]> Frank Brehm's Git Trees - pixelpark/hiera.git/commitdiff
configured proxy service for jenkins
authorThomas Heller <thomas.heller@pixelpark.com>
Fri, 31 Aug 2018 12:42:22 +0000 (14:42 +0200)
committerThomas Heller <thomas.heller@pixelpark.com>
Fri, 31 Aug 2018 12:42:22 +0000 (14:42 +0200)
customer/pixelpark/brauhaus.pixelpark.com.yaml

index 3b0442d3c925d4f4820fbb228ffd4a4ad755de38..89fdc1459a63b429820aee71b2bb4707e19b7017 100644 (file)
@@ -1,2 +1,39 @@
 ---
 infra::role: base
+infra::additional_classes:
+  - infra::profile::apache
+  - apache::mod::headers
+
+infra::profile::apache::pp_vhosts:
+  jenkins:
+    docroot: '/srv'
+    servername: 'brauhaus.pixelpark.com'
+    cert_servername: 'wildcard.pixelpark.net'
+    cert_customer: 'pixelpark'
+    ssl_cert: '/etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem'
+    ssl_key: '/etc/pki/tls/private/wildcard.pixelpark.net-key.pem'
+    ssl_chain: '/etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem'
+    proxy_preserve_host: true
+    allow_encoded_slashes: nodecode
+    proxy_pass:
+      - path: /
+        url: 'http://127.0.0.1:8080/'
+        keywords:
+          - 'nocanon'
+    directories:
+      # Root Directory
+      - provider: directory
+        path: '/srv'
+        options:
+          - FollowSymLinks
+          - MultiViews
+        allow_override:
+          - None
+    rewrites:
+      - comment: 'Alles auf https umleiten.'
+        rewrite_cond:
+          - '%%{ich-trickse}{HTTPS} !=on'
+        rewrite_rule:
+          - ^(.*)$ https://%{literal("%")}{HTTP_HOST}$1 [R=301,L]
+    request_headers_ssl:
+      - 'set X-Forwarded-Proto "https"'