Puppet Class: profile::wmcs::paws::k8s::haproxy

Defined in:
modules/profile/manifests/wmcs/paws/k8s/haproxy.pp

Overview

Parameters:

  • ingress_nodes (Array[Stdlib::Fqdn]) (defaults to: lookup('profile::wmcs::paws::ingress_nodes', {default_value => ['localhost']}))
  • ingress_backend_port (Stdlib::Port) (defaults to: lookup('profile::wmcs::paws::ingress_backend_port', {default_value => 30000}))
  • ingress_bind_tls_port (Stdlib::Port) (defaults to: lookup('profile::wmcs::paws::ingress_bind_tls_port', {default_value => 443}))
  • ingress_bind_http_port (Stdlib::Port) (defaults to: lookup('profile::wmcs::paws::ingress_bind_http_port',{default_value => 80}))
  • control_nodes (Array[Stdlib::Fqdn]) (defaults to: lookup('profile::wmcs::paws::control_nodes', {default_value => ['localhost']}))
  • api_port (Stdlib::Port) (defaults to: lookup('profile::wmcs::paws::apiserver_port', {default_value => 6443}))
  • keepalived_vips (Array[Stdlib::Fqdn]) (defaults to: lookup('profile::wmcs::paws::keepalived::vips', {default_value => ['localhost']}))
  • keepalived_peers (Array[Stdlib::Fqdn]) (defaults to: lookup('profile::wmcs::paws::keepalived::peers', {default_value => ['localhost']}))
  • keepalived_password (String) (defaults to: lookup('profile::wmcs::paws::keepalived::password', {default_value => 'notarealpassword'}))


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
# File 'modules/profile/manifests/wmcs/paws/k8s/haproxy.pp', line 1

class profile::wmcs::paws::k8s::haproxy (
    Array[Stdlib::Fqdn] $ingress_nodes          = lookup('profile::wmcs::paws::ingress_nodes',         {default_value => ['localhost']}),
    Stdlib::Port        $ingress_backend_port   = lookup('profile::wmcs::paws::ingress_backend_port',  {default_value => 30000}),
    Stdlib::Port        $ingress_bind_tls_port  = lookup('profile::wmcs::paws::ingress_bind_tls_port', {default_value => 443}),
    Stdlib::Port        $ingress_bind_http_port = lookup('profile::wmcs::paws::ingress_bind_http_port',{default_value => 80}),
    Array[Stdlib::Fqdn] $control_nodes          = lookup('profile::wmcs::paws::control_nodes',         {default_value => ['localhost']}),
    Stdlib::Port        $api_port               = lookup('profile::wmcs::paws::apiserver_port',        {default_value => 6443}),
    Array[Stdlib::Fqdn] $keepalived_vips        = lookup('profile::wmcs::paws::keepalived::vips',      {default_value => ['localhost']}),
    Array[Stdlib::Fqdn] $keepalived_peers       = lookup('profile::wmcs::paws::keepalived::peers',     {default_value => ['localhost']}),
    String              $keepalived_password    = lookup('profile::wmcs::paws::keepalived::password',  {default_value => 'notarealpassword'}),
) {
    requires_os('debian >= buster')

    $cert_name = 'paws'
    acme_chief::cert { $cert_name:
        puppet_rsc => Service['haproxy'],
    }
    $cert_file = "/etc/acmecerts/${cert_name}/live/ec-prime256v1.chained.crt.key"

    package { 'haproxy':
        ensure => present,
    }

    file { '/etc/haproxy/conf.d':
        ensure => directory,
        owner  => 'root',
        group  => 'root',
        mode   => '0755',
    }

    file { '/etc/haproxy/haproxy.cfg':
        ensure  => present,
        mode    => '0444',
        owner   => 'root',
        group   => 'root',
        content => template('profile/wmcs/paws/k8s/haproxy/haproxy.cfg.erb'),
        notify  => Service['haproxy'],
    }

    file { '/etc/haproxy/conf.d/k8s-api-servers.cfg':
        owner   => 'root',
        group   => 'root',
        mode    => '0444',
        content => template('profile/wmcs/paws/k8s/haproxy/k8s-api-servers.cfg.erb'),
        notify  => Service['haproxy'],
    }

    file { '/etc/haproxy/conf.d/k8s-ingress.cfg':
        owner   => 'root',
        group   => 'root',
        mode    => '0444',
        content => template('profile/wmcs/paws/k8s/haproxy/k8s-ingress.cfg.erb'),
        notify  => Service['haproxy'],
    }

    # this file is loaded as environmentfile in the .service file shipped by
    # the debian package in Buster
    file { '/etc/default/haproxy':
        owner   => 'root',
        group   => 'root',
        mode    => '0644',
        content => "EXTRAOPTS='-f /etc/haproxy/conf.d/'\n",
        notify  => Service['haproxy'],
    }

    service { 'haproxy':
        ensure    => 'running',
        subscribe => [
                  File['/etc/haproxy/haproxy.cfg'],
                  File['/etc/haproxy/conf.d/k8s-api-servers.cfg'],
                  File['/etc/haproxy/conf.d/k8s-ingress.cfg'],
                  File['/etc/default/haproxy'],
        ],
    }

    class { 'prometheus::haproxy_exporter': }

    class { 'keepalived':
        auth_pass => $keepalived_password,
        peers     => delete($keepalived_peers, $::fqdn),
        vips      => $keepalived_vips.map |$host| { ipresolve($host, 4) }
    }
}