9 ms·
HAProxy 2.7
- linsomniac 4y agoCongratulations to the team on this release! I switched to haproxy for load balancing our production traffic 5-6 years ago and it's proven incredibly reliable. Creating a ticket to update our dev & staging environments to 2.7 right now.
- bklyn11201 4y agoI've spent the last decade on Nginx and then of course spending lots of money on Nginx Plus for their upstream health checking. I knew HAProxy was a possible solution but was too happy with Nginx. The slow evolution of open-source Nginx has been frustrating to watch and the lack of basic features like upstream health checking in the open-source project is now ridiculous considering the excellent competition.
- phamilton 4y agoIs there a good alternative to openresty (aka nginx w/ lua) ? I too have fought nginx on upstream health checking and have avoided the cost of Nginx Plus. I'd love a good alternative, but we have a number of lua plugins we depend on for rate limiting, metrics, auth, etc.
- bedis9 4y agoWell, HAProxy Community can do all this :)
- petre 4y agoI'm using caddy because it takes care of Lets Encrypt TLS certs. I'd use HAProxy but I don't know if it can do this without additional scripts.
- akvadrako 4y agoHopefully it comes soon: https://github.com/haproxy/haproxy/issues/1864 https://github.com/haproxy/haproxy/issues/1864
- bedis9 4y agoStay tune (tips: dataplaneapi)
- rfmoz 4y agoACME support must be integrated, this was turned into a mandatory feature nowadays…
- linsomniac 4y agoI also use caddy, for my personal sites and I also have a work site that is a bunch of TLS redirectors for domains that the company owns to redirect to other domains. It works spectacularly in those use cases. At the time I set it up it wasn't possible to do that with an S3 endpoint, but now it is. I do have an haproxy setup that does the right thing with LetsEncrypt, but it's just a path-based forwarder that works with an acme script on the system, not directly built in.
- fullstop 4y agoThis looks like a fantastic update for bigger servers.
- theandrewbailey 4y agoI've been running HAProxy on my home server for almost 2 years. I don't use the load-balancing features though.
- mihaigalos 4y agoAre you only using it for reverse proxying/rate limiting?
- theandrewbailey 4y agoI primarily use it to terminate SSL, route based on hostname (subdomain), and cache.
- fullstop 4y agoI use mine to also terminate TLS and proxy mosquitto (mqtt) traffic. mosquitto's TLS configuration is a pain and it's so much easier to have it all in one place.
- unixhero 4y agoI need to start using reverse proxy and such things. Have you decided upon that instead of Nginx Proxy Manager or Caddy? Or are you using HAProxy to solve other challenges?
- theandrewbailey 4y agoI use it for a few other things than reverse proxying. HAProxy seemed like a light weight solution to what I was looking for: parse an incoming request and hand it to something else as fast as possible, and doesn't do any web hosting itself.
- TimWolla 4y agoI do the same for my personal machine. It's acting as the router/gateway in front of several Docker containers (both HTTP and also other protocols, such as SMTP or IRC). Disclosure: I'm a community contributor to HAProxy.
- capableweb 4y ago> However, due to the fast, atomic operations involved at many places, HAProxy was previously limited to 64 threads, and therefore 64 CPU cores, on 64-bit machines. This limit is now raised to 4096 threads by the introduction of thread groups. This is such a welcome change! I've been in more than one situation where I rediscovered this limitations when trying to scale things while trying to remain monolith (due to costs and performance reasons) but noticing HAProxy not being able to utilize the newly upgraded machine. This will make a huge difference!
- ilyt 4y agoLess than you think. You only need few cores to saturate tens of gigabits of traffic, HAProxy already is very performant. It's future-proofing basically. The page is ancient https://www.haproxy.org/10g.html https://www.haproxy.org/10g.html but they were doing 10Gbits on Core2Duo in '09 (sans SSL but back then AES acceleration wasn't very common either)
- wtarreau 4y agoIndeed, we've done 100Gbps about a year ago on a 8-core machine. Usually the only reason to use many cores is SSL, but since OpenSSL 3.0 that totally collapses under load, even then you're forced to significantly lower the number of threads (or to downgrade to 1.1.1 that about any high traffic site does).
- ivanr 4y agoDo you know what's behind the performance degradation of OpenSSL 3.0? Has the problem been documented anywhere?
- wtarreau 4y agoHorrible locking. 95% CPU spent in spinlocks. We're still doing measurements that we'll report with all data shortly. Anyway many of them were already collected by the project; there are so many that they created a meta-issue to link to them: https://github.com/openssl/openssl/issues/17627#issuecomment-1060123659 https://github.com/openssl/openssl/issues/17627#issuecomment... 3.1-dev is slightly less worse but still far behind 1.1.1. They made it too dynamic, and certain symbols that were constants or macroes have become functions running over lists under a lock. We noticed the worst degradation in client mode where the performance was divided by 200 for 48 threads, making it literally unusable.
- tiffanyh 4y agoWhat's the current (2022) view on HAProxy vs. Nginx? I know the sentiment has changed over the years. Curious what's the opinion today on which is the best tool for a new project. (Yes, I realize they do different things but there's also considerable overlap as well)
- osrec 4y agoI would say HAProxy is a better load balancer, than a web server. I like to have a few NGINX instances as the actual web servers sitting behind a HAProxy instance that spreads load across them.
- ilyt 4y agoHAProxy is not a web server in the first place. The only thing it serves, from memory only (need reload to change) are error pages.
- wtarreau 4y agoOr the cache :-) (also "return" directives but that doesn't count).
- wtarreau 4y agoI definitely agree. If you need the best load balancer, take haproxy. If you need the best web server, take nginx. The two combined work amazingly well together, that's why they're very often found together :-)
- emptysongglass 4y agoThis is very biased because it's published by NGINX[1]: "NGINX suffers virtually no latency at any percentile. The highest latency that any significant number of users might experience (at the 99.9999th percentile) is roughly 8ms. What do these results tell us about user experience? As mentioned in the introduction, the metric that really matters is response time from the end‑user perspective, and not the service time of the system under test." [1] https://www.nginx.com/blog/nginx-and-haproxy-testing-user-experience-in-the-cloud/ https://www.nginx.com/blog/nginx-and-haproxy-testing-user-ex...
- alanwreath 4y agohaproxy is awesome, I have a Raspberry Pi where it runs dedicated and never causes me issues. The best software can be forgotten.
- ipevans 4y agoThat's a good example. I was at HAProxyConf in November, and Willy showed HAProxy running on a solar-powered device to demonstrate its efficiency. Disclosure: I'm part of the HAProxy team.
- sekh 4y agoFor those interested, the device is a breadbee. (https://github.com/breadbee/breadbee https://github.com/breadbee/breadbee).
- jjice 4y agoIf we forget about it, it might be because it gives us so little issue. Software you don't think about is a treat :)
- wtarreau 4y agoI agree. I'm used to saying this to the rest of the development team: we are very critical about our own code because we receive all the bug reports, which tends to give us a feeling that there's always something to fix. But seeing it another way, with hundreds of thousands of deployments, having 2-3 issues a week is ridiculously low and means that the vast majority of deployments will never face a bug in their life. It still poses us a problem which is that users don't upgrade. For example 1.6 is still routinely met in production despite having been unsupported for 2 years, and sometimes with 3 or 4 years of uptime because users forget about it or just don't want to risk an upgrade for no perceived benefit. I can't blame them honestly, as long as they upgrade before reporting problems or asking for help!
- jiehong 4y agoWith the recent discussions about memory safe languages, HAProxy is still surprisingly written in C [0]. [0]: https://github.com/haproxy/haproxy https://github.com/haproxy/haproxy
- babarock 4y agoYou'd be surprised what's still written in C.
- ilyt 4y agoNothing surprising here, it is old project, and one very performance-conscious.
- TickleSteve 4y agoThe vast majority of the software running on your machine is still written in C.
- orthecreedence 4y agoWritten in C and probably one of the most rock-solid pieces of user level software anyone could imagine. I doubt, connection-per-connection, any other piece of software is more battle hardened than HAProxy.
- ok123456 4y agoWhy is that surprising.
- _joel 4y agoI've used HAProxy in several roles over the year, been pretty much bullet-proof everywhere.
- sigmonsays 4y agoProfessionally, i've recently used haproxy with the dataplane api to provide programmatically controlled layer 7 load balanacing. Personally, i also use haproxy as a load balancer to terminate https and proxy traffic to internal services. it's features, such as logging and debugging are far superior than nginx. While the haproxy config can be a little cryptic at times, you can do a lot more with it too.
- causenad 4y agoWe'd love to hear about different use cases on our next HAProxyConf. both community and enterprise environments. We just wrapped up HAProxyConf 2022 in Paris (https://www.haproxy.com/blog/haproxyconf-2022-recap/ https://www.haproxy.com/blog/haproxyconf-2022-recap/) and are starting to plan for next one. The Call for papers hasn't been announced yet but feel free to shoot as an email at submission@haproxy.com.
- ozarker 4y agoLove HAProxy, the most reliable service in my homelab :)
- jabart 4y agoHAProxy is great. I use the dataplane api with our releases to drop servers from the group for zero downtime release. Easy curl command, which they provide, and switched it to powershell too. I have another script that downloads our SSL/TLS certs and reloads haproxy using their no downtime reload option. I ran a load test earlier this year using loader[.]io and managed 57,782 requests in 20 seconds using a single haproxy server (tls) and two .net core web servers. Around 300mb/sec of data after brotli compression. Bottleneck was clearly the two web servers and could have scaled more but it was on a 1gb link and testing 10gb links over the internet is not something I am prepared for testing. HAProxy was basically idle the whole time.
- deleted 4y ago[deleted]
- haproxy1647849 4y agoI don't know if my testing was right. If anyone from HAProxy team reading this. retry count is 3 and you have 5 server in backend and 1 backup server and you have health check. if all servers are down, request will be forwarded to backup server but what if all the servers are down, but health check is not updated yet. (extreme timing) the request will be retried 3 times, servers will be mark down. as all the 3 request were failed, HAProxy will return 503. I think the request should go to the backup server, even if retry limit was 3, HAProxy was not able connect to any of the 3 server and servers were down actually.
- nickramirez 4y agoYou can think of it as having layers of redundancy. * Retries are one layer. By default set to 3 retries. HAProxy will retry the failed connection or request with the same server. * "option redispatch" is another layer. If HAProxy can't connect to a server that is reporting as healthy, it will send the request to a different server. * health checks are a layer. HAProxy removes unresponsive servers from load balancing. * Backup servers are another layer. If all servers fail their health checks and are down, then backup servers come online to service requests. All these things can be enabled in combination, and it would reduce the chance of a client getting a server error. To answer your question, HAProxy will not connect with a server that is down (failed all its health checks). It will not retry with it either.
- wtarreau 4y agoOne approach that some users who want this mechanism use is the "on-error sudden-death" mechanism: the server responses are inspected, and upon error (from selectable types), the server can be marked dead. If all of them are dead the backup server will come into the dance and the last attempt will end up on it.