Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- global
- log /dev/log local0
- log /dev/log local1 notice
- chroot /var/lib/haproxy
- stats socket /run/haproxy/admin.sock mode 660 level admin
- stats timeout 30s
- user haproxy
- group haproxy
- daemon
- # Default SSL material locations
- ca-base /etc/ssl/certs
- crt-base /etc/ssl/private
- # See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate
- ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
- ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
- ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets
- defaults
- log global
- mode http
- option httplog
- option dontlognull
- timeout connect 30
- timeout client 2h
- timeout server 2h
- timeout tunnel 2h
- errorfile 400 /etc/haproxy/errors/400.http
- errorfile 403 /etc/haproxy/errors/403.http
- errorloc 404 https://thispagedoesnotexist.mydomain.dev
- errorfile 408 /etc/haproxy/errors/408.http
- errorfile 500 /etc/haproxy/errors/500.http
- errorfile 502 /etc/haproxy/errors/502.http
- errorloc 503 https://somethinghappened503.mydomain.dev
- errorfile 504 /etc/haproxy/errors/504.http
- frontend www-https
- # bind mypublicip:443 ssl crt /etc/haproxy/ssl/mydomain.dev/cert.pem
- bind mypublicip.145:443
- http-request set-header X-Forwarded-Proto https
- http-request set-header X-Forwarded-Host %[req.hdr(Host)]
- http-request set-header X-Client-IP req.hdr_ip([X-Forwarded-For])
- http-request add-header X-Forwarded-Port 443
- http-response set-header Strict-Transport-Security "max-age=16000000; includeSubDomains; preload;"
- acl letsencrypt-acl path_beg /.well-known/acme-challenge/
- use_backend letsencrypt-backend if letsencrypt-acl
- acl gokapi hdr(host) -i files.mydomain.dev
- use_backend gokapi if gokapi
- default_backend www-backend
- frontend www-http
- bind mypublicip:80
- # http-request set-header X-Forwarded-Proto https
- http-request set-header X-Forwarded-Host %[req.hdr(Host)]
- default_backend www-backend
- backend letsencrypt-backend
- server letsencrypt 127.0.0.1:54321
- backend gokapi
- acl is_root path /
- http-request redirect code 301 location https://files.mydomain.dev/login if is_root
- option forwardfor
- option httpchk GET /login
- http-check expect status 200
- timeout client 120m
- timeout server 120m
- option http-server-close
- server gokapi-server 127.0.0.1:53842 check inter 2s
- backend www-backend
- http-request redirect scheme https code 301 unless { ssl_fc }
- server catchall 127.0.0.1:443
Advertisement
Add Comment
Please, Sign In to add comment