diff --git a/env-stage-hy/group_vars/all.yml b/env-stage-hy/group_vars/all.yml index 9abe8db..87d0c65 100644 --- a/env-stage-hy/group_vars/all.yml +++ b/env-stage-hy/group_vars/all.yml @@ -3,6 +3,11 @@ maat_redis_server: port: 7002 db: 0 +dynamic_maat_redis_server: + address: 192.168.100.3 + port: 7002 + db: 0 + cert_store_server: address: 192.168.100.1 port: 9991 @@ -27,7 +32,6 @@ kni: switch: 1 maat: readconf_mode: 2 - default_action: 128 send_logger: switch: 1 tfe_nodes: diff --git a/env-stage-xxg/group_vars/all.yml b/env-stage-xxg/group_vars/all.yml index 33b25fa..c238d14 100644 --- a/env-stage-xxg/group_vars/all.yml +++ b/env-stage-xxg/group_vars/all.yml @@ -2,6 +2,11 @@ maat_redis_server: address: 192.168.40.120 port: 7002 db: 0 + +dynamic_maat_redis_server: + address: 192.168.100.3 + port: 7002 + db: 0 cert_store_server: address: 192.168.40.161 @@ -27,7 +32,6 @@ kni: switch: 1 maat: readconf_mode: 2 - default_action: 128 send_logger: switch: 1 tfe_nodes: diff --git a/roles/kni/files/kni-2.1.0.b0bbde4-1.el7.centos.x86_64.rpm b/roles/kni/files/kni-2.1.0.b0bbde4-1.el7.centos.x86_64.rpm deleted file mode 100644 index fb0f2ff..0000000 Binary files a/roles/kni/files/kni-2.1.0.b0bbde4-1.el7.centos.x86_64.rpm and /dev/null differ diff --git a/roles/kni/files/kni-2.1.1.e65880a-1.el7.centos.x86_64.rpm b/roles/kni/files/kni-2.1.1.e65880a-1.el7.centos.x86_64.rpm new file mode 100644 index 0000000..84f787a Binary files /dev/null and b/roles/kni/files/kni-2.1.1.e65880a-1.el7.centos.x86_64.rpm differ diff --git a/roles/kni/templates/kni.conf.j2 b/roles/kni/templates/kni.conf.j2 index a4612b6..e128e61 100644 --- a/roles/kni/templates/kni.conf.j2 +++ b/roles/kni/templates/kni.conf.j2 @@ -35,16 +35,21 @@ keepalive_idle = 2 keepalive_intvl = 1 keepalive_cnt = 3 -[maat] +[static_maat] readconf_mode = {{ kni.maat.readconf_mode }} -tableinfo_path = ./conf/kni/maat_tableinfo.conf +tableinfo_path = ./conf/kni/static_maat_tableinfo.conf maatjson_path = ./conf/kni/maat_test.json redis_ip = {{ maat_redis_server.address }} redis_port = {{ maat_redis_server.port }} redis_index = {{ maat_redis_server.db }} -tablename_intercept_ip = PXY_INTERCEPT_IP -tablename_intercept_domain = PXY_INTERCEPT_DOMAIN -default_action = {{ kni.maat.default_action }} + +[dynamic_maat] +readconf_mode = {{ kni.maat.readconf_mode }} +tableinfo_path = ./conf/kni/dynamic_maat_tableinfo.conf +maatjson_path = ./conf/kni/maat_test.json +redis_ip = {{ dynamic_maat_redis_server.address }} +redis_port = {{ dynamic_maat_redis_server.port }} +redis_index = {{ dynamic_maat_redis_server.db }} [send_logger] switch = {{ kni.send_logger.switch }}