106 lines
4.7 KiB
Django/Jinja
106 lines
4.7 KiB
Django/Jinja
#---------------------------------------------------------------------
|
|
# Global settings
|
|
#---------------------------------------------------------------------
|
|
global
|
|
log 127.0.0.1 local2
|
|
chroot /var/lib/haproxy
|
|
# pidfile /var/run/haproxy.pid
|
|
maxconn 200000
|
|
user haproxy
|
|
group haproxy
|
|
daemon
|
|
|
|
# turn on stats unix socket
|
|
stats socket /var/lib/haproxy/stats
|
|
|
|
# utilize system-wide crypto-policies
|
|
# ssl-default-bind-ciphers PROFILE=SYSTEM
|
|
# ssl-default-bind-ciphers TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-128-GCM-SHA256:TLS13-AES-256-GCM-SHA384:ECDHE:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS
|
|
# intermediate configuration
|
|
# See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate
|
|
ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
|
|
ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
|
|
ssl-default-bind-options prefer-client-ciphers no-sslv3 no-tlsv10 no-tlsv11 no-tls-tickets
|
|
|
|
ssl-default-server-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
|
|
ssl-default-server-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
|
|
ssl-default-server-options no-sslv3 no-tlsv10 no-tlsv11 no-tls-tickets
|
|
|
|
# DH Param
|
|
ssl-dh-param-file /etc/ssl/certs/dhparam
|
|
|
|
# CA certs
|
|
ca-base /etc/ssl/certs
|
|
crt-base /etc/ssl/private
|
|
|
|
#---------------------------------------------------------------------
|
|
# common defaults that all the 'listen' and 'backend' sections will
|
|
# use if not designated in their block
|
|
#---------------------------------------------------------------------
|
|
|
|
defaults
|
|
mode http
|
|
log global
|
|
option dontlognull
|
|
option http-server-close
|
|
option httplog
|
|
option httpclose
|
|
option redispatch
|
|
retries 3
|
|
timeout http-request 15s
|
|
timeout queue 2m
|
|
timeout connect 15s
|
|
timeout client 60m
|
|
timeout server 60m
|
|
timeout http-keep-alive 5m
|
|
timeout check 10s
|
|
timeout tunnel 1h
|
|
maxconn 200000
|
|
|
|
#---------------------------------------------------------------------
|
|
#Stats
|
|
#---------------------------------------------------------------------
|
|
frontend stats
|
|
bind *:8888
|
|
stats enable
|
|
stats hide-version
|
|
stats realm Haproxy\ Statistics
|
|
stats uri /stats
|
|
stats refresh 10s
|
|
stats auth admin:Pa$$w0rd!
|
|
|
|
#---------------------------------------------------------------------
|
|
# Load balance
|
|
#---------------------------------------------------------------------
|
|
frontend minio
|
|
mode http
|
|
bind 0.0.0.0:9000 ssl crt /etc/haproxy/certs/minio-ext.pem crt /etc/haproxy/certs/minio-int.pem
|
|
http-response set-header Cache-Control no-cache
|
|
option http-keep-alive
|
|
option forwardfor
|
|
default_backend minio
|
|
|
|
backend minio
|
|
mode http
|
|
http-reuse safe
|
|
option http-keep-alive
|
|
option forwardfor
|
|
default-server inter 5s fall 3 rise 3
|
|
server minio 127.0.0.1:{{ minio_server_port }} check
|
|
|
|
frontend minio_console
|
|
mode http
|
|
bind 0.0.0.0:443 ssl crt /etc/haproxy/certs/minio-int.pem
|
|
http-response set-header Cache-Control no-cache
|
|
option http-keep-alive
|
|
option forwardfor
|
|
default_backend minio_console
|
|
|
|
backend minio_console
|
|
mode http
|
|
http-reuse safe
|
|
option http-keep-alive
|
|
option forwardfor
|
|
default-server inter 5s fall 3 rise 3
|
|
server minio 127.0.0.1:{{ minio_console_port }} check
|