Wener Site

HAProxy Ingress

约 1 分钟阅读

haproxytech ingress

annotationdefaultnote
ssl-passthroughfalse透传 SSL
ssl-redirectfalseHTTP -> HTTPS
server-sslfalse后端 HTTPS
forwarded-fortrue
backend-config-snippet
path-rewrite
send-proxy-protocolproxy,proxy-v1,proxy-v2,proxy-v2-ssl,proxy-v2-ssl-cn
whitelist
yaml
# 等同于 nginx-ingress backend-protocol HTTPS
# 等同于 nginx proxy_ssl_verify off;
# HAProxy ssl verify none
haproxy.org/server-ssl: 'true'
configmapdefaultnote
scale-server-slots42生成的 server 个数
global-config-snippet
frontend-config-snippet
stats-config-snippet
proxy-protocolIPs or CIDRs
syslog-server
  • proxy-protocol
    • 接受的 PROXY 客户端来源
    • 0.0.0.0/0 允许所有
controllerdefault
--default-backend-servicee.g. nginx-ingress
--default-ssl-certificate

Trouableshooting

bash
cat /etc/haproxy/haproxy.cfg | grep -v disabled

ls /etc/haproxy/maps
# host.map path-exact.map path-prefix.map sni.map

关联信息

反向链接和本文引用的外部资料。

References

GitHub

10 条

另有 2 个未显示 references。

其他外链

2 条

另有 2 个 references 未显示。

最近更新commit 2cb4a0bEdit

On this page