3 ms·
I did something almost identical and it's working wonders with haproxy and "mode tcp" to pass the ssl connection just reading SNI to the backend without termina
by gandalfk7 4y ago
I did something almost identical and it's working wonders with haproxy and "mode tcp" to pass the ssl connection just reading SNI to the backend without terminating it.
I've used a delegated zone to achieve that, I like your catch-all approach better since it's cleaner, in a future rewrite I might change it.
I am now testing the configuration with proxy-protocol to pass the information on the client IP which otherwise would be lost, it's working but certbot does not like it so it needs a dedicated backend with a rule.
I've also created an Ansible playbook that does the installation for you and retrieves the haproxy config from a git repo so it's always in-sync on the balancer machines: https://blog.gandalfk7.it/posts/20220201_01_diy-balancer-with-dns https://blog.gandalfk7.it/posts/20220201_01_diy-balancer-wit...
- Snawoot 4y agoNice to know, thanks! > certbot does not like it so it needs a dedicated backend with a rule. What exactly fails in the certbot when you use proxy protocol by the way? Are you using certbot in standalone mode, making it listen socket on its own? I usually pass acme paths with Nginx to certbot workdir and use webroot mode. Speaking about synchronization, on some job I had configs in SVN repo which were checked out with fabric job - it worked nicely. But afterwards I moved configs to git and made small daemon to listen webhooks for repo update to checkout and reload loadbalancers. Sort of gitops.
- gandalfk7 4y agoIt looks like unknowingly we followed a very similar route :D For the git repo I am not using webhooks but wrote a script that checks if the repo has been updated, downloads the new configfile, tests the syntax and if ok copies it and reloads haproxy. I use certbot in standalone mode, I want to review that approach and integrate it with nginx in the near future. But yes, in standalone mode proxy-protocol is not working with certbot, I think it's due HTTP01 challenge [0] but I have to look into that with more time at hand. I am now using these lines in haproxy config to route it to the correct backend (which just won't have "send-proxy" in the server options): acl letsenc_example path_beg /.well-known/acme-challenge/ hdr_dom(host) -m end example.org use_backend bk_http_letsenc if letsenc_example thanks for the ideas for improvement! [0]: https://github.com/cert-manager/cert-manager/issues/466 https://github.com/cert-manager/cert-manager/issues/466