3 ms·
Hello, HAProxy has a long history of being secure [1]. In a standard configuration it also segregates itself and spawns within a chroot. Booking.com [2] uses
by rogerdonut 8y ago
Hello, HAProxy has a long history of being secure [1]. In a standard configuration it also segregates itself and spawns within a chroot.
Booking.com [2] uses HAProxy for edge delivery over other software load balancers.
Github [3][4] has used it to mitigate DDoS attacks and StackOverflow [5] has used it to detect and protect against bot threats.
Finally, phk, the author of Varnish states [6] (in regards to implementing SSL/TLS): “When I look at something like Willy Tarreau's HAProxy I have a hard time to see any significant opportunity for improvement.”
[1] https://www.haproxy.org/#secu https://www.haproxy.org/#secu
[2] https://events.static.linuxfound.org/sites/events/files/slides/DLB-LinuxConf-Berlin.pdf https://events.static.linuxfound.org/sites/events/files/slid...
[3] https://www.youtube.com/watch?v=xxs7CoLMXt8 https://www.youtube.com/watch?v=xxs7CoLMXt8
[4] https://githubengineering.com/glb-part-2-haproxy-zero-downtime-zero-delay-reloads-with-multibinder https://githubengineering.com/glb-part-2-haproxy-zero-downti...
[5] https://events.static.linuxfound.org/sites/events/files/slides/DLB-LinuxConf-Berlin.pdf https://events.static.linuxfound.org/sites/events/files/slid...
[6] https://varnish-cache.org/docs/trunk/phk/ssl_again.html https://varnish-cache.org/docs/trunk/phk/ssl_again.html
- fulafel 8y agoThanks for the well founded argument. I'm still worried about the TLS implementation. I think in your [6] phk considered just incremental improvements, not switching away from C - after all the whole post is about not wanting to implement TLS at all in his own C codebase, having anticipated problems like Heartbleed. (Also at the time of writing, 2015 the Go TLS stack might have been too new to rely on?)