FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

robertdebock/ansible-role-haproxy: Install and configure haproxy on your system. · GitHub

Install and configure haproxy on your system.

GitHub GitLab Downloads Version

This example is taken from molecule/default/converge.yml and is tested on each push, pull request and release.

---
- name: Converge
  hosts: all
  become: true
  gather_facts: true

  roles:
    - role: robertdebock.haproxy
      haproxy_frontends:
        - name: http
          address: "*"
          port: 80
          default_backend: backend
        - name: https
          address: "*"
          port: 443
          default_backend: backend
          http_response: set-header Strict-Transport-Security max-age=63072000
          ssl: true
          crts:
            - /tmp/haproxy.keycrt
        - name: smtp
          address: "*"
          port: 25
          default_backend: smtp
          mode: tcp
        - name: prometheus
          address: "*"
          port: 8405
          mode: http
          http_request: use-service prometheus-exporter
          no_log: true
      haproxy_backend_default_balance: roundrobin
      haproxy_backends:
        - name: backend
          httpcheck: true
          # You can tell how the health check must be done.
          # This requires haproxy version 2
          # http_check:
          #   send:
          #     method: GET
          #     uri: /health.html
          #   expect: status 200
          balance: roundrobin
          # You can refer to hosts in an Ansible group.
          # The `ansible_default_ipv4` will be used as an address to connect to.
          servers: "{{ groups['all'] }}"
          port: 8080
          options:
            - check
        - name: smtp
          balance: leastconn
          mode: tcp
          # You can also refer to a list of servers.
          servers:
            - name: first
              address: "127.0.0.1"
              port: 25
            - name: second
              address: "127.0.0.2"
              port: 25
          port: 25
        - name: vault
          mode: tcp
          httpcheck: GET /v1/sys/health HTTP/1.1
          servers: "{{ groups['all'] }}"
          http_send_name_header: Host
          port: 8200
          options:
            - check
            - check-ssl
            - ssl verify none

      haproxy_listen_default_balance: roundrobin
      haproxy_listens:
        - name: listen
          address: "*"
          httpcheck: true
          listen_port: 8081
          balance: roundrobin
          # You can refer to hosts in an Ansible group.
          # The `ansible_default_ipv4` will be used as an address to connect to.
          servers: "{{ groups['all'] }}"
          port: 8080
          options:
            - maxconn 100000

The machine needs to be prepared. In CI this is done using molecule/default/prepare.yml:

---
- name: Prepare
  hosts: all
  become: true
  gather_facts: false

  roles:
    - role: robertdebock.bootstrap
    - role: robertdebock.core_dependencies
    - role: robertdebock.epel
    - role: robertdebock.buildtools
    - role: robertdebock.python_pip
    - role: robertdebock.openssl
      openssl_key_directory: /tmp
      openssl_items:
        - name: haproxy
          common_name: "{{ ansible_facts['fqdn'] }}"
    # This role is applied to serve as a mock "backend" server. See `molecule/default/verify.yml`.
    - role: robertdebock.httpd
      httpd_port: 8080

  vars:
    _httpd_data_directory:
      default: /var/www/html
      Alpine: /var/www/localhost/htdocs
      Suse: /srv/www/htdocs

    httpd_data_directory: "{{ _httpd_data_directory[ansible_facts['os_family']] | default(_httpd_data_directory['default'] ) }}"
  post_tasks:
    - name: Place health check
      ansible.builtin.copy:
        content: 'ok'
        dest: "{{ httpd_data_directory }}/health.html"

    - name: Place sample page
      ansible.builtin.copy:
        content: 'Hello world!'
        dest: "{{ httpd_data_directory }}/index.html"

Also see a full explanation and example on how to use these roles.

The default values for the variables are set in defaults/main.yml:

---
# defaults file for haproxy

# Complete HAProxy configuration as a string (alternative to individual parameters)
# If set, this will be used instead of individual parameters
# haproxy_config: |
#   global
#       log         127.0.0.1 local2
#       chroot      /var/lib/haproxy
#       pidfile     /var/run/haproxy.pid
#       maxconn     4000
#       user        haproxy
#       group       haproxy
#       daemon
#       stats       socket /var/lib/haproxy/stats

#   defaults
#       mode                    http
#       log                     global
#       option                  httplog
#       option                  dontlognull
#       option                  http-server-close
#       option                  forwardfor except 127.0.0.0/8
#       option                  redispatch
#       retries                 3
#       timeout http-request    10s
#       timeout queue           10s
#       timeout connect         10s
#       timeout client          1m
#       timeout server          1m
#       timeout http-keep-alive 10s
#       timeout check           10s
#       maxconn                 3000

#   listen stats
#       bind                0.0.0.0:1936
#       mode                http
#       stats               enable
#       stats               uri /stats

#   frontend http
#       bind *:80
#       default_backend backend
#       mode http
#       option httplog

#   backend backend
#       balance roundrobin
#       mode http
#       server server1 127.0.0.1:8080 check
#       server server2 127.0.0.2:8080 check

# Default is to use individual parameters.
haproxy_config: ""

# Configure stats in HAProxy?
haproxy_stats: true
haproxy_stats_port: 1936
haproxy_stats_bind_addr: "0.0.0.0"

# Default settings for HAProxy.
haproxy_mode: http
haproxy_globals:
  - log 127.0.0.1 local2
  - chroot /var/lib/haproxy
  - pidfile /var/run/haproxy.pid
  - maxconn 4000
  - user haproxy
  - group haproxy
  - daemon
  - stats socket /var/lib/haproxy/stats
haproxy_options:
  - httplog
  - dontlognull
  - http-server-close
  - forwardfor except 127.0.0.0/8
  - redispatch
haproxy_retries: 3
haproxy_timeout_http_request: 10s
haproxy_timeout_queue: 10s
haproxy_timeout_connect: 10s
haproxy_timeout_client: 1m
haproxy_timeout_server: 1m
haproxy_timeout_http_keep_alive: 10s
haproxy_timeout_check: 10s
haproxy_maxconn: 3000

# A list of frontends. See `molecule/default/converge.yml` for an example.
haproxy_frontends: []
haproxy_backend_default_balance: roundrobin
haproxy_backends: []

# For the listening lists:
haproxy_listen_default_balance: roundrobin
haproxy_listens: []

The following roles are used to prepare a system. You can prepare your system in another way.

Requirement GitHub GitLab
robertdebock.bootstrap
robertdebock.buildtools
robertdebock.core_dependencies
robertdebock.epel
robertdebock.httpd
robertdebock.openssl
robertdebock.python_pip

This role is part of many compatible roles. Have a look at the documentation of these roles for further information.

Here is an overview of related roles:

This role has been tested on these container images:

container tags
Debian all
EL all
Fedora all
Ubuntu jammy, noble

The minimum version of Ansible required is 2.12, tests have been done on:

  • The previous version.
  • The current version.
  • The development version.

If you find issues, please register them on GitHub.

Apache-2.0.

robertdebock

Please consider sponsoring me.

About

Install and configure haproxy on your system.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

25 stars

Watchers

3 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages


Back | FazBrowse Home | New Git URL