mirror of
https://github.com/netbirdio/plugins.git
synced 2026-05-22 18:44:07 -07:00
net/haproxy: use /tmp for autogenerated files
As suggested by @fichtner this ensures that files are always cleaned up. We will remove the old directory in a future release.
This commit is contained in:
@@ -37,6 +37,7 @@ require_once("legacy_bindings.inc");
|
||||
use OPNsense\Core\Config;
|
||||
|
||||
global $config;
|
||||
$export_path = '/tmp/haproxy/ssl/';
|
||||
|
||||
// configure ssl elements
|
||||
$configNodes = [
|
||||
@@ -58,7 +59,7 @@ foreach ($configNodes as $key => $value) {
|
||||
foreach ($certTypes as $type) {
|
||||
// every child node needs its own set of lists
|
||||
$crtlist = array();
|
||||
$crtlist_filename = "/var/etc/haproxy/ssl/" . (string)$child->id . "." . $type . "list";
|
||||
$crtlist_filename = $export_path . (string)$child->id . "." . $type . "list";
|
||||
|
||||
// multiple comma-separated values are possible
|
||||
$certs = explode(',', $child->$sslchild);
|
||||
@@ -87,7 +88,7 @@ foreach ($configNodes as $key => $value) {
|
||||
// generate pem file for individual certs
|
||||
// (only supported for type "cert")
|
||||
if ($type == cert) {
|
||||
$output_pem_filename = "/var/etc/haproxy/ssl/" . $cert_refid . ".pem";
|
||||
$output_pem_filename = $export_path . $cert_refid . ".pem";
|
||||
file_put_contents($output_pem_filename, $pem_content);
|
||||
chmod($output_pem_filename, 0600);
|
||||
echo "exported $type to " . $output_pem_filename . "\n";
|
||||
@@ -112,7 +113,7 @@ foreach ($configNodes as $key => $value) {
|
||||
// check if a default certificate is configured
|
||||
if (($type == cert) and isset($child->ssl_default_certificate) and (string)$child->ssl_default_certificate != "") {
|
||||
$default_cert = (string)$child->ssl_default_certificate;
|
||||
$default_cert_filename = "/var/etc/haproxy/ssl/" . $default_cert . ".pem";
|
||||
$default_cert_filename = $export_path . $default_cert . ".pem";
|
||||
// ensure default certificate is the first entry on the list
|
||||
unset($crtlist[$default_cert]);
|
||||
array_unshift($crtlist, $default_cert_filename);
|
||||
|
||||
@@ -37,6 +37,7 @@ require_once("legacy_bindings.inc");
|
||||
use OPNsense\Core\Config;
|
||||
|
||||
global $config;
|
||||
$export_path = '/tmp/haproxy/errorfiles/';
|
||||
|
||||
// traverse HAProxy error files
|
||||
$configObj = Config::getInstance()->object();
|
||||
@@ -46,7 +47,7 @@ if (isset($configObj->OPNsense->HAProxy->errorfiles)) {
|
||||
$ef_id = (string)$errorfile->id;
|
||||
if ($ef_id != "") {
|
||||
$ef_content = htmlspecialchars_decode(str_replace("\r", "", (string)$errorfile->content));
|
||||
$ef_filename = "/var/etc/haproxy/errorfiles/" . $ef_id . ".txt";
|
||||
$ef_filename = $export_path . $ef_id . ".txt";
|
||||
file_put_contents($ef_filename, $ef_content);
|
||||
chmod($ef_filename, 0600);
|
||||
echo "error file exported to " . $ef_filename . "\n";
|
||||
|
||||
@@ -37,6 +37,7 @@ require_once("legacy_bindings.inc");
|
||||
use OPNsense\Core\Config;
|
||||
|
||||
global $config;
|
||||
$export_path = '/tmp/haproxy/lua/';
|
||||
|
||||
// traverse HAProxy Lua scripts
|
||||
$configObj = Config::getInstance()->object();
|
||||
@@ -49,7 +50,7 @@ if (isset($configObj->OPNsense->HAProxy->luas)) {
|
||||
$lua_id = (string)$lua->id;
|
||||
if ($lua_id != "") {
|
||||
$lua_content = htmlspecialchars_decode(str_replace("\r", "", (string)$lua->content));
|
||||
$lua_filename = "/var/etc/haproxy/lua/" . $lua_id . ".lua";
|
||||
$lua_filename = $export_path . $lua_id . ".lua";
|
||||
file_put_contents($lua_filename, $lua_content);
|
||||
chmod($lua_filename, 0600);
|
||||
echo "lua script exported to " . $lua_filename . "\n";
|
||||
|
||||
@@ -37,6 +37,7 @@ require_once("legacy_bindings.inc");
|
||||
use OPNsense\Core\Config;
|
||||
|
||||
global $config;
|
||||
$export_path = '/tmp/haproxy/mapfiles/';
|
||||
|
||||
// traverse HAProxy map files
|
||||
$configObj = Config::getInstance()->object();
|
||||
@@ -46,7 +47,7 @@ if (isset($configObj->OPNsense->HAProxy->mapfiles)) {
|
||||
$mf_id = (string)$mapfile->id;
|
||||
if ($mf_id != "") {
|
||||
$mf_content = htmlspecialchars_decode(str_replace("\r", "", (string)$mapfile->content));
|
||||
$mf_filename = "/var/etc/haproxy/mapfiles/" . $mf_id . ".txt";
|
||||
$mf_filename = $export_path . $mf_id . ".txt";
|
||||
file_put_contents($mf_filename, $mf_content);
|
||||
chmod($mf_filename, 0600);
|
||||
echo "map file exported to " . $mf_filename . "\n";
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
#!/bin/sh
|
||||
|
||||
# NOTE: Keep /var/haproxy on this list, see GH issue opnsense/plugins #39.
|
||||
HAPROXY_DIRS="/var/haproxy /var/haproxy/var/run /var/etc/haproxy/ssl /var/etc/haproxy/lua /var/etc/haproxy/errorfiles /var/etc/haproxy/mapfiles"
|
||||
HAPROXY_DIRS="/var/haproxy /var/haproxy/var/run /tmp/haproxy /tmp/haproxy/ssl /tmp/haproxy/lua /tmp/haproxy/errorfiles /tmp/haproxy/mapfiles"
|
||||
|
||||
for directory in ${HAPROXY_DIRS}; do
|
||||
mkdir -p ${directory}
|
||||
|
||||
@@ -29,7 +29,7 @@
|
||||
{% else %}
|
||||
{% do http_codes_seen.append(errorfile_data.code) %}
|
||||
# ERROR FILE: {{errorfile_data.name}}
|
||||
errorfile {{errorfile_data.code|replace("x", "")}} /var/etc/haproxy/errorfiles/{{errorfile_data.id}}.txt
|
||||
errorfile {{errorfile_data.code|replace("x", "")}} /tmp/haproxy/errorfiles/{{errorfile_data.id}}.txt
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
{% else %}
|
||||
@@ -310,7 +310,7 @@
|
||||
{# # First get the map file path #}
|
||||
{% if action_data.map_use_backend_file|default("") != "" %}
|
||||
{% set mapfile_data = helpers.getUUID(action_data.map_use_backend_file) %}
|
||||
{% set mapfile_path = '/var/etc/haproxy/mapfiles/' ~ mapfile_data.id ~ '.txt' %}
|
||||
{% set mapfile_path = '/tmp/haproxy/mapfiles/' ~ mapfile_data.id ~ '.txt' %}
|
||||
{# # Check if a default backend is specified #}
|
||||
{% if action_data.map_use_backend_default|default("") != "" %}
|
||||
{% set defaultbackend_data = helpers.getUUID(action_data.map_use_backend_default) %}
|
||||
@@ -686,7 +686,7 @@ global
|
||||
{% for lua in helpers.toList('OPNsense.HAProxy.luas.lua') %}
|
||||
{% if lua.enabled == '1' %}
|
||||
# lua script: {{lua.name}}
|
||||
lua-load /var/etc/haproxy/lua/{{lua.id}}.lua
|
||||
lua-load /tmp/haproxy/lua/{{lua.id}}.lua
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
@@ -762,7 +762,7 @@ frontend {{frontend.name}}
|
||||
{# # check if ssl certs are configured #}
|
||||
{% if frontend.ssl_certificates|default("") != "" %}
|
||||
{# # NOTE: Cert lists are generated by exportCerts.php #}
|
||||
{% do ssl_certs.append('crt-list /var/etc/haproxy/ssl/' ~ frontend.id ~ '.certlist') %}
|
||||
{% do ssl_certs.append('crt-list /tmp/haproxy/ssl/' ~ frontend.id ~ '.certlist') %}
|
||||
{% endif %}
|
||||
{# # advanced ssl parameters (pass-through) #}
|
||||
{% if frontend.ssl_customOptions|default("") != "" %}
|
||||
@@ -796,7 +796,7 @@ frontend {{frontend.name}}
|
||||
{# # check for CAs (required) #}
|
||||
{% if frontend.ssl_clientAuthCAs|default("") != "" %}
|
||||
{# # NOTE: CA lists are generated by exportCerts.php #}
|
||||
{% do ssl_options.append('ca-file /var/etc/haproxy/ssl/' ~ frontend.id ~ '.calist') %}
|
||||
{% do ssl_options.append('ca-file /tmp/haproxy/ssl/' ~ frontend.id ~ '.calist') %}
|
||||
{# # check for verification mode #}
|
||||
{% if frontend.ssl_clientAuthVerify|default("") != "" %}
|
||||
{% do ssl_options.append('verify ' ~ frontend.ssl_clientAuthVerify) %}
|
||||
@@ -804,7 +804,7 @@ frontend {{frontend.name}}
|
||||
{# # check for CRL #}
|
||||
{% if frontend.ssl_clientAuthCRLs|default("") != "" %}
|
||||
{# # NOTE: CRL lists are generated by exportCerts.php #}
|
||||
{% do ssl_options.append('crl-file /var/etc/haproxy/ssl/' ~ frontend.id ~ '.crllist') %}
|
||||
{% do ssl_options.append('crl-file /tmp/haproxy/ssl/' ~ frontend.id ~ '.crllist') %}
|
||||
{% endif %}
|
||||
{% endif %}
|
||||
{% endif %}
|
||||
@@ -1122,15 +1122,15 @@ backend {{backend.name}}
|
||||
{% do server_options.append('verify required') %}
|
||||
{# # check for SSL CA #}
|
||||
{% if server_data.sslCA|default("") != "" %}
|
||||
{% do server_options.append('ca-file /var/etc/haproxy/ssl/' ~ server_data.sslCA ~ '.pem') %}
|
||||
{% do server_options.append('ca-file /tmp/haproxy/ssl/' ~ server_data.sslCA ~ '.pem') %}
|
||||
{% endif %}
|
||||
{# # check for SSL CRL #}
|
||||
{% if server_data.sslCRL|default("") != "" %}
|
||||
{% do server_options.append('crl-file /var/etc/haproxy/ssl/' ~ server_data.sslCRL ~ '.pem') %}
|
||||
{% do server_options.append('crl-file /tmp/haproxy/ssl/' ~ server_data.sslCRL ~ '.pem') %}
|
||||
{% endif %}
|
||||
{# # check for SSL client cert #}
|
||||
{% if server_data.sslClientCertificate|default("") != "" %}
|
||||
{% do server_options.append('crt /var/etc/haproxy/ssl/' ~ server_data.sslClientCertificate ~ '.pem') %}
|
||||
{% do server_options.append('crt /tmp/haproxy/ssl/' ~ server_data.sslClientCertificate ~ '.pem') %}
|
||||
{% endif %}
|
||||
{% else %}
|
||||
{% do server_options.append('verify none') %}
|
||||
|
||||
Reference in New Issue
Block a user