--- apiVersion: v1 kind: ConfigMap metadata: name: haproxy-config namespace: haproxy data: certificate.list: | # First entry is the default cert for non-matching SNI. /etc/haproxy/certs/unkin-net/tls.crt /etc/haproxy/certs/main-unkin-net/tls.crt /etc/haproxy/certs/ceph-unkin-net/tls.crt fe_http.map: | sonarr.main.unkin.net be_sonarr radarr.main.unkin.net be_radarr lidarr.main.unkin.net be_lidarr readarr.main.unkin.net be_readarr prowlarr.main.unkin.net be_prowlarr nzbget.main.unkin.net be_nzbget jellyfin.main.unkin.net be_jellyfin fafflix.unkin.net be_jellyfin git.unkin.net be_gitea grafana.unkin.net be_grafana dashboard.ceph.unkin.net be_ceph_dashboard mail-webadmin.main.unkin.net be_stalwart_webadmin autoconfig.main.unkin.net be_stalwart_webadmin autodiscovery.main.unkin.net be_stalwart_webadmin auth.unkin.net be_k8s_kanidm fe_https.map: | sonarr.main.unkin.net be_sonarr radarr.main.unkin.net be_radarr lidarr.main.unkin.net be_lidarr readarr.main.unkin.net be_readarr prowlarr.main.unkin.net be_prowlarr nzbget.main.unkin.net be_nzbget jellyfin.main.unkin.net be_jellyfin fafflix.unkin.net be_jellyfin git.unkin.net be_gitea grafana.unkin.net be_grafana dashboard.ceph.unkin.net be_ceph_dashboard mail-webadmin.main.unkin.net be_stalwart_webadmin autoconfig.main.unkin.net be_stalwart_webadmin autodiscovery.main.unkin.net be_stalwart_webadmin auth.unkin.net be_k8s_kanidm haproxy.cfg: | global log stdout format raw local0 log stdout format raw local1 notice maxconn 4000 hard-stop-after 2m ssl-default-bind-ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH ssl-default-bind-options ssl-min-ver TLSv1.2 ssl-max-ver TLSv1.3 ssl-default-server-ciphers kEECDH+aRSA+AES:kRSA+AES:+AES256:RC4-SHA:!kEDH:!LOW:!EXP:!MD5:!aNULL:!eNULL ssl-default-server-options no-sslv3 stats timeout 30s stats socket /var/lib/haproxy/stats stats socket /var/lib/haproxy/admin.sock mode 660 level admin tune.ssl.default-dh-param 2048 defaults log global maxconn 5000 mode http option httplog option dontlognull option http-server-close option forwardfor except 127.0.0.0/8 option redispatch retries 3 stats enable timeout http-request 10s timeout queue 1m timeout connect 10s timeout client 5m timeout server 5m timeout http-keep-alive 10s timeout check 10s frontend fe_http bind 0.0.0.0:80 mode http description Global HTTP Frontend acl acl-letsencrypt path_beg /.well-known/acme-challenge/ http-request set-header X-Forwarded-Proto https http-request set-header X-Real-IP %[src] use_backend be_letsencrypt if acl-letsencrypt use_backend %[req.hdr(host),lower,map(/usr/local/etc/haproxy/fe_http.map,be_default)] frontend fe_https bind 0.0.0.0:443 ssl crt-list /usr/local/etc/haproxy/certificate.list ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH force-tlsv12 mode http description Global HTTPS Frontend acl acl-letsencrypt path_beg /.well-known/acme-challenge/ acl acl_sonarr req.hdr(host) -i sonarr.main.unkin.net acl acl_radarr req.hdr(host) -i radarr.main.unkin.net acl acl_lidarr req.hdr(host) -i lidarr.main.unkin.net acl acl_readarr req.hdr(host) -i readarr.main.unkin.net acl acl_prowlarr req.hdr(host) -i prowlarr.main.unkin.net acl acl_nzbget req.hdr(host) -i nzbget.main.unkin.net acl acl_jellyfin req.hdr(host) -i jellyfin.main.unkin.net acl acl_fafflix req.hdr(host) -i fafflix.unkin.net acl acl_gitea req.hdr(host) -i git.unkin.net acl acl_grafana req.hdr(host) -i grafana.unkin.net acl acl_ceph_dashboard req.hdr(host) -i dashboard.ceph.unkin.net acl acl_stalwart_webadmin req.hdr(host) -i mail-webadmin.main.unkin.net acl acl_stalwart_webadmin req.hdr(host) -i autoconfig.main.unkin.net acl acl_stalwart_webadmin req.hdr(host) -i autodiscovery.main.unkin.net acl acl_kanidm req.hdr(host) -i auth.unkin.net http-request set-header X-Forwarded-Proto https http-request set-header X-Real-IP %[src] http-response set-header X-Frame-Options DENY if acl_sonarr http-response set-header X-Frame-Options DENY if acl_radarr http-response set-header X-Frame-Options DENY if acl_lidarr http-response set-header X-Frame-Options DENY if acl_readarr http-response set-header X-Frame-Options DENY if acl_prowlarr http-response set-header X-Frame-Options DENY if acl_nzbget http-response set-header X-Frame-Options DENY if acl_jellyfin http-response set-header X-Frame-Options DENY if acl_fafflix http-response set-header X-Frame-Options DENY if acl_gitea http-response set-header X-Frame-Options DENY if acl_grafana http-response set-header X-Frame-Options DENY if acl_ceph_dashboard http-response set-header X-Frame-Options DENY if acl_stalwart_webadmin http-response set-header X-Frame-Options DENY if acl_kanidm http-response set-header X-Content-Type-Options nosniff http-response set-header X-XSS-Protection 1;mode=block use_backend be_letsencrypt if acl-letsencrypt use_backend %[req.hdr(host),lower,map(/usr/local/etc/haproxy/fe_https.map,be_default)] frontend fe_imap bind 0.0.0.0:143 mode tcp description Frontend for Stalwart IMAP (STARTTLS) default_backend be_stalwart_imap log global option tcplog tcp-request inspect-delay 5s tcp-request content accept if { req_len 0 } frontend fe_imaps bind 0.0.0.0:993 mode tcp description Frontend for Stalwart IMAPS (implicit TLS) default_backend be_stalwart_imaps log global option tcplog tcp-request inspect-delay 5s tcp-request content accept if { req_len 0 } frontend fe_metrics bind 0.0.0.0:8405 mode http description Metrics Frontend http-request set-header X-Forwarded-Proto https http-request set-header X-Real-IP %[src] http-request use-service prometheus-exporter if { path /metrics } frontend fe_smtp bind 0.0.0.0:25 mode tcp description Frontend for Stalwart SMTP default_backend be_stalwart_smtp log global option tcplog tcp-request inspect-delay 5s tcp-request content accept if { req_len 0 } frontend fe_submission bind 0.0.0.0:587 mode tcp description Frontend for Stalwart SMTP Submission default_backend be_stalwart_submission log global option tcplog tcp-request inspect-delay 5s tcp-request content accept if { req_len 0 } backend be_ceph_dashboard description Backend for Ceph Dashboard from Mgr instances balance roundrobin cookie SRVNAME insert indirect nocache http-check expect status 200 http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 9443 } http-reuse always option httpchk GET / option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } stick-table type ip size 200k expire 30m server prodnxsr0009 198.18.23.9:9443 check cookie prodnxsr0009 fall 2 inter 2s rise 3 ssl verify none server prodnxsr0010 198.18.23.10:9443 check cookie prodnxsr0010 fall 2 inter 2s rise 3 ssl verify none server prodnxsr0011 198.18.23.11:9443 check cookie prodnxsr0011 fall 2 inter 2s rise 3 ssl verify none server prodnxsr0012 198.18.23.12:9443 check cookie prodnxsr0012 fall 2 inter 2s rise 3 ssl verify none server prodnxsr0013 198.18.23.13:9443 check cookie prodnxsr0013 fall 2 inter 2s rise 3 ssl verify none backend be_default description Backend for unmatched HTTP traffic balance roundrobin cookie SRVNAME insert http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } option httpchk GET / option forwardfor backend be_gitea description Backend for gitea cluster balance roundrobin cookie SRVNAME insert indirect nocache http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } http-reuse always option httpchk GET / option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } stick on src stick-table type ip size 200k expire 30m server ausyd1nxvm2080 198.18.26.18:443 check cookie ausyd1nxvm2080 fall 2 inter 2s rise 3 ssl verify none server ausyd1nxvm2081 198.18.27.117:443 check cookie ausyd1nxvm2081 fall 2 inter 2s rise 3 ssl verify none server ausyd1nxvm2082 198.18.28.71:443 check cookie ausyd1nxvm2082 fall 2 inter 2s rise 3 ssl verify none backend be_grafana description Backend for grafana nodes balance roundrobin cookie SRVNAME insert indirect nocache http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } http-reuse always option httpchk GET / option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } stick on src stick-table type ip size 200k expire 30m server ausyd1nxvm2015 198.18.27.2:443 check cookie ausyd1nxvm2015 fall 2 inter 2s rise 3 ssl verify none server ausyd1nxvm2016 198.18.28.189:443 check cookie ausyd1nxvm2016 fall 2 inter 2s rise 3 ssl verify none backend be_jellyfin description Backend for au-syd1 jellyfin balance roundrobin cookie SRVNAME insert indirect nocache http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } http-reuse always option httpchk GET / option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } server ausyd1nxvm2051 198.18.25.164:443 check cookie ausyd1nxvm2051 fall 2 inter 2s rise 3 ssl verify none backend be_k8s_kanidm description Backend for Kanidm (auth.unkin.net via Kubernetes internal Traefik) balance roundrobin http-reuse always http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } redirect scheme https if !{ ssl_fc } option httpchk option forwardfor option http-keep-alive option prefer-last-server http-check connect ssl sni auth.unkin.net http-check send meth GET uri /status ver HTTP/1.1 hdr Host auth.unkin.net http-check expect status 200 server k8s-traefik-internal 198.18.200.4:443 ssl verify none check inter 2s rise 3 fall 2 sni str(auth.unkin.net) backend be_letsencrypt description Backend for LetsEncrypt Verifications balance roundrobin server ausyd1nxvm2057 198.18.25.3:8888 backend be_lidarr description Backend for au-syd1 lidarr balance roundrobin cookie SRVNAME insert indirect nocache http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } http-reuse always option httpchk GET /consul/health option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } server ausyd1nxvm2048 198.18.28.165:443 check cookie ausyd1nxvm2048 fall 2 inter 2s rise 3 ssl verify none backend be_nzbget description Backend for au-syd1 nzbget balance roundrobin cookie SRVNAME insert indirect nocache http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } http-reuse always option httpchk GET /consul/health option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } server ausyd1nxvm2045 198.18.25.44:443 check cookie ausyd1nxvm2045 fall 2 inter 2s rise 3 ssl verify none backend be_prowlarr description Backend for au-syd1 prowlarr balance roundrobin cookie SRVNAME insert indirect nocache http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } http-reuse always option httpchk GET /consul/health option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } server ausyd1nxvm2050 198.18.25.66:443 check cookie ausyd1nxvm2050 fall 2 inter 2s rise 3 ssl verify none backend be_radarr description Backend for au-syd1 radarr balance roundrobin cookie SRVNAME insert indirect nocache http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } http-reuse always option httpchk GET /consul/health option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } server ausyd1nxvm2047 198.18.27.131:443 check cookie ausyd1nxvm2047 fall 2 inter 2s rise 3 ssl verify none backend be_readarr description Backend for au-syd1 readarr balance roundrobin cookie SRVNAME insert indirect nocache http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } http-reuse always option httpchk GET /consul/health option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } server ausyd1nxvm2049 198.18.29.32:443 check cookie ausyd1nxvm2049 fall 2 inter 2s rise 3 ssl verify none backend be_sonarr description Backend for au-syd1 sonarr balance roundrobin cookie SRVNAME insert indirect nocache http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 443 } http-reuse always option httpchk GET /consul/health option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } server ausyd1nxvm2046 198.18.26.161:443 check cookie ausyd1nxvm2046 fall 2 inter 2s rise 3 ssl verify none backend be_stalwart_imap description Backend for Stalwart IMAP (STARTTLS) balance roundrobin mode tcp option tcp-check option prefer-last-server stick on src stick-table type ip size 200k expire 30m tcp-check connect port 143 send-proxy tcp-check expect string "* OK" tcp-check send "A001 STARTTLS\r\n" tcp-check expect rstring "A001 (OK|2.0.0)" server ausyd1nxvm2124 198.18.28.76:143 check fall 3 inter 3s rise 2 send-proxy-v2 server ausyd1nxvm2125 198.18.29.44:143 check fall 3 inter 3s rise 2 send-proxy-v2 server ausyd1nxvm2126 198.18.25.160:143 check fall 3 inter 3s rise 2 send-proxy-v2 backend be_stalwart_imaps description Backend for Stalwart IMAPS (implicit TLS) balance roundrobin mode tcp option tcp-check option prefer-last-server stick on src stick-table type ip size 200k expire 30m tcp-check connect ssl send-proxy tcp-check expect string "* OK" server ausyd1nxvm2124 198.18.28.76:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none server ausyd1nxvm2125 198.18.29.44:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none server ausyd1nxvm2126 198.18.25.160:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none backend be_stalwart_smtp description Backend for Stalwart SMTP balance roundrobin mode tcp option tcp-check option prefer-last-server stick on src stick-table type ip size 200k expire 30m tcp-check connect port 25 send-proxy tcp-check expect string "220 " server ausyd1nxvm2124 198.18.28.76:25 check fall 3 inter 3s rise 2 send-proxy-v2 server ausyd1nxvm2125 198.18.29.44:25 check fall 3 inter 3s rise 2 send-proxy-v2 server ausyd1nxvm2126 198.18.25.160:25 check fall 3 inter 3s rise 2 send-proxy-v2 backend be_stalwart_submission description Backend for Stalwart SMTP Submission balance roundrobin mode tcp option tcp-check option prefer-last-server stick on src stick-table type ip size 200k expire 30m tcp-check connect port 587 send-proxy tcp-check expect string "220 " server ausyd1nxvm2124 198.18.28.76:587 check fall 3 inter 3s rise 2 send-proxy-v2 server ausyd1nxvm2125 198.18.29.44:587 check fall 3 inter 3s rise 2 send-proxy-v2 server ausyd1nxvm2126 198.18.25.160:587 check fall 3 inter 3s rise 2 send-proxy-v2 backend be_stalwart_webadmin description Backend for Stalwart Webadmin balance roundrobin cookie SRVNAME insert indirect nocache http-check expect status 200 http-request set-header X-Forwarded-Port %[dst_port] http-request add-header X-Forwarded-Proto https if { dst_port 9443 } http-reuse always option httpchk GET / option forwardfor option http-keep-alive option prefer-last-server redirect scheme https if !{ ssl_fc } stick-table type ip size 200k expire 30m server ausyd1nxvm2124 198.18.28.76:443 check cookie ausyd1nxvm2124 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none server ausyd1nxvm2125 198.18.29.44:443 check cookie ausyd1nxvm2125 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none server ausyd1nxvm2126 198.18.25.160:443 check cookie ausyd1nxvm2126 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none # The `peers au-syd1-prod` section is dropped: peer names must be static and a # Deployment cannot provide them. Service sessionAffinity: ClientIP pins a # client to one replica so the per-replica stick-tables behave as before. listen health bind 0.0.0.0:8404 mode http monitor-uri /healthz listen stats bind 127.0.0.1:9090 mode http stats uri / stats auth admin:admin