issue #32
This commit is contained in:
parent
5c491f749a
commit
79819aeacb
6 changed files with 41 additions and 20 deletions
|
|
@ -1,10 +1,11 @@
|
||||||
# Docker environment variables
|
# Docker environment variables
|
||||||
|
|
||||||
| Environment Variable | Description | Default |
|
| Environment Variable | Description | Default |
|
||||||
|-------------------------------|-------------------------------------------------------------------------------------------------|------------------|
|
|---------------------------------|-------------------------------------------------------------------------------------------------|------------------|
|
||||||
| EASYHAPROXY_DISCOVER | How the services will be discovered to create `haproxy.cfg`: `static`, `docker`, `swarm` or `kubernetes` | **required** |
|
| EASYHAPROXY_DISCOVER | How the services will be discovered to create `haproxy.cfg`: `static`, `docker`, `swarm` or `kubernetes` | **required** |
|
||||||
| EASYHAPROXY_LABEL_PREFIX | (Optional) The key will search for matching resources. | `easyhaproxy` |
|
| EASYHAPROXY_LABEL_PREFIX | (Optional) The key will search for matching resources. | `easyhaproxy` |
|
||||||
| EASYHAPROXY_LETSENCRYPT_EMAIL | (Optional) The email will be used to request the certificate to Letsencrypt | *empty* |
|
| EASYHAPROXY_LETSENCRYPT_EMAIL | (Optional) The email will be used to request the certificate to Letsencrypt | *empty* |
|
||||||
|
| EASYHAPROXY_LETSENCRYPT_STAGING | (Optional) If true, will try to connect to the Letsencrypt test server | false |
|
||||||
| EASYHAPROXY_SSL_MODE | (Optional) `strict` supports only the most recent TLS version; `default` good SSL integration with recent browsers; `loose` supports all old SSL protocols for old browsers (not recommended). | `default`|
|
| EASYHAPROXY_SSL_MODE | (Optional) `strict` supports only the most recent TLS version; `default` good SSL integration with recent browsers; `loose` supports all old SSL protocols for old browsers (not recommended). | `default`|
|
||||||
| EASYHAPROXY_REFRESH_CONF | (Optional) Check configuration every N seconds. | 10 |
|
| EASYHAPROXY_REFRESH_CONF | (Optional) Check configuration every N seconds. | 10 |
|
||||||
| EASYHAPROXY_LOG_LEVEL | (Optional) The log level for EasyHAproxy messages. Available: TRACE,DEBUG,INFO,WARN,ERROR,FATAL | DEBUG |
|
| EASYHAPROXY_LOG_LEVEL | (Optional) The log level for EasyHAproxy messages. Available: TRACE,DEBUG,INFO,WARN,ERROR,FATAL | DEBUG |
|
||||||
|
|
|
||||||
|
|
@ -49,7 +49,7 @@ class HaproxyConfigGenerator:
|
||||||
def __init__(self, mapping):
|
def __init__(self, mapping):
|
||||||
self.mapping = mapping
|
self.mapping = mapping
|
||||||
self.mapping.setdefault("ssl_mode", 'default')
|
self.mapping.setdefault("ssl_mode", 'default')
|
||||||
self.mapping.setdefault("letsencrypt", {"email": ""})
|
self.mapping.setdefault("letsencrypt", {"email": "", "staging": False})
|
||||||
self.mapping["ssl_mode"] = self.mapping["ssl_mode"].lower()
|
self.mapping["ssl_mode"] = self.mapping["ssl_mode"].lower()
|
||||||
self.label = DockerLabelHandler(mapping['lookup_label'] if 'lookup_label' in mapping else "easyhaproxy")
|
self.label = DockerLabelHandler(mapping['lookup_label'] if 'lookup_label' in mapping else "easyhaproxy")
|
||||||
self.letsencrypt_hosts = []
|
self.letsencrypt_hosts = []
|
||||||
|
|
|
||||||
|
|
@ -174,9 +174,10 @@ class DaemonizeHAProxy:
|
||||||
|
|
||||||
|
|
||||||
class Certbot:
|
class Certbot:
|
||||||
def __init__(self, certs, email):
|
def __init__(self, certs, email, staging):
|
||||||
self.certs = certs
|
self.certs = certs
|
||||||
self.email = email
|
self.email = email
|
||||||
|
self.staging = staging
|
||||||
|
|
||||||
def check_certificates(self, hosts):
|
def check_certificates(self, hosts):
|
||||||
if self.email == "" or len(hosts) == 0:
|
if self.email == "" or len(hosts) == 0:
|
||||||
|
|
@ -201,7 +202,7 @@ class Certbot:
|
||||||
Functions.log(Functions.CERTBOT_LOG, Functions.DEBUG, "Renew certificate for %s" % (host))
|
Functions.log(Functions.CERTBOT_LOG, Functions.DEBUG, "Renew certificate for %s" % (host))
|
||||||
renew_certs.append(host_arg)
|
renew_certs.append(host_arg)
|
||||||
|
|
||||||
certbot_certonly = ('/usr/bin/certbot certonly '
|
certbot_certonly = ('/usr/bin/certbot certonly {staging}'
|
||||||
' --standalone'
|
' --standalone'
|
||||||
' --preferred-challenges http'
|
' --preferred-challenges http'
|
||||||
' --http-01-port 2080'
|
' --http-01-port 2080'
|
||||||
|
|
@ -210,7 +211,9 @@ class Certbot:
|
||||||
' --no-eff-email'
|
' --no-eff-email'
|
||||||
' --non-interactive'
|
' --non-interactive'
|
||||||
' --max-log-backups=0'
|
' --max-log-backups=0'
|
||||||
' %s --email %s' % (' '.join(request_certs), self.email)
|
' {certs} --email {email}'.format(certs = ' '.join(request_certs),
|
||||||
|
email = self.email,
|
||||||
|
staging = '--staging' if self.staging else '')
|
||||||
)
|
)
|
||||||
|
|
||||||
ret_reload = False
|
ret_reload = False
|
||||||
|
|
|
||||||
|
|
@ -22,7 +22,7 @@ def start():
|
||||||
haproxy.haproxy("start")
|
haproxy.haproxy("start")
|
||||||
haproxy.sleep()
|
haproxy.sleep()
|
||||||
|
|
||||||
certbot = Certbot(Consts.certs_letsencrypt, os.getenv("EASYHAPROXY_LETSENCRYPT_EMAIL"))
|
certbot = Certbot(Consts.certs_letsencrypt, os.getenv("EASYHAPROXY_LETSENCRYPT_EMAIL"), os.getenv("EASYHAPROXY_LETSENCRYPT_STAGING", "false").lower() in ["true", "1", "yes"])
|
||||||
|
|
||||||
while True:
|
while True:
|
||||||
if old_haproxy is not None:
|
if old_haproxy is not None:
|
||||||
|
|
|
||||||
|
|
@ -27,7 +27,8 @@ class ContainerEnv:
|
||||||
env_vars["lookup_label"] = os.getenv("EASYHAPROXY_LABEL_PREFIX") if os.getenv("EASYHAPROXY_LABEL_PREFIX") else "easyhaproxy"
|
env_vars["lookup_label"] = os.getenv("EASYHAPROXY_LABEL_PREFIX") if os.getenv("EASYHAPROXY_LABEL_PREFIX") else "easyhaproxy"
|
||||||
if (os.getenv("EASYHAPROXY_LETSENCRYPT_EMAIL")):
|
if (os.getenv("EASYHAPROXY_LETSENCRYPT_EMAIL")):
|
||||||
env_vars["letsencrypt"] = {
|
env_vars["letsencrypt"] = {
|
||||||
"email": os.getenv("EASYHAPROXY_LETSENCRYPT_EMAIL")
|
"email": os.getenv("EASYHAPROXY_LETSENCRYPT_EMAIL"),
|
||||||
|
"staging": os.getenv("EASYHAPROXY_LETSENCRYPT_STAGING", "false").lower() in ["true", "1", "yes"]
|
||||||
}
|
}
|
||||||
|
|
||||||
return env_vars
|
return env_vars
|
||||||
|
|
|
||||||
|
|
@ -95,8 +95,24 @@ def test_container_env_stats_password():
|
||||||
"lookup_label": "easyhaproxy",
|
"lookup_label": "easyhaproxy",
|
||||||
"letsencrypt": {
|
"letsencrypt": {
|
||||||
"email": "acme@example.org",
|
"email": "acme@example.org",
|
||||||
|
"staging": False
|
||||||
}
|
}
|
||||||
} == ContainerEnv.read()
|
} == ContainerEnv.read()
|
||||||
finally:
|
finally:
|
||||||
os.environ['EASYHAPROXY_LETSENCRYPT_EMAIL'] = ''
|
os.environ['EASYHAPROXY_LETSENCRYPT_EMAIL'] = ''
|
||||||
|
|
||||||
|
def test_container_env_letsencrypt():
|
||||||
|
os.environ['EASYHAPROXY_LETSENCRYPT_EMAIL'] = 'acme@example.org'
|
||||||
|
os.environ['EASYHAPROXY_LETSENCRYPT_STAGING'] = 'true'
|
||||||
|
try:
|
||||||
|
assert {
|
||||||
|
"customerrors": False,
|
||||||
|
"ssl_mode": "default",
|
||||||
|
"lookup_label": "easyhaproxy",
|
||||||
|
"letsencrypt": {
|
||||||
|
"email": "acme@example.org",
|
||||||
|
"staging": True
|
||||||
|
}
|
||||||
|
} == ContainerEnv.read()
|
||||||
|
finally:
|
||||||
|
os.environ['EASYHAPROXY_LETSENCRYPT_EMAIL'] = ''
|
||||||
Loading…
Add table
Add a link
Reference in a new issue