Sign inSign up

intel/intel-qat-haproxy

Verified Publisher

By Intel Corporation

•Updated 2 months ago

Image
0

1.7K

intel/intel-qat-haproxy repository overview

⁠Introduction

Intel QuickAssist Technology (QAT) OpenSSL Engine is an OpenSSL Plug-In Engine that provides cryptographic acceleration for both hardware and optimized software using Intel QuickAssist Technology enabled Intel platforms. 

⁠How to Use The Docker Image

⁠BIOS Setting

⁠Grub Settings

  • Intel IOMMU should be enabled and QAT VF to be bind to kernel. Follow the below steps.
⁠Ubuntu:
  • Edit the grub file: sudo vim /etc/default/grub
  • Modify GRUB_CMDLINE_LINUX to add intel_iommu=on vfio-pci.ids=8086:4941 (SPR)
  • Update grub: sudo update-grub
  • Reboot the system
⁠CentOS/Fedora:

⁠Docker Environment Setup

  • The environment must be set up to build and run containers. Certain packages will need to be loaded and configuration files created and/or updated, which can be system specific.
  • Install Docker following the steps in Docker Package Installation⁠.
  • Configure the proxy setting following Proxy settings⁠.

⁠Enable Intel® QAT Virtual Function (VF) Devices

  • Enable the VF devices using the following script:   sh   for i in `(lspci -D -d :4940 || lspci -D -d :4942) | awk '{print $1}'`; do echo 16 | sudo tee /sys/bus/pci/devices/$i/sriov_numvfs; done  

⁠Configure Services in the Host

  • Stop the Intree or OOT services if any running on the host:   sh   systemctl stop qat     sh   systemctl stop qat_service     sh   systemctl disable qat_service  
  • Bring the QAT device down:   sh   for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo down > /sys/bus/pci/devices/$i/qat/state; done  
  • Set the correct service in the QAT devices:   sh   for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo "sym;asym" > /sys/bus/pci/devices/$i/qat/cfg_services; done  
  • Bring the QAT device up:   sh   for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo up > /sys/bus/pci/devices/$i/qat/state; done  
  • Check the status:   sh   for i in `lspci -D -d :4940 | awk '{print $1}'`; do cat /sys/bus/pci/devices/$i/qat/state; done  
  • Ensure the GID using the below command in host. The GID of the QAT group on the host should be same as GID of the docker Image. The QAT group of the host should be ‘1001’ :   sh   getent group qat | cut -d ':' -f 3  
  • Enable the VF devices with the previously mentioned script and set correct permissions:   sh   chown root:qat /dev/vfio/*     sh   chmod 660 /dev/vfio/*  

⁠Run Image

To run the Docker image, use the following command:

Server command: docker run --rm -it  --cpuset-cpus <n cores> --cap-add=IPC_LOCK --security-opt seccomp=unconfined --security-opt apparmor=unconfined $(for i in `ls /dev/vfio/*`; do echo --device $i; done) --env QAT_POLICY=1 --ulimit memlock=50000000:50000000 -v /usr/local/etc/haproxy/:/usr/local/etc/haproxy/ -d -p 8080:8080 intel/intel-qat-haproxy:<tag_number> haproxy -f /usr/local/etc/haproxy/haproxy.cfg

Client command: openssl s_time -connect <server_ip>:8080 -cipher AES128-SHA256 -www /20b-file.html -time 5

Note: n is the number of thread. 8080 port to be used for starting the haproxy service. HAproxy config file mounted from the host to the container using -v /usr/local/etc/haproxy/haproxy.cfg.

⁠Configuration

Refer haproxy.cfg⁠ sample configuration with QAT Enabled

Intel, Intel Atom, and Xeon are trademarks of Intel Corporation in the U.S. and/or other countries.

*Other names and brands may be claimed as the property of others.

Copyright © 2026, Intel Corporation. All rights reserved.

Tag summary

Content type

Image

Digest

sha256:4a6b8c6b0…

Size

240.5 MB

Last updated

2 months ago

docker pull intel/intel-qat-haproxy:2.2.0

This week's pulls

Pulls:

4

Sep 14 to Sep 20