Re: haproxy 1.9.2 with boringssl

2019-01-24 Thread Aleksandar Lazic
Am 24.01.2019 um 15:09 schrieb Aleksandar Lazic: > Am 24.01.2019 um 03:49 schrieb Willy Tarreau: >> On Wed, Jan 23, 2019 at 09:37:46PM +0100, Aleksandar Lazic wrote: >>> >>> Am 23.01.2019 um 21:27 schrieb Willy Tarreau: >>>> On Wed, Jan 23, 2019 at 0

Re: h1-client to h2-server host header / authority conversion failure.?

2019-01-25 Thread Aleksandar Lazic
Hi List. Am 25-01-2019 01:01, schrieb PiBa-NL: Hi List, Attached a regtest which i 'think' should pass. **   s1    0.0 === expect tbl.dec[1].key == ":authority" s1    0.0 EXPECT tbl.dec[1].key (host) == ":authority" failed It seems to me the Host <> Authority conversion isn't happening p

Re: V1.9 SSL engine and ssl-mode-async is unstable

2019-01-25 Thread Aleksandar Lazic
Hi. Am 25-01-2019 08:55, schrieb Kevin Zhu: HI HAProxy Team,: I am trying to use Intel qat work with HAProxy-1.9.0, but it work very unstable. and i had other try HAProxy-1.8.16 and it work will, How can i find what is wrong? 1.8.16 and 1.9.0 use same hardwave and system to running and compil

Re: [ANNOUNCE] haproxy-1.9.3

2019-01-29 Thread Aleksandar Lazic
Am 29.01.2019 um 06:52 schrieb Willy Tarreau: > Hi, > > HAProxy 1.9.3 was released on 2019/01/29. It added 35 new commits after > version 1.9.2. > > It mainly addresses a few stability issues affecting versions up to 1.9.2. > Several of these issues are only reproducible when using H2 to connect

Cache question

2019-01-29 Thread Aleksandar Lazic
Hi. I plan to use HAProxy 1.9.x cache with ~50-100k Objects which will could use 1-2G RAM. Have anyone used the cache features in prod with such specs? The Idea is to use HAProxy in AUS for a Webserver in FR for caching as the latency delays the delivery from FR to AUS Clients. Thank you for

Re: HTTP connection is reset after each request

2019-01-30 Thread Aleksandar Lazic
Hi. Am 30.01.2019 um 11:53 schrieb Marco Corte: > Il 2019-01-30 11:40 Luke Seelenbinder ha scritto: > > >> Are you on 1.9.x? 1.8.x does not support reuse of backend connections >> when using an h2 frontend. 1.9.x does support this and it works quite >> nicely. > > Yes! I am on version 1.8.17. >

Re: HTTP connection is reset after each request

2019-01-30 Thread Aleksandar Lazic
t; — > Luke Seelenbinder > Stadia Maps | Founder > stadiamaps.com > > ‐‐‐ Original Message ‐‐‐ > On Wednesday, January 30, 2019 12:02 PM, Aleksandar Lazic > wrote: > >> Hi. >> > >> Am 30.01.2019 um 11:53 schrieb Marco Corte: >> > >

Re: RTMP and Seamless Reload

2019-01-30 Thread Aleksandar Lazic
Hi. Am 30.01.2019 um 13:08 schrieb Erlangga Pradipta Suryanto: > Hi, > > I'm trying to use haproxy to proxy rtmp stream to an nginx rtmp backend. > what we want to achieve is, we will add more nginx rtmp servers on the > backend, and when we do we want to reload the haproxy config without closin

Re: Early connection close, incomplete transfers

2019-01-31 Thread Aleksandar Lazic
Hi. Am 31.01.2019 um 10:29 schrieb Veiko Kukk: > HAproxy 1.9.3, but happens also with 1.7.10, 1.7.11. > > Connections are getting closed during data transfer phase at random sizes on > backend. Sometimes just as little as 420 bytes get transferred, but usually > more is transferred before sudde

Re: RTMP and Seamless Reload

2019-01-31 Thread Aleksandar Lazic
ential and/or privileged information. If you are not the named > addressee or have received this e-mail in error, please notify the sender > immediately. The unauthorised disclosure, use or reproduction of this email's > content is prohibited. Unless expressly agreed, no reliance on

Re: Early connection close, incomplete transfers

2019-02-01 Thread Aleksandar Lazic
Hi. Do you have any errors in lighthttpds log? Regards Aleks Ursprüngliche Nachricht Von: Veiko Kukk Gesendet: 1. Februar 2019 12:33:39 MEZ An: Aleksandar Lazic CC: haproxy@formilux.org Betreff: Re: Early connection close, incomplete transfers On 2019-01-31 12:57

[PATCH] DOC: Add HTX part in the documentation

2019-02-02 Thread Aleksandar Lazic
Hi. attached a doc update for the new features of HAProxy 1.9. I hope the patch full fills the CONTRIBUTING rules as I haven't send patched to the list for long time ;-) Regards AleksFrom c0e025e81b87a23f679aff80bddc02a96c4d43b0 Mon Sep 17 00:00:00 2001 From: Aleksandar Lazic Date: Sat,

Re: [PATCH] DOC: Add HTX part in the documentation

2019-02-02 Thread Aleksandar Lazic
Sorry have forgotten to add. Need to backport to 1.9 Regards Aleks Ursprüngliche Nachricht Von: Aleksandar Lazic Gesendet: 2. Februar 2019 10:01:26 MEZ An: haproxy@formilux.org Betreff: [PATCH] DOC: Add HTX part in the documentation Hi. attached a doc update for the new

Opinions about DoH (=DNS over HTTPS) as resolver for HAProxy

2019-02-04 Thread Aleksandar Lazic
Hi. I have just opened a new Issue about DoH for resolving. https://github.com/haproxy/haproxy/issues/33 As I know that this is a major change in the Infrastructure I would like to here what you think about this suggestion. My opinion was at the beginning against this change as there was only

Re: Opinions about DoH (=DNS over HTTPS) as resolver for HAProxy

2019-02-04 Thread Aleksandar Lazic
Hi Lukas. Am 04.02.2019 um 21:39 schrieb Lukas Tribus: > Hello, > > On Mon, 4 Feb 2019 at 12:14, Aleksandar Lazic wrote: >> >> Hi. >> >> I have just opened a new Issue about DoH for resolving. >> >> https://github.com/haproxy/haproxy/issues/33 >&

Re: info defaults maxconn

2019-02-06 Thread Aleksandar Lazic
Hi Federico. Am 06.02.2019 um 15:33 schrieb Federico Iezzi: > Hey there, > > Maybe this is gonna be a very simple answer. > In HAProxy 1.5.18 seems that the defaults maxconn have a global influence and > not per backend one. > > In my case I have global maxconn at 5120001, while defaults at 256

Re: [ANNOUNCE] haproxy-1.9.4

2019-02-06 Thread Aleksandar Lazic
Hi willy. Am 06.02.2019 um 15:25 schrieb Willy Tarreau: > Hi, > > HAProxy 1.9.4 was released on 2019/02/06. It added 65 new commits > after version 1.9.3. Images are updated. https://hub.docker.com/r/me2digital/haproxy-19-boringssl https://hub.docker.com/r/me2digital/haproxy19 Maybe this patch

Re: Weighted Backend's

2019-02-06 Thread Aleksandar Lazic
Hi James. Am 06.02.2019 um 16:16 schrieb James Root: > Hi All, > > I am doing some research and have not really found a great way to configure > HAProxy to get the desired results. The problem I face is that I a service > backed by two separate collections of servers. I would like to split traffi

Re: [ANNOUNCE] haproxy-1.9.4

2019-02-07 Thread Aleksandar Lazic
Am 06.02.2019 um 17:19 schrieb Willy Tarreau: > Hi Aleks, > > On Wed, Feb 06, 2019 at 05:16:58PM +0100, Aleksandar Lazic wrote: >> Maybe this patch was to late for 1.9.4 please can you consider to add it >> to 2.0 and later 1.9.5, thanks. >> >> https://www.mail

Re: [PATCH] CONTRIB: contrib/prometheus-exporter: Add a Prometheus exporter for HAProxy

2019-02-09 Thread Aleksandar Lazic
Hi Christopher. Am 07-02-2019 22:09, schrieb Christopher Faulet: Hi, This patch adds a new component in contrib. It is a Prometheus exporter for HAProxy. [snipp] More details in the README. I'm not especially a Prometheus expert. And I must admit I never use it. So if anyone have comments

Anyone heard about DPDK?

2019-02-10 Thread Aleksandar Lazic
Hi. I have seen this in some twitter posts and asked me if it's something useable for a Loadbalancer like HAProxy ? https://www.dpdk.org/ To be honest it looks like a virtual NIC, but I'm not sure. Regards Aleks

Re: Anyone heard about DPDK?

2019-02-10 Thread Aleksandar Lazic
Am 10.02.2019 um 12:06 schrieb Lukas Tribus: > On Sun, 10 Feb 2019 at 10:48, Aleksandar Lazic wrote: >> >> Hi. >> >> I have seen this in some twitter posts and asked me if it's something >> useable for a Loadbalancer like HAProxy ? >> >> https:

Re: [PATCH] CONTRIB: contrib/prometheus-exporter: Add a Prometheus exporter for HAProxy

2019-02-11 Thread Aleksandar Lazic
Am 11.02.2019 um 10:40 schrieb Christopher Faulet: > Le 09/02/2019 à 10:47, Aleksandar Lazic a écrit : >> Hi Christopher. >> >> Am 07-02-2019 22:09, schrieb Christopher Faulet: >>> Hi, >>> >>> This patch adds a new component in contrib. It is a P

Re: Anyone heard about DPDK?

2019-02-12 Thread Aleksandar Lazic
Hi all. Wow so much feedback, thanks all for the answers ;-) Am 12.02.2019 um 15:23 schrieb Alexandre Cassen: > There has been a lot of applications/stack built around DPDK last few years. > Mostly because people found it easy to code stuff around DPDK and are so happy > to display perf graph abo

Re: haproxy segfault

2019-02-12 Thread Aleksandar Lazic
Hi. Am 12.02.2019 um 18:36 schrieb Mildis: > Hi list, > > haproxy is segfaulting multiple times these days for no apparent reason. > At first i thought is was a load issue but even few RPS made it crash. > > Symptoms are always the same : segfault of a worker then spawn of a new. > If load is ve

Re: HAProxy in front of Docker Enterprise problem

2019-02-13 Thread Aleksandar Lazic
Hi. Am 13.02.2019 um 00:21 schrieb Norman Branitsky: > I have an HAProxy 1.7 server sitting in front of a number of Docker Enterprise > Manager nodes and Worker nodes. > > The Worker nodes don’t appear to have any problem with HAProxy terminating the > SSL and connecting to them via HTTP. > > Th

Re: Compilation fails on OS-X

2019-02-13 Thread Aleksandar Lazic
Am 13.02.2019 um 14:45 schrieb Patrick Hemmer: > Trying to compile haproxy on my local machine for testing purposes and am > running into the following: Which compiler do you use? >         # make TARGET=osx >     src/proto_http.c:293:1: error: argument to 'section' attribute is not > valid f

Re: [RFC PATCH] MEDIUM: compression: Add support for brotli compression

2019-02-14 Thread Aleksandar Lazic
Hi Tim. Am 13.02.2019 um 17:57 schrieb Tim Duesterhus: > Willy, > Aleks, > List, > > this (absolutely non-ready-to-merge) patch adds support for brotli > compression as suggested in issue #21: > https://github.com/haproxy/haproxy/issues/21 Cool ;-) > It is tested on Ubuntu Xenial with libbrotl

Re: Compilation fails on OS-X

2019-02-14 Thread Aleksandar Lazic
Looks like apples llvm is not based on master branch. https://news.ycombinator.com/item?id=16545037 Ursprüngliche Nachricht Von: Frederic Lecaille Gesendet: 14. Februar 2019 16:13:01 MEZ An: Patrick Hemmer CC: Olivier Houchard , Aleksandar Lazic , haproxy@formilux.org

Re: Early connection close, incomplete transfers

2019-02-14 Thread Aleksandar Lazic
Am 14.02.2019 um 15:31 schrieb Veiko Kukk: > > On 2019-02-01 13:30, Veiko Kukk wrote: >> On 2019-02-01 12:34, Aleksandar Lazic wrote: >> >>> Do you have any errors in lighthttpds log? >> >> Yes, it has error messages about not being enable to write to socke

Re: Early connection close, incomplete transfers

2019-02-15 Thread Aleksandar Lazic
Am 15.02.2019 um 08:47 schrieb Veiko Kukk: > On 2019-02-14 18:29, Aleksandar Lazic wrote: >>> Replaced HAproxy with Nginx for testing and with Nginx, not a single >>> connection >>> was interrupted, did millions of requests. >> >> In 1.9.4 are a lot

Re: Tune HAProxy in front of a large k8s cluster

2019-02-15 Thread Aleksandar Lazic
Hi Joao. Am 15.02.2019 um 10:21 schrieb Joao Morais: > > Hi list, I'm tuning some HAProxy instances in front of a large kubernetes > cluster. The config has about 500 hostnames (a la apache/nginx virtual > hosts), 3 frontends, 1500 backends and 4000 servers. The first frontend is on > tcp mode bi

Re: Tune HAProxy in front of a large k8s cluster

2019-02-15 Thread Aleksandar Lazic
Hi Joao. Am 15.02.2019 um 11:15 schrieb Joao Morais: > > >> Em 15 de fev de 2019, à(s) 07:44, Aleksandar Lazic >> escreveu: >> >> Hi Joao. >> >> Am 15.02.2019 um 10:21 schrieb Joao Morais: >>> >>> Hi list, I'm tuning some

Re: Tune HAProxy in front of a large k8s cluster

2019-02-15 Thread Aleksandar Lazic
Am 15.02.2019 um 22:11 schrieb Joao Morais: > >> Em 15 de fev de 2019, à(s) 08:43, Aleksandar Lazic >> escreveu: >> >> Hi Joao. >> >> Am 15.02.2019 um 11:15 schrieb Joao Morais: >>> >>> Hi Aleks, sure. Regarding the config, it has

Question about haproxy in front of coturn turnserver

2019-02-20 Thread Aleksandar Lazic
Hi. I would like to run haproxy in front of the https://github.com/coturn/coturn turnserver for nextcloud talk. Have anyone tried this or have setup-ed successfully such a config? I would like to disable the udp part on coturn `no-udp` just because for now have haproxy not the option to proxy ud

Re: RTMP and Seamless Reload

2019-02-21 Thread Aleksandar Lazic
he runtime API for the time being. Sounds like a solution. > Thanks, > > *Erlangga Pradipta Suryanto* Regards Aleks > __ > > *T. *+62118898168| *BBM PIN. D8F39521*__ > > *E. esuryanto*@bbmtek.com <mailto:mtal...@bbmtek.com> > > > > > On Th

Re: http/2 server-push support

2019-02-27 Thread Aleksandar Lazic
Hi Patrick. Am 26.02.2019 um 20:13 schrieb Patrick Hemmer: > Now that we have h2 support on frontends, backends, trailers, etc, I'm hoping > that server side server-push is somewhere on the roadmap. By "server side" I > mean not this middleware based server-push methodology frequently used where a

Re: Does anyone *really* use 51d or WURFL ?

2019-03-05 Thread Aleksandar Lazic
Hi. Am 05.03.2019 um 13:47 schrieb Willy Tarreau: > Hi all, > > back to this old thread : > > On Mon, Jan 21, 2019 at 03:36:22PM +0100, Willy Tarreau wrote: >> I don't know if wurfl builds at all by the way since the last update to >> the module is its introduction more than 2 years ago. > > So

Re: Adding Configuration parts via File

2019-03-08 Thread Aleksandar Lazic
Hi. In addition to Bruno's answer there was a thread on the ML which explains why such a "simple" directive like include isn't easy to implement. https://www.mail-archive.com/haproxy@formilux.org/msg05215.html As I also think that in some setups can a include can make the main config shorter i

Re: segfault in eb32sc_lookup_ge (1.9.4)

2019-03-24 Thread Aleksandar Lazic
Hi. Please can you try to use 1.9.5 and see if still happen. Best regards Aleks Ursprüngliche Nachricht Von: "Максим Куприянов" Gesendet: 24. März 2019 16:59:59 MEZ An: HAProxy Betreff: segfault in eb32sc_lookup_ge (1.9.4) Hi! I caught 2 segfaults on different machines. Bo

Re: FEATURE: Add range iterator item variable for server-template and zero-padding converter

2019-03-29 Thread Aleksandar Lazic
Hi. Am 29.03.2019 um 09:34 schrieb Matous Jan Fialka: > Hello, > > please consider adding range iterator item variable (say `rng.iteritem`) for > the `server-template` directive so that it can be expanded in the > `:` > part of the statement or anywhere else where applicable (see in the example

Re: [ANNOUNCE] haproxy-1.9.6

2019-03-29 Thread Aleksandar Lazic
Am 29.03.2019 um 11:50 schrieb Willy Tarreau: > Hi, > > HAProxy 1.9.6 was released on 2019/03/29. It added 34 new commits > after version 1.9.5. > > As mentioned in the 2.0-dev2 release, we've addressed quite a number > of issues recently and these fixes have now been backported into this > relea

Re: [ANNOUNCE] haproxy-1.9.6

2019-03-29 Thread Aleksandar Lazic
Am 29.03.2019 um 14:25 schrieb Willy Tarreau: > Hi Aleks, > > On Fri, Mar 29, 2019 at 02:09:28PM +0100, Aleksandar Lazic wrote: >> With openssl are 2 tests failed but I'm not sure because of the setup or a >> bug. >> https://gitlab.com/aleks001/haproxy19-centos

Re: Using haproxy to have SSH in a HTTPS connection with HTX

2019-03-31 Thread Aleksandar Lazic
Hi Matthias. Am 31.03.2019 um 10:11 schrieb Matthias Fechner: > Dear all, > > as HTTP2 is getting stable in haproxy 1.9.6 I decided to give it a try. > Currently I have the following setup: >     frontend www-https >     mode tcp >     option tcplog >     b

Re: Upcoming haproxy build fixes for Cygwin & AIX

2019-04-01 Thread Aleksandar Lazic
Am 01.04.2019 um 09:06 schrieb Willy Tarreau: > On Mon, Apr 01, 2019 at 09:04:06AM +0800, ??? wrote: >> Many thanks Willy, I will wait and to try and study your patch. > > You're welcome. [good infos snipped] > I managed to build this version with openssl 1.0.2 support on a very > old Power3/333

Re: Upcoming haproxy build fixes for Cygwin & AIX

2019-04-01 Thread Aleksandar Lazic
Am 01.04.2019 um 15:15 schrieb Willy Tarreau: > On Mon, Apr 01, 2019 at 03:04:24PM +0200, Aleksandar Lazic wrote: >>> I managed to build this version with openssl 1.0.2 support on a very >>> old Power3/333 MHz running AIX 5.1 and to run an H2 test. This sounds >>> a

Look at "HTTP/3 and QUIC: the details" from curlup 2019

2019-04-01 Thread Aleksandar Lazic
Hi. In the last curlup https://daniel.haxx.se/blog/2019/04/01/curl-up-2019-is-over/ was a some interesting talks like QUIC: the details https://youtu.be/mDc2kHPtavE The slide link is on curlup or on youtube. Regards Aleks

Re: [ANNOUNCE] haproxy-1.9.6

2019-04-09 Thread Aleksandar Lazic
Hi Manu. Am 05.04.2019 um 12:36 schrieb Emmanuel Hocdet: > Hi Aleks, > > Thanks you to have integrate BoringSSL! > >> Le 29 mars 2019 à 14:51, Aleksandar Lazic > <mailto:al-hapr...@none.at>> a écrit : >> >> Am 29.03.2019 um 14:25 schrieb Willy Tarreau:

Re: [ANNOUNCE] haproxy-1.9.6

2019-04-09 Thread Aleksandar Lazic
Am 09.04.2019 um 18:06 schrieb Emmanuel Hocdet: > >> Le 9 avr. 2019 à 09:58, Aleksandar Lazic > <mailto:al-hapr...@none.at>> a écrit : >> >> Hi Manu. >> >> Am 05.04.2019 um 12:36 schrieb Emmanuel Hocdet: >>> Hi Aleks, >>> >>&g

Re: SSL termination with HA proxy

2019-04-15 Thread Aleksandar Lazic
Hi. Am 15.04.2019 um 17:19 schrieb bhanu chandra suman: > Hi Team, > > I installed haproxy in ubuntu machine. and after that i edited the > haproxy.cfg file. Please can you tell us more about this. haproxy -vv uname -a > bind *:18083 > mode http > default_backend backendnodes > backend backen

Re: SSL termination with HA proxy

2019-04-15 Thread Aleksandar Lazic
Hi. Please keep the Mailinglist in the loop. Am 15.04.2019 um 17:27 schrieb bhanu chandra suman: > image.png It's not easy to copy text from Screenshot's so please copy text into the mail. Please use 2 v. haproxy -vv Thanks. > On Mon, Apr 15, 2019 at 8:53 PM Aleksandar L

Re: SSL termination with HA proxy

2019-04-15 Thread Aleksandar Lazic
nto this blog post which describes how to add TLS/SSL termination into haproxy. https://www.haproxy.com/blog/how-to-get-ssl-with-haproxy-getting-rid-of-stunnel-stud-nginx-or-pound/ Regards Aleks > On Mon, Apr 15, 2019 at 8:58 PM Aleksandar Lazic <mailto:al-hapr...@none.at>> wrote: >

Re: SSL termination with HA proxy

2019-04-15 Thread Aleksandar Lazic
cate? Maybe this post helps you to create certificates. https://serversforhackers.com/c/using-ssl-certificates-with-haproxy Regards Aleks > On Mon, Apr 15, 2019 at 9:27 PM Aleksandar Lazic <mailto:al-hapr...@none.at>> wrote: > > Hi. > > Am 15.04.2019

Re: [ANNOUNCE] haproxy-1.9.7

2019-04-26 Thread Aleksandar Lazic
Am 25.04.2019 um 23:18 schrieb Christopher Faulet: > Hi, > > HAProxy 1.9.7 was released on 2019/04/25. It added 100 new commits after > version > 1.9.6. > > After a month since the last release, a huge number of bugs were addressed > into > this release. The most significant are fixes of 100% C

Re: [ANNOUNCE] haproxy-1.9.7

2019-04-26 Thread Aleksandar Lazic
Hi Christopher. Am 26.04.2019 um 10:40 schrieb Christopher Faulet: > Le 26/04/2019 à 10:29, Aleksandar Lazic a écrit : >> >> THe new images are also available on docker hub. >> >> https://hub.docker.com/r/me2digital/haproxy19 >> https://hub.docker.com/r/me2digita

haproxy 2.0 docker images

2019-04-27 Thread Aleksandar Lazic
Hi. I have now created some HAProxy 2.0 images ;-). The outputs below raises some questions to me. * Should in the OPTIONS output also be the EXTRA_OBJS ? * Should PCRE2 be used instead of PCRE ? * Should PRIVATE_CACHE be used in the default build? * Should SLZ be used in the default build? * M

Re: haproxy 2.0 docker images

2019-05-05 Thread Aleksandar Lazic
Hi. Any answer to the questions below? Regards Aleks Sat Apr 27 12:47:17 GMT+02:00 2019 Aleksandar Lazic : > Hi. > > > I have now created some HAProxy 2.0 images ;-). > > The outputs below raises some questions to me. > > * Should in the OPTIONS output also be the

Re: [PATCH 0/6] Kill deprecated configuration options

2019-05-14 Thread Aleksandar Lazic
Hi. Wed May 15 05:07:05 GMT+02:00 2019 Willy Tarreau : > Hi Tim, > > On Tue, May 14, 2019 at 08:57:55PM +0200, Tim Duesterhus wrote: > > Okay, I did a sweep through the configuration parser and: > > > > 1. Made deprecated directives fatal and removed them from the docs. The > > error mess

Re: [PATCH 0/6] Kill deprecated configuration options

2019-05-15 Thread Aleksandar Lazic
Am 15.05.2019 um 17:09 schrieb Tim Düsterhus: > Willy, > > Am 15.05.19 um 11:31 schrieb Tim Düsterhus: 2. 'req*' and 'rsp*'. I remember that they allow some modification that cannot easily be replicated otherwise (but I'll have to check that first). >>> >>> Sure but practicall

Re: [ANNOUNCE] haproxy-1.9.8

2019-05-15 Thread Aleksandar Lazic
Am 13.05.2019 um 16:57 schrieb Willy Tarreau: > Hi, > > HAProxy 1.9.8 was released on 2019/05/13. It added 53 new commits > after version 1.9.7. > > The most important bugs fall into 3 main categories here : > - a possible crash in multi-threads when issuing "show map" or > "show acl" on th

Re: [ANNOUNCE] haproxy-2.0-dev3

2019-05-15 Thread Aleksandar Lazic
Am 15.05.2019 um 18:52 schrieb Willy Tarreau: > Hi, > > HAProxy 2.0-dev3 was released on 2019/05/15. It added 393 new commits > after version 2.0-dev2. > > This is another huge version, having been distacted by a number of bugs > lately, this one was postponed a bit too much in my taste. As usual

Re: [ANNOUNCE] haproxy-2.0-dev3

2019-05-15 Thread Aleksandar Lazic
Tim, Am 16.05.2019 um 00:32 schrieb Tim Düsterhus: > Aleks, > > Am 15.05.19 um 22:59 schrieb Aleksandar Lazic: >> As we use more and more the CI features of github what's the opinion of the >> community to use this features to create and push Container images to the

Re: [PATCH 0/6] Kill deprecated configuration options

2019-05-16 Thread Aleksandar Lazic
Am 16.05.2019 um 11:16 schrieb Willy Tarreau: > Hi Aleks, > > On Wed, May 15, 2019 at 09:09:08PM +0200, Aleksandar Lazic wrote: >>> The obvious `http-request set-path %[path,regsub(...)]` as suggested in >>> the docs for `http-request set-query` does *NOT* wo

Re: Host header and sni extension differ

2019-05-16 Thread Aleksandar Lazic
Am 16.05.2019 um 16:37 schrieb Joao Morais: > > Hi list! The symptom is as follow: when logging Host: header I receive > `myapp.io` while in the same request the sni extension says `anotherapp.com`. > > This happens in a very few requests (about 0.5%) but this is enough to make > some noise - r

ssl_fc_sni vs req.ssl_sni

2019-05-16 Thread Aleksandar Lazic
Hi. I use the following lines: use_backend xmppc2s-backend if { req.ssl_sni -i domain.im } use_backend cloud-hop-backend if { ssl_fc_sni -i cloud.domain.at } and asked myself which one is the recommended line? Makes this lines sense? tcp-request content accept if { ssl_fc_sni 1 }

Re: [ANNOUNCE] haproxy-2.0-dev3

2019-05-17 Thread Aleksandar Lazic
Tim, Am 16.05.2019 um 20:19 schrieb Tim Düsterhus: > Aleks, > > Am 16.05.19 um 01:04 schrieb Aleksandar Lazic: >>> As a avid Docker user: I tend to absolutely avoid any Docker images that >>> are not built using Docker Hub's autobuilder, because I cannot veri

Re: [ANNOUNCE] haproxy-2.0-dev3

2019-05-17 Thread Aleksandar Lazic
Am 16.05.2019 um 10:00 schrieb Илья Шипицин: > > чт, 16 мая 2019 г. в 02:02, Aleksandar Lazic <mailto:al-hapr...@none.at>>: > > Am 15.05.2019 um 18:52 schrieb Willy Tarreau: > > Hi, > > [snipp] > > I'd like to emit a new -dev relea

Re: ssl_fc_sni vs req.ssl_sni

2019-05-17 Thread Aleksandar Lazic
Am 16.05.2019 um 20:30 schrieb Tim Düsterhus: > Aleks, > > Am 16.05.19 um 18:36 schrieb Aleksandar Lazic: >> I will only accept requests which have sni and only when they are client >> requests. > > Consider using strict-sni then: > https://cbonte.github.io/haprox

Re: ssl_fc_sni vs req.ssl_sni

2019-05-17 Thread Aleksandar Lazic
Hi. Looks like my last mail was not passed to the list. Am 16.05.2019 um 22:27 schrieb Lukas Tribus: > Hello! > > > On Thu, 16 May 2019 at 18:37, Aleksandar Lazic wrote: >> >> Hi. >> >> I use the following lines: >> >> use_backen

Re: ssl_fc_sni vs req.ssl_sni

2019-05-17 Thread Aleksandar Lazic
Am 17.05.2019 um 20:51 schrieb Lukas Tribus: > Hello, > > > On Fri, 17 May 2019 at 16:42, Aleksandar Lazic wrote: >> After some reading and testing I have created that config file. >> >> https://gist.github.com/git001/73d1b7bcc3813ba40028c887e4f3e7f6 >> >

Re: ssl_fc_sni vs req.ssl_sni

2019-05-17 Thread Aleksandar Lazic
Hi. Fri May 17 21:31:41 GMT+02:00 2019 Lukas Tribus : > Hello, > > > On Fri, 17 May 2019 at 21:10, Aleksandar Lazic wrote: > > > Ok, that's correct, except for the use of ssl_fc_has_sni, which I'd > > > advise to not use. > > > Instead,

Re: ssl_fc_sni vs req.ssl_sni

2019-05-18 Thread Aleksandar Lazic
Am 17.05.2019 um 22:19 schrieb Lukas Tribus: > On Fri, 17 May 2019 at 21:44, Aleksandar Lazic wrote: >> > Here you need to use req.ssl_sni as you don't terminate SSL in that >> > frontend, and need to look at SNI to be able to route it >> > appropriately.

httplog clf missing values

2019-05-18 Thread Aleksandar Lazic
Hi. I tried today this settings and miss some values in the log. ``` frontend https-in option httplog clf option http-use-htx ... ``` :::Client - - [18/May/2019:17:27:56 +] "GET /ocs/v2.php/apps/notifications/api/v2/notifications HTTP/2.0" 200 691 "" "" 51818 485 "https-in~" "nextclo

Question about httplog and backend prot

2019-05-18 Thread Aleksandar Lazic
Hi. I have the following setup ``` frontend public_ssl bind :::443 v4v6 option tcplog tcp-request inspect-delay 5s tcp-request content capture req.ssl_sni len 25 tcp-request content accept if { req.ssl_hello_type 1 } # https://www.haproxy.com/blog/introduction-

Re: haproxy configuration issue

2019-05-21 Thread Aleksandar Lazic
Hi. Am 20.05.2019 um 17:04 schrieb Mortada, Mahmoud: > Hi All, > > I am using haproxy version 1.5.18 with Atlassian Jira data center. > > [root@ies-esd-jiradc-loadb-stage haproxy]# haproxy -version > > HA-Proxy version 1.5.18 2016/05/10 > > Copyright 2000-2016 Willy Tarreau > > Please find b

Re: haproxy configuration issue

2019-05-22 Thread Aleksandar Lazic
30m > >     server ies-esd-jiradc-node1-stage.ies.mentorg.com 10.249.2.152:8080 check > cookie ies-esd-jiradc-node1-stage.ies.mentorg.com > >     # The following "backup" servers are just here to show the startup page > when > all nodes are starting up > >  

Re: haproxy configuration issue

2019-05-22 Thread Aleksandar Lazic
returned by jira. > Regards, > > Mahmoud Mortada Regards Aleks > -Original Message- > From: Mortada, Mahmoud > Sent: Wednesday, May 22, 2019 11:11 AM > To: 'Aleksandar Lazic' > Cc: haproxy@formilux.org > Subject: RE: haproxy configuration issue > >

Re: Chained HA proxy with proxy protocol not working

2019-05-22 Thread Aleksandar Lazic
You need to add `accept-proxy` keyword in receiving haproxy bind line. https://cbonte.github.io/haproxy-dconv/1.9/configuration.html#5.1-accept-proxy Hth Aleks Wed May 22 14:03:26 GMT+02:00 2019 praveen kumar : > > have a haproxy setup as follow: > > Client --> Haproxy (LOCATION A)--> HAP

Re: RE: haproxy configuration issue

2019-05-22 Thread Aleksandar Lazic
ge.ies.mentorg.com' was defined without an explicit > ID at line You need to change the names in the server line. > Is this what you want me to do ? > > Thanks. > > Regards, > Mahmoud Mortada > > > -Original Message- > From: Aleksandar Lazi

Re: Sticky-table persistence in a Kubernetes environment

2019-05-22 Thread Aleksandar Lazic
Hi Eduardo. That's a pretty interesting question, at least for me. First why do you restart all haproxies at the same time and don't use rolling updates ? https://kubernetes.io/docs/tutorials/kubernetes-basics/update/update-intro/ Maybe you can add a init container to update the peers in the

Re: do we consider using patchwork ?

2019-05-22 Thread Aleksandar Lazic
Hi. Wed May 22 23:41:13 GMT+02:00 2019 Willy Tarreau : > Hi Ilya, > > On Thu, May 23, 2019 at 01:29:53AM +0500, ??? wrote: > > Hello, > > > > if we do not like using github PR and Willy receives 2k emails a day... > > do we consider using something like that > > https://patchwor

RFE: insert server into peer section

2019-05-23 Thread Aleksandar Lazic
Hi. We had a interesting discussion on Kubeconf how a session table in peer's can survive a restart of a haproxy instance. We came to a request for enhancement (RFE) to be able to add a peer server, not a peer section, to a existing peers section, similar to add server for backend. Opinions?

Re: Sticky-table persistence in a Kubernetes environment

2019-05-23 Thread Aleksandar Lazic
uot;* how many entries are in the tables?" > I don't know exactly, maybe between thousand and ten thousand. > > Thanks! > Att, Eduardo > > > > Em qua, 22 de mai de 2019 às 16:10, Aleksandar Lazic < al-hapr...@none.at [] > > escreveu: > >&

Re: RFE: insert server into peer section

2019-05-24 Thread Aleksandar Lazic
Hi Willy. Am 23.05.2019 um 16:48 schrieb Willy Tarreau: > Hi Aleks, > > On Thu, May 23, 2019 at 01:12:48PM +0200, Aleksandar Lazic wrote: >> We had a interesting discussion on Kubeconf how a session table in peer's can >> survive a restart of a haproxy instance. >

Re: Capturing headers from http/2 trailers?

2019-05-24 Thread Aleksandar Lazic
Hi. Fri May 24 15:00:55 GMT+02:00 2019 Patrick Hemmer : > Is there a way to capture (and log) headers from http/2 response > trailers? The documentation doesn't mention trailers, and when I try to > reference headers which are present in the trailers (e.g. > "res.fhdr(grpc-status)"), it does

Re: httplog clf missing values

2019-05-25 Thread Aleksandar Lazic
bq %CC %CS %hrl %hsl" > > The empty fields are expected if you haven't configured http request and > response header captures. Therefore, %hrl and %hsl are empty. Cool thanks. > Best regards, > > Bruno > > ‐‐‐‐‐‐‐ Original Message ‐‐‐ > On Saturday,

Re: Question about httplog and backend prot

2019-05-25 Thread Aleksandar Lazic
Am 24.05.2019 um 16:30 schrieb Moemen MHEDHBI: > > On 19/05/2019 00:28, Aleksandar Lazic wrote: >> Hi. >> >> I have the following setup [snipp] >> What variable can I use for the log to see which protocol is used for the >> backend, as with htx the fronten

[PATCH] DOC: Add informations for httplog clf mode

2019-05-25 Thread Aleksandar Lazic
Hi. attached a patch for the doc to make it clear that for clf are request header capture required. Regards aleks From 897bd17130c7051300ca5bd5569ac47c86da2488 Mon Sep 17 00:00:00 2001 From: aleks Date: Sat, 25 May 2019 12:11:26 +0200 Subject: [PATCH] DOC: Add informations for httplog clf mode

Re: [PATCH] DOC: Add informations for httplog clf mode

2019-05-27 Thread Aleksandar Lazic
Am 26.05.2019 um 21:39 schrieb Willy Tarreau: > Hi Aleks, > > On Sat, May 25, 2019 at 02:59:09PM +0200, Aleksandar Lazic wrote: >> Hi. >> >> attached a patch for the doc to make it clear that for clf are request header >> capture required. > > I'm so

Re: ACL criterion src [!] contained in ipset?

2019-05-27 Thread Aleksandar Lazic
Hi. Am 27.05.2019 um 20:52 schrieb Frank Myhr: > Hi, > > I have a setup with multiple domains that resolve to a single public IP > address, > with https handled by haproxy using SNI feeding an apache http backend using > name-base virtual hosting. Access to some (but not all) of the virtual host

Fwd: Fwd: ESNI initiative

2019-05-30 Thread Aleksandar Lazic
FYI. Is anyone here involved in this initiative ? Would be interesting how the routing will work based on ESNI. Best regards Aleks Weitergeleitete Nachricht Betreff:Fwd: ESNI initiative Datum: Wed, 29 May 2019 22:36:55 +0100 Von:Niall O'Reilly via curl-library An

Discussion about "Upstream socks proxy support #82"

2019-06-02 Thread Aleksandar Lazic
Hi. cipriancraciun, nutinshell and I discussed in the issue above some Socks use cases. Let me summarize the thread here. cipriancraciun suggest to handle socks similar to proxy protocol. https://github.com/haproxy/haproxy/issues/82#issuecomment-498004333 I don't think that socks could be hand

Re: [ANNOUNCE] haproxy-2.0-dev5

2019-06-03 Thread Aleksandar Lazic
Am 02.06.2019 um 13:00 schrieb Willy Tarreau: > Hi, > > HAProxy 2.0-dev5 was released on 2019/06/02. It added 92 new commits > after version 2.0-dev4. > > This version addresses a small number of no-to-trivial issues met while > working on fixing other bugs and during benchmarks. > > One such is

Re: [ANNOUNCE] haproxy-2.0-dev5

2019-06-03 Thread Aleksandar Lazic
Hi Willy. Mon Jun 03 14:05:07 GMT+02:00 2019 Willy Tarreau : > Hi Aleks, > > On Mon, Jun 03, 2019 at 01:42:45PM +0200, Aleksandar Lazic wrote: > > Is this test usefull in docker setup? > > > > ## Starting vtest #

Re: [ANNOUNCE] haproxy-2.0-dev7

2019-06-11 Thread Aleksandar Lazic
Am 11.06.2019 um 20:02 schrieb Willy Tarreau: > Hi, > > HAProxy 2.0-dev7 was released on 2019/06/11. It added 34 new commits > after version 2.0-dev6. [snipp] > Please find the usual URLs below : >Site index : http://www.haproxy.org/ >Discourse: http://discourse.haproxy.org

Re: [ANNOUNCE] haproxy-2.0-dev7

2019-06-11 Thread Aleksandar Lazic
Am 11.06.2019 um 22:01 schrieb Willy Tarreau: > On Tue, Jun 11, 2019 at 09:42:13PM +0200, Aleksandar Lazic wrote: >> Sorry to say that but there is no dev7 and in >> http://www.haproxy.org/download/2.0/src/devel/ >> also not. > > Ah silly me! And who forgot to run "

Re: Haproxy 1.9.8 comsumes 100% CPU

2019-06-13 Thread Aleksandar Lazic
Am 13.06.2019 um 13:47 schrieb Akom II: > Hello, >    Ubuntu 18.04  and haproxy 1.9.8 with latest patch on 2019/06/08 >    I'm currently encounter haproxy consume all CPU core, at the begging I > curious might relate  to peers function which is our app rely heavily on > those , > it happen quite f

Re: [ANNOUNCE] haproxy-2.0.0

2019-06-17 Thread Aleksandar Lazic
Am 16.06.2019 um 21:56 schrieb Willy Tarreau: > Hi, > > HAProxy 2.0.0 was released on 2019/06/16. It added 63 new commits > after version 2.0-dev7. [snipp] > Please find the usual URLs below : >Site index : http://www.haproxy.org/ >Discourse: http://discourse.haproxy.org/ >

Bugfix version 2.0.1/2.1?

2019-06-24 Thread Aleksandar Lazic
Hi, as this cookie bug prevent some user to use the shiny new haproxy 2 is there any plan to release a bugfix version soon? Regards Aleks

Re: Bugfix version 2.0.1/2.1?

2019-06-24 Thread Aleksandar Lazic
Hi Christopher. Thanks for answer. Regards Aleks Mon Jun 24 15:29:58 GMT+02:00 2019 Christopher Faulet : > Le 24/06/2019 à 14:46, Aleksandar Lazic a écrit : > > Hi, > > > > as this cookie bug prevent some user to use the shiny new haproxy 2 is > > there any &

<    1   2   3   4   5   6   7   8   9   10   >