#jinja2: lstrip_blocks:"True", trim_blocks:"True", keep_trailing_newline: True
# {{ ansible_managed }}
{% set stats_username = haproxy_server_config.haproxy_cfg.listener_stats.haproxy_server_listener_user %}
{% set stats_password = haproxy_server_config.haproxy_cfg.listener_stats.haproxy_server_listener_password %}
{% if ads_ssl_enabled %}
    {% set merged_pem_certificate = haproxy_server_config.haproxy_cfg.haproxy_ssl_frontend %}
    {% set haproxy_ssl_frontend = "ssl crt " ~ merged_pem_certificate | default('/etc/ssl/merged.pem', true) %}
{% endif %}


#---------------------------------------------------------------------
# Global settings
#---------------------------------------------------------------------
global
    log /dev/log    local0
    chroot      /var/lib/haproxy/
    maxconn     1024
    user        haproxy
    group       haproxy
    daemon
#---------------------------------------------------------------------
# common defaults that all the 'listen' and 'backend' sections will
# use if not designated in their block
#---------------------------------------------------------------------
defaults
    mode                    http
    log                     global
    option                  httplog
    option                  dontlognull
    option http-server-close
    option forwardfor       except 127.0.0.0/8
    option                  redispatch
    retries                 3
    timeout http-request    10s
    timeout queue           1m
    timeout connect         10s
    timeout client          1m
    timeout server          1m
    timeout http-keep-alive 10s
    timeout check           10s
#---------------------------------------------------------------------
# HAProxy statistics
#---------------------------------------------------------------------
listen stats
    bind *:{{ haproxy_server_config.haproxy_cfg.listener_stats.haproxy_server_listener_port }} {% if ads_ssl_enabled %} {{ haproxy_ssl_frontend }}{% endif %}

    stats enable
    stats uri /stats
    stats hide-version
    stats auth {{ stats_username }}:{{ stats_password }}
