Skip to main content

HAProxy HTTPS SSH Bitbucket

Atlassian Bitbucket

Bitbucket is a software developped by Atlassian and I define it like an interface to Git, in order to make it more friendly.
There is a bunch of software in Bitbucket, acting as layers in order to facilitate collaboration on code.
Last but not least, Bitbucket has a good integration with Jira, which is one of the main reasons I choosed it to be our tool at ESTI.
I thank Atlassian very much for metting ESTI use community licence of both Jira and Bitbucket.

The goal: HTTPS and SSH on regular ports

Default HTTP and SSH port for Bitbucket is neither 443 nor 22. Their are configurable and it would be possible to directly make Bitbucket face those ports, but we dont like that, we'd rather setup a HAProxy instance that will forward the ports for us.
Prerequisite for that is to have a HTTPS certificate. It might be self signed or not. The one I use is not self-signed, and I bought it to Gandi, which provides an intermediate SHA2 certificate.

To sum it up, I have in my hand:
  • The private key I used to request the certificate: rktmb.org.key
  • The certificate for the domain: rktmb.org.crt
  • The intermediate Gandi certificate: gandi.pem

Configure HAProxy for HTTPS

Configuring HAProxy to make SSL termination sur Bitbucket is already documented on Atlassian Website. Pointing to that very good documentation is essential, but it misses one point: how to build the certificate that HAProxy need in order to trigger the SSL handshake?

As you can see in the sample configuration file, there is a "crt /etc/haproxy/certAndKey.pem" in the configuration and there is no indication is given on how to build it. We are going to fill that point here.

In HAProxy, the "crt" option has a unique value, which is a filename, hich points to the certificate issued by the authority you bought the certificate from. But it is not that simple: It should be in fact the concatenation of the "private key" and the "certificate". If you notice in the Atlassian documentation linked above, the name is "certAndKey.pem".
You build it with:

# cat rktmb.org.crt rktmb.org.key > certAndKey.pem

But if you ever need to use an intermediate certificate, this usually happens on some old browsers, the "certAndKey.pem" file then become a "cert_inter_private.pem" file, which is composed of the concatenation of the "private key" the "intermadiate" and the "certificate".
You buid it with:

# cat rktmb.org.crt gandi.pem rktmb.org.key > rktmb.org.cert_inter_private.pem

Conclusion

We end up with a 100% similar configuration to the one provided by Atlassian, but we brought a small explanation on how to build the expected certificate.

Popular posts from this blog

Undefined global vim

Defining vim as global outside of Neovim When developing plugins for Neovim, particularly in Lua, developers often encounter the "Undefined global vim" warning. This warning can be a nuisance and disrupt the development workflow. However, there is a straightforward solution to this problem by configuring the Lua Language Server Protocol (LSP) to recognize 'vim' as a global variable. Getting "Undefined global vim" warning when developing Neovim plugin While developing Neovim plugins using Lua, the Lua language server might not recognize the 'vim' namespace by default. This leads to warnings about 'vim' being an undefined global variable. These warnings are not just annoying but can also clutter the development environment with unnecessary alerts, potentially hiding other important warnings or errors. Defining vim as global in Lua LSP configuration to get rid of the warning To resolve the "Undefined global vi...

npm run build base-href

Using NPM to specify base-href When building an Angular application, people usually use "ng" and pass arguments to that invocation. Typically, when wanting to hard code "base-href" in "index.html", one will issue: ng build --base-href='https://ngx.rktmb.org/foo' I used to build my angular apps through Bamboo or Jenkins and they have a "npm" plugin. I got the habit to build the application with "npm run build" before deploying it. But the development team once asked me to set the "--base-href='https://ngx.rktmb.org/foo'" parameter. npm run build --base-href='https://ngx.rktmb.org/foo did not set the base href in indext.html After looking for a while, I found https://github.com/angular/angular-cli/issues/13560 where it says: You need to use −− to pass arguments to npm scripts. This did the job! The command to issue is then: npm run build -- --base-href='https://ngx.rktmb.org/foo...

CopilotChat GlobFile Configuration

CopilotChat GlobFile Configuration Want to feed multiple files into GitHub Copilot Chat from Neovim without listing each one manually? Let's add a tiny feature that does exactly that: a file glob that includes full file contents . In this post, we'll walk through what CopilotChat.nvim offers out of the box, why the missing piece matters, and how to implement a custom #file_glob:<pattern> function to include the contents of all files matching a glob. Using Copilot Chat with Neovim CopilotChat.nvim brings GitHub Copilot's chat right into your editing flow. No context switching, no browser hopping — just type your prompt in a Neovim buffer and let the AI help you refactor code, write tests, or explain tricky functions. You can open the chat (for example) with a command like :CopilotChat , then provide extra context using built-in functions. That “extra context” is where the magic really happens. Built-in functio...