Defined Type: envoyproxy::tls_terminator
- Defined in:
- modules/envoyproxy/manifests/tls_terminator.pp
Summary
Configure envoy to be a TLS proxy to local services. It's thought as a simple shoe-in replacement for tlsproxy::localssl in limited use-cases for internal usage. The port on which Envoy should listen must be specified in the title.Overview
SPDX-License-Identifier: Apache-2.0
140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 |
# File 'modules/envoyproxy/manifests/tls_terminator.pp', line 140
define envoyproxy::tls_terminator(
Array[Envoyproxy::Tlsconfig] $upstreams = [],
Boolean $access_log = false,
Boolean $websockets = false,
Boolean $use_remote_address = true,
Integer $fast_open_queue = 0,
Float $connect_timeout = 1.0,
Float $upstream_response_timeout = 65.0,
Envoyproxy::Headerkeyformat $header_key_format = 'none',
Boolean $listen_ipv6 = false,
Boolean $generate_request_id = true,
Hash[String, String] $response_headers_to_add = {},
Envoyproxy::Circuitbreakersconfig $circuit_breakers_config = 'defaults',
Hash $retry_policy = {},
Optional[Stdlib::Port] $redir_port = undef,
Array[Envoyproxy::Tlscertificate] $global_certs = [],
Optional[Envoyproxy::Tlsparams] $global_tlsparams = undef,
Array[Stdlib::UnixPath] $stek_files = [],
Optional[Envoyproxy::Alpn] $global_alpn_protocols = undef,
Optional[Float] $idle_timeout = undef,
Optional[Float] $downstream_idle_timeout = undef,
Optional[Float] $stream_idle_timeout = undef,
Optional[Float] $request_timeout = undef,
Optional[Float] $request_headers_timeout = undef,
Optional[Float] $delayed_close_timeout = undef,
Optional[Float] $tls_handshake_timeout = undef,
Optional[Integer] $max_requests_per_conn = undef,
Optional[String] $lua_script = undef,
Optional[Integer] $connection_buffer_limit = undef,
Optional[Envoyproxy::Http2options] $http2_options = undef,
Boolean $has_error_page = false,
Float $local_otel_reporting_pct = 0.0,
) {
# First of all, we can't configure a tls terminator if envoy is not installed.
if !defined(Class['envoyproxy']) {
fail('envoyproxy::tls_terminator should only be used once the envoyproxy class is declared.')
}
# As this is a fundamental function, install it with high priority
# Please note they will be removed if we remove the terminator declaration.
# We need a separate definition for each upstream cluster
$upstreams.each |$upstream| {
$upstream_name = $upstream['upstream'] ? {
Envoyproxy::Ipupstream => "local_port_${upstream['upstream']['port']}",
Envoyproxy::Udsupstream => "local_path_${upstream['upstream']['path']}",
}
if !defined(Envoyproxy::Cluster["cluster_${upstream_name}"]) { # nothing wrong with several listeners using the same cluster
envoyproxy::cluster { "cluster_${upstream_name}":
priority => 0,
content => template('envoyproxy/tls_terminator/cluster.yaml.erb'),
}
}
}
envoyproxy::listener { "tls_terminator_${name}":
priority => 0,
content => template('envoyproxy/tls_terminator/listener.yaml.erb'),
}
if $redir_port {
# Redirection is less important, install it at the bottom of the pyle.
envoyproxy::listener { "http_redirect_${name}":
priority => 99,
content => template('envoyproxy/tls_terminator/redirect_listener.yaml.erb'),
}
}
}
|