HAProxy - Handle all SSL except for one domain (handle one in backend)

Viewed 148

I'm an HAProxy neophyte (coming from Nginx)

I must say I'm enjoying a significant increase in response time.

What I wish to do is basically have a wildcard ssl certificate for one domain (handled by HAProxy) but have another domain that handles its own ssl.

So e.g. domains

  1. myserver.com (ssl handled by HAProxy)
  2. myotherserver.com (SSL handled at servers backend)

I have the configuration working for myserver.com (hopefully I have done it correctly)

How can I add myotherserver.com to this configuration where myotherserver.com's backend handles its own ssl?

NOTE: It is important that myotherserver.com handles its own SSL. i.e. I do not want HAProxy to handle both domains

frontend http_in
    mode http
    option httplog
    option forwardfor
    bind :80
    bind :443 ssl crt /etc/letsencrypt/live/myserver.com/haproxy.pem
    redirect scheme https if !{ ssl_fc }

        acl host_server1 hdr(host) -i www.myserver.com
        acl host_server2 hdr(host) -i billing.myserver.com

        use_backend website_server if host_server1
        use_backend billing_server if host_server2


backend website_server
        mode http
        option forwardfor
        option httpchk HEAD / HTTP/1.1\r\nHost:localhost
        server web.server web.server:80 check
        http-request set-header X-Forwarded-Port %[dst_port]
        http-request add-header X-Forwarded-Proto https if { ssl_fc }


backend billing_server
        mode http
        option forwardfor
        option httpchk HEAD / HTTP/1.1\r\nHost:localhost
        server billing.server billing.server:80
        http-request set-header X-Forwarded-Port %[dst_port]
        http-request add-header X-Forwarded-Proto https if { ssl_fc }
0 Answers
Related