Sign inSign up

intellisrc/haproxy

By intellisrc

•Updated 9 months ago

HAProxy image with a web service to manage certificates

Image
0

1.1K

intellisrc/haproxy repository overview

This is a custom build which contains:

  • Alpine Linux
  • haproxy which will read /etc/haproxy/haproxy.cfg
  • Let's Encrypt certbot
  • a tiny web service to restart, issue, renew and revoke certificates at port 7878
  • a static web server (BusyBox HTTPD) at port 88 (used for certificate validation) or serve static sites as backup
  • a cron job to renew certificates every month
  • logrotate for /var/log/haproxy.log and /var/log/haproxy.err

Web service usage:

http://ha_proxy:7878/restart/
http://ha_proxy:7878/status/
http://ha_proxy:7878/issue/example.com
http://ha_proxy:7878/renew/example.com
http://ha_proxy:7878/revoke/example.com

⁠Environment variables

# If specified will issue a certificate for that domain on start:
DOMAIN="example.com"
# Email to use for Let's Encrypt
EMAIL="[email protected]"

⁠Volumes / Files:

  • /etc/haproxy/haproxy.cfg
  • /etc/haproxy/certs/ # Where does certificates will be stored as bundle
  • /etc/letsencrypt/ # Better to keep this one persistent in order to renew
  • /var/www/ # Static content
  • /var/log/ # Where does logs are stored

⁠Docker stack example:

services:
  haproxy:
    image: intellisrc/haproxy
    environment:
      DOMAIN: example.com
      EMAIL: [email protected]
    ports:
      - published: 80
        target: 80
        protocol: tcp
        mode: host      
      - published: 443
        target: 443
        protocol: tcp
        mode: host
    volumes:
      - type: bind
        source: /mnt/docker/haproxy
        target: /etc/haproxy
      - type: bind
        source: /mnt/docker/logs/haproxy
        target: /var/log
      - type: bind
        source: /mnt/docker/static
        target: /var/www
      - type: bind
        source: /mnt/docker/certbot
        target: /etc/letsencrypt        
    networks:
      - ha
    deploy:
      mode: replicated
      replicas: 10
      endpoint_mode: dnsrr
      placement:
        constraints: 
          - node.labels.proxy == true

networks:
  ha:
    driver: overlay

Tag summary

Content type

Image

Digest

sha256:e183cbb82…

Size

33.7 MB

Last updated

9 months ago

docker pull intellisrc/haproxy