mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,4 Tsd.
aktive Profile

#haproxy

0 Beiträge0 Beteiligte0 Beiträge heute
Oliver<p>What I wanted to do: <br>Move this mastodon instance from its current datacenter location to my homelab. </p><p>What I did: <br>Update all my <a href="https://lfnt.site/tags/proxmox" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>proxmox</span></a> nodes to the latest release, remove <a href="https://lfnt.site/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> and <a href="https://lfnt.site/tags/acme" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>acme</span></a> packages from <a href="https://lfnt.site/tags/pfsense" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pfsense</span></a> in favour of a dedicated machine handling it. </p><p>That machine, however, still needs an ansible role and playbook to be written, in order to set it up 🙈 </p><p>Let's gooooo! 😂 </p><p><a href="https://lfnt.site/tags/homelab" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>homelab</span></a> <a href="https://lfnt.site/tags/automation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>automation</span></a> <a href="https://lfnt.site/tags/selfhosting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>selfhosting</span></a></p>
Nils Goroll 🕊️:varnishcache:<p><span class="h-card" translate="no"><a href="https://toot.community/@jorijn" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>jorijn</span></a></span> <span class="h-card" translate="no"><a href="https://floss.social/@monospace" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>monospace</span></a></span> i did also use nginx and have no hard arguments against it besides "project governance" maybe. but a relevant benefit of using <a href="https://fosstodon.org/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> in tcp mode is to avoid any double processing of http, which otherwise is prone to desync bugs. tcp mode simply adds/removes the tls pipe, nothing more, nothing less. all the http processing remains in <a href="https://fosstodon.org/tags/varnishcache" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>varnishcache</span></a> only.</p>
Nils Goroll 🕊️:varnishcache:<p><span class="h-card" translate="no"><a href="https://toot.community/@jorijn" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>jorijn</span></a></span> yes, as of today, the recommended way is to use <a href="https://fosstodon.org/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> as a combined tls onloader/offloader with the PROXY2 protocol such that haproxy has "zero" configuration: see <a href="http://varnish-cache.org/docs/trunk/users-guide/vcl-backends.html#connecting-through-a-proxy" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">http://</span><span class="ellipsis">varnish-cache.org/docs/trunk/u</span><span class="invisible">sers-guide/vcl-backends.html#connecting-through-a-proxy</span></a> and .via in <a href="http://varnish-cache.org/docs/trunk/reference/vcl-backend.html#vcl-backend-7" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">http://</span><span class="ellipsis">varnish-cache.org/docs/trunk/r</span><span class="invisible">eference/vcl-backend.html#vcl-backend-7</span></a><br>this also works with dns: <a href="https://github.com/nigoroll/libvmod-dynamic/blob/master/src/vmod_dynamic.vcc" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/nigoroll/libvmod-dy</span><span class="invisible">namic/blob/master/src/vmod_dynamic.vcc</span></a></p><p>that said, we will do something about this eventually <a href="https://fosstodon.org/tags/varnishcache" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>varnishcache</span></a></p>
Mike Tobias<p>Did a quick writeup of how I use <a href="https://infosec.exchange/tags/anubis" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>anubis</span></a> behind <a href="https://infosec.exchange/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> in my <a href="https://infosec.exchange/tags/homelab" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>homelab</span></a>.</p><p><a href="https://mktbs.net/blog/2025/05/19/running-anubis-behind-haproxy/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mktbs.net/blog/2025/05/19/runn</span><span class="invisible">ing-anubis-behind-haproxy/</span></a></p><p>Thanks to <span class="h-card" translate="no"><a href="https://pony.social/@cadey" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>cadey</span></a></span> for the project. Support them!</p>
Matt "msw" Wilson<p>“AWS-LC looks like a very active project with a strong community. […] Even the recently reported performance issue was quickly fixed and released with the next version. […] This is definitely a library that anyone interested in the topic should monitor.”</p><p><a href="https://mstdn.social/tags/OpenSSL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSL</span></a> <a href="https://mstdn.social/tags/BoringSSL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BoringSSL</span></a> <a href="https://mstdn.social/tags/WolfSSL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WolfSSL</span></a> <a href="https://mstdn.social/tags/AWSLC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AWSLC</span></a> <a href="https://mstdn.social/tags/HAProxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HAProxy</span></a> <a href="https://mstdn.social/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://mstdn.social/tags/FreeSoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FreeSoftware</span></a> <a href="https://mstdn.social/tags/FOSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FOSS</span></a> <a href="https://mstdn.social/tags/OSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OSS</span></a> <a href="https://mstdn.social/tags/TLS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TLS</span></a> <a href="https://mstdn.social/tags/QUIC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>QUIC</span></a><br><a href="https://www.haproxy.com/blog/state-of-ssl-stacks" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">haproxy.com/blog/state-of-ssl-</span><span class="invisible">stacks</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://chaos.social/@f4grx" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>f4grx</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@nixCraft" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>nixCraft</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>torproject</span></a></span> not really.</p><ol><li><a href="https://infosec.space/tags/aws" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aws</span></a> has pretty chunky blocks like /14.</li><li>They don't use <a href="https://infosec.space/tags/IPv6" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IPv6</span></a>, only <a href="https://infosec.space/tags/IPv4" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IPv4</span></a>.</li><li>Blocking entrie <a href="https://infosec.space/tags/ASN" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ASN</span></a>|s is easy.</li></ol><p>I do this with <a href="https://infosec.space/tags/pfSense" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pfSense</span></a> &amp; <a href="https://infosec.space/tags/pfBlockerNG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pfBlockerNG</span></a> for quite a while…</p><p>And the same <a href="https://infosec.space/tags/blocklist" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>blocklist</span></a> also works for other applications like <a href="https://infosec.space/tags/nginx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nginx</span></a>, <a href="https://infosec.space/tags/HAproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HAproxy</span></a>, <a href="https://infosec.space/tags/httpd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>httpd</span></a>, etc.</p>
Indiealexh<p>I spent probably a weeks worth of hours learning more <a href="https://tny.social/tags/kubernetes" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>kubernetes</span></a> so I could save $60 a month.</p><p>I have a nice 3 node kube cluster with a 2 node <a href="https://tny.social/tags/keepalived" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>keepalived</span></a> <a href="https://tny.social/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> TCP load balancer. All on <a href="https://tny.social/tags/ARM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ARM</span></a> VPS.</p><p>Haproxy ingress<br><a href="https://tny.social/tags/ExternalDNS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ExternalDNS</span></a> operator<br><a href="https://tny.social/tags/CertManager" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CertManager</span></a><br><a href="https://tny.social/tags/RookCeph" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RookCeph</span></a><br><a href="https://tny.social/tags/ArgoCD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ArgoCD</span></a><br><a href="https://tny.social/tags/KeyCloak" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KeyCloak</span></a><br><a href="https://tny.social/tags/ValKey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ValKey</span></a><br><a href="https://tny.social/tags/Mastodon" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Mastodon</span></a><br><a href="https://tny.social/tags/CloudNativePG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudNativePG</span></a> <a href="https://tny.social/tags/Postgresql" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Postgresql</span></a></p>
Mikael Hansson<p>Because I'm stupid, my next little project is simplifying not only <a href="https://hachyderm.io/tags/distrohopping" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>distrohopping</span></a> but OS-hopping (in a very limited and specific way): </p><p>I'm attempting to build an <a href="https://hachyderm.io/tags/Ansible" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Ansible</span></a> play to deploy <a href="https://hachyderm.io/tags/HAProxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HAProxy</span></a> with <a href="https://hachyderm.io/tags/acme" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>acme</span></a> (via acme.sh) identically across <a href="https://hachyderm.io/tags/Fedora" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Fedora</span></a> <a href="https://hachyderm.io/tags/Debian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Debian</span></a> <a href="https://hachyderm.io/tags/Ubuntu" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Ubuntu</span></a> and <a href="https://hachyderm.io/tags/FreeBSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FreeBSD</span></a> servers. Why? Why not?</p>
raspbeguy<p>Le numéro mai-juin de Linux Pratique (disponible en kiosque dans une semaine) contient mon nouvel article traitant de la gestion de <a href="https://social.gugod.fr/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> à l'aide de <a href="https://social.gugod.fr/tags/terraform" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>terraform</span></a>.<br>Si vous le lisez, n'hésitez pas à me partager vos retours 👍</p><p><a href="https://social.gugod.fr/tags/publication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>publication</span></a> <a href="https://social.gugod.fr/tags/magazine" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>magazine</span></a> <a href="https://social.gugod.fr/tags/papier" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>papier</span></a> <a href="https://social.gugod.fr/tags/linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linux</span></a> <a href="https://social.gugod.fr/tags/devops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>devops</span></a></p>
Carsten Rieger IT-Services 🔒<p><a href="https://digitalcourage.social/tags/HAProxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HAProxy</span></a> v.3 Installationsanleitung</p><p>Mit Hilfe unserer Installationsanleitung für den HAProxy Version 3 stable (LTS) können Sie beispielsweise zwei verschiedene Cloud-Anwendungen parallel betreiben und diese mit LetsEncrypt Zertifikaten versorgen. Wir nutzen dafür einen Mixed Mode, also Layer 6 (http) und Layer 4 (tcp für https) in der HAProxy-Konfiguration.<br>Der HAProxy agiert dabei als klassischer ReverseProxy und kann auf Wunsch auch zum Loadbalancer erweitert werden.<br>Nachfolgend stellen wir dafür unsere HAProxy-Konfiguration aus dem Labor bereit. Diese nutzen wir bspw. für unsere Cloud-Testinstanzen (bspw. <a href="https://digitalcourage.social/tags/Nextcloud" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Nextcloud</span></a> und <a href="https://digitalcourage.social/tags/opencloud" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opencloud</span></a> auf einem dedizierten Server. Die SSL-Terminierung übernimmt dabei das jeweilige Backend, also Nextcloud und OpenCloud und nicht der HAProxy selbst. Der HAProxy reicht die https-Anfragen an die Anwendung durch und agiert im tcp-Mode (Layer 4) quasi transparent. 👇 <br><a href="https://www.c-rieger.de/haproxy-installationsanleitung/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">c-rieger.de/haproxy-installati</span><span class="invisible">onsanleitung/</span></a></p>
✰ 𝔽𝕣𝕖𝕕 ✰<span class="h-card"><a href="https://mamot.fr/users/ploum" class="u-url mention" rel="nofollow noopener" target="_blank">@ploum@mamot.fr</a></span><br><br>i am also using it<br><a href="https://social.freebsd.amsterdam?t=snac" class="mention hashtag" rel="nofollow noopener" target="_blank">#snac</a> <a href="https://social.freebsd.amsterdam?t=haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#haproxy</a><br>
✰ 𝔽𝕣𝕖𝕕 ✰do you have anything in between <a href="https://social.freebsd.amsterdam?t=snac" class="mention hashtag" rel="nofollow noopener" target="_blank">#snac</a> and <a href="https://social.freebsd.amsterdam?t=haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#haproxy</a>?<br><br>I am currently unable to find a way to get rid of the<br><br><pre># webfinger<br>location /.well-known/webfinger {<br> proxy_pass http://localhost:8001;<br> proxy_set_header Host $http_host;<br> proxy_set_header X-Forwarded-For $remote_addr;<br>}<br><br></pre>and the like in <a href="https://social.freebsd.amsterdam?t=nginx" class="mention hashtag" rel="nofollow noopener" target="_blank">#nginx</a><br>
✰ 𝔽𝕣𝕖𝕕 ✰great work!<br>Looking forward to a (speedy) blog posting<br><br>Is there no other service between <a href="https://social.freebsd.amsterdam?t=snac" class="mention hashtag" rel="nofollow noopener" target="_blank">#snac</a> and <a href="https://social.freebsd.amsterdam?t=haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#haproxy</a> ?<br>
Stefano Marinelli<p>I've performed some tests, and it's great. <a href="https://mastodon.bsd.cafe/tags/snac" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>snac</span></a> and <a href="https://mastodon.bsd.cafe/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> are working great together - now with caching of media and json responses, to scale up, and up, and up...and up!<br><a href="https://mastodon.bsd.cafe/tags/Varnish" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Varnish</span></a> is the best tool for caching, but the setup I've tested doesn't require it and it's still good enough.<br>I think this will be a blog post, as soon as I'll have enough time.</p><p><a href="https://mastodon.bsd.cafe/tags/snac2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>snac2</span></a> <a href="https://mastodon.bsd.cafe/tags/Fediverse" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Fediverse</span></a> <a href="https://mastodon.bsd.cafe/tags/IT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IT</span></a> <a href="https://mastodon.bsd.cafe/tags/SysAdmin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SysAdmin</span></a></p>
Stefano MarinelliGoing on with <a href="https://fedihome.stefanomarinelli.it?t=haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#haproxy</a> in front of <a href="https://fedihome.stefanomarinelli.it?t=snac2" class="mention hashtag" rel="nofollow noopener" target="_blank">#snac2</a> - I've just tested an interesting caching for json response. This will surely help instances like FediMeteo. It's not struggling, but I love optimizing stuff!<br>
Koen de Jonge - SynQ<p>I just unfollowed <a href="https://procolix.social/tags/HAProxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HAProxy</span></a> from Twitter, but it seems they are not here on the Fediverse.</p><p>A pity, I will miss them.</p><p><a href="https://procolix.social/tags/eXit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eXit</span></a></p>
✰ 𝔽𝕣𝕖𝕕 ✰Seems my snac2 instance is running behind <a href="https://social.freebsd.amsterdam?t=haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#haproxy</a>. \o/<br><br>CC: <span class="h-card"><a href="https://snac.it-notes.dragas.net/itnotes" class="u-url mention" rel="nofollow noopener" target="_blank">@itnotes@snac.it-notes.dragas.net</a></span><br>
@𝕗𝕕𝟘@𝕓𝕤𝕕.𝕟𝕖𝕥𝕨𝕠𝕣𝕜<p><span class="h-card" translate="no"><a href="https://mastodon.bsd.cafe/@stefano" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>stefano</span></a></span> <span class="h-card" translate="no"><a href="https://snac.it-notes.dragas.net/itnotes" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>itnotes</span></a></span> <br>connection to <a href="https://exquisite.social/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> works fine, including TLS offloading. connection from <a href="https://exquisite.social/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> to <a href="https://exquisite.social/tags/snac" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>snac</span></a> also works fine. <br>I guess I still need to convert the <a href="https://exquisite.social/tags/apache" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>apache</span></a> or <a href="https://exquisite.social/tags/nginx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nginx</span></a> proxying to work properly….</p>
@𝕗𝕕𝟘@𝕓𝕤𝕕.𝕟𝕖𝕥𝕨𝕠𝕣𝕜<p>trying to setup <a href="https://exquisite.social/tags/snac" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>snac</span></a> behind <a href="https://exquisite.social/tags/haproxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>haproxy</span></a> <br>if all works well, will connect to another instance<br><span class="h-card" translate="no"><a href="https://snac.it-notes.dragas.net/itnotes" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>itnotes</span></a></span></p>
ScriptFanix💍⏚ ⸫<p>The aboce applies if the client reports "NS_PARTIAL_TRANSFER" and the stream state at disconnection reported by <a href="https://maly.io/tags/HAProxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HAProxy</span></a> is "cD"</p><p>Stream state at disconnection: <a href="http://docs.haproxy.org/3.0/configuration.html#8.5" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">http://</span><span class="ellipsis">docs.haproxy.org/3.0/configura</span><span class="invisible">tion.html#8.5</span></a></p>