diff options
author | Christian Breunig <christian@breunig.cc> | 2023-12-14 17:24:22 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2023-12-14 17:24:22 +0100 |
commit | 9f72aff65e0589b9387227f69a25545eba5ba4f5 (patch) | |
tree | e0534e40c7d58ce940860513bdf885e147dcaf10 /data/templates | |
parent | 0917ed315aa3e8707ad8b67293b38e7452f9cda8 (diff) | |
parent | fe99c45e05fd5794905145ddca80e6078145c2e8 (diff) | |
download | vyos-1x-9f72aff65e0589b9387227f69a25545eba5ba4f5.tar.gz vyos-1x-9f72aff65e0589b9387227f69a25545eba5ba4f5.zip |
Merge pull request #2590 from sever-sever/T5798
T5798: load-balancing revese-proxy add multiple SSL certificates
Diffstat (limited to 'data/templates')
-rw-r--r-- | data/templates/load-balancing/haproxy.cfg.j2 | 13 |
1 files changed, 9 insertions, 4 deletions
diff --git a/data/templates/load-balancing/haproxy.cfg.j2 b/data/templates/load-balancing/haproxy.cfg.j2 index a75ee9904..defb76fba 100644 --- a/data/templates/load-balancing/haproxy.cfg.j2 +++ b/data/templates/load-balancing/haproxy.cfg.j2 @@ -50,13 +50,19 @@ defaults {% if service is vyos_defined %} {% for front, front_config in service.items() %} frontend {{ front }} -{% set ssl_front = 'ssl crt /run/haproxy/' ~ front_config.ssl.certificate ~ '.pem' if front_config.ssl.certificate is vyos_defined else '' %} +{% set ssl_front = [] %} +{% if front_config.ssl.certificate is vyos_defined and front_config.ssl.certificate is iterable %} +{% for cert in front_config.ssl.certificate %} +{% set _ = ssl_front.append('crt /run/haproxy/' ~ cert ~ '.pem') %} +{% endfor %} +{% endif %} +{% set ssl_directive = 'ssl' if ssl_front else '' %} {% if front_config.listen_address is vyos_defined %} {% for address in front_config.listen_address %} - bind {{ address | bracketize_ipv6 }}:{{ front_config.port }} {{ ssl_front }} + bind {{ address | bracketize_ipv6 }}:{{ front_config.port }} {{ ssl_directive }} {{ ssl_front | join(' ') }} {% endfor %} {% else %} - bind :::{{ front_config.port }} v4v6 {{ ssl_front }} + bind :::{{ front_config.port }} v4v6 {{ ssl_directive }} {{ ssl_front | join(' ') }} {% endif %} {% if front_config.redirect_http_to_https is vyos_defined %} http-request redirect scheme https unless { ssl_fc } @@ -161,4 +167,3 @@ backend {{ back }} {% endfor %} {% endif %} - |