Compare commits
No commits in common. "f29" and "rawhide" have entirely different histories.
2 changed files with 0 additions and 126 deletions
33
Dockerfile
33
Dockerfile
|
|
@ -1,33 +0,0 @@
|
||||||
#
|
|
||||||
# This is the egress router HTTP proxy for OpenShift Origin
|
|
||||||
#
|
|
||||||
# The standard name for this image is openshift/origin-egress-http-proxy
|
|
||||||
#
|
|
||||||
FROM registry.fedoraproject.org/f29/origin-base:latest
|
|
||||||
|
|
||||||
ENV NAME=origin-egress-http-proxy \
|
|
||||||
VERSION=3.11 \
|
|
||||||
ARCH=x86_64
|
|
||||||
|
|
||||||
RUN INSTALL_PKGS="squid" && \
|
|
||||||
dnf install -y $INSTALL_PKGS && \
|
|
||||||
rpm -V $INSTALL_PKGS && \
|
|
||||||
dnf clean all && \
|
|
||||||
rmdir /var/log/squid /var/spool/squid && \
|
|
||||||
rm -f /etc/squid/squid.conf
|
|
||||||
|
|
||||||
LABEL io.k8s.display-name="OpenShift Origin HTTP proxy egress router" \
|
|
||||||
io.k8s.description="This is the egress router HTTP proxy for OpenShift Origin" \
|
|
||||||
io.openshift.tags="openshift,router,egress,http" \
|
|
||||||
summary="This is the egress router HTTP proxy for OpenShift Origin" \
|
|
||||||
maintainer="Jakub Cajka <jcajka@fedoraproject.org>" \
|
|
||||||
License="GPLv2+" \
|
|
||||||
name="$FGC/$NAME" \
|
|
||||||
com.redhat.component="$NAME" \
|
|
||||||
version="$VERSION" \
|
|
||||||
architecture="$ARCH" \
|
|
||||||
usage="This is the egress router HTTP proxy for OpenShift Origin"
|
|
||||||
|
|
||||||
ADD egress-http-proxy.sh /bin/egress-http-proxy.sh
|
|
||||||
|
|
||||||
ENTRYPOINT /bin/egress-http-proxy.sh
|
|
||||||
|
|
@ -1,93 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# OpenShift egress HTTP proxy setup script
|
|
||||||
|
|
||||||
set -o errexit
|
|
||||||
set -o nounset
|
|
||||||
set -o pipefail
|
|
||||||
|
|
||||||
function die() {
|
|
||||||
echo "$*" 1>&2
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
|
|
||||||
if [[ -z "${EGRESS_HTTP_PROXY_DESTINATION}" ]]; then
|
|
||||||
die "No EGRESS_HTTP_PROXY_DESTINATION specified"
|
|
||||||
fi
|
|
||||||
|
|
||||||
IPADDR_REGEX="[[:xdigit:].:]*[.:][[:xdigit:].:]+"
|
|
||||||
OPT_CIDR_MASK_REGEX="(/[[:digit:]]+)?"
|
|
||||||
HOSTNAME_REGEX="[[:alnum:]][[:alnum:].-]+"
|
|
||||||
DOMAIN_REGEX="\*\.${HOSTNAME_REGEX}"
|
|
||||||
|
|
||||||
function generate_acls() {
|
|
||||||
n=0
|
|
||||||
saw_wildcard=
|
|
||||||
while read dest; do
|
|
||||||
if [[ "${dest}" =~ ^\w*$ || "${dest}" =~ ^# ]]; then
|
|
||||||
# comment or blank line
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
n=$(($n + 1))
|
|
||||||
|
|
||||||
if [[ "${dest}" == "*" ]]; then
|
|
||||||
saw_wildcard=1
|
|
||||||
continue
|
|
||||||
elif [[ -n "${saw_wildcard}" ]]; then
|
|
||||||
die "Wildcard must be last rule, if present"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ "${dest}" =~ ^! ]]; then
|
|
||||||
rule=deny
|
|
||||||
dest="${dest#!}"
|
|
||||||
else
|
|
||||||
rule=allow
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo ""
|
|
||||||
if [[ "${dest}" =~ ^${IPADDR_REGEX}${OPT_CIDR_MASK_REGEX}$ ]]; then
|
|
||||||
echo acl dest$n dst "${dest}"
|
|
||||||
echo http_access "${rule}" dest$n
|
|
||||||
elif [[ "${dest}" =~ ^${DOMAIN_REGEX}$ ]]; then
|
|
||||||
echo acl dest$n dstdomain "${dest#\*}"
|
|
||||||
echo http_access "${rule}" dest$n
|
|
||||||
elif [[ "${dest}" =~ ^${HOSTNAME_REGEX}$ ]]; then
|
|
||||||
echo acl dest$n dstdomain "${dest}"
|
|
||||||
echo http_access "${rule}" dest$n
|
|
||||||
else
|
|
||||||
die "Bad destination '${dest}'"
|
|
||||||
fi
|
|
||||||
done <<< "${EGRESS_HTTP_PROXY_DESTINATION}"
|
|
||||||
|
|
||||||
echo ""
|
|
||||||
if [[ -n "${saw_wildcard}" ]]; then
|
|
||||||
echo "http_access allow all"
|
|
||||||
else
|
|
||||||
echo "http_access deny all"
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
if [[ "${EGRESS_HTTP_PROXY_MODE:-}" == "unit-test" ]]; then
|
|
||||||
generate_acls
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
CONF=/etc/squid/squid.conf
|
|
||||||
rm -f ${CONF}
|
|
||||||
|
|
||||||
cat > ${CONF} <<EOF
|
|
||||||
http_port 8080
|
|
||||||
cache deny all
|
|
||||||
access_log none all
|
|
||||||
debug_options ALL,0
|
|
||||||
shutdown_lifetime 0
|
|
||||||
EOF
|
|
||||||
|
|
||||||
generate_acls >> ${CONF}
|
|
||||||
|
|
||||||
echo "Running squid with config:"
|
|
||||||
sed -e 's/^/ /' ${CONF}
|
|
||||||
echo ""
|
|
||||||
echo ""
|
|
||||||
|
|
||||||
exec squid -N
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue