Official Repository

Last pushed: 6 days ago
Short Description
HAProxy - The Reliable, High Performance TCP/HTTP Load Balancer
Full Description

Supported tags and respective Dockerfile links

For more information about this image and its history, please see the relevant manifest file (library/haproxy). This image is updated via pull requests to the docker-library/official-images GitHub repo.

For detailed information about the virtual/transfer sizes and individual layers of each of the above supported tags, please see the repos/haproxy/ file in the docker-library/repo-info GitHub repo.

What is HAProxy?

HAProxy is a free, open source high availability solution, providing load balancing and proxying for TCP and HTTP-based applications by spreading requests across multiple servers. It is written in C and has a reputation for being fast and efficient (in terms of processor and memory usage).

How to use this image

Since no two users of HAProxy are likely to configure it exactly alike, this image does not come with any default configuration.

Please refer to upstream's excellent (and comprehensive) documentation on the subject of configuring HAProxy for your needs.

It is also worth checking out the examples/ directory from upstream.

Note: Many configuration examples propose to put daemon into the global section to run haproxy as daemon. Do not configure this or the Docker container will exit immediately after launching because the haproxy process would go into the background.

Create a Dockerfile

FROM haproxy:1.7
COPY haproxy.cfg /usr/local/etc/haproxy/haproxy.cfg

Build the container

$ docker build -t my-haproxy .

Test the configuration file

$ docker run -it --rm --name haproxy-syntax-check my-haproxy haproxy -c -f /usr/local/etc/haproxy/haproxy.cfg

Run the container

$ docker run -d --name my-running-haproxy my-haproxy

You may need to publish the ports your haproxy is listening on to the host by specifying the -p option, for example -p 8080:80 to publish port 8080 from the container host to port 80 in the container. Make sure the port you're using is free.

Directly via bind mount

$ docker run -d --name my-running-haproxy -v /path/to/etc/haproxy:/usr/local/etc/haproxy:ro haproxy:1.7

Note that your host's /path/to/etc/haproxy folder should be populated with a file named haproxy.cfg. If this configuration file refers to any other files within that folder then you should ensure that they also exist (e.g. template files such as 400.http, 404.http, and so forth). However, many minimal configurations do not require any supporting files.

Reloading config

If you used a bind mount for the config and have edited your haproxy.cfg file, you can use haproxy's graceful reload feature by sending a SIGHUP to the container:

$ docker kill -s HUP my-running-haproxy

The entrypoint script in the image checks for running the command haproxy and replaces it with haproxy-systemd-wrapper from haproxy upstream which takes care of signal handling to do the graceful reload. Under the hood this uses the -sf option of haproxy so "there are two small windows of a few milliseconds each where it is possible that a few connection failures will be noticed during high loads" (see Stopping and restarting HAProxy).

Image Variants

The haproxy images come in many flavors, each designed for a specific use case.


This is the defacto image. If you are unsure about what your needs are, you probably want to use this one. It is designed to be used both as a throw away container (mount your source code and start the container to start your app), as well as the base to build other images off of.


This image is based on the popular Alpine Linux project, available in the alpine official image. Alpine Linux is much smaller than most distribution base images (~5MB), and thus leads to much slimmer images in general.

This variant is highly recommended when final image size being as small as possible is desired. The main caveat to note is that it does use musl libc instead of glibc and friends, so certain software might run into issues depending on the depth of their libc requirements. However, most software doesn't have an issue with this, so this variant is usually a very safe choice. See this Hacker News comment thread for more discussion of the issues that might arise and some pro/con comparisons of using Alpine-based images.

To minimize image size, it's uncommon for additional related tools (such as git or bash) to be included in Alpine-based images. Using this image as a base, add the things you need in your own Dockerfile (see the alpine image description for examples of how to install packages if you are unfamiliar).


View license information for the software contained in this image.

Supported Docker versions

This image is officially supported on Docker version 17.03.1-ce.

Support for older versions (down to 1.6) is provided on a best-effort basis.

Please see the Docker installation documentation for details on how to upgrade your Docker daemon.

User Feedback


If you have any problems with or questions about this image, please contact us through a GitHub issue. If the issue is related to a CVE, please check for a cve-tracker issue on the official-images repository first.

You can also reach many of the official image maintainers via the #docker-library IRC channel on Freenode.


You are invited to contribute new features, fixes, or updates, large or small; we are always thrilled to receive pull requests, and do our best to process them as fast as we can.

Before you start to code, we recommend discussing your plans through a GitHub issue, especially for more ambitious contributions. This gives other contributors a chance to point you in the right direction, give you feedback on your design, and help you find out if someone else is working on the same thing.


Documentation for this image is stored in the haproxy/ directory of the docker-library/docs GitHub repo. Be sure to familiarize yourself with the repository's file before attempting a pull request.

Docker Pull Command

Comments (23)
12 days ago

Here is an alternative, stateless way to set up your haproxy.cfg:

docker run -it --rm --name haproxy -p 80:80 --entrypoint /bin/bash -e HAPROXY_CFG="$(cat /etc/haproxy.cfg)" haproxy -c "echo \"\$HAPROXY_CFG\" >/usr/local/etc/haproxy/haproxy.cfg && / haproxy -f /usr/local/etc/haproxy/haproxy.cfg"

No need to build an image with your own config or use a volume mount.

4 months ago

@jslill Just swap 1.5 for 1.7 everywhere in the examples :)

4 months ago

Could you please publish a shiny new 1.7.0 based version when you get the chance?


PS: I've been having a lot of fun working with HAProxy. It's been great so far!

5 months ago

How can I upgrade openssl?

$ apt-get upgrade openssl
Unpacking openssl (1.0.1t-1+deb8u5) ...

$ ldd which haproxy | grep ssl => /usr/lib/x86_64-linux-gnu/ (0x00007f833b0bd000)

6 months ago

Hey guys,
I had trouble with reloading the configuration using Docker kill and I found out why. Using vi/vim to edit the config file creates a new file with a new inode. The config file is mounted directly (if you follow the given instructions). If you edit the file and log into the container using Docker exec, you will still see the original file.
The workaround for this is to mount the directory instead:
$ docker run -d --name my-running-haproxy -p 80:80 -v /path/to/haproxycfg/:/usr/local/etc/haproxy/:ro haproxy

7 months ago

Hello all,

Sorry to bother but I'm have some issues and I want to be sure I'm doing things right:
Since the "Directly via bind mount" run a default haproxy with my own configuration file, I don't necessary need to build my own container (as long as I specify my config file) right ?
I start haproxy exclusively that way:
docker run -d --name haproxy -v /data/config/haproxy/haproxy.cfg:/usr/local/etc/haproxy/haproxy.cfg:ro haproxy:latest

Am I correct ?

7 months ago

@engfouad I was about to pull my hair out trying to figure out why the configuration file couldn't be found on the image. Thanks for pointing that out!

10 months ago

There is a typo:

Test the configuration file

$ docker run -it --rm --name haproxy-syntax-check haproxy:1.5 haproxy -c -f /usr/local/etc/haproxy/haproxy.cfg

should be

$ docker run -it --rm --name haproxy-syntax-check my-haproxy haproxy -c -f /usr/local/etc/haproxy/haproxy.cfg
a year ago

I dont think the reload command is working
docker kill -s HUP my-running-haproxy
does the image has to be 1.5?

a year ago

which is the recommended way to get logs from this container? Send the logs to another container running rsyslog?