Sign inSign up

openqsafe/haproxy-alpine

By openqsafe

•Updated about 6 years ago

QSC-enabled HAproxy (using OpenQuantumSafe crypto)

Image
0

501

openqsafe/haproxy-alpine repository overview

This image contains a Quantum-Safe Crypto (QSC) version of HAProxy⁠. The default entry point expects correct (QSC-)server keys and certificates mounted at '/opt/haproxy/conf' (send an email to [email protected]⁠ to receive some -- or if you know how to use openssl, use the QSC-enabled openssl version built into the image to create your own). If provided these keys via virtualmount the default entrypoint starts an HAproxy based on the configuration located in '/opt/haproxy/server'. For localised adaptations of this configuration, also this folder can be virtualmounted with suitable alternative configurations, e.g., for HTTP(s) backends other than the default test web server also located in the image (lighttpd).

A second entrypoint ('/opt/haproxy/client/startup.sh') permits running the HAproxy in reverse, client-side operation, connecting to a server-side running instance. This way, the two HAproxy instances in effect can be used to establish a QSC-TLS protected application-level virtual private network (VPN) tunnel for Web services.

A third entrypoint ('/opt/haproxy/sh.sh') permits starting any command under the alpine shell. This encompasses all standard alpine commands as well as QSC-enabled versions of openssl and curl (and haproxy, of course).

Root privileges are not required nor granted. All operations run under user ID 'oqs' (UID=1000).

See Github⁠ for details.

Tag summary

Content type

Image

Digest

Size

30.8 MB

Last updated

about 6 years ago

docker pull openqsafe/haproxy-alpine