haproxy.cfg
Unterschiede
Hier werden die Unterschiede zwischen zwei Versionen angezeigt.
| Nächste Überarbeitung | Vorhergehende Überarbeitung | ||
| haproxy.cfg [2025/04/06 03:12] – angelegt admin | haproxy.cfg [2025/04/06 03:21] (aktuell) – admin | ||
|---|---|---|---|
| Zeile 1: | Zeile 1: | ||
| **aktuelle config** | **aktuelle config** | ||
| + | <file bash / | ||
| + | global | ||
| + | log / | ||
| + | log / | ||
| + | chroot / | ||
| + | stats socket / | ||
| + | stats timeout 30s | ||
| + | user haproxy | ||
| + | group haproxy | ||
| + | daemon | ||
| + | setenv ACCOUNT_THUMBPRINT ' | ||
| + | # Default SSL material locations | ||
| + | # ca-base / | ||
| + | # crt-base / | ||
| + | # See: https:// | ||
| + | ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256: | ||
| + | ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256: | ||
| + | ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets | ||
| + | | ||
| + | log global | ||
| + | mode http | ||
| + | option httplog | ||
| + | option dontlognull | ||
| + | option | ||
| + | timeout connect 5000 | ||
| + | timeout client | ||
| + | timeout server | ||
| + | errorfile 400 / | ||
| + | errorfile 403 / | ||
| + | errorfile 408 / | ||
| + | errorfile 500 / | ||
| + | errorfile 502 / | ||
| + | errorfile 503 / | ||
| + | errorfile 504 / | ||
| + | |||
| + | | ||
| + | # | ||
| + | bind | ||
| + | mode http | ||
| + | option httplog | ||
| + | maxconn 5 | ||
| + | stats enable | ||
| + | stats show-legends | ||
| + | stats hide-version | ||
| + | stats refresh 60s | ||
| + | stats show-node | ||
| + | stats uri / | ||
| + | |||
| + | | ||
| + | bind [::]:80 v4v6 | ||
| + | # | ||
| + | bind [::]:443 ssl crt / | ||
| + | # | ||
| + | acl lets_encrypt path_beg / | ||
| + | use_backend lets_encrypt if lets_encrypt | ||
| + | |||
| + | acl url_discovery path / | ||
| + | http-request redirect location / | ||
| + | http-request return status 200 content-type text/plain lf-string " | ||
| + | # | ||
| + | redirect scheme https code 301 if !{ ssl_fc } | ||
| + | # acl pro hostname | ||
| + | acl host_wiki hdr(host) -i wiki.schubert.home | ||
| + | acl host_wiki hdr(host) -i wiki.bamasch.de | ||
| + | acl host_nc hdr(host) -i nc.schubert-waltringen.de: | ||
| + | acl host_nc hdr(host) -i nc.schubert.home | ||
| + | acl host_nc hdr(host) -i oc.bamasch.de | ||
| + | use_backend wiki-backend if host_wiki | ||
| + | use_backend nc-backend if host_nc | ||
| + | |||
| + | | ||
| + | # | ||
| + | balance roundrobin | ||
| + | # | ||
| + | option forwardfor header X-Client | ||
| + | http-check expect status 200 | ||
| + | http-request add-header X-Forwarded-Proto https if { ssl_fc } | ||
| + | # | ||
| + | server wiki.schubert.home-be 192.168.16.173: | ||
| + | |||
| + | | ||
| + | mode http | ||
| + | http-request set-header X-Client-IP %[src] | ||
| + | http-request add-header X-Forwarded-Proto https if { ssl_fc } | ||
| + | http-response set-header Strict-Transport-Security max-age=63072000 | ||
| + | http-response set-header X-Content-Type-Options nosniff | ||
| + | http-response set-header X-Robots-Tag noindex, | ||
| + | http-response set-header X-Frame-Options SAMEORIGIN | ||
| + | http-response set-header X-Permitted-Cross-Domain-Policies none | ||
| + | http-response set-header X-XSS-Protection "1; mode=block" | ||
| + | http-response set-header Referrer-Policy no-referrer | ||
| + | balance roundrobin | ||
| + | # | ||
| + | # | ||
| + | server oc.schubert.home-be 192.168.16.173: | ||
| + | |||
| + | | ||
| + | mode http | ||
| + | server local localhost: | ||
| + | </ | ||
haproxy.cfg.1743909171.txt.gz · Zuletzt geändert: von admin
