Re: no session failover on cluster

2009-09-21 Thread Aleksandar Lazic
Hi, On Mon 21.09.2009 22:28, Stefan wrote: Hello Am Montag 21 September 2009 20:59:01 schrieb Hank A. Paulson: I think you are getting a new cookie because of how your openais/etc is failing over, not haproxy. haproxy doesn't create the cookie it just passes it along. I understood haproxy

Re: [ANNOUNCE] haproxy-1.4-dev3

2009-10-01 Thread Aleksandar Lazic
Hi Willy, On Don 24.09.2009 01:15, Willy Tarreau wrote: Hi all ! After approximately one month, we managed to gather enough features and fixes to release a new development version. [snipp] For a developper, it means that the door is open to try to implement internal services running as

Re: [ANNOUNCE] haproxy-1.4-dev3

2009-10-02 Thread Aleksandar Lazic
On Fre 02.10.2009 06:48, Willy Tarreau wrote: Hi Aleks, On Thu, Oct 01, 2009 at 10:06:12PM +0200, Aleksandar Lazic wrote: (...) For a developper, it means that the door is open to try to implement internal services running as applets (eg: a CLI) and multi-layer protocols. It's the right moment

Re: [ANNOUNCE] haproxy-1.4-dev3

2009-10-04 Thread Aleksandar Lazic
On Fre 02.10.2009 22:54, Willy Tarreau wrote: On Fri, Oct 02, 2009 at 10:19:47PM +0200, Aleksandar Lazic wrote: Hm so if I want to add ajp,fcgi, ... protocol I think I will need a buffer for the 'header' and for the content. Yes, the principle is to chain two series of buffers like

Re: multiple applications using HAproxy LB

2009-10-12 Thread Aleksandar Lazic
On Mon 12.10.2009 14:42, Ryan Schlesinger wrote: It sounds like what you really want is to put apache (or some other web server) in front of haproxy to do name based virtual hosting. Requests for your two domains would work like this: client - apache:80 (domain1 virtual host) - haproxy:8080

Re: Small patch for the appsession feature

2009-10-13 Thread Aleksandar Lazic
On Die 13.10.2009 21:34, Cyril Bonté wrote: Le lundi 12 octobre 2009 23:17:43, Aleksandar Lazic a écrit : Yes, you're right, I missed it after several tests on different snapshots. Here comes a second patch to reintroduce these debug lines : Thanks.

Re: multiple applications using HAproxy LB

2009-10-13 Thread Aleksandar Lazic
On Die 13.10.2009 09:14, Xia Jiang wrote: Hi, Ryan Sorry, I might not have explained this clearly. What I need is explained here: http://agiletesting.blogspot.com/2009/02/load-balancing-in-amazon-ec2-with.html However, I am having problem of acl Boolean statement: how about to use this

Re: Small patch for the appsession feature

2009-10-14 Thread Aleksandar Lazic
On Mit 14.10.2009 21:40, Willy Tarreau wrote: On Tue, Oct 13, 2009 at 10:41:59PM +0200, Aleksandar Lazic wrote: On Die 13.10.2009 21:34, Cyril Bonté wrote: Le lundi 12 octobre 2009 23:17:43, Aleksandar Lazic a écrit : Yes, you're right, I missed it after several tests on different snapshots

Re: OT: murmurhash

2009-10-16 Thread Aleksandar Lazic
On Fre 16.10.2009 06:32, Willy Tarreau wrote: Hi Aleks, On Fri, Oct 16, 2009 at 12:56:02AM +0200, Aleksandar Lazic wrote: Dear Listmember, does anybody have seen or used this 'new' hash? http://murmurhash.googlepages.com/ http://murmurhash.googlepages.com/MurmurHash2A.cpp For me it looks

Re: Sticky session, dumb client

2009-10-27 Thread Aleksandar Lazic
Dear Michael, On Mon 26.10.2009 21:18, Robinson, Michael wrote: I've got HAproxy 1.3.22 configured on two EC2 servers in front of two Apache/Tomcat frontends serving a JSP-based mobile phone application. The application requires session stickiness - I've tried every documented alternative

Re: Sticky session, dumb client

2009-10-28 Thread Aleksandar Lazic
the documentation I've read. I tried using the latest dev version of HAproxy too - didn't work. Thoughts? Thanks again for the feedback. Mike From: Aleksandar Lazic [mailto:al-hapr...@none.at] Sent: Tuesday, October 27, 2009 2:54 PM To: haproxy@formilux.org Subject: Re: Sticky session, dumb

Re: Preventing bots from starving other users?

2009-11-15 Thread Aleksandar Lazic
On Son 15.11.2009 15:57, Wout Mertens wrote: Hi there, I was wondering if HAProxy helps in the following situation: - We have a wiki site which is quite slow - Regular users don't have many problems - We also get crawled by a search bot, which creates many concurrent connections, more than

Re: Small patch for the appsession feature

2009-11-15 Thread Aleksandar Lazic
Hi Cyril, On Fre 13.11.2009 22:50, Cyril Bonté wrote: Hello Willy, sorry, I didn't have time to work on the patch as I wanted. Le jeudi 5 novembre 2009 06:19:41, Willy Tarreau a écrit : Sorry but I can't see in the haproxy sources how the cookie prefix can be used for appsession. capture

Re: Small patch for the appsession feature

2009-11-16 Thread Aleksandar Lazic
On Mon 16.11.2009 08:52, Willy Tarreau wrote: Hi, On Sun, Nov 15, 2009 at 10:28:21PM +0100, Aleksandar Lazic wrote: Hi Cyril, On Fre 13.11.2009 22:50, Cyril Bonté wrote: Hello Willy, [snipp] First I added it as I did for request-learn but shouldn't it be better to define these options

Re: ACL matching on URLs

2010-02-12 Thread Aleksandar Lazic
Hi Mallin Eoin, On Fre 12.02.2010 14:43, Mallin, Eoin wrote: Hi all, I'm looking for the best approach for matching the first part of a URL in ACLs. Some examples of the types of URLs include: [snipp] how about Won't work acl backend1_acl path_beg /web acl backend1_acl path_beg /web/

Re: Script greasmonkey to navigate in Haproxy docs ...

2010-05-12 Thread Aleksandar Lazic
On Don 29.04.2010 08:41, Aleksandar Lazic wrote: how about to use: http://txt2html.sourceforge.net/ I will try it today and post the results. forget it this produces to much crap ;-( BR Aleks

Re: HA SSL Offload Option

2010-06-28 Thread Aleksandar Lazic
Dear Hari, On Mon 28.06.2010 14:11, Hari Ganesh wrote: Hi , This is Hariganesh , I would like to know the design architecture of the HA proxy in the if i wanted to use the SSL offload function along with the Load Balancing . could you help me some is it possible in HA proxy and if Yes how

Re: HAProxy is incompatible with WebSocket protocol revision 76?

2010-06-30 Thread Aleksandar Lazic
Dear Juhani, On Mit 30.06.2010 15:09, Juhani Åhman wrote: Hi everyone I've recently tried to use HAProxy as a reverse proxy to a WebSocket server like Moskovitz in this thread (http://www.mail-archive.com/haproxy@formilux.org/msg02754.html), but I've run into problems. I can only get

Re: HAProxy is incompatible with WebSocket protocol revision 76?

2010-06-30 Thread Aleksandar Lazic
Dear Juhani, On Mit 30.06.2010 16:59, Juhani Åhman wrote: On Wed, 2010-06-30 at 14:46 +0200, Aleksandar Lazic wrote: Dear Juhani, On Mit 30.06.2010 15:09, Juhani Åhman wrote: Hi everyone I've recently tried to use HAProxy as a reverse proxy to a WebSocket server like Moskovitz in this thread

Re: HAProxy is incompatible with WebSocket protocol revision 76?

2010-06-30 Thread Aleksandar Lazic
On Mit 30.06.2010 17:38, Juhani Åhman wrote: On Wed, 2010-06-30 at 16:18 +0200, Aleksandar Lazic wrote: I think you will need the client-keepalive option. I'am not sure if this is the only option to activate this, I hope anybody else on this list can say more about this. Hth Aleks I

Re: Can HAProxy do that?

2010-07-08 Thread Aleksandar Lazic
Dear Mikael, yes it is possible with haproxy. On Die 06.07.2010 21:40, zabrane Mikael wrote: Hi List, I'm new to HAProxy, so please apologize if the question was already asked before. I've a homemade web server running on my internat. It works like this. [snipp] So, my question is

SSL with delegate

2010-11-07 Thread Aleksandar Lazic
Dear Listmember, does anybody use delegate http://www.delegate.org/ as ssl-terminator, insteas of nginx or stunnel? BR Aleks

Re: New benchmark of HAProxy at 10 Gbps using Myricom's 10GbE NICs possible?

2011-09-08 Thread Aleksandar Lazic
On Don 08.09.2011 07:51, Willy Tarreau wrote: Hi Aleks, On Thu, Sep 08, 2011 at 12:52:20AM +0200, Aleksandar Lazic wrote: Hi Willy, I have take a look about the last test on http://haproxy.1wt.eu/10g.html and thought it would be nice to see a test with the brand new 1.5 version. What do

RE: syslogd dropping requests from haproxy

2011-10-14 Thread Aleksandar Lazic
Hi, On 14.10.2011 22:05, Sachin Shetty wrote: Found some more info, when haproxy configured to send logs to remote host instead of local syslogd, it works fine. Definately something to do with the local syslogd under heavy load. Which syslogd do you use? Remote: Local: Which Distribution do

Re: option httpchk

2011-10-31 Thread Aleksandar Lazic
Hi, On 31.10.2011 13:48, Christophe Rahier wrote: Hi, What a pity, this could be very useful! Indeed, as Haproxy detects that there is no response, it may perform an another action :-) How about a backup setup?! http://haproxy.1wt.eu/download/1.4/doc/configuration.txt 5. Server and

another round for configuration.txt = html

2011-11-02 Thread Aleksandar Lazic
Hi all, I have now started do change the configuration.txt in that way that asciidoc an produce nice HTML output. asciidoc -b html5 -o haproxy-conf.html configuration.txt http://www.none.at/haproxy-conf.html I have stopped at section 2.3 to get your feedback. As you can see in the diff there

Re: another round for configuration.txt = html

2011-11-03 Thread Aleksandar Lazic
and I might push something in my github very soon: a bash/sed/awk tool to translate the HAProxy documentation in Markdown format (could be HTML as well). Contribution will be welcome :) cheers On Thu, Nov 3, 2011 at 12:57 AM, Aleksandar Lazic al-hapr...@none.at wrote: Hi all, I have now

Re: Help with SSL

2011-11-04 Thread Aleksandar Lazic
Hi Christophe, On 03.11.2011 22:00, Christophe Rahier wrote: Hello, My config of HAProxy is: -- CUT -- [snipp] -- CUT -- The problem with SSL is that the IP address that I get to the web server is the IP address of the loadbalancer and not the original IP address. This is a big

Re: output of haproxy 1.5-dev8 -vv

2012-03-31 Thread Aleksandar Lazic
Hi, On 31-03-2012 18:31, Willy Tarreau wrote: Hi Aleks, On Wed, Mar 28, 2012 at 05:40:08PM +0200, Aleksandar Lazic wrote: When I call -vv I don't know if the SPLICE is integrated int the build or not? You have OPTIONS = USE_LINUX_SPLICE=1 USE_PCRE=1, which means that if you do make

Re: Q: no option http-server-close

2012-03-31 Thread Aleksandar Lazic
Hi Willy, On 31-03-2012 23:18, Willy Tarreau wrote: Hi Aleks, On Sat, Mar 31, 2012 at 10:33:26PM +0200, Aleksandar Lazic wrote: [snipp] Is there a flag or option in the haproxy custom log format http://haproxy.1wt.eu/git?p=haproxy.git;a=blob;f=doc/configuration.txt;h

Re: nice wiki doc of haproxy

2012-04-09 Thread Aleksandar Lazic
Hi Cyril, really nice work. On 08-04-2012 21:42, Cyril Bonté wrote: [snipp] The code itself is in python and recently started to use Mako Templates as a first attempt to make the code cleaner. Oh python, ok. The generated pages are based on Bootstrap, from Twitter. I believe it will

Re: Q about mobile browser detection

2012-04-10 Thread Aleksandar Lazic
Hi Willy, On 10-04-2012 07:14, Willy Tarreau wrote: Hi Aleks, On Tue, Apr 10, 2012 at 01:22:36AM +0200, Aleksandar Lazic wrote: Hi, have anybody a haproxy solution which detects the common mobile browsers, like http://detectmobilebrowsers.mobi/ I think about a acl rule, thanks for any

Re: nice wiki doc of haproxy

2012-04-10 Thread Aleksandar Lazic
On 09-04-2012 20:37, Willy Tarreau wrote: Hi Aleks, On Mon, Apr 09, 2012 at 06:38:42PM +0200, Aleksandar Lazic wrote: Some questions for open discussion. 1.) Where is the right page for the 'HTMLFIED' document? http://haproxy.1wt.eu/#docs = separate page such as doc.haproxy

Re: nice wiki doc of haproxy

2012-04-10 Thread Aleksandar Lazic
Hi, On 10-04-2012 15:07, Aleksandar Lazic wrote: On 09-04-2012 20:37, Willy Tarreau wrote: Hi Aleks, On Mon, Apr 09, 2012 at 06:38:42PM +0200, Aleksandar Lazic wrote: Some questions for open discussion. 1.) Where is the right page for the 'HTMLFIED' document? http://haproxy.1wt.eu/#docs

Re: clarification on peers and inclusion into 1.4 soon?

2012-04-23 Thread Aleksandar Lazic
Dear David, On 24-04-2012 01:31, David Birdsong wrote: On Mon, Apr 23, 2012 at 2:48 PM, Kevin Heatwole ke...@heatwoles.us wrote: You might want to block the IPs before they get into haproxy. Maybe put an nginx reverse proxy in front of haproxy? I use nginx to dynamically block/allow HTTP

Re: [ANNOUNCE] haproxy 1.5-dev9

2012-05-08 Thread Aleksandar Lazic
Hi, On 08-05-2012 22:33, Willy Tarreau wrote: Hi all, I found some time to work on haproxy last weeks and to perform a number of fundamental changes that have been needed for a long time. [snipp] Some of these changes conflicted with the ACL and pattern frameworks, so it was the right

Re: [ANNOUNCE] haproxy 1.5-dev9

2012-05-09 Thread Aleksandar Lazic
Hi Willy, On 09-05-2012 05:47, Willy Tarreau wrote: Hi Aleks, On Wed, May 09, 2012 at 12:26:38AM +0200, Aleksandar Lazic wrote: After all this changes is it still necessary to have the appsession directive in haproxy? Could it not be removed to avoid confusions and future question what

appsession redesign (was: Re: [ANNOUNCE] haproxy 1.5-dev9)

2012-05-09 Thread Aleksandar Lazic
Hi all, On 09-05-2012 14:08, Willy Tarreau wrote: Hi Cyril, On Wed, May 09, 2012 at 08:55:45AM +0200, Cyril Bonté wrote: Hi, Le 09/05/2012 07:04, Baptiste a écrit : Hi, Yes, appsession has been obsoleted by cookie and set-cookie stick tables pattern extraction (in HAProxy 1.5-dev7 as far

Re: Fwd: unresolvable host names as error

2012-05-13 Thread Aleksandar Lazic
Hi Willy, On 13-05-2012 11:00, Willy Tarreau wrote: Hi Aleks, On Sun, May 13, 2012 at 09:43:40AM +0200, Aleksandar Lazic wrote: Be careful, if you want to implement a resolver, you can't use the libc's since the process is supposed to be chrooted, so you'll need to implement an autonomous

log format different and CAPTURE_LEN settings

2012-08-09 Thread Aleksandar Lazic
Hi, I wanted to add the uniq-id logging to the http-log format, I just copied the format string from src/log.c but I got different log entries. (see below) I also needed to capture more then 63 bytes so I have build HAProxy like this make TARGET=linux26 USE_LINUX_SPLICE=1 USE_STATIC_PCRE=1

Re: log format different and CAPTURE_LEN settings

2012-08-09 Thread Aleksandar Lazic
Hi William, On 09-08-2012 16:52, William Lallemand wrote: On Thu, Aug 09, 2012 at 03:16:07PM +0200, Aleksandar Lazic wrote: Hi, Hello, [...] As you can see I have not 'option logasap' but get the '+'-sign?! Please can anybody help me to find the error, thanks. Best regards Aleks

Re: log format different and CAPTURE_LEN settings

2012-08-09 Thread Aleksandar Lazic
Hi will, On 09-08-2012 19:21, Willy Tarreau wrote: On Thu, Aug 09, 2012 at 06:57:16PM +0200, Aleksandar Lazic wrote: [snip] after the first minute the log is now as defined ;-) Thanks guys, patch applied. how about the CAPTURE_LEN setting. ### After rebuild I still get the warning

Re: log format different and CAPTURE_LEN settings

2012-08-12 Thread Aleksandar Lazic
Hi Willy, On 10-08-2012 04:56, Willy Tarreau wrote: Hi Aleks, On Fri, Aug 10, 2012 at 12:56:18AM +0200, Aleksandar Lazic wrote: Hi will, On 09-08-2012 19:21, Willy Tarreau wrote: On Thu, Aug 09, 2012 at 06:57:16PM +0200, Aleksandar Lazic wrote: [snip] after the first minute the log is now

Re: HAProxy with native SSL support !

2012-09-04 Thread Aleksandar Lazic
Hi Willy, congratulations to the whole Team. Thanks for this feature, now the SSL-chain is much simpler ;-) BR Aleks Am 04-09-2012 01:37, schrieb Willy Tarreau: Hi all, today is a great day (could say night considering the time I'm posting) ! After several months of efforts by the

Re: DTLS termination

2013-11-28 Thread Aleksandar Lazic
Hai pablo, Am 27-11-2013 16:51, schrieb pablo platt: Any other proxy that can terminate DTLS? http://lmgtfy.com/?q=dtls+proxy Thanks BR Aleks On Wed, Nov 27, 2013 at 5:40 PM, Lukas Tribus luky...@hotmail.com wrote: Hi! Can version 1.5 terminate DTLS connections like it does for

Re: [ANNOUNCE] haproxy-1.5.0

2014-06-19 Thread Aleksandar Lazic
Gratulations ;-) Am 19-06-2014 21:54, schrieb Willy Tarreau: Hi everyone, The list has been unusually silent today, just as if everyone was waiting for something to happen :-) Today is a great day, the reward of 4 years of hard work. I'm announcing the release of HAProxy 1.5.0. For

Re: Roadmap for 1.6

2014-07-26 Thread Aleksandar Lazic
Hi Willy. Am 25-07-2014 19:28, schrieb Willy Tarreau: Hi all, Here I'm putting down my analysis of what was right and what was wrong in the development model for 1.4 and 1.5, hoping to improve it for 1.6. [long e-mail, even for one from me]. [long and detailed Informations snipped]

Re: Roadmap for 1.6

2014-07-27 Thread Aleksandar Lazic
Hi Willy. Am 26-07-2014 16:50, schrieb Willy Tarreau: Hi Aleks, On Sat, Jul 26, 2014 at 03:46:30PM +0200, Aleksandar Lazic wrote: Concerning the new features, no promises, but we know that we need to progress in the following areas : - multi-process : better synchronization of stats

Re: Roadmap for 1.6

2014-07-29 Thread Aleksandar Lazic
Hi Willy. Am 27-07-2014 16:22, schrieb Willy Tarreau: Hi Aleks, On Sun, Jul 27, 2014 at 01:44:01PM +0200, Aleksandar Lazic wrote: Peers are a bit different, as they can be accessed at a very high rate. However I'm pretty sure we'll move that to a shared memory just like the SSL session

Re: Experiment with an anti-spam on the list

2014-10-22 Thread Aleksandar Lazic
Hi Willy. [exceptionally top post] Many thanks to you and all involved Peoples for your effort to remove the spam from this list. Best regards, Aleks Am 22-10-2014 20:01, schrieb Willy Tarreau: Hi all, I said that some time ago I had plans for testing a non-intrusive anti-spam solution. So

Re: connection pooling

2014-12-10 Thread Aleksandar Lazic
Hi. Am 09-12-2014 22:04, schrieb Pavlos Parissis: Hi, It has been mentioned that 1.5 version doesn't support connection pooling, meaning that 1 TCP session to a backend server can serve multiple HTTP requests originated from than 1 client. Do you guys have plans to introduce this

Question about A resizable, Scalable, Concurrent Hash Table

2014-12-12 Thread Aleksandar Lazic
Hi. Today I have read the http://kernelnewbies.org/Linux_3.17#head-1ad106b24bd61288c6f89e13674c84a650359e95 and found this very interesting. A resizable, Scalable, Concurrent Hash Table

Re: Support For Postfix

2015-03-15 Thread Aleksandar Lazic
Hi Am 15-03-2015 15:02, schrieb adcd gmail: Hi I am struggling with haproxy and postfix the load balance works well but it doesnt send the client ip address to the backend servers I think it because of postfix configuration this what I get /usr/sbin/postconf: warning: /etc/postfix/main.cf:

Re: Lua patchset merged

2015-03-02 Thread Aleksandar Lazic
Am 02-03-2015 14:51, schrieb Thierry FOURNIER: On Sun, 01 Mar 2015 17:34:36 +0100 Aleksandar Lazic al-hapr...@none.at wrote: [snipp] Maybe it would be possible to integrate lua-scripting into the check agent framework? Hi, thank you. It is certainly possible. Have you some concrete

Re: Lua patchset merged

2015-03-01 Thread Aleksandar Lazic
Dear Thierry. Cool work ;-) Am 01-03-2015 13:47, schrieb Thierry FOURNIER: Hi everyone, Thanks Willy for the introduction. I join the first part of the document. All the function are not yet available. The doc uses a markdown format like that uses GitHub. I join the original format, and the

Re: Question on rewriting query string

2015-05-07 Thread Aleksandar Lazic
Hi Am 07-05-2015 23:07, schrieb Patrick Slattery: I ended up trying out the new Lua functionality in 1.6 and was able to get this to work with it. That's cool ;-) haproxy.cfg global lua-load /path/query.lua [snipp] I'm just curious if this is the right way to do this in HAProxy? I'm

Re: HAProxy for - AddOutputFilterByType SUBSTITUTE text/html

2015-05-12 Thread Aleksandar Lazic
Hi Am 12-05-2015 12:18, schrieb Peter BUtler: I have managed to migrate all my Apache config to HAProxy, but I am stuck on the following. I cant seem to find anything. Is it possible in HAProxy? currently not, afaik. In 1.6 looks like there are some intention to be able to handle the body

Re: HAProxy for - AddOutputFilterByType SUBSTITUTE text/html

2015-05-14 Thread Aleksandar Lazic
;a=commitdiff;h=a5910cc6ef96c39310f84063766953c914a2f58f I don't know what's the plan with body processing is. Cheers Aleks -Original Message- From: Aleksandar Lazic Sent: Tuesday, May 12, 2015 9:10 PM To: Peter BUtler Cc: haproxy@formilux.org Subject: Re: HAProxy for - AddOutputFilterByType

Re: Complete rewrite of HAProxy in Lua

2015-04-02 Thread Aleksandar Lazic
Hi. nice try ;-) But some parts are not that bad, IMHO. Am 01-04-2015 10:43, schrieb Willy Tarreau: Hi, As some might have noticed, HAProxy development is progressively slowing down over time. I have analyzed the situation and came to the following conclusions : [snipp] Recently with

Re: Complete rewrite of HAProxy in Lua

2015-04-03 Thread Aleksandar Lazic
Hi Willy. Am 03-04-2015 13:24, schrieb Willy Tarreau: Hi Aleks, On Thu, Apr 02, 2015 at 03:39:27PM +0200, Aleksandar Lazic wrote: (...) I think it would be worth to check how much time costs to switch from c to lua and back. I already tried. On my laptop I was seeing 55k conn/s on a simple

Re: new primes in haproxy after logjam

2015-06-04 Thread Aleksandar Lazic
Hi. Am 04-06-2015 23:29, schrieb Emmanuel Thomé: On Thu, Jun 04, 2015 at 05:54:51PM +0200, Willy Tarreau wrote: I simply used openssl dhparam size as suggested, and am trusting openssl to provide something reasonably safe since this is how every user builds their own dhparam when they don't

Re: RFC: appsession removal in 1.6 ?

2015-06-04 Thread Aleksandar Lazic
Hi Willy. Am 04-06-2015 17:42, schrieb Willy Tarreau: Hi all, while discussing with Emeric about what is changing in 1.6, we were speaking about appsession which doesn't make much sense anymore given that it is not replicated between nodes and almost all it does can be done using stick tables.

Re: Rewrite cookie path cookie domain

2015-07-06 Thread Aleksandar Lazic
Dear rickytato rickytato. Am 06-07-2015 15:32, schrieb rickytato rickytato: Hi all, I've problem to rewrite cookie path and cookie domain in HAproxy; I've a Nginx configuration but I want to move from Nginx to HAProxy for this proxy pass. Which Version of haproxy do you use? haproxy -vv ?

Re: [PATCH] Add log-format variable %HQ, to log HTTP query strings

2015-08-02 Thread Aleksandar Lazic
Hi Andrew. Am 31-07-2015 18:21, schrieb Andrew Hayworth: Since this came up in another thread, it seems reasonable to add a patch that implements %HQ as a log-format variable to record the HTTP query string. Leaving the initial '?' is intentional, but I don't feel strongly one way or another.

Upcomming varnish with proxy protocol

2015-08-06 Thread Aleksandar Lazic
Hi all. That's cool ;-) https://www.varnish-cache.org/docs/trunk/whats-new/changes.html#proxy-protocol-support Maybe this will substitute the x-forwarded-for in the future. Cheers Aleks

Re: HAProxy with apache SSL

2015-08-06 Thread Aleksandar Lazic
Hi Victor. Am 06-08-2015 22:45, schrieb Victor Acosta: Hi everyone, I need to use haproxy as load balancer off many apache servers with SSL encryption, it’s works great, but i can’t get the client ip address in my php application. Watching on google, I see the solution can be put the SSL

Re: HAProxy - Combination of SSL Termination and Pass through

2015-08-14 Thread Aleksandar Lazic
Hi. Am 13-08-2015 08:45, schrieb Baptiste: Hi Sandeep, No, HAProxy doesn't pass through. [snipp] What you mean by passthrough would be something like: listen ssl_passthourgh mode tcp bind :443 server 10.0.0.1:443 Maybe that this 'passthrough' wording comes from openshift

RE: cookie prefix strange behavior

2015-07-26 Thread Aleksandar Lazic
Hi Roberto. Am 25-07-2015 09:05, schrieb mlist: Hi Willy, any new on the strange cookie behavior ? Also I ask you for haproxy configuration problem cannot I found a solution searching hard on Internet... To be honest I can't believe this. Have you tried to read the documentation carefully

Re: cookie prefix strange behavior

2015-07-27 Thread Aleksandar Lazic
Hi willy. Am 27-07-2015 07:26, schrieb Willy Tarreau: Hi Aleks, On Sun, Jul 26, 2015 at 11:42:42PM +0200, Aleksandar Lazic wrote: As far as I know there is not yet a flow chart like http://redmine.lighttpd.net/projects/lighttpd/repository/entry/trunk/doc/state.dot You can see the picture

haproxy 1.6 with lua in docker

2015-10-29 Thread Aleksandar Lazic
Hi. I have created a Dockerfile which build haproxy with lua and pcre jit, it is based on centos:latest. https://github.com/git001/haproxy I have already opend an Issue in the official Docker haproxy repo. That’s the output ;-) ## haproxy -vv HA-Proxy version 1.6.1

Scaling out SSL with haproxy 1.5/6

2015-10-23 Thread Aleksandar Lazic
Hi. Currently we Need to scale out ssl handshakes and we Need to do this with haproxy ;-) In 2011 was a blog post with stud http://blog.haproxy.com/2011/11/07/scaling-out-ssl/ and in 2012 a post how to get out the stud ;-)

Re: appsession replacement in 1.6

2015-11-10 Thread Aleksandar Lazic
Dear Sylvain Faivre, Am 10-11-2015 12:48, schrieb Sylvain Faivre: On 11/10/2015 12:00 AM, Aleksandar Lazic wrote: Hi Sylvain Faivre. Am 09-11-2015 17:31, schrieb Sylvain Faivre: [snipp] So, I've got this so far : backend http stick-table type string len 24 size 10m expire 1h peers

Re: Debug mode not working?!

2015-11-09 Thread Aleksandar Lazic
Am 09-11-2015 11:34, schrieb Willy Tarreau: Hi Aleks, On Sun, Nov 08, 2015 at 04:24:29PM +0100, Aleksandar Lazic wrote: Hi. Today I have tried to debug haproxy as in the old days ;-), I was not able to see the communication on stderr. I'm sure I have something missed in the past

Re: Debug mode not working?!

2015-11-09 Thread Aleksandar Lazic
Am 09-11-2015 22:21, schrieb Willy Tarreau: On Mon, Nov 09, 2015 at 10:15:46PM +0100, Aleksandar Lazic wrote: ... epoll_wait(3, {}, 200, 1000)= 0 epoll_wait(3, {{EPOLLIN, {u32=5, u64=5}}}, 200, 1000) = 1 accept4(5, {sa_family=AF_INET, sin_port=htons(52310), sin_addr

Re: Debug mode not working?!

2015-11-09 Thread Aleksandar Lazic
Hi Nenad, Am 09-11-2015 22:52, schrieb Nenad Merdanovic: Hello Aleksandar, Okay after removing accept-proxy from bind *:${HTTP_BIND_PORT} accept-proxy tfo It comes what expected. If you are using 'accept-proxy', HAproxy expects the payload to start with a PROXY protocol header.

Debug mode not working?!

2015-11-08 Thread Aleksandar Lazic
Hi. Today I have tried to debug haproxy as in the old days ;-), I was not able to see the communication on stderr. I'm sure I have something missed in the past on the list to be able to see the output. My steps. curl -vO http://www.haproxy.org/download/1.6/src/haproxy-1.6.2.tar.gz tar

Re: acl regex

2015-11-12 Thread Aleksandar Lazic
Hi. Am 12-11-2015 21:16, schrieb Guillaume Bourque: Hi all, I’m not far but it does not work so any recommendation would be very helpfull I just need some very simple redirect but after looking into aloa doc the happy doc, I can’t find examples that could help me do this, okay I must admit I

Re: HAProxy and backend on the same box

2015-11-12 Thread Aleksandar Lazic
Am 13-11-2015 06:14, schrieb jaleel: It works if HAProxy and backend are in different box, but when both are in same box it didn't work Maybe because the iptables rule is a different from 'localhost' then from external. Please take a look at the picture

Re: HAProxy and backend on the same box

2015-11-12 Thread Aleksandar Lazic
Hi. But do you really think this is a haproxy Problem? Am 13-11-2015 08:38, schrieb Aleksandar Lazic: Am 13-11-2015 06:14, schrieb jaleel: It works if HAProxy and backend are in different box, but when both are in same box it didn't work Maybe because the iptables rule is a different from

Re: Experiences with Docker and linking containers for zero downtime deployments

2015-11-15 Thread Aleksandar Lazic
Hi Paul. Am 14-11-2015 14:00, schrieb Paul Menzel: Dear HAProxy folks, I am using a Docker setup to serve Web application using a database. HAProxy, the Web app and the database each run in a separate Docker container. The HAProxy container is than started with the command below.

Re: appsession replacement in 1.6

2015-11-16 Thread Aleksandar Lazic
Hi Sylvain. Am 16-11-2015 17:06, schrieb Sylvain Faivre: Hi Aleks, On 11/10/2015 10:56 PM, Aleksandar Lazic wrote: Dear Sylvain Faivre, [snipp] This would be helpfully to see the full response. Maybe some appserver behaves different. As far as I know, there is no way for the server

Re: appsession replacement in 1.6

2015-11-09 Thread Aleksandar Lazic
Hi Sylvain Faivre. Am 09-11-2015 17:31, schrieb Sylvain Faivre: Hi, Sorry I'm late on this discussion, following this thread : https://marc.info/?l=haproxy=143345620219498=2 We are using appsession with HAproxy 1.5 like this : Thanks ;-) backend http appsession JSESSIONID len 24

Re: How to Externally Access PHP Application that has Internal Links to Itself

2015-11-02 Thread Aleksandar Lazic
run http://open-emr.org therefore please take a look into this code. https://github.com/openemr/openemr/blob/8b9d250de3c76aeb4f706342c2f3c3f1e1b9c6db/interface/globals.php#L137 https://github.com/openemr/openemr/blob/8b9d250de3c76aeb4f706342c2f3c3f1e1b9c6db/interface/globals.php#L38 Best regards A

Re: How to Externally Access PHP Application that has Internal Links to Itself

2015-10-31 Thread Aleksandar Lazic
Dear Susheel Jalali. Am 31-10-2015 08:43, schrieb Susheel Jalali: Dear HAProxy Developers: [snipp] This is same as what Apache server’s mod_proxy_html serves to: rewrite http://appserver.example.com/foo/bar.html;>foobar to http://www.example.com/appserver/foo/bar.html;>foobar. Is there an

Re: HTTP Response Rewriting to Replace Internal IP with FQDN

2015-10-14 Thread Aleksandar Lazic
Subject: Re: HTTP Response Rewriting to Replace Internal IP with FQDN From: Aleksandar Lazic <al-hapr...@none.at> Date: Tue, October 13, 2015 2:44 pm To: Susheel Jalali <susheel.jal...@coscend.com> Cc: haproxy@formilux.org, "i...@coscend.com" <i...@coscend.com>

Re: HTTP Response Rewriting to Replace Internal IP with FQDN

2015-10-07 Thread Aleksandar Lazic
Dear Susheel Jalali. Am 07-10-2015 23:24, schrieb Susheel Jalali: Dear Igor and Aleks, Thank you for your insights. Very useful to us, as we are implementing HAProxy for the first time. Below we have described how we have implemented your advise and the result. Output of "haproxy -vv" is

Re: HTTP Response Rewriting to Replace Internal IP with FQDN

2015-10-07 Thread Aleksandar Lazic
Hi Susheel Jalali. please can you show us the out put of haproxy -vv Am 06-10-2015 22:06, schrieb Susheel Jalali: Dear HAProxy Developers, After incorporating insights from Bryan Talbot and articles from Baptiste Assman on HAProxy Web site, we have been able to get the basic configuration of

Re: HTTP Response Rewriting to Replace Internal IP with FQDN

2015-10-12 Thread Aleksandar Lazic
OT)com -- CONFIDENTIALITY NOTICE: See 'Confidentiality Notice Regarding E-mail Messages from Coscend Communications Solutions' posted at: www(DOT)Coscend(DOT)com/Terms_and_Conditions.html On 10/08/15 03:50, Aleksandar Lazic wrote: Dear Susheel Jalali. Am 07-10-2015

Re: HTTP Response Rewriting to Replace Internal IP with FQDN

2015-10-13 Thread Aleksandar Lazic
Dear Susheel Jalali. Am 13-10-2015 22:20, schrieb Susheel Jalali: Dear Aleks, [snipp] ++ Tomcat’s web.xml In web.xml, the context parameter is: globalScope default and the filter mapping for the application is: Product1Application

Re: [ANNOUNCE] haproxy-1.6.0 now released!

2015-10-13 Thread Aleksandar Lazic
Hi. Am 13-10-2015 21:50, schrieb Willy Tarreau: On Tue, Oct 13, 2015 at 09:42:25PM +0200, Baptiste wrote: Great, amazing! Looking forward to 1.7! Already online : $ ./haproxy -v HA-Proxy version 1.7-dev0 2015/10/13 :-) As always fast, quite fast, flashy ;-) BR Aleks

Re: HTTP Response Rewriting to Replace Internal IP with FQDN

2015-10-13 Thread Aleksandar Lazic
Am 13-10-2015 23:36, schrieb Aleksandar Lazic: Dear Susheel Jalali. Am 13-10-2015 22:20, schrieb Susheel Jalali: Dear Aleks, [snipp] ++ Tomcat’s web.xml In web.xml, the context parameter is: globalScope default and the filter mapping

Re: Question about the status of the connection pool

2015-09-05 Thread Aleksandar Lazic
Hi. Am 05-09-2015 03:42, schrieb thierry.fourn...@arpalert.org: On Fri, 04 Sep 2015 22:30:08 +0200 Aleksandar Lazic <al-hapr...@none.at> wrote: Dear Developers ;-). Please can you tell me/us what's the status of the backend connection pooling? Are the specs defined? will the conn

Re: Question about the status of the connection pool

2015-09-07 Thread Aleksandar Lazic
Hi Baptiste. Am 07-09-2015 09:28, schrieb Baptiste: Hi Aleks; There is a official docker repository for haproxy https://hub.docker.com/_/haproxy/ Is anyone from haproxy community involved into this repo? HAProxy Technologies and Docker Inc are going to work together on this repository

Re: [PATCH] Support statistics in multi-process mode

2015-09-14 Thread Aleksandar Lazic
Hi. Am 14-09-2015 12:17, schrieb Willy Tarreau: Hi Philipp, [snipped] What I'd like to have instead would be a per-proxy shared memory segment for stats in addition to the per-process one, that is updated using atomic operations each time other stats are updated. The max are a bit tricky

Re: tune.bufsize and tune.maxrewrites questions

2015-09-17 Thread Aleksandar Lazic
Hi John. Am 17-09-2015 07:03, schrieb John Skarbek: Good Morning! So recently I went into battle between our CDN provider and our application team due to some HTTP400's coming from somewhere. At first I never suspected haproxy to be at fault due to the way I was groking our logs. The end

Re: Haproxy app cookie is not working

2015-09-15 Thread Aleksandar Lazic
Hi. Am 15-09-2015 11:07, schrieb Jayapal Reddy: Hi All, ssh proxy is send to both machines, it is honouring the session cookie. Below is my harpy config snippet*, complete logs can be found here. https://www.digitalocean.com/community/questions/haproxy-appcookie-is-not-working Please can

Re: tune.bufsize and tune.maxrewrites questions

2015-09-27 Thread Aleksandar Lazic
``` On Thu, Sep 17, 2015 at 12:18 AM, Aleksandar Lazic <al-hapr...@none.at> wrote: Hi John. Am 17-09-2015 07:03, schrieb John Skarbek: Good Morning! So recently I went into battle between our CDN provider and our application team due to some HTTP400's coming from somewhere. At f

Re: x-forwarded-for help

2015-10-05 Thread Aleksandar Lazic
Hi. Am 05-10-2015 14:29, schrieb Travis Fitch: Hello, Some quick background; My current setup is haproxy in front of Apache on the same host. If I send a request to haproxy, I see the x-forwarded-for entry in Apache's logs and also with tcpdump tcpdump -i any -nn -A - -s 'host

Re: urlp strange behaviour ?

2015-12-08 Thread Aleksandar Lazic
Hi. Am 08-12-2015 11:23, schrieb Thierry FOURNIER: Hi, I agree with you, but in HAProxy, the ';' is considered as parameter delimiter. Its hardcoded, and I don't known the reason. There are several reasons for the ';' to be a separator similar like '&'.

Re: Source IP Affinity

2015-12-31 Thread Aleksandar Lazic
Hi. Am 30-12-2015 15:57, schrieb Hall, Colton: Hello, was wondering if you could answer a couple of questions pertaining to HAPROXY. We are interested in evaluating the product but not sure it will accomplish our goals. The main concerns are listed below. 1. Can we set persistency

  1   2   3   4   5   6   7   8   9   10   >