# Latest

**URL:** https://discourse.haproxy.org/latest.md

[Latest](https://discourse.haproxy.org/latest.md) · [Categories](https://discourse.haproxy.org/categories.md)

---

## [Welcome to discourse.haproxy.org](https://discourse.haproxy.org/t/welcome-to-discourse-haproxy-org/8)

<div class="topic-metadata">

**Author:** [@system](https://discourse.haproxy.org/u/system)\
**Replies:** 0\
**Last updated:** [December 4, 2015, 4:22pm UTC](https://discourse.haproxy.org/t/welcome-to-discourse-haproxy-org/8 "2015-12-04T16:22:38Z")

</div>

This place is made available for HAProxy users who want to exchange configuration examples and scripts sorted by categories and topics in a way that is easier to index than a mailing list. It does not replace the mailing…

---

## [Intermittent wrong fallback cert served on TCP-mode SNI passthrough (3.4.4), even with recent SNI/session-resumption fixes included](https://discourse.haproxy.org/t/intermittent-wrong-fallback-cert-served-on-tcp-mode-sni-passthrough-3-4-4-even-with-recent-sni-session-resumption-fixes-included/12697)

<div class="topic-metadata">

**Author:** [@Tech1UAE](https://discourse.haproxy.org/u/Tech1UAE)\
**Replies:** 2\
**Last updated:** [September 22, 2026, 7:21am UTC](https://discourse.haproxy.org/t/intermittent-wrong-fallback-cert-served-on-tcp-mode-sni-passthrough-3-4-4-even-with-recent-sni-session-resumption-fixes-included/12697 "2026-09-22T07:21:14Z")

</div>

HAProxy version: 3.4.4 (also reproduced earlier on 3.2.23 before upgrading) OS: Ubuntu 24.04/26.04, installed via vbernat’s PPA Setup: TCP-mode frontend doing SNI-based passthrough routing to a mail server (SmarterMail…

---

## [Haproxy, letsencrypt and docker compose problem](https://discourse.haproxy.org/t/haproxy-letsencrypt-and-docker-compose-problem/12250)

<div class="topic-metadata">

**Author:** [@jsimon](https://discourse.haproxy.org/u/jsimon)\
**Replies:** 9\
**Last updated:** [September 6, 2026, 1:32pm UTC](https://discourse.haproxy.org/t/haproxy-letsencrypt-and-docker-compose-problem/12250 "2026-09-06T13:32:13Z")

</div>

Hi, I am very new to all of this, so please bear with me. I have a docker compose setup with 2 backend services and a haproxy. The proxy uses the (experimental) ACME integration with letsencrypt. The DNS is handled b…

---

## [How to get latest Haproxy version string via curl?](https://discourse.haproxy.org/t/how-to-get-latest-haproxy-version-string-via-curl/12260)

<div class="topic-metadata">

**Author:** [@den-is](https://discourse.haproxy.org/u/den-is)\
**Replies:** 2\
**Last updated:** [August 28, 2026, 7:18am UTC](https://discourse.haproxy.org/t/how-to-get-latest-haproxy-version-string-via-curl/12260 "2026-08-28T07:18:36Z")

</div>

TLDR: How to get latest HAproxy release version using curl? Without web scraping. I have my own opinionated and minimalistic Ansible collection to install dozens of various “devops” tools and services. GitHub - den-is/a…

---

## [I am new to HAPROXY DONT KNOW WHAT TO DO](https://discourse.haproxy.org/t/i-am-new-to-haproxy-dont-know-what-to-do/12519)

<div class="topic-metadata">

**Author:** [@spd2612](https://discourse.haproxy.org/u/spd2612)\
**Replies:** 0\
**Last updated:** [July 31, 2026, 6:00pm UTC](https://discourse.haproxy.org/t/i-am-new-to-haproxy-dont-know-what-to-do/12519 "2026-07-31T18:00:56Z")

</div>

I have haproxy installed and tested but config is where im lost My haproxy server does not have a cert on it I was just forwarding port 80 and 443 to it My backend servers all have letsencrypt already installed and hav…

---

## [Building Containers stops HAProxy to redirect correctly](https://discourse.haproxy.org/t/building-containers-stops-haproxy-to-redirect-correctly/12373)

<div class="topic-metadata">

**Author:** [@Daniele.Bottino](https://discourse.haproxy.org/u/Daniele.Bottino)\
**Replies:** 0\
**Last updated:** [July 10, 2026, 1:44pm UTC](https://discourse.haproxy.org/t/building-containers-stops-haproxy-to-redirect-correctly/12373 "2026-07-10T13:44:03Z")

</div>

Hi!!! :smiley: It’s the first time writing onto this site. I have an Openshift istance, and 2 namespaces: First-layer Second-layer the “default” namespace is occupied by HAProxy. I have configured HAProxy to balanc…

---

## [Upgrade from far past (1.5)](https://discourse.haproxy.org/t/upgrade-from-far-past-1-5/12267)

<div class="topic-metadata">

**Author:** [@ghap](https://discourse.haproxy.org/u/ghap)\
**Replies:** 5\
**Last updated:** [July 8, 2026, 2:03pm UTC](https://discourse.haproxy.org/t/upgrade-from-far-past-1-5/12267 "2026-07-08T14:03:30Z")

</div>

Dear all, this is my very first post in this forum so a big hello to everybody and thank you to anybody who will spend a little time to help me. I inherited a quite old setup with haproxy 1.5 and 2 backends. What’s the…

---

## [Delete HAProxy discourse account](https://discourse.haproxy.org/t/delete-haproxy-discourse-account/12174)

<div class="topic-metadata">

**Author:** [@anon26196567](https://discourse.haproxy.org/u/anon26196567)\
**Replies:** 3\
**Last updated:** [July 6, 2026, 9:57pm UTC](https://discourse.haproxy.org/t/delete-haproxy-discourse-account/12174 "2026-07-06T21:57:05Z")

</div>

Hi, I’d like to request the deletion of my HAProxy account. From what I could find on your Discourse forum, there doesn’t appear to be any option to remove it myself. Please also erase any personal data associated with…

---

## [Block all datacenters](https://discourse.haproxy.org/t/block-all-datacenters/12270)

<div class="topic-metadata">

**Author:** [@jsimon](https://discourse.haproxy.org/u/jsimon)\
**Replies:** 4\
**Last updated:** [July 1, 2026, 12:06pm UTC](https://discourse.haproxy.org/t/block-all-datacenters/12270 "2026-07-01T12:06:21Z")

</div>

Hi there, I noticed right away that my completely obscure little home-hosted private application was swarmed with scraping requests from data centers all over the place. Every time I looked one of those spammy IPs up, …

---

## [Problem with a 2 certificates configuration](https://discourse.haproxy.org/t/problem-with-a-2-certificates-configuration/12196)

<div class="topic-metadata">

**Author:** [@Ric](https://discourse.haproxy.org/u/Ric)\
**Replies:** 4\
**Last updated:** [June 14, 2026, 2:44pm UTC](https://discourse.haproxy.org/t/problem-with-a-2-certificates-configuration/12196 "2026-06-14T14:44:47Z")

</div>

Hello, I recently added a second certificate on my HAproxy configuration. The goal : provide a wildcard cert for the corresponding requested subdomains, and a default cert for others requests.The config is functional, b…

---

## ['mode tcp' performace degradation with two different backends](https://discourse.haproxy.org/t/mode-tcp-performace-degradation-with-two-different-backends/12194)

<div class="topic-metadata">

**Author:** [@doka.ua](https://discourse.haproxy.org/u/doka.ua)\
**Replies:** 1\
**Last updated:** [June 10, 2026, 11:45am UTC](https://discourse.haproxy.org/t/mode-tcp-performace-degradation-with-two-different-backends/12194 "2026-06-10T11:45:13Z")

</div>

I’m trying to test new connections rate in ‘mode tcp’ with the following config frontend default\_fe mode tcp bind \*:443 default\_backend default\_be backend default\_be mode tcp balance roundrobin # three auto…

---

## [Syslog Forwarding with send-proxy not working](https://discourse.haproxy.org/t/syslog-forwarding-with-send-proxy-not-working/11771)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discourse.haproxy.org/u/dot-mike)\
**Replies:** 2\
**Last updated:** [May 7, 2026, 7:54pm UTC](https://discourse.haproxy.org/t/syslog-forwarding-with-send-proxy-not-working/11771 "2026-05-07T19:54:44Z")

</div>

Hi community, I’ve tried for a few hours to have syslog forwarding enabling with send-proxy / send-proxy-v2 and neither of them is working properly. What I want to achieve: syslog input supporting both udp & tcp throug…

---

## [Adding a server with FQDN and resolvers via Data Plane API](https://discourse.haproxy.org/t/adding-a-server-with-fqdn-and-resolvers-via-data-plane-api/12173)

<div class="topic-metadata">

**Author:** [@ema-pe](https://discourse.haproxy.org/u/ema-pe)\
**Replies:** 1\
**Last updated:** [May 7, 2026, 2:53pm UTC](https://discourse.haproxy.org/t/adding-a-server-with-fqdn-and-resolvers-via-data-plane-api/12173 "2026-05-07T14:53:33Z")

</div>

Hi, I have a question regarding the usage of some Data Plane API APIs that wrap the Runtime API. I’m using HAProxy 3.2.6. I specified a resolvers section in my HAProxy configuration similarly to the following example, a…

---

## [Agent check over Unix socket](https://discourse.haproxy.org/t/agent-check-over-unix-socket/12172)

<div class="topic-metadata">

**Author:** [@buzztee](https://discourse.haproxy.org/u/buzztee)\
**Replies:** 2\
**Last updated:** [May 6, 2026, 7:37pm UTC](https://discourse.haproxy.org/t/agent-check-over-unix-socket/12172 "2026-05-06T19:37:59Z")

</div>

Hi! I have built a custom monitor which HAProxy uses via agent checks. The agent protocol is quite simple, HAProxy opens a TCP connection, send something, wait for the response, close connection. It would be neat if HA…

---

## [Using API when HAProxy is an extension of PFSense](https://discourse.haproxy.org/t/using-api-when-haproxy-is-an-extension-of-pfsense/12166)

<div class="topic-metadata">

**Author:** [@CrazyMasterMC](https://discourse.haproxy.org/u/CrazyMasterMC)\
**Replies:** 4\
**Last updated:** [May 5, 2026, 6:27pm UTC](https://discourse.haproxy.org/t/using-api-when-haproxy-is-an-extension-of-pfsense/12166 "2026-05-05T18:27:03Z")

</div>

Hello, I am running HAProxy as a pfSense package for multi-tenant routing (one subdomain per backend, all behind a single 80/443 entry point). I would like to automate the creation of frontend and backend rules. Is the…

---

## [Chroot can't quit](https://discourse.haproxy.org/t/chroot-cant-quit/12162)

<div class="topic-metadata">

**Author:** [@Kodey](https://discourse.haproxy.org/u/Kodey)\
**Replies:** 1\
**Last updated:** [April 28, 2026, 9:21am UTC](https://discourse.haproxy.org/t/chroot-cant-quit/12162 "2026-04-28T09:21:02Z")

</div>

I’m attempting to harden a forwarding proxy that currently runs on a standard Trixie deployment with haproxy version 3.0.11-1+deb13u2. When I try to chroot it, the control processes timeout. In an attempt to isolate th…

---

## [Update server weights via Data Plane API without reload](https://discourse.haproxy.org/t/update-server-weights-via-data-plane-api-without-reload/12151)

<div class="topic-metadata">

**Author:** [@ema-pe](https://discourse.haproxy.org/u/ema-pe)\
**Replies:** 1\
**Last updated:** [April 24, 2026, 1:45pm UTC](https://discourse.haproxy.org/t/update-server-weights-via-data-plane-api-without-reload/12151 "2026-04-24T13:45:20Z")

</div>

Hi! I am using HAProxy and I would like to use the Data Plane API to dynamically configure the proxy at runtime. I am looking for an API that allows updating the balancing weights of servers within a backend, but I have …

---

## [Slow downloads through Haproxy when under load](https://discourse.haproxy.org/t/slow-downloads-through-haproxy-when-under-load/8358)

<div class="topic-metadata">

**Author:** [@richard.a](https://discourse.haproxy.org/u/richard.a)\
**Replies:** 4\
**Last updated:** [April 23, 2026, 2:12am UTC](https://discourse.haproxy.org/t/slow-downloads-through-haproxy-when-under-load/8358 "2026-04-23T02:12:49Z")

</div>

We running an Haproxy server on version 2.0.29 on Ubuntu 20.04. It has a 10Gb/s NIC for connection to our LAN and the backend servers and is connected to a firewall capable of running at 1Gb/s. It is running various fr…

---

## [HAProxy source code missing from download site?](https://discourse.haproxy.org/t/haproxy-source-code-missing-from-download-site/12160)

<div class="topic-metadata">

**Author:** [@fitzy](https://discourse.haproxy.org/u/fitzy)\
**Replies:** 3\
**Last updated:** [April 22, 2026, 7:38am UTC](https://discourse.haproxy.org/t/haproxy-source-code-missing-from-download-site/12160 "2026-04-22T07:38:23Z")

</div>

Our production builds for HAP started failing around of 2026-04-21T01:46:00Z (UTC). Upon investigation, I found it was because source code is no longer available at Index of /download. Note the Last modified times…

---

## [Contour HTTPS Traffic with HAProxy](https://discourse.haproxy.org/t/contour-https-traffic-with-haproxy/12155)

<div class="topic-metadata">

**Author:** [@granth](https://discourse.haproxy.org/u/granth)\
**Replies:** 3\
**Last updated:** [April 20, 2026, 12:05pm UTC](https://discourse.haproxy.org/t/contour-https-traffic-with-haproxy/12155 "2026-04-20T12:05:47Z")

</div>

I have a httpproxy resource listening on port 443 and I have HAProxy pointing to the LoadBalancer IP of Contour with the following configuration: \`:443 check ssl verify none\`. When I try to curl the url I setup with HAPr…

---

## [How to route different domains to TCP and WebSocket backends using a single HAProxy port?](https://discourse.haproxy.org/t/how-to-route-different-domains-to-tcp-and-websocket-backends-using-a-single-haproxy-port/12159)

<div class="topic-metadata">

**Author:** [@qooke](https://discourse.haproxy.org/u/qooke)\
**Replies:** 4\
**Last updated:** [April 14, 2026, 10:00am UTC](https://discourse.haproxy.org/t/how-to-route-different-domains-to-tcp-and-websocket-backends-using-a-single-haproxy-port/12159 "2026-04-14T10:00:38Z")

</div>

I would like to configure HAProxy to handle multiple domains on a single listening port and route traffic to different backend services based on the requested domain name. Here is my scenario: I have two different do…

---

## [Idea/question: Optional healthchecks for old processes after soft-reload (with exact use-case)](https://discourse.haproxy.org/t/idea-question-optional-healthchecks-for-old-processes-after-soft-reload-with-exact-use-case/12158)

<div class="topic-metadata">

**Author:** [@masc](https://discourse.haproxy.org/u/masc)\
**Replies:** 1\
**Last updated:** [April 13, 2026, 8:02am UTC](https://discourse.haproxy.org/t/idea-question-optional-healthchecks-for-old-processes-after-soft-reload-with-exact-use-case/12158 "2026-04-13T08:02:29Z")

</div>

If I understood various sources correctly, there is currently no healthchecks for old processes remaining from a process rollover. While the workaround of hard-stop-after n may be suited to wait a little and hard-stop…

---

## [Struggles with Stick-table string](https://discourse.haproxy.org/t/struggles-with-stick-table-string/12156)

<div class="topic-metadata">

**Author:** [@Sybren](https://discourse.haproxy.org/u/Sybren)\
**Replies:** 1\
**Last updated:** [April 9, 2026, 9:39am UTC](https://discourse.haproxy.org/t/struggles-with-stick-table-string/12156 "2026-04-09T09:39:50Z")

</div>

Hello, Im having a bit of an issue blocking based on a token. My intention is to allow a token specified in the url. To be allowed only once. (in the below example per hour) It’s a http backend, my original config is q…

---

## [No custom error page for non-standard status code](https://discourse.haproxy.org/t/no-custom-error-page-for-non-standard-status-code/12157)

<div class="topic-metadata">

**Author:** [@Toni](https://discourse.haproxy.org/u/Toni)\
**Replies:** 4\
**Last updated:** [April 9, 2026, 8:57am UTC](https://discourse.haproxy.org/t/no-custom-error-page-for-non-standard-status-code/12157 "2026-04-09T08:57:39Z")

</div>

I would like to return non-standard status codes (like e.g. 419) in certain situations. haproxy refuses to provide custom error pages for arbitrary status codes: parsing \[/etc/haproxy/haproxy.cfg:4\] : errorfile : statu…

---

## [Control socket becomes stale on config reload](https://discourse.haproxy.org/t/control-socket-becomes-stale-on-config-reload/12154)

<div class="topic-metadata">

**Author:** [@buzztee](https://discourse.haproxy.org/u/buzztee)\
**Replies:** 0\
**Last updated:** [April 2, 2026, 6:09pm UTC](https://discourse.haproxy.org/t/control-socket-becomes-stale-on-config-reload/12154 "2026-04-02T18:09:02Z")

</div>

We’re connecting to the control socket to retrieve stats for the configured proxies / frontend / servers (running on HAProxy 3.3.5). The current implementation keeps the UNIX socket connection open (via “prompt i”) and …

---

## [Unexpected gRPC stream resets (CD + CANCELLED) during scale‑out](https://discourse.haproxy.org/t/unexpected-grpc-stream-resets-cd-cancelled-during-scale-out/12153)

<div class="topic-metadata">

**Author:** [@wojle](https://discourse.haproxy.org/u/wojle)\
**Replies:** 2\
**Last updated:** [April 2, 2026, 12:24pm UTC](https://discourse.haproxy.org/t/unexpected-grpc-stream-resets-cd-cancelled-during-scale-out/12153 "2026-04-02T12:24:07Z")

</div>

Hello, I’m using HAProxy Community Edition (3.3-dev14-8418c00) in OpenShift (4.X) to load-balance gRPC (HTTP/2) traffic to backend pods via server-template and A‑record DNS discovery. During Pod scale‑out, I consisten…

---

## [Routing based on certificate name/alias](https://discourse.haproxy.org/t/routing-based-on-certificate-name-alias/12134)

<div class="topic-metadata">

**Author:** [@Yenya](https://discourse.haproxy.org/u/Yenya)\
**Replies:** 11\
**Last updated:** [April 2, 2026, 8:34am UTC](https://discourse.haproxy.org/t/routing-based-on-certificate-name-alias/12134 "2026-04-02T08:34:12Z")

</div>

Hi all, is it possible to use conditional rules/routing based on which certificate was actually used in this connection? Let’s say I have a bunch of certificates, each certificate with more than one subjectAltName (e.g…

---

## [Dataplaneapi PUT to replace backend is not actually updating the backend](https://discourse.haproxy.org/t/dataplaneapi-put-to-replace-backend-is-not-actually-updating-the-backend/11291)

<div class="topic-metadata">

**Author:** [@kingsley](https://discourse.haproxy.org/u/kingsley)\
**Replies:** 3\
**Last updated:** [April 2, 2026, 7:37am UTC](https://discourse.haproxy.org/t/dataplaneapi-put-to-replace-backend-is-not-actually-updating-the-backend/11291 "2026-04-02T07:37:05Z")

</div>

Hi. Firstly, I’m a newbie here and a newbie to haproxy. I’ve searched the forum and googled loads but can’d find an answer to my problem, so really sorry if this is a FAQ. I’m using the dataplaneapi to update servers o…

---

## [HAProxy Kubernetes Ingress Controller: memory consumption at startup](https://discourse.haproxy.org/t/haproxy-kubernetes-ingress-controller-memory-consumption-at-startup/12152)

<div class="topic-metadata">

**Author:** [@Fagioletti](https://discourse.haproxy.org/u/Fagioletti)\
**Replies:** 2\
**Last updated:** [April 1, 2026, 11:16am UTC](https://discourse.haproxy.org/t/haproxy-kubernetes-ingress-controller-memory-consumption-at-startup/12152 "2026-04-01T11:16:29Z")

</div>

Working on HAProxy Ingress Controller for Kubernetes (3.2.6) i see reloads every few seconds if the memory allocation is not above 500Mib. When running the footprint is very low, but if allocated less (\>500Mib) HAProxy k…

---

## [Drain mode VS MAINT mode](https://discourse.haproxy.org/t/drain-mode-vs-maint-mode/12149)

<div class="topic-metadata">

**Author:** [@romgo](https://discourse.haproxy.org/u/romgo)\
**Replies:** 1\
**Last updated:** [March 30, 2026, 4:24pm UTC](https://discourse.haproxy.org/t/drain-mode-vs-maint-mode/12149 "2026-03-30T16:24:47Z")

</div>

Dear community, by reading some documentation about the dataplane API I got confused with regards to put out of production gracefully a backend server. Seems there is two ways to do it : disable server, will result i…

[Next page](https://discourse.haproxy.org/latest.md?page=1)
