HNHacker News
TopNewBestAskShowJobs

nickramirez

187 karma · joined September 14, 2018

submissionscomments
nickramirez··on HAProxy is not affected by the HTTP/2 Rapid Reset Attack
If getting Let's Encrypt to work with HAProxy is your only struggle, you'll soon overcome it and be loving HAProxy. And there are multiple ways to set up Let's Encrypt, if you don't want to use acme.sh. For example, you could use certbot. There are blog posts that cover that pretty well.
nickramirez··on HAProxy 2.7
You can think of it as having layers of redundancy.

* Retries are one layer. By default set to 3 retries. HAProxy will retry the failed connection or request with the same server.

* "option redispatch" is another layer. If HAProxy can't connect to a server that is reporting as healthy, it will send the request to a different server.

* health checks are a layer. HAProxy removes unresponsive servers from load balancing.

* Backup servers are another layer. If all servers fail their health checks and are down, then backup servers come online to service requests.

All these things can be enabled in combination, and it would reduce the chance of a client getting a server error.

To answer your question, HAProxy will not connect with a server that is down (failed all its health checks). It will not retry with it either.

nickramirez··on HAProxy 2.4
kzrdude, great feedback. These big version announcements gather the attention of people who may not be familiar with HAProxy and so, I'd say they are a unique case where we should introduce the product for newcomers.
nickramirez··on The New HAProxy Data Plane API: Two Examples of Programmatic Configuration
The HAProxy Data Plane API performs a validation check: it sends the -c flag to the HAProxy process before reloading to make sure that it is a valid configuration. If the configuration is invalid, the changes will not take effect and you will see errors in your console or log. With transactions, it's not quite stateless (as HTTP is). Transactions provide a way to make multiple changes and apply them with a single commit. The main benefit of an API is towards program-ability (is that a word?), in which configuring HAProxy can be controlled by "control plane" software, slick looking UIs, tools like Ansible, etc. in an automated way. You can also generate client-side code from the API, such as for Go/Python/[insert language] coding. It goes beyond the use case of "I'm a human who wants to control HAProxy manually or with templates".
nickramirez··on The New HAProxy Data Plane API: Two Examples of Programmatic Configuration
Try the haproxytech images, which are updated for 2.0: https://hub.docker.com/search?q=haproxytech&type=image. There is also information on using the ingress controller here: https://www.haproxy.com/documentation/hapee/1-9r1/traffic-ma...
nickramirez··on The New HAProxy Data Plane API: Two Examples of Programmatic Configuration
The HAProxy Kubernetes Ingress Controller (https://github.com/haproxytech/kubernetes-ingress) uses the same Go library that the API is layered on top of: the "client-native" library. https://github.com/haproxytech/client-native
nickramirez··on The New HAProxy Data Plane API: Two Examples of Programmatic Configuration
It was fun writing this blog post because the API covers a lot of ground in terms of what can be done programmatically with the configuration. I've wanted something like this for integrating into a CD pipeline, for example.
nickramirez··on HAProxy 2.0
In fact there is a software-based Enterprise version of HAProxy that is subscription based.
nickramirez··on HAProxy 2.0
Although HAProxy is not a web server, it does have Small Object Caching so files can be cached on the proxy. https://www.haproxy.com/blog/whats-new-haproxy-1-8/#http-sma...
nickramirez··on HAProxy 2.0
With the Data Plane API, expect to see tighter integration with Consul. For now, there is this integration https://www.haproxy.com/blog/building-a-service-mesh-with-ha...
nickramirez··on HAProxy 2.0
HAProxy can proxy HTTP/2 at Layer 4 or at Layer 7, to get all the HTTP message data and perform routing based on that, etc.
nickramirez··on HAProxy 2.0
What open-source NGINX lacks that open-source HAProxy has:

* ACL rules with full support for logical if statements [1]

* active health checks

* end-to-end HTTP/2 [2]

* Robust logging or a dashboard with metrics

* The ability to read env variables

* session stickiness

* DNS service discovery [3]

These are just things I'm aware of, there could be a lot more.

HAProxy has shown itself to perform better for certain users such as Booking.com [4]

[1] https://www.nginx.com/resources/wiki/start/topics/depth/ifis... [2] https://trac.nginx.org/nginx/ticket/923 [3] https://danielparker.me/haproxy/nginx/comparison/nginx-vs-ha... [4] https://events.static.linuxfound.org/sites/events/files/slid...

nickramirez··on Using HAProxy as an API Gateway, Part 3 [Health Checks]
I'm one of the co-authors. Any questions? Happy to try to answer.
nickramirez··on HAProxy 1.9.2 Adds GRPC Support
As the author, any questions I might be able to answer, let me know.