Skip to content

Commit b8a6e80

Browse files
author
OpenShift Bot
committed
Merge pull request #9175 from cw-aleks/patch-2
Merged by openshift-bot
2 parents 7f170dc + b81bc0e commit b8a6e80

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

images/router/haproxy/conf/haproxy-config.template

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -121,11 +121,11 @@ frontend public_ssl
121121
# traffic
122122
##########################################################################
123123
backend be_sni
124-
server fe_sni 127.0.0.1:10444 weight 1 send-proxy
124+
server fe_sni 127.0.0.1:{{env "ROUTER_SERVICE_SNI_PORT" "10444"}} weight 1 send-proxy
125125

126126
frontend fe_sni
127127
# terminate ssl on edge
128-
bind 127.0.0.1:10444 ssl no-sslv3 {{ if (len .DefaultCertificate) gt 0 }}crt {{.DefaultCertificate}}{{ else }}crt /var/lib/haproxy/conf/default_pub_keys.pem{{ end }} crt {{ $workingDir }}/certs accept-proxy
128+
bind 127.0.0.1:{{env "ROUTER_SERVICE_SNI_PORT" "10444"}} ssl no-sslv3 {{ if (len .DefaultCertificate) gt 0 }}crt {{.DefaultCertificate}}{{ else }}crt /var/lib/haproxy/conf/default_pub_keys.pem{{ end }} crt {{ $workingDir }}/certs accept-proxy
129129
mode http
130130

131131
# Remove port from Host header
@@ -158,11 +158,11 @@ frontend fe_sni
158158
##########################################################################
159159
# backend for when sni does not exist, or ssl term needs to happen on the edge
160160
backend be_no_sni
161-
server fe_no_sni 127.0.0.1:10443 weight 1 send-proxy
161+
server fe_no_sni 127.0.0.1:{{env "ROUTER_SERVICE_NO_SNI_PORT" "10443"}} weight 1 send-proxy
162162

163163
frontend fe_no_sni
164164
# terminate ssl on edge
165-
bind 127.0.0.1:10443 ssl no-sslv3 {{ if (len .DefaultCertificate) gt 0 }}crt {{.DefaultCertificate}}{{ else }}crt /var/lib/haproxy/conf/default_pub_keys.pem{{ end }} accept-proxy
165+
bind 127.0.0.1:{{env "ROUTER_SERVICE_NO_SNI_PORT" "10443"}} ssl no-sslv3 {{ if (len .DefaultCertificate) gt 0 }}crt {{.DefaultCertificate}}{{ else }}crt /var/lib/haproxy/conf/default_pub_keys.pem{{ end }} accept-proxy
166166
mode http
167167

168168
# Remove port from Host header

0 commit comments

Comments
 (0)