feat(haproxy): ship per-site exempt list for the wp-admin edge gate
This commit is contained in:
@@ -40,6 +40,7 @@ COPY trusted_ips.map /etc/haproxy/trusted_ips.map
|
|||||||
# volume shadows /etc/haproxy with.
|
# volume shadows /etc/haproxy with.
|
||||||
COPY cloudflare_ips.list /haproxy/defaults/cloudflare_ips.list
|
COPY cloudflare_ips.list /haproxy/defaults/cloudflare_ips.list
|
||||||
COPY trusted_proxies.list /haproxy/defaults/trusted_proxies.list
|
COPY trusted_proxies.list /haproxy/defaults/trusted_proxies.list
|
||||||
|
COPY wpadmin_gate_exempt.list /haproxy/defaults/wpadmin_gate_exempt.list
|
||||||
# Place errorfiles outside the volumed path; the HAProxy config references
|
# Place errorfiles outside the volumed path; the HAProxy config references
|
||||||
# them by absolute path.
|
# them by absolute path.
|
||||||
COPY errors /haproxy/errors
|
COPY errors /haproxy/errors
|
||||||
|
|||||||
+12
-4
@@ -27,11 +27,12 @@ mkdir -p /etc/haproxy
|
|||||||
# existing hosts instead of being permanently shadowed by the volume.
|
# existing hosts instead of being permanently shadowed by the volume.
|
||||||
# Overwrite it from the baked copy on every start.
|
# Overwrite it from the baked copy on every start.
|
||||||
#
|
#
|
||||||
# trusted_proxies.list is OPERATOR DATA: operators add entries directly on
|
# trusted_proxies.list and wpadmin_gate_exempt.list are OPERATOR DATA:
|
||||||
# the server and those must survive restarts/recreates. Seed it from the
|
# operators add entries directly on the server and those must survive
|
||||||
# baked copy only when it's missing; never overwrite an existing one.
|
# restarts/recreates. Seed each from the baked copy only when it's missing;
|
||||||
|
# never overwrite an existing one.
|
||||||
#
|
#
|
||||||
# Both branches fall back to an empty file if the baked default is somehow
|
# All branches fall back to an empty file if the baked default is somehow
|
||||||
# absent, because "acl ... -f <missing file>" is a fatal HAProxy config
|
# absent, because "acl ... -f <missing file>" is a fatal HAProxy config
|
||||||
# error -- the list files must exist unconditionally by the time HAProxy starts.
|
# error -- the list files must exist unconditionally by the time HAProxy starts.
|
||||||
if [ -f /haproxy/defaults/cloudflare_ips.list ]; then
|
if [ -f /haproxy/defaults/cloudflare_ips.list ]; then
|
||||||
@@ -46,6 +47,13 @@ if [ ! -f /etc/haproxy/trusted_proxies.list ]; then
|
|||||||
: > /etc/haproxy/trusted_proxies.list
|
: > /etc/haproxy/trusted_proxies.list
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
if [ ! -f /etc/haproxy/wpadmin_gate_exempt.list ]; then
|
||||||
|
if [ -f /haproxy/defaults/wpadmin_gate_exempt.list ]; then
|
||||||
|
cp /haproxy/defaults/wpadmin_gate_exempt.list /etc/haproxy/wpadmin_gate_exempt.list
|
||||||
|
else
|
||||||
|
: > /etc/haproxy/wpadmin_gate_exempt.list
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
cron &
|
cron &
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,16 @@
|
|||||||
|
# Per-site opt-out from the WordPress admin edge gate.
|
||||||
|
#
|
||||||
|
# Hostnames listed here are EXEMPT: unauthenticated /wp-admin/* requests for
|
||||||
|
# these sites pass through to PHP instead of being redirected to wp-login.php.
|
||||||
|
# One hostname per line, lowercase. Matched against the Host header.
|
||||||
|
#
|
||||||
|
# Referenced by templates/hap_listener.tpl:
|
||||||
|
# acl wp_gate_exempt hdr(host),lower -f /etc/haproxy/wpadmin_gate_exempt.list
|
||||||
|
#
|
||||||
|
# Add a site here when a plugin legitimately serves unauthenticated visitors
|
||||||
|
# from a /wp-admin/ URL that is not in the rule's allowlist. Symptom: "my
|
||||||
|
# plugin's admin page redirects to login".
|
||||||
|
#
|
||||||
|
# Do NOT commit real customer domains — this repo is mirrored publicly. Add
|
||||||
|
# entries directly on the server; the file lives in the /etc/haproxy named
|
||||||
|
# volume and persists across container recreates.
|
||||||
Reference in New Issue
Block a user