#jinja2: lstrip_blocks:"True", trim_blocks:"True", keep_trailing_newline: True
# {{ ansible_managed }}
{% if ads_ssl_enabled %}
    {% set merged_pem_certificate = haproxy_server_config.haproxy_cfg.haproxy_ssl_frontend %}
    {% set haproxy_ssl_frontend = "ssl crt " ~ merged_pem_certificate | default('/etc/ssl/merged.pem', true) %}
    {% set haproxy_ssl_backend = "ssl verify required ca-file @system-ca" %}
{% endif %}
{% set kafka_rest_port = services.kafka_rest.config.Main.rest_listener_port%}
{% set kafka_rest_group = groups['kafka_rest'] %}

# Kafka REST frontend
frontend kafka_rest_frontend
    default_backend kafka_rest_backend
    http-response add-header X-Backend %s
    bind *:{{ haproxy_server_config.haproxy_cfg.listener_kafka_rest.kafka_rest_front_port }} {% if ads_ssl_enabled %} {{ haproxy_ssl_frontend }}{% endif %}

# Kafka REST backend
backend kafka_rest_backend
    balance {{ haproxy_server_config.haproxy_cfg.listener_kafka_rest.haproxy_server_backend_balance }}
    option {{ haproxy_server_config.haproxy_cfg.listener_kafka_rest.haproxy_server_backend_option }}
{% if ads_basic_auth_enabled %}
    http-check send hdr Authorization "Basic {{ haproxy_check_auth_b64 }}"
{% endif %}
{% if ads_ssl_enabled %}
    http-send-name-header Host
{% endif %}
    {# # `ipv4@{{ host }}` - Force IPv4 address resolution. Without an explicit IP protocol prefix,
    ALT Linux may resolve FQDN via IPv6 by default. #}
{% for host in kafka_rest_group %}
    {% set __host = ("ipv4@" if haproxy_server_config.haproxy_cfg.backend_network.force_ipv4 else "") ~ host %}
    {% set _ssl_settings = '' %}
    {% if ads_ssl_enabled %}
        {% set _ssl_settings = haproxy_ssl_backend ~ ' sni str(' ~ host ~ ')' %}
    {% endif %}
    {# # Server name must stay the host FQDN: http-send-name-header sends it as the Host header,
        and the backend rejects a Host absent from its certificate (400 Invalid SNI). #}
    server {{ host }} {{ __host }}:{{ kafka_rest_port }} check inter 10s rise 2 fall 3 {{ _ssl_settings }}
{% endfor %}
