1
0
Fork 0
docker-easy-haproxy/docs/plugins/deny-pages.md
Joao Gilberto Magalhaes b4944ac544 Add use_builtin_ips support and reorganize plugin documentation
- Enhanced Cloudflare Plugin with `use_builtin_ips` option to automatically use and update built-in IP ranges.
- Updated Cloudflare IP restoration logic, including metadata and HAProxy config generation.
- Reorganized plugin documentation with sidebar positions for improved accessibility.
- Extended Cloudflare documentation to detail built-in IP ranges, examples, and configurations.
- Added new test cases to validate `use_builtin_ips` functionality and file handling.
2025-12-01 18:00:52 -05:00

2.9 KiB

sidebar_position
4

Deny Pages Plugin

Type: Domain Plugin Runs: Once for each discovered domain/host

Overview

The Deny Pages plugin blocks access to specific paths for a domain, returning a configurable HTTP status code.

Why Use It

Protect admin panels, internal APIs, or debugging endpoints from public access.

Configuration Options

Option Description Default
enabled Enable/disable plugin true
paths Comma-separated list of paths to block (required)
status_code HTTP status code to return 403

Configuration Examples

Docker/Docker Compose (Basic)

services:
  webapp:
    labels:
      easyhaproxy.http.host: example.com
      easyhaproxy.http.plugins: deny_pages
      easyhaproxy.http.plugin.deny_pages.paths: /admin,/private,/debug
      easyhaproxy.http.plugin.deny_pages.status_code: 404

WordPress Protection

labels:
  easyhaproxy.http.host: wordpress.example.com
  easyhaproxy.http.plugins: deny_pages
  easyhaproxy.http.plugin.deny_pages.paths: /wp-admin,/wp-login.php,/.env
  easyhaproxy.http.plugin.deny_pages.status_code: 404

Kubernetes Annotations

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  annotations:
    easyhaproxy.plugins: "deny_pages"
    easyhaproxy.plugin.deny_pages.paths: "/admin,/private"
    easyhaproxy.plugin.deny_pages.status_code: "403"
spec:
  rules:
    - host: example.com
      http:
        paths:
          - path: /
            backend:
              service:
                name: webapp
                port:
                  number: 80

Static YAML Configuration

# /etc/haproxy/static/config.yaml
easymapping:
  - host: example.com
    port: 80
    container: webapp:80
    plugins:
      - deny_pages
    plugin_config:
      deny_pages:
        paths: /admin,/private,/debug
        status_code: 403

Multiple Plugins (with Cloudflare)

labels:
  easyhaproxy.http.host: secure-app.com
  easyhaproxy.http.plugins: cloudflare,deny_pages
  easyhaproxy.http.plugin.deny_pages.paths: /admin,/config
  easyhaproxy.http.plugin.deny_pages.status_code: 403

Generated HAProxy Configuration

# Deny Pages - Block specific paths
acl denied_path path_beg /admin /private /debug
http-request deny deny_status 404 if denied_path

Important Notes

  • The plugin runs once per domain during the discovery cycle
  • Path matching uses path_beg (prefix matching), so /admin blocks /admin/* too
  • Consider using 404 instead of 403 to hide the existence of blocked paths
  • Works well in combination with other security plugins