3 ms·
Hey, author of this blog post here. If you have any questions feel free to ask (or if you want to insult me that is also acceptable).
by idealhavoc 8y ago
Hey, author of this blog post here. If you have any questions feel free to ask (or if you want to insult me that is also acceptable).
- neelesteele 8y ago"Your mother was a hamster, and your father smelt of elderberries.” Seriously, great article OP. Def. gave me a much better understanding of stick tables!
- abnoxae 8y agoAwesome post!
- gog 8y agoHi, can you explain the: > tcp-request inspect-delay 10s line, under "http_req_rate" section. In the article you wrote: "The second line is what inserts or updates a key in the table and updates its counters.". I think with that you were talking about the third line and that you skipped the second line in the explanation.
- idealhavoc 8y agoYour right, I frequently look as inspect-delay as not being a real line given that it doesn't do much itself. I have an explanation of inspect-delay a bit further down: When tcp-request inspect-delay is present, it will hold the request until the rules in that block have the data they need to make a decision or until the specified delay is reached, whichever is first. Basically if an ACL requires an http request (such as updating the http_req_rate counter) but the action is tcp-request it tells HAProxy to wait until it has a http request before it continues. If using an http-request track-* action its not required as HAProxy won't process http-request until it has an HTTP request to add to the counters. Since HAProxy won't send a request to a backend in HTTP mode until it has a full request inspect-delay doesn't actually delay the request at all; just the processing phase for a bit (in TCP mode where it doesn't it gets a bit more complicated).