[5.0] Terminate ssl on haproxy (bsc#1149535)#2347
Open
bbobrov wants to merge 2 commits intocrowbar:stable/5.0-pikefrom
Open
[5.0] Terminate ssl on haproxy (bsc#1149535)#2347bbobrov wants to merge 2 commits intocrowbar:stable/5.0-pikefrom
bbobrov wants to merge 2 commits intocrowbar:stable/5.0-pikefrom
Conversation
jsuchome
requested changes
Mar 27, 2020
added 2 commits
March 27, 2020 14:41
If ssl is passed-thru on haproxy, the source ip gets replaced with the one of the node where haproxy lives, and there is no way to get the original ip on the services side. Add ssl termination on haproxy. Two new hidden options are added: loadbalancer_terminate_ssl (boolean) and pemfile (path to the certificate to use in haproxy-recognized format). (cherry picked from commit 94fc788)
If ssl is passed-thru on haproxy, the source ip gets replaced with the one of the node where haproxy lives, and there is no way to get the original ip on the services side. Add ssl termination on haproxy. Two new hidden options are added: loadbalancer_terminate_ssl (boolean) and pemfile (path to the certificate to use in haproxy-recognized format). This patch adds support for cinder. (cherry picked from commit 44e0f6a)
015bd0f to
fd1427a
Compare
jsuchome
approved these changes
Mar 27, 2020
skazi0
reviewed
Mar 30, 2020
| @@ -0,0 +1,12 @@ | |||
| def upgrade(template_attrs, template_deployment, attrs, deployment) | |||
| key = "loadbalancer_terminate_ssl" | |||
Contributor
Author
There was a problem hiding this comment.
you are right, and the same problem exists in other pull requests. Thanks, will do
Contributor
|
Needs to be refreshed with the changes from master. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
If ssl is passed-thru on haproxy, the source ip gets replaced with
the one of the node where haproxy lives, and there is no way to get the
original ip on the services side.
Add ssl termination on haproxy. Two new hidden options are added:
loadbalancer_terminate_ssl (boolean) and pemfile (path to the
certificate to use in haproxy-recognized format).