Skip to content

deny_paths config enhancements #378

@alexdlukens

Description

@alexdlukens

Enhancement Proposal

Feature requests for enhancement to the "deny_paths" configuration on the haproxy-ddos-protection-configurator charm

  1. Per-site deny_paths support. Currently deny_paths is applied to all hosts haproxy serves traffic for
  2. Configurable deny behavior akin to limit-policy-http. In cases where we want traffic to only be allowed from specific subnets, we will set ip-allow-list accordingly and want to silent-drop or deny-503 traffic from other subnets.

Impact

High (The feature has short-term technical value)

Impact Rationale

HAProxy is used in the PS7 ingress solution.

Here, deployments serve backends for many domains. In these situations it is difficult to use deny_paths config as this applies to all served domains. It would be preferable to set deny_paths per-domain, so that this configuration is not used on some sites, and enabled on differing paths per-site.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request
    No fields configured for Feature.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions