From: Tom Hughes Date: Thu, 10 Sep 2020 08:37:58 +0000 (+0100) Subject: Handle all requests on frontends and stop proxying to backends X-Git-Url: https://git.openstreetmap.org./chef.git/commitdiff_plain/a91c38fb36e6b131585d5ccde797d66cf0cd22fa Handle all requests on frontends and stop proxying to backends --- diff --git a/cookbooks/web/recipes/frontend.rb b/cookbooks/web/recipes/frontend.rb index 4fa375fba..ecfaea7ef 100644 --- a/cookbooks/web/recipes/frontend.rb +++ b/cookbooks/web/recipes/frontend.rb @@ -29,8 +29,8 @@ web_passwords = data_bag_item("web", "passwords") apache_module "alias" apache_module "expires" apache_module "headers" -apache_module "proxy_http" -apache_module "proxy_balancer" +apache_module "proxy" +apache_module "proxy_fcgi" apache_module "lbmethod_byrequests" apache_module "lbmethod_bybusyness" apache_module "rewrite" diff --git a/cookbooks/web/templates/default/apache.frontend.erb b/cookbooks/web/templates/default/apache.frontend.erb index d99dd532f..ae34b9456 100644 --- a/cookbooks/web/templates/default/apache.frontend.erb +++ b/cookbooks/web/templates/default/apache.frontend.erb @@ -12,7 +12,6 @@ # Enable SSL # SSLEngine on - SSLProxyEngine on SSLCertificateFile /etc/ssl/certs/www.openstreetmap.org.pem SSLCertificateKeyFile /etc/ssl/private/www.openstreetmap.org.key @@ -138,38 +137,24 @@ Alias /attachments /store/rails/attachments # - # Preserve the host name when forwarding to the proxy + # Pass authentication related headers to cgimap # - ProxyPreserveHost on - - # - # Set a long timeout - changeset uploads can take a long time - # - ProxyTimeout 3600 - - # - # Allow all proxy requests - # - - Require all granted - + + CGIPassAuth On + # - # Pass some other API calls to the backends via a load balancer + # Pass supported calls to cgimap # - ProxyPassMatch ^(/api/0\.6/map(\.json|\.xml)?)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/tracepoints)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/amf/read)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/swf/trackpoints)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/changeset/[0-9]+(\.json|\.xml)?)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/changeset/[0-9]+/upload(\.json|\.xml)?)$ balancer://amsterdam$1 - ProxyPassMatch ^(/api/0\.6/changeset/[0-9]+/download(\.json|\.xml)?)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/(node|way|relation)/[0-9]+(\.json|\.xml)?)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/(node|way|relation)/[0-9]+/(full|history|search|ways|relations)(\.json|\.xml)?)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/nodes(\.json|\.xml)?)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/ways(\.json|\.xml)?)$ balancer://backend$1 - ProxyPassMatch ^(/api/0\.6/relations(\.json|\.xml)?)$ balancer://backend$1 - ProxyPassMatch ^(/trace/[0-9]+/data(|/|.xml))$ balancer://backend$1 + RewriteRule ^/api/0\.6/map(\.json|\.xml)?$ fcgi://127.0.0.1:8000$0 [P] + RewriteCond %{REQUEST_METHOD} ^(HEAD|GET)$ + RewriteRule ^/api/0\.6/(node|way|relation|changeset)/[0-9]+(\.json|\.xml)?$ fcgi://127.0.0.1:8000$0 [P] + RewriteRule ^/api/0\.6/(node|way|relation)/[0-9]+/history(\.json|\.xml)?$ fcgi://127.0.0.1:8000$0 [P] + RewriteRule ^/api/0\.6/(node|way|relation)/[0-9]+/relations(\.json|\.xml)?$ fcgi://127.0.0.1:8000$0 [P] + RewriteRule ^/api/0\.6/node/[0-9]+/ways(\.json|\.xml)?$ fcgi://127.0.0.1:8000$0 [P] + RewriteRule ^/api/0\.6/(way|relation)/[0-9]+/full(\.json|\.xml)?$ fcgi://127.0.0.1:8000$0 [P] + RewriteRule ^/api/0\.6/(nodes|ways|relations)(\.json|\.xml)?$ fcgi://127.0.0.1:8000$0 [P] + RewriteRule ^/api/0\.6/changeset/[0-9]+/(upload|download)(\.json|\.xml)?$ fcgi://127.0.0.1:8000$0 [P] # # Redirect trac and wiki requests to the right places @@ -183,36 +168,6 @@ RedirectPermanent /images/osm_logo.png https://www.openstreetmap.org/assets/osm_logo.png RedirectPermanent /images/cc_button.png https://www.openstreetmap.org/assets/cc_button.png - # - # Define a load balancer for the local backends - # - - ProxySet lbmethod=bybusyness -<% Array(node[:web][:backends]).each do |backend| -%> - BalancerMember https://<%= backend %> disablereuse=on -<% end -%> - - - # - # Define a load balancer for the Amsterdam backends - # - - ProxySet lbmethod=bybusyness -<% ["rails1.ams", "rails2.ams", "rails3.ams"].each do |backend| -%> - BalancerMember https://<%= backend %> disablereuse=on -<% end -%> - - - # - # Define a load balancer for the Bytemark backends - # - - ProxySet lbmethod=bybusyness -<% ["rails4.bm", "rails5.bm"].each do |backend| -%> - BalancerMember https://<%= backend %> disablereuse=on -<% end -%> - - # # Redirect api requests made to www.osm.org to api.osm.org #