Commit Graph
2 Commits
  • haproxy: deploy script can add a new certificate over the stats socket
    DEPLOY_HAPROXY_HOT_UPDATE="yes" now allows to add a new certificate
    within HAProxy instead of updating an existing one.
    
    In order to work, the ${DEPLOY_HAPROXY_PEM_PATH} value must be used as a
    parameter to the "crt" keyword in the haproxy configuration.
    
    The patch uses the following commands over HAProxy stats socket:
    - show ssl cert
    - new ssl cert
    - set ssl cert
    - commit ssl cert
    - add ssl crt-list
  • haproxy: deploy script can update existing certificate over stats socket
    Since version 2.2, HAProxy is able to update dynamically certificates,
    without a reload.
    
    This patch uses socat to push the certificate into HAProxy in order to
    achieve hot update. With this method, reloading is not required.
    This should be used only to update an existing certificate in haproxy.
    
    2 new variables are available:
    
    - DEPLOY_HAPROXY_HOT_UPDATE="yes" update over the stats socket instead
      of reloading
    
    - DEPLOY_HAPROXY_STATS_SOCKET="UNIX:/run/haproxy/admin.sock" set the path on
      the stats socket.