486 lines
20 KiB
YAML
486 lines
20 KiB
YAML
---
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: haproxy-config
|
|
namespace: haproxy
|
|
data:
|
|
certificate.list: |
|
|
# First entry is the default cert for non-matching SNI.
|
|
/etc/haproxy/certs/unkin-net/tls.crt
|
|
/etc/haproxy/certs/main-unkin-net/tls.crt
|
|
/etc/haproxy/certs/ceph-unkin-net/tls.crt
|
|
|
|
fe_http.map: |
|
|
au-syd1-pve.main.unkin.net be_ausyd1pve_web
|
|
au-syd1-pve-api.main.unkin.net be_ausyd1pve_api
|
|
sonarr.main.unkin.net be_sonarr
|
|
radarr.main.unkin.net be_radarr
|
|
lidarr.main.unkin.net be_lidarr
|
|
readarr.main.unkin.net be_readarr
|
|
prowlarr.main.unkin.net be_prowlarr
|
|
nzbget.main.unkin.net be_nzbget
|
|
jellyfin.main.unkin.net be_jellyfin
|
|
fafflix.unkin.net be_jellyfin
|
|
git.unkin.net be_gitea
|
|
grafana.unkin.net be_grafana
|
|
dashboard.ceph.unkin.net be_ceph_dashboard
|
|
mail-webadmin.main.unkin.net be_stalwart_webadmin
|
|
autoconfig.main.unkin.net be_stalwart_webadmin
|
|
autodiscovery.main.unkin.net be_stalwart_webadmin
|
|
auth.unkin.net be_k8s_kanidm
|
|
|
|
fe_https.map: |
|
|
au-syd1-pve.main.unkin.net be_ausyd1pve_web
|
|
au-syd1-pve-api.main.unkin.net be_ausyd1pve_api
|
|
sonarr.main.unkin.net be_sonarr
|
|
radarr.main.unkin.net be_radarr
|
|
lidarr.main.unkin.net be_lidarr
|
|
readarr.main.unkin.net be_readarr
|
|
prowlarr.main.unkin.net be_prowlarr
|
|
nzbget.main.unkin.net be_nzbget
|
|
jellyfin.main.unkin.net be_jellyfin
|
|
fafflix.unkin.net be_jellyfin
|
|
git.unkin.net be_gitea
|
|
grafana.unkin.net be_grafana
|
|
dashboard.ceph.unkin.net be_ceph_dashboard
|
|
mail-webadmin.main.unkin.net be_stalwart_webadmin
|
|
autoconfig.main.unkin.net be_stalwart_webadmin
|
|
autodiscovery.main.unkin.net be_stalwart_webadmin
|
|
auth.unkin.net be_k8s_kanidm
|
|
|
|
haproxy.cfg: |
|
|
global
|
|
log stdout format raw local0
|
|
log stdout format raw local1 notice
|
|
maxconn 4000
|
|
hard-stop-after 2m
|
|
ssl-default-bind-ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH
|
|
ssl-default-bind-options ssl-min-ver TLSv1.2 ssl-max-ver TLSv1.3
|
|
ssl-default-server-ciphers kEECDH+aRSA+AES:kRSA+AES:+AES256:RC4-SHA:!kEDH:!LOW:!EXP:!MD5:!aNULL:!eNULL
|
|
ssl-default-server-options no-sslv3
|
|
stats timeout 30s
|
|
stats socket /var/lib/haproxy/stats
|
|
stats socket /var/lib/haproxy/admin.sock mode 660 level admin
|
|
tune.ssl.default-dh-param 2048
|
|
|
|
defaults
|
|
log global
|
|
maxconn 5000
|
|
mode http
|
|
option httplog
|
|
option dontlognull
|
|
option http-server-close
|
|
option forwardfor except 127.0.0.0/8
|
|
option redispatch
|
|
retries 3
|
|
stats enable
|
|
timeout http-request 10s
|
|
timeout queue 1m
|
|
timeout connect 10s
|
|
timeout client 5m
|
|
timeout server 5m
|
|
timeout http-keep-alive 10s
|
|
timeout check 10s
|
|
|
|
frontend fe_http
|
|
bind 0.0.0.0:80
|
|
mode http
|
|
description Global HTTP Frontend
|
|
acl acl-letsencrypt path_beg /.well-known/acme-challenge/
|
|
http-request set-header X-Forwarded-Proto https
|
|
http-request set-header X-Real-IP %[src]
|
|
use_backend be_letsencrypt if acl-letsencrypt
|
|
use_backend %[req.hdr(host),lower,map(/usr/local/etc/haproxy/fe_http.map,be_default)]
|
|
|
|
frontend fe_https
|
|
bind 0.0.0.0:443 ssl crt-list /usr/local/etc/haproxy/certificate.list ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH force-tlsv12
|
|
mode http
|
|
description Global HTTPS Frontend
|
|
acl acl-letsencrypt path_beg /.well-known/acme-challenge/
|
|
acl acl_ausyd1pve req.hdr(host) -i au-syd1-pve.main.unkin.net
|
|
acl acl_sonarr req.hdr(host) -i sonarr.main.unkin.net
|
|
acl acl_radarr req.hdr(host) -i radarr.main.unkin.net
|
|
acl acl_lidarr req.hdr(host) -i lidarr.main.unkin.net
|
|
acl acl_readarr req.hdr(host) -i readarr.main.unkin.net
|
|
acl acl_prowlarr req.hdr(host) -i prowlarr.main.unkin.net
|
|
acl acl_nzbget req.hdr(host) -i nzbget.main.unkin.net
|
|
acl acl_jellyfin req.hdr(host) -i jellyfin.main.unkin.net
|
|
acl acl_fafflix req.hdr(host) -i fafflix.unkin.net
|
|
acl acl_gitea req.hdr(host) -i git.unkin.net
|
|
acl acl_grafana req.hdr(host) -i grafana.unkin.net
|
|
acl acl_ceph_dashboard req.hdr(host) -i dashboard.ceph.unkin.net
|
|
acl acl_stalwart_webadmin req.hdr(host) -i mail-webadmin.main.unkin.net
|
|
acl acl_stalwart_webadmin req.hdr(host) -i autoconfig.main.unkin.net
|
|
acl acl_stalwart_webadmin req.hdr(host) -i autodiscovery.main.unkin.net
|
|
acl acl_kanidm req.hdr(host) -i auth.unkin.net
|
|
acl acl_internalsubnets src 198.18.0.0/16 10.10.12.0/24
|
|
http-request set-header X-Forwarded-Proto https
|
|
http-request set-header X-Real-IP %[src]
|
|
http-request deny if { hdr_dom(host) -i au-syd1-pve.main.unkin.net } !acl_internalsubnets
|
|
http-response set-header X-Frame-Options DENY if acl_ausyd1pve
|
|
http-response set-header X-Frame-Options DENY if acl_sonarr
|
|
http-response set-header X-Frame-Options DENY if acl_radarr
|
|
http-response set-header X-Frame-Options DENY if acl_lidarr
|
|
http-response set-header X-Frame-Options DENY if acl_readarr
|
|
http-response set-header X-Frame-Options DENY if acl_prowlarr
|
|
http-response set-header X-Frame-Options DENY if acl_nzbget
|
|
http-response set-header X-Frame-Options DENY if acl_jellyfin
|
|
http-response set-header X-Frame-Options DENY if acl_fafflix
|
|
http-response set-header X-Frame-Options DENY if acl_gitea
|
|
http-response set-header X-Frame-Options DENY if acl_grafana
|
|
http-response set-header X-Frame-Options DENY if acl_ceph_dashboard
|
|
http-response set-header X-Frame-Options DENY if acl_stalwart_webadmin
|
|
http-response set-header X-Frame-Options DENY if acl_kanidm
|
|
http-response set-header X-Content-Type-Options nosniff
|
|
http-response set-header X-XSS-Protection 1;mode=block
|
|
use_backend be_letsencrypt if acl-letsencrypt
|
|
use_backend %[req.hdr(host),lower,map(/usr/local/etc/haproxy/fe_https.map,be_default)]
|
|
|
|
frontend fe_imap
|
|
bind 0.0.0.0:143
|
|
mode tcp
|
|
description Frontend for Stalwart IMAP (STARTTLS)
|
|
default_backend be_stalwart_imap
|
|
log global
|
|
option tcplog
|
|
tcp-request inspect-delay 5s
|
|
tcp-request content accept if { req_len 0 }
|
|
|
|
frontend fe_imaps
|
|
bind 0.0.0.0:993
|
|
mode tcp
|
|
description Frontend for Stalwart IMAPS (implicit TLS)
|
|
default_backend be_stalwart_imaps
|
|
log global
|
|
option tcplog
|
|
tcp-request inspect-delay 5s
|
|
tcp-request content accept if { req_len 0 }
|
|
|
|
frontend fe_metrics
|
|
bind 0.0.0.0:8405
|
|
mode http
|
|
description Metrics Frontend
|
|
http-request set-header X-Forwarded-Proto https
|
|
http-request set-header X-Real-IP %[src]
|
|
http-request use-service prometheus-exporter if { path /metrics }
|
|
|
|
frontend fe_smtp
|
|
bind 0.0.0.0:25
|
|
mode tcp
|
|
description Frontend for Stalwart SMTP
|
|
default_backend be_stalwart_smtp
|
|
log global
|
|
option tcplog
|
|
tcp-request inspect-delay 5s
|
|
tcp-request content accept if { req_len 0 }
|
|
|
|
frontend fe_submission
|
|
bind 0.0.0.0:587
|
|
mode tcp
|
|
description Frontend for Stalwart SMTP Submission
|
|
default_backend be_stalwart_submission
|
|
log global
|
|
option tcplog
|
|
tcp-request inspect-delay 5s
|
|
tcp-request content accept if { req_len 0 }
|
|
|
|
backend be_ausyd1pve_api
|
|
description Backend for au-syd1 pve cluster (API only)
|
|
balance roundrobin
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
|
|
backend be_ausyd1pve_web
|
|
description Backend for au-syd1 pve cluster (Web)
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
|
|
backend be_ceph_dashboard
|
|
description Backend for Ceph Dashboard from Mgr instances
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-check expect status 200
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 9443 }
|
|
http-reuse always
|
|
option httpchk GET /
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
stick-table type ip size 200k expire 30m
|
|
server prodnxsr0009 198.18.23.9:9443 check cookie prodnxsr0009 fall 2 inter 2s rise 3 ssl verify none
|
|
server prodnxsr0010 198.18.23.10:9443 check cookie prodnxsr0010 fall 2 inter 2s rise 3 ssl verify none
|
|
server prodnxsr0011 198.18.23.11:9443 check cookie prodnxsr0011 fall 2 inter 2s rise 3 ssl verify none
|
|
server prodnxsr0012 198.18.23.12:9443 check cookie prodnxsr0012 fall 2 inter 2s rise 3 ssl verify none
|
|
server prodnxsr0013 198.18.23.13:9443 check cookie prodnxsr0013 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_default
|
|
description Backend for unmatched HTTP traffic
|
|
balance roundrobin
|
|
cookie SRVNAME insert
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
option httpchk GET /
|
|
option forwardfor
|
|
|
|
backend be_gitea
|
|
description Backend for gitea cluster
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
stick on src
|
|
stick-table type ip size 200k expire 30m
|
|
server ausyd1nxvm2080 198.18.26.18:443 check cookie ausyd1nxvm2080 fall 2 inter 2s rise 3 ssl verify none
|
|
server ausyd1nxvm2081 198.18.27.117:443 check cookie ausyd1nxvm2081 fall 2 inter 2s rise 3 ssl verify none
|
|
server ausyd1nxvm2082 198.18.28.71:443 check cookie ausyd1nxvm2082 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_grafana
|
|
description Backend for grafana nodes
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
stick on src
|
|
stick-table type ip size 200k expire 30m
|
|
server ausyd1nxvm2015 198.18.27.2:443 check cookie ausyd1nxvm2015 fall 2 inter 2s rise 3 ssl verify none
|
|
server ausyd1nxvm2016 198.18.28.189:443 check cookie ausyd1nxvm2016 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_jellyfin
|
|
description Backend for au-syd1 jellyfin
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
server ausyd1nxvm2051 198.18.25.164:443 check cookie ausyd1nxvm2051 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_k8s_kanidm
|
|
description Backend for Kanidm (auth.unkin.net via Kubernetes internal Traefik)
|
|
balance roundrobin
|
|
http-reuse always
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
redirect scheme https if !{ ssl_fc }
|
|
option httpchk
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
http-check connect ssl sni auth.unkin.net
|
|
http-check send meth GET uri /status ver HTTP/1.1 hdr Host auth.unkin.net
|
|
http-check expect status 200
|
|
server k8s-traefik-internal 198.18.200.4:443 ssl verify none check inter 2s rise 3 fall 2 sni str(auth.unkin.net)
|
|
|
|
backend be_letsencrypt
|
|
description Backend for LetsEncrypt Verifications
|
|
balance roundrobin
|
|
server ausyd1nxvm2057 198.18.25.3:8888
|
|
|
|
backend be_lidarr
|
|
description Backend for au-syd1 lidarr
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /consul/health
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
server ausyd1nxvm2048 198.18.28.165:443 check cookie ausyd1nxvm2048 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_nzbget
|
|
description Backend for au-syd1 nzbget
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /consul/health
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
server ausyd1nxvm2045 198.18.25.44:443 check cookie ausyd1nxvm2045 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_prowlarr
|
|
description Backend for au-syd1 prowlarr
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /consul/health
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
server ausyd1nxvm2050 198.18.25.66:443 check cookie ausyd1nxvm2050 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_radarr
|
|
description Backend for au-syd1 radarr
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /consul/health
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
server ausyd1nxvm2047 198.18.27.131:443 check cookie ausyd1nxvm2047 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_readarr
|
|
description Backend for au-syd1 readarr
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /consul/health
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
server ausyd1nxvm2049 198.18.29.32:443 check cookie ausyd1nxvm2049 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_sonarr
|
|
description Backend for au-syd1 sonarr
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
|
http-reuse always
|
|
option httpchk GET /consul/health
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
server ausyd1nxvm2046 198.18.26.161:443 check cookie ausyd1nxvm2046 fall 2 inter 2s rise 3 ssl verify none
|
|
|
|
backend be_stalwart_imap
|
|
description Backend for Stalwart IMAP (STARTTLS)
|
|
balance roundrobin
|
|
mode tcp
|
|
option tcp-check
|
|
option prefer-last-server
|
|
stick on src
|
|
stick-table type ip size 200k expire 30m
|
|
tcp-check connect port 143 send-proxy
|
|
tcp-check expect string "* OK"
|
|
tcp-check send "A001 STARTTLS\r\n"
|
|
tcp-check expect rstring "A001 (OK|2.0.0)"
|
|
server ausyd1nxvm2124 198.18.28.76:143 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
server ausyd1nxvm2125 198.18.29.44:143 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
server ausyd1nxvm2126 198.18.25.160:143 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
|
|
backend be_stalwart_imaps
|
|
description Backend for Stalwart IMAPS (implicit TLS)
|
|
balance roundrobin
|
|
mode tcp
|
|
option tcp-check
|
|
option prefer-last-server
|
|
stick on src
|
|
stick-table type ip size 200k expire 30m
|
|
tcp-check connect ssl send-proxy
|
|
tcp-check expect string "* OK"
|
|
server ausyd1nxvm2124 198.18.28.76:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none
|
|
server ausyd1nxvm2125 198.18.29.44:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none
|
|
server ausyd1nxvm2126 198.18.25.160:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none
|
|
|
|
backend be_stalwart_smtp
|
|
description Backend for Stalwart SMTP
|
|
balance roundrobin
|
|
mode tcp
|
|
option tcp-check
|
|
option prefer-last-server
|
|
stick on src
|
|
stick-table type ip size 200k expire 30m
|
|
tcp-check connect port 25 send-proxy
|
|
tcp-check expect string "220 "
|
|
server ausyd1nxvm2124 198.18.28.76:25 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
server ausyd1nxvm2125 198.18.29.44:25 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
server ausyd1nxvm2126 198.18.25.160:25 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
|
|
backend be_stalwart_submission
|
|
description Backend for Stalwart SMTP Submission
|
|
balance roundrobin
|
|
mode tcp
|
|
option tcp-check
|
|
option prefer-last-server
|
|
stick on src
|
|
stick-table type ip size 200k expire 30m
|
|
tcp-check connect port 587 send-proxy
|
|
tcp-check expect string "220 "
|
|
server ausyd1nxvm2124 198.18.28.76:587 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
server ausyd1nxvm2125 198.18.29.44:587 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
server ausyd1nxvm2126 198.18.25.160:587 check fall 3 inter 3s rise 2 send-proxy-v2
|
|
|
|
backend be_stalwart_webadmin
|
|
description Backend for Stalwart Webadmin
|
|
balance roundrobin
|
|
cookie SRVNAME insert indirect nocache
|
|
http-check expect status 200
|
|
http-request set-header X-Forwarded-Port %[dst_port]
|
|
http-request add-header X-Forwarded-Proto https if { dst_port 9443 }
|
|
http-reuse always
|
|
option httpchk GET /
|
|
option forwardfor
|
|
option http-keep-alive
|
|
option prefer-last-server
|
|
redirect scheme https if !{ ssl_fc }
|
|
stick-table type ip size 200k expire 30m
|
|
server ausyd1nxvm2124 198.18.28.76:443 check cookie ausyd1nxvm2124 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none
|
|
server ausyd1nxvm2125 198.18.29.44:443 check cookie ausyd1nxvm2125 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none
|
|
server ausyd1nxvm2126 198.18.25.160:443 check cookie ausyd1nxvm2126 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none
|
|
|
|
# The `peers au-syd1-prod` section is dropped: peer names must be static and a
|
|
# Deployment cannot provide them. Service sessionAffinity: ClientIP pins a
|
|
# client to one replica so the per-replica stick-tables behave as before.
|
|
|
|
listen health
|
|
bind 0.0.0.0:8404
|
|
mode http
|
|
monitor-uri /healthz
|
|
|
|
listen stats
|
|
bind 127.0.0.1:9090
|
|
mode http
|
|
stats uri /
|
|
stats auth admin:admin
|