Production Reference and Architecture Guide
Introduction
- How This Book Is Organized
- Prerequisites
- Version Conventions
- A Note on HAProxy Enterprise
- How to Use This Book
Part I: Foundations
Chapter 1: What Is HAProxy and Why Does It Exist
- The Proxy Problem Space
- HAProxy’s Origins and Design Philosophy
- HAProxy Among Alternatives
- When to Use HAProxy and When Not To
- Community Edition vs Enterprise: What Differs
Chapter 2: Architecture and Internals from First Principles
- The HAProxy Process Model
- Master and Worker Processes
- Threads and Task Scheduling
- The Event Loop and Epoll/Kqueue/Devpoll
- Buffers, Queues and Data Flow
- Connection vs Session vs Stream vs Transaction
- The Lifecycle of a Single Request
- Runtime Memory Layout and File Descriptors
Chapter 3: Installation, Versioning and Build Considerations
- HAProxy Versioning and Release Cadence
- Package Managers vs Building from Source
- Critical Build Options and Their Impact
- OpenSSL and TLS Build Choices
- Container Images and Runtime Environments
- Verifying Your Installation
Part II: Configuration Fundamentals
Chapter 4: Configuration Language, Parsers and Processing Order
- The Five Sections: global, defaults, frontend, listen, backend
- Configuration Parsing Rules and Syntax
- Directive Precedence and Inheritance
- The Order Matters: Processing Flow Overview
- Validation, Dry-Run and Testing Configuration
- Common Configuration Mistakes and How to Avoid Them
Chapter 5: Global Configuration
- Master-Worker Mode and Process Control
- Logging Configuration
- SSL/TLS Global Settings
- Tuning Directives
- Runtime and Statistics Sockets
- Security and Hardening in Global
Chapter 6: Defaults Section
- Setting Global Timeouts
- Default Mode and Options
- Connection Reuse and Keep-Alive Defaults
- Log Format Defaults
- Retries and Error Handling Defaults
- When to Use Defaults vs Inline Configuration
Part III: Core Proxying
Chapter 7: Frontends, Backends and Server Configuration
- Frontends: Binding and Accepting Connections
- Backends: Server Pools and Selection
- Servers: Defining Upstream Endpoints
- Listen Sections: The Combined Approach
- Complete Working Configuration Examples
- Line-by-Line Explanation of a Production Baseline
Chapter 8: Load-Balancing Algorithms and Server Selection
- Round Robin and Static Round Robin
- Least Connections
- Source IP Hashing and URI Hashing
- Consistent Hashing (where applicable)
- Random Selection and Weighted Selection
- Choosing an Algorithm for Your Use Case
Chapter 9: Server States, Health Checks and Resilience
- Server States: DOWN, UP, MAINT, DRAINING
- Active Health Checks: Types and Configuration
- Passive Health Checks and Error Tracking
- Agent-Based Health Checks
- Slow Start and Gradual Traffic Ramp
- Backup Servers and Maintenance Modes
- Failover Behavior and Failback Patterns
Chapter 10: Connection Management and Timeouts
- The Timeout Family: client, server, connect, queue and others
- Setting Timeouts Correctly
- Keep-Alive and Connection Reuse
- Connection Draining and Graceful Shutdown
- Idle Connection Behavior
- Timeout-Related Production Failures
Chapter 11: TCP Proxying: Layer 4 Load Balancing
- TCP Mode vs HTTP Mode
- Binding and Server Configuration in TCP
- TLS Passthrough in TCP Mode
- Health Checks in TCP Mode
- Use Cases: Databases, Redis, SSH, Custom Protocols
- Limitations and Considerations of TCP Proxying
Part IV: HTTP and Routing
Chapter 12: HTTP Processing and the Request/Response Cycle
- HTTP Parsing in HAProxy
- Request and Response Processing Order
- HTTP Version Handling
- Header Management Fundamentals
- Status Codes and Error Pages
- WebSockets and Upgrade Requests
Chapter 13: ACLs, Fetch Methods and Conditionals
- ACL Syntax and Evaluation
- Common ACL Types: host, path, header, method and others
- Fetch Methods and Samples
- Sample Fetchers vs Converters vs ACLs
- Using Maps for Complex Lookups
- Performance Implications of ACL Evaluation
Chapter 14: Routing: Content Switching and Traffic Distribution
- Host-Based Routing (Virtual Hosts)
- Path-Based Routing
- Header and Cookie-Based Routing
- Method and Content-Type Routing
- Multi-Tenant and Geolocation Routing
- Complete Working Routing Examples
Chapter 15: HTTP Headers, Redirects and Traffic Manipulation
- Adding, Removing and Setting Headers
- Redirect Rules and Permanent Redirects
- URL Rewriting with Use-Backend and Rewrite
- Forwarded and X-Forwarded-* Headers
- CORS and Trust-Proxy Considerations
Part V: Sessions, Stickiness and State
Chapter 16: Stickiness and Session Persistence
- Why Stickiness Matters
- Cookie-Based Persistence (insert, rewrite, prefix)
- Source IP Stickiness
- Custom Cookie and Header-Based Stickiness
- Stick Tables: Architecture and Use
- Stick Tables and Peer Synchronization
Chapter 17: Stick Tables, Rate Limiting and Abuse Prevention
- Stick-Table Configuration
- Tracking Clients and Servers
- Rate Limiting Requests and Connections
- Connection Limiting per Client
- Abuse Detection Patterns
- Circuit-Breaking with Stick Tables
Part VI: TLS and Security
Chapter 18: TLS Termination, Passthrough and Re-Encryption
- TLS Termination at HAProxy
- TLS Passthrough (Layer 4)
- Re-Encryption Patterns
- SNI and Virtual Host Selection
- ALPN and Protocol Negotiation
- Complete TLS Configuration Examples
Chapter 19: TLS Certificates, Configuration and Management
- Certificate Formats and Loading
- Certificate Chains and Intermediate Certificates
- Multiple Certificates and SNI Mapping
- Protocol Versions and Security Hardening
- Cipher Suites and Security Recommendations
- Certificate Rotation and Zero-Downtime Renewal
Chapter 20: Mutual TLS, Authentication and Security Hardening
- Mutual TLS (mTLS) Configuration
- Client Certificate Validation
- OCSP and Certificate Revocation
- HSTS and Security Headers
- SSL/TLS Security Scanning and Grading
- Hardening Checklist for Production
Part VII: Performance, Scalability and Tuning
Chapter 21: HAProxy Performance Characteristics
- CPU Usage and Thread Affinity
- NUMA and Multi-Socket Considerations
- Memory Behavior and Limits
- File Descriptors and Connection Limits
- Kernel Networking Tuning
- Benchmarking Methodology and Interpretation
Chapter 22: Advanced Tuning and Optimization
- Tuning maxconn and Connection Limits
- Buffer and Queue Tuning
- TLS Acceleration and Performance
- Compression (gzip, brotli)
- Logging Overhead and Optimization
- Connection Reuse and Capacity Planning
- Real-World Tuning Examples at Scale
Part VIII: High Availability and Deployment Architecture
Chapter 23: High Availability Architectures
- Active-Standby with VRRP and Keepalived
- Floating IPs and Failover Mechanics
- DNS-Based Failover and Its Limitations
- Active-Active Topologies
- Multi-Region and Multi-AZ Architectures
- State Synchronization and Consistency
Chapter 24: Deployment Models and Integration
- Bare-Metal and VM Deployments
- HAProxy in Containers (Docker, Podman)
- HAProxy in Kubernetes: Ingress, Sidecar, Gateway
- HAProxy and Service Discovery
- Cloud Load Balancers and HAProxy Together
- Edge and Hybrid Deployments
Chapter 25: Configuration Management, Automation and CI/CD
- Configuration as Code and Version Control
- Template Engines and Dynamic Config
- Validation Pipelines and CI Integration
- Rolling Updates and Zero-Downtime Reloads
- The Data Plane API and Automation
- Rollback Strategies and Emergency Procedures
Part IX: Operations and Observability
Chapter 26: Logging, Monitoring and Observability
- Log Formats and Structure
- Syslog and Centralized Logging Integration
- The Stats Page and Its Data
- Prometheus Metrics and Exporters
- Runtime API and Socket Commands
- Building Alerting and Dashboards
Chapter 27: Troubleshooting, Debugging and Incident Response
- Debugging Methodology and Checklist
- Runtime Diagnostics
- Log-Based Troubleshooting
- Packet-Level Debugging with tcpdump
- Configuration Issues and Validation Errors
- Performance Degradation Investigation
- Real Incident Scenarios and Postmortems
Part X: Advanced Architectures and Patterns
Chapter 28: Production Architectures and Design Patterns
- Public-Facing Web Application Architecture
- API Gateway and Backend-for-Frontend Patterns
- Blue/Green and Canary Deployments with HAProxy
- Multi-Tenant Platform Design
- Database Adjacent Proxying (MySQL, Redis)
- Geographically Distributed Architecture
Chapter 29: Upgrade, Migration and Change Management
- HAProxy Version Upgrade Strategies
- Backward Compatibility and Breaking Changes
- Migration from Nginx or Other Proxies
- Testing and Validation of Upgrades
- Blue/Green HAProxy Deployments
- Rollback and Recovery Procedures
Part XI: Reference
Chapter 30: Configuration Reference and Quick Lookups
- Essential Directives Quick Reference
- Common ACL Types and Syntax
- Key Fetch Methods and Converters
- Map File Syntax and Patterns
- Timeout Defaults and Recommendations
- Useful Runtime API Commands
Chapter 31: Troubleshooting Reference and Decision Trees
- Connection and Timeout Issues
- TLS and Certificate Problems
- Routing and ACL Troubleshooting
- Performance and Capacity Issues
- Health Check and Failover Problems
Conclusion: Operating HAProxy as a Platform
- The HAProxy Ecosystem Today
- Emerging Trends and Future Directions
- Building an HAProxy Competence Organization
- Final Checklist for Production Readiness
