Skip to main content

haproxy

Expert HAProxy load balancer assistance covering Layer 4 / Layer 7 routing, health checks, SSL termination, and rate limiting. Use when building high-availability, low-latency traffic proxies.

Informações da origem

Repositório
G1Joshi/Agent-Skills
Última atividade na origem
1 de outubro de 2026 às 16:37
Idioma detectado do SKILL.md
inglês
Estrelas
14
Forks
2

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.

Exibindo SKILL.md

SKILL.md
Instruções da origem · Visualização somente leitura
name
haproxy
description
Expert HAProxy load balancer assistance covering Layer 4 / Layer 7 routing, health checks, SSL termination, and rate limiting. Use when building high-availability, low-latency traffic proxies.
# HAProxy HAProxy is a high-availability, high-performance TCP/HTTP load balancer and proxying solution, offering ultra-low latency traffic routing, SSL termination, and robust health checking. ## When to Use - **High-Performance Layer 4 & Layer 7 Load Balancing**: Distributing millions of concurrent TCP/HTTP connections with low CPU overhead. - **TLS Termination & SSL Offloading**: Offloading cryptographic handshakes at the edge before proxying to backend servers. - **Advanced Rate Limiting & Stick Tables**: Tracking client IPs across sliding time windows to neutralize DDoS and brute force. - **Health Checking & Circuit Breaking**: Detecting unhealthy backend servers and rerouting traffic instantaneously. ## Quick Start ```haproxy frontend http_front bind *:80 default_backend web_servers backend web_servers balance roundrobin server web1 10.0.0.1:80 check server web2 10.0.0.2:80 check ``` ## Core Concepts ### Production HTTP Load Balancer Configuration Configuring frontend and backend pools with health checks: ```haproxy # /etc/haproxy/haproxy.cfg global log /dev/log local0 maxconn 50000 user haproxy group haproxy daemon ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384 ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets defaults log global mode http option httplog option dontlognull timeout connect 5000ms timeout client 50000ms timeout server 50000ms frontend http_front bind *:80 bind *:443 ssl crt /etc/ssl/certs/example.com.pem alpn h2,http/1.1 redirect scheme https code 301 if !{ ssl_fc } # Rate limiting stick-table: 100 requests per 10 seconds per IP stick-table type ip size 100k expire 30s store http_req_rate(10s) http-request track-sc0 src http-request deny deny_status 429 if { sc_http_req_rate(0) gt 100 } default_backend web_cluster backend web_cluster balance roundrobin option httpchk GET /healthz http-check expect status 200 cookie SERVERID insert indirect nocache server web1 10.0.1.10:8080 check cookie web1 fall 3 rise 2 server web2 10.0.1.11:8080 check cookie web2 fall 3 rise 2 ``` ### TCP Layer 4 Load Balancing (Database Proxy) Distributing MySQL or PostgreSQL connections across read replicas: ```haproxy frontend db_in bind *:5432 mode tcp option tcplog default_backend db_replicas backend db_replicas mode tcp balance leastconn option tcp-check server db-replica-1 10.0.2.20:5432 check server db-replica-2 10.0.2.21:5432 check ``` ### Statistics Dashboard Configuration Enabling real-time traffic monitoring interface: ```haproxy listen stats bind *:8404 mode http stats enable stats uri / stats refresh 5s stats auth admin:SuperSecretPassword2026 ``` ## Common Patterns ### Layer 7 Round-Robin Backend with Active Health Checks **Problem**: Distributing web traffic across backend workers while automatically evicting degraded instances. **Solution**: Configure `haproxy.cfg` frontend and backend: ```haproxy frontend http_front bind *:80 bind *:443 ssl crt /etc/ssl/certs/site.pem redirect scheme https if !{ ssl_fc } default_backend web_servers backend web_servers balance roundrobin cookie SERVERID insert indirect nocache option httpchk GET /health http-check expect status 200 server app01 10.0.0.10:8080 check cookie app01 server app02 10.0.0.11:8080 check cookie app02 ``` ## Best Practices **Do**: - Test HAProxy configuration files (`haproxy -c -f /etc/haproxy/haproxy.cfg`) before reloading. - Use `balance leastconn` for long-running connections (WebSockets, database pools) and `roundrobin` for short HTTP APIs. - Configure `stick-table` to defend endpoints against brute-force attacks and volumetric DDoS. - Configure `option httpchk` to verify that application backends are genuinely healthy before routing traffic. **Don't**: - Run HAProxy with single-threaded defaults on multi-core servers; configure `nbthread` or multi-threading. - Leave stats dashboards accessible without authentication or IP restrictions. - Set excessively low client/server timeouts that sever legitimate long-polling or file upload connections. ## Troubleshooting | Error | Cause | Solution | | :----------------------------------------------------------------------- | :------------------------------------------------- | :--------------------------------------------------------------------- | | `[ALERT] 085/120000 : parsing [haproxy.cfg:20] : syntax error` | Indentation or syntax error in configuration line. | Run `haproxy -c -f /etc/haproxy/haproxy.cfg` to validate syntax. | | `503 Service Unavailable: No server is available to handle this request` | All backend servers failed health checks. | Check backend server health logs and verify `option httpchk` endpoint. | | `Cannot bind socket [0.0.0.0:80]` | Port 80 bound by another service. | Kill conflicting service or configure HAProxy on custom port. | ## References - [HAProxy Documentation](https://www.haproxy.org/)
Ver no GitHub