2bf2d65c4d
Keepalived, luckily for us, currently ship an example file of a SELinux rule to read haproxy pid. We could simply use this available file to compile the selinux rules. Change-Id: I8e6d811bca7553d82591a6c96f4316377d0d1829 Fixes-Bug: #1702123
38 lines
1.6 KiB
YAML
38 lines
1.6 KiB
YAML
---
|
|
# Copyright 2016, Rackspace US, Inc.
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
haproxy_bind_on_non_local: "{% if groups.haproxy|length > 1 %}True{% else %}False{% endif %}"
|
|
haproxy_use_keepalived: "{% if groups.haproxy|length > 1 %}True{% else %}False{% endif %}"
|
|
keepalived_selinux_compile_rules:
|
|
- keepalived_ping
|
|
- keepalived_haproxy_pid_file
|
|
|
|
# Ensure that the package state matches the global setting
|
|
haproxy_package_state: "{{ package_state }}"
|
|
|
|
haproxy_whitelist_networks:
|
|
- 192.168.0.0/16
|
|
- 172.16.0.0/12
|
|
- 10.0.0.0/8
|
|
|
|
haproxy_galera_whitelist_networks: "{{ haproxy_whitelist_networks }}"
|
|
haproxy_glance_registry_whitelist_networks: "{{ haproxy_whitelist_networks }}"
|
|
haproxy_keystone_admin_whitelist_networks: "{{ haproxy_whitelist_networks }}"
|
|
haproxy_nova_metadata_whitelist_networks: "{{ haproxy_whitelist_networks }}"
|
|
haproxy_rabbitmq_management_whitelist_networks: "{{ haproxy_whitelist_networks }}"
|
|
haproxy_repo_git_whitelist_networks: "{{ haproxy_whitelist_networks }}"
|
|
haproxy_repo_cache_whitelist_networks: "{{ haproxy_whitelist_networks }}"
|
|
haproxy_octavia_whitelist_networks: "{{ haproxy_whitelist_networks }}"
|