QSC-enabled HAproxy (using OpenQuantumSafe crypto)
501
This image contains a Quantum-Safe Crypto (QSC) version of HAProxy. The default entry point expects correct (QSC-)server keys and certificates mounted at '/opt/haproxy/conf' (send an email to [email protected] to receive some -- or if you know how to use openssl, use the QSC-enabled openssl version built into the image to create your own). If provided these keys via virtualmount the default entrypoint starts an HAproxy based on the configuration located in '/opt/haproxy/server'. For localised adaptations of this configuration, also this folder can be virtualmounted with suitable alternative configurations, e.g., for HTTP(s) backends other than the default test web server also located in the image (lighttpd).
A second entrypoint ('/opt/haproxy/client/startup.sh') permits running the HAproxy in reverse, client-side operation, connecting to a server-side running instance. This way, the two HAproxy instances in effect can be used to establish a QSC-TLS protected application-level virtual private network (VPN) tunnel for Web services.
A third entrypoint ('/opt/haproxy/sh.sh') permits starting any command under the alpine shell. This encompasses all standard alpine commands as well as QSC-enabled versions of openssl and curl (and haproxy, of course).
Root privileges are not required nor granted. All operations run under user ID 'oqs' (UID=1000).
See Github for details.
Content type
Image
Digest
Size
30.8 MB
Last updated
about 6 years ago
docker pull openqsafe/haproxy-alpine