#jinja2: lstrip_blocks:"True", trim_blocks:"True", keep_trailing_newline: True
# {{ ansible_managed }}
{% if ads_ssl_enabled %}
    {% set merged_pem_certificate = haproxy_server_config.haproxy_cfg.haproxy_ssl_frontend %}
    {% set haproxy_ssl_frontend = "ssl crt " ~ merged_pem_certificate | default('/etc/ssl/merged.pem', true) %}
    {% set haproxy_ssl_backend = "ssl verify required ca-file @system-ca" %}
{% endif %}
{% set sr_port = services.schema_registry.config.Main.schema_registry_listener_port%}
{% set sr_group = groups['schema_registry'] %}

# Schema Registry frontend
frontend schema_registry_frontend
    default_backend schema_registry_backend
    http-response add-header X-Backend %s
    bind *:{{ haproxy_server_config.haproxy_cfg.listener_schema_registry.schema_registry_front_port }} {% if ads_ssl_enabled %} {{ haproxy_ssl_frontend }}{% endif %}

# Schema Registry backend
backend schema_registry_backend
    balance {{ haproxy_server_config.haproxy_cfg.listener_schema_registry.haproxy_server_backend_balance }}
    option {{ haproxy_server_config.haproxy_cfg.listener_schema_registry.haproxy_server_backend_option }}
{% if ads_basic_auth_enabled %}
    http-check send hdr Authorization "Basic {{ haproxy_check_auth_b64 }}"
{% endif %}
{% if ads_ssl_enabled %}
    http-send-name-header Host
{% endif %}
    {# # `ipv4@{{ host }}` - Force IPv4 address resolution. Without an explicit IP protocol prefix,
    ALT Linux may resolve FQDN via IPv6 by default. #}
{% for host in sr_group %}
    {% set __host = ("ipv4@" if haproxy_server_config.haproxy_cfg.backend_network.force_ipv4 else "") ~ host %}
    {% set _ssl_settings = '' %}
    {% if ads_ssl_enabled %}
        {% set _ssl_settings = haproxy_ssl_backend ~ ' sni str(' ~ host ~ ')' %}
    {% endif %}
    {#  Server name must stay the host FQDN: http-send-name-header sends it as the Host header,
        and the backend rejects a Host absent from its certificate (400 Invalid SNI). #}
    server {{ host }} {{ __host }}:{{ sr_port }} check inter 10s rise 2 fall 3 {{ _ssl_settings }}
{% endfor %}
