add nginx, sshd, ssl roles
This commit is contained in:
@@ -0,0 +1,13 @@
|
||||
---
|
||||
- name: validate haproxy config
|
||||
ansible.builtin.command: haproxy -c -f /etc/haproxy/haproxy.cfg
|
||||
changed_when: false
|
||||
listen: restart haproxy
|
||||
|
||||
- name: restart haproxy systemd service unit
|
||||
ansible.builtin.systemd_service:
|
||||
name: haproxy
|
||||
daemon_reload: true
|
||||
state: restarted
|
||||
enabled: true
|
||||
listen: restart haproxy
|
||||
@@ -0,0 +1,10 @@
|
||||
---
|
||||
- name: render haproxy config
|
||||
ansible.builtin.template:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/haproxy/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
loop: "{{ query('fileglob', role_path + '/templates/' + inventory_hostname + '/*.cfg.j2') }}"
|
||||
notify: restart haproxy
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: install haproxy
|
||||
ansible.builtin.apt:
|
||||
name: haproxy
|
||||
state: latest
|
||||
update_cache: true
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: include install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: include configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
@@ -0,0 +1,90 @@
|
||||
global
|
||||
log /dev/log local2
|
||||
chroot /var/lib/haproxy
|
||||
maxconn 4000
|
||||
user haproxy
|
||||
group haproxy
|
||||
daemon
|
||||
stats socket /var/lib/haproxy/stats mode 660 level admin
|
||||
|
||||
defaults
|
||||
log global
|
||||
mode tcp
|
||||
option tcplog
|
||||
option dontlognull
|
||||
retries 3
|
||||
timeout connect 5s
|
||||
timeout client 1h
|
||||
timeout server 1h
|
||||
timeout check 10s
|
||||
|
||||
frontend http_frontend
|
||||
bind 127.0.0.1:10080
|
||||
mode http
|
||||
option httplog
|
||||
acl host_dttx hdr_end(host) -m end dttx.ru
|
||||
use_backend dttx_http_srv if host_dttx
|
||||
default_backend oyacoi_http_srv
|
||||
|
||||
backend oyacoi_http_srv
|
||||
mode http
|
||||
server oyacoi_srv {{ hostvars['nginx']['container_ip'] }}:81 send-proxy-v2
|
||||
|
||||
backend dttx_http_srv
|
||||
mode http
|
||||
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:81 send-proxy-v2
|
||||
|
||||
frontend https_frontend
|
||||
bind 127.0.0.1:10443
|
||||
mode tcp
|
||||
option tcplog
|
||||
tcp-request inspect-delay 5s
|
||||
tcp-request content accept if { req_ssl_hello_type 1 }
|
||||
acl host_dttx req_ssl_sni -m end dttx.ru
|
||||
acl host_telemt req_ssl_sni -m end regionculture.ru
|
||||
use_backend dttx_https_srv if host_dttx
|
||||
use_backend telemt_https_srv if host_telemt
|
||||
default_backend oyacoi_https_srv
|
||||
|
||||
backend oyacoi_https_srv
|
||||
mode tcp
|
||||
server nginx_srv {{ hostvars['nginx']['container_ip'] }}:444 send-proxy-v2
|
||||
|
||||
backend dttx_https_srv
|
||||
mode tcp
|
||||
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:444 send-proxy-v2
|
||||
|
||||
backend telemt_https_srv
|
||||
mode tcp
|
||||
option tcp-check
|
||||
server telemt_srv {{ hostvars['vector']['container_ip'] }}:8080 check send-proxy-v2
|
||||
server telemt_srv_backup {{ hostvars['dev']['container_ip'] }}:8080 check send-proxy-v2 backup
|
||||
|
||||
listen mcsmanager_service
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:24444
|
||||
mode tcp
|
||||
server mcs_srv {{ hostvars['mcsmanager']['container_ip'] }}:24445 send-proxy-v2
|
||||
|
||||
listen xmpp_c2s
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5222
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5222
|
||||
|
||||
listen xmpp_legacy_ssl
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5223
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5223
|
||||
|
||||
listen xmpp_s2s
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5269
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5269
|
||||
|
||||
listen prosody_proxy65
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5000
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5000
|
||||
|
||||
listen prosody_components
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5270
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5270
|
||||
|
||||
listen prosody_bosh_http
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5280
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5280
|
||||
Reference in New Issue
Block a user