " bind *:31339\n"
frontend_cfg += " mode tcp\n"
frontend_cfg += " option tcplog\n"
frontend_cfg += " log global\n"
frontend_cfg += " default_backend srv_agent_quantum_local_31339_1\n\n"
assert frontend_cfg in haproxy_config
backend_cfg = "backend srv_agent_quantum_local_31339_1\n"
backend_cfg += " balance roundrobin\n"
backend_cfg += " mode tcp\n"
backend_cfg += " option tcp-check\n"
backend_cfg += " tcp-check connect ssl\n"
backend_cfg += " server srv test_agent:9001 check weight 1 verify none"
assert backend_cfg in haproxy_config