123 lines
4.3 KiB
Bash
123 lines
4.3 KiB
Bash
sudo apt update && sudo apt install -y haproxy
|
|
|
|
sudo tee /etc/haproxy/haproxy.cfg > /dev/null <<'EOF'
|
|
global
|
|
log /dev/log local0
|
|
maxconn 20000
|
|
tune.bufsize 16384
|
|
# SSL configuration for future HTTPS endpoints
|
|
ca-base /etc/ssl/certs
|
|
crt-base /etc/ssl/private
|
|
|
|
# Modern SSL configuration - only secure protocols
|
|
ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
|
|
ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
|
|
ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets
|
|
|
|
defaults
|
|
log global
|
|
mode http
|
|
option httplog
|
|
option dontlognull
|
|
timeout connect 5000
|
|
timeout client 50000
|
|
timeout server 50000
|
|
errorfile 400 /etc/haproxy/errors/400.http
|
|
errorfile 403 /etc/haproxy/errors/403.http
|
|
errorfile 408 /etc/haproxy/errors/408.http
|
|
errorfile 500 /etc/haproxy/errors/500.http
|
|
errorfile 502 /etc/haproxy/errors/502.http
|
|
errorfile 503 /etc/haproxy/errors/503.http
|
|
errorfile 504 /etc/haproxy/errors/504.http
|
|
|
|
frontend rke2_registration_frontend
|
|
bind *:9345
|
|
mode tcp
|
|
option tcplog
|
|
default_backend rke2_registration_backend
|
|
|
|
#---------------------------------------------------------------------
|
|
# RKE2 Supervisor/Registration Backend
|
|
# Round-robin between masters for node registration
|
|
#---------------------------------------------------------------------
|
|
backend rke2_registration_backend
|
|
mode tcp
|
|
balance roundrobin
|
|
option tcp-check
|
|
# Health check ensures we only send traffic to healthy masters
|
|
server POC-Master0 POC-Master0:9345 check
|
|
server POC-Master1 POC-Master1:9345 check
|
|
server POC-Master2 POC-Master2:9345 check
|
|
|
|
#---------------------------------------------------------------------
|
|
# Kubernetes API Frontend
|
|
# This is where kubectl commands and apps connect
|
|
#---------------------------------------------------------------------
|
|
frontend k8s_api_frontend
|
|
bind *:6443
|
|
mode tcp
|
|
option tcplog
|
|
default_backend k8s_api_backend
|
|
|
|
#---------------------------------------------------------------------
|
|
# Kubernetes API Backend
|
|
# Distributes API requests across all masters
|
|
#---------------------------------------------------------------------
|
|
backend k8s_api_backend
|
|
mode tcp
|
|
balance roundrobin
|
|
option tcp-check
|
|
# TCP health checks on the API port
|
|
server POC-Master0 POC-Master0:6443 check
|
|
server POC-Master1 POC-Master1:6443 check
|
|
server POC-Master2 POC-Master2:6443 check
|
|
|
|
#---------------------------------------------------------------------
|
|
# Statistics Page (Optional but useful for monitoring)
|
|
#---------------------------------------------------------------------
|
|
listen stats
|
|
bind *:8080
|
|
stats enable
|
|
stats uri /stats
|
|
stats refresh 30s
|
|
stats show-node
|
|
stats auth admin:admin # Change this password!
|
|
|
|
#---------------------------------------------------------------------
|
|
# nginx ingress
|
|
# This is where kubectl commands and apps connect
|
|
#---------------------------------------------------------------------
|
|
frontend nginx_frontend_443
|
|
bind *:443
|
|
mode tcp
|
|
option tcplog
|
|
default_backend nginx_backend
|
|
|
|
frontend nginx_frontend_80
|
|
bind *:80
|
|
mode http
|
|
http-response set-header Access-Control-Allow-Origin %[hdr(origin)]
|
|
default_backend nginx_backend_http
|
|
#---------------------------------------------------------------------
|
|
# Kubernetes API Backend
|
|
# Distributes API requests across all masters
|
|
#---------------------------------------------------------------------
|
|
backend nginx_backend
|
|
mode tcp
|
|
balance roundrobin
|
|
option tcp-check
|
|
# TCP health checks on the API port
|
|
server POC-Master0 POC-Master0:30864 check
|
|
server POC-Master1 POC-Master1:30864 check
|
|
server POC-Master2 POC-Master2:30864 check
|
|
|
|
backend nginx_backend_http
|
|
mode http
|
|
balance roundrobin
|
|
# TCP health checks on the API port
|
|
server POC-Master0 POC-Master0:30864 check ssl verify none
|
|
server POC-Master1 POC-Master1:30864 check ssl verify none
|
|
server POC-Master2 POC-Master2:30864 check ssl verify none
|
|
EOF
|
|
|
|
sudo systemctl enable --now haproxy |