- Added individual markdown files with examples, configuration options, and HAProxy outputs for each plugin. - Updated `README.md` to link plugin-specific documentation. - Enhanced `plugins.md` to summarize plugin features and usage. - Included Docker, Kubernetes, Swarm, and static configuration examples for all plugins.
2.8 KiB
2.8 KiB
Deny Pages Plugin
Type: Domain Plugin Runs: Once for each discovered domain/host
Overview
The Deny Pages plugin blocks access to specific paths for a domain, returning a configurable HTTP status code.
Why Use It
Protect admin panels, internal APIs, or debugging endpoints from public access.
Configuration Options
| Option | Description | Default |
|---|---|---|
enabled |
Enable/disable plugin | true |
paths |
Comma-separated list of paths to block | (required) |
status_code |
HTTP status code to return | 403 |
Configuration Examples
Docker/Docker Compose (Basic)
services:
webapp:
labels:
easyhaproxy.http.host: example.com
easyhaproxy.http.plugins: deny_pages
easyhaproxy.http.plugin.deny_pages.paths: /admin,/private,/debug
easyhaproxy.http.plugin.deny_pages.status_code: 404
WordPress Protection
labels:
easyhaproxy.http.host: wordpress.example.com
easyhaproxy.http.plugins: deny_pages
easyhaproxy.http.plugin.deny_pages.paths: /wp-admin,/wp-login.php,/.env
easyhaproxy.http.plugin.deny_pages.status_code: 404
Kubernetes Annotations
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
annotations:
easyhaproxy.plugins: "deny_pages"
easyhaproxy.plugin.deny_pages.paths: "/admin,/private"
easyhaproxy.plugin.deny_pages.status_code: "403"
spec:
rules:
- host: example.com
http:
paths:
- path: /
backend:
service:
name: webapp
port:
number: 80
Static YAML Configuration
# /etc/haproxy/static/config.yaml
easymapping:
- host: example.com
port: 80
container: webapp:80
plugins:
- deny_pages
plugin_config:
deny_pages:
paths: /admin,/private,/debug
status_code: 403
Multiple Plugins (with Cloudflare)
labels:
easyhaproxy.http.host: secure-app.com
easyhaproxy.http.plugins: cloudflare,deny_pages
easyhaproxy.http.plugin.deny_pages.paths: /admin,/config
easyhaproxy.http.plugin.deny_pages.status_code: 403
Generated HAProxy Configuration
# Deny Pages - Block specific paths
acl denied_path path_beg /admin /private /debug
http-request deny deny_status 404 if denied_path
Important Notes
- The plugin runs once per domain during the discovery cycle
- Path matching uses
path_beg(prefix matching), so/adminblocks/admin/*too - Consider using
404instead of403to hide the existence of blocked paths - Works well in combination with other security plugins