Skip to content

Instantly share code, notes, and snippets.

@sergerdn
Last active July 25, 2023 13:16
Show Gist options
  • Save sergerdn/65654d7e3b7922edf1ae6b88c3dc5ae7 to your computer and use it in GitHub Desktop.
Save sergerdn/65654d7e3b7922edf1ae6b88c3dc5ae7 to your computer and use it in GitHub Desktop.
curl --proxy http://ip_of_your_server_with_haproxy:9000 --proxy-user proxy_user_of_proxy_service:proxy_password_of_proxy_service https://lumtest.com/myip.json && echo ""
global
log /dev/log local0
log /dev/log local1 notice
chroot /var/lib/haproxy
stats socket /run/haproxy/admin.sock mode 660 level admin expose-fd listeners
stats timeout 30s
user haproxy
group haproxy
daemon
# Default SSL material locations
ca-base /etc/ssl/certs
crt-base /etc/ssl/private
# See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate
ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets
defaults
log global
mode http
option httplog
option dontlognull
timeout connect 5000
timeout client 50000
timeout server 50000
errorfile 400 /etc/haproxy/errors/400.http
errorfile 403 /etc/haproxy/errors/403.http
errorfile 408 /etc/haproxy/errors/408.http
errorfile 500 /etc/haproxy/errors/500.http
errorfile 502 /etc/haproxy/errors/502.http
errorfile 503 /etc/haproxy/errors/503.http
errorfile 504 /etc/haproxy/errors/504.http
### Added ####
listen stats
# Change the port number to your desired port for accessing the stats page
bind *:8888
mode http
stats enable
stats hide-version
stats realm Haproxy\ Statistics
stats uri /stats
stats auth admin:cool_secure_password
frontend front_proxy_1
mode http
timeout client 1s
maxconn 50
bind :9000
default_backend back_proxy_1
backend back_proxy_1
mode http
# this option will ensure server connection closure after processing
option http-server-close
balance leastconn
# Capture Proxy-Authorization header

capture request header Proxy-Authorization len 200
server s1 zproxy.lum-superproxy.io:22225 maxconn 50
watch netstat -ant
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment