derFelix244

haproxy-cfg

Jun 13th, 2026 (edited)
63
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.08 KB | None | 0 0
  1. global
  2. log /dev/log local0
  3. log /dev/log local1 notice
  4. chroot /var/lib/haproxy
  5. stats socket /run/haproxy/admin.sock mode 660 level admin
  6. stats timeout 30s
  7. user haproxy
  8. group haproxy
  9. daemon
  10.  
  11. # Default SSL material locations
  12. ca-base /etc/ssl/certs
  13. crt-base /etc/ssl/private
  14.  
  15. # See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate
  16. ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
  17. ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
  18. ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets
  19.  
  20. defaults
  21. log global
  22. mode http
  23. option httplog
  24. option dontlognull
  25. timeout connect 30
  26. timeout client 2h
  27. timeout server 2h
  28. timeout tunnel 2h
  29. errorfile 400 /etc/haproxy/errors/400.http
  30. errorfile 403 /etc/haproxy/errors/403.http
  31. errorloc 404 https://thispagedoesnotexist.mydomain.dev
  32. errorfile 408 /etc/haproxy/errors/408.http
  33. errorfile 500 /etc/haproxy/errors/500.http
  34. errorfile 502 /etc/haproxy/errors/502.http
  35. errorloc 503 https://somethinghappened503.mydomain.dev
  36. errorfile 504 /etc/haproxy/errors/504.http
  37.  
  38. frontend www-https
  39. # bind mypublicip:443 ssl crt /etc/haproxy/ssl/mydomain.dev/cert.pem
  40. bind mypublicip.145:443
  41.  
  42. http-request set-header X-Forwarded-Proto https
  43. http-request set-header X-Forwarded-Host %[req.hdr(Host)]
  44. http-request set-header X-Client-IP req.hdr_ip([X-Forwarded-For])
  45. http-request add-header X-Forwarded-Port 443
  46. http-response set-header Strict-Transport-Security "max-age=16000000; includeSubDomains; preload;"
  47. acl letsencrypt-acl path_beg /.well-known/acme-challenge/
  48. use_backend letsencrypt-backend if letsencrypt-acl
  49.  
  50. acl gokapi hdr(host) -i files.mydomain.dev
  51. use_backend gokapi if gokapi
  52.  
  53. default_backend www-backend
  54.  
  55. frontend www-http
  56. bind mypublicip:80
  57. # http-request set-header X-Forwarded-Proto https
  58. http-request set-header X-Forwarded-Host %[req.hdr(Host)]
  59. default_backend www-backend
  60.  
  61. backend letsencrypt-backend
  62. server letsencrypt 127.0.0.1:54321
  63.  
  64. backend gokapi
  65. acl is_root path /
  66. http-request redirect code 301 location https://files.mydomain.dev/login if is_root
  67. option forwardfor
  68. option httpchk GET /login
  69. http-check expect status 200
  70. timeout client 120m
  71. timeout server 120m
  72. option http-server-close
  73.  
  74. server gokapi-server 127.0.0.1:53842 check inter 2s
  75.  
  76. backend www-backend
  77. http-request redirect scheme https code 301 unless { ssl_fc }
  78.  
  79. server catchall 127.0.0.1:443
Advertisement
Add Comment
Please, Sign In to add comment