# Hitless operation with chroot

**URL:** <https://discourse.haproxy.org/t/hitless-operation-with-chroot/4044>\
**Category:** Help!\
**Created:** [July 15, 2019, 7:13am UTC](https://discourse.haproxy.org/t/hitless-operation-with-chroot/4044 "2019-07-15T07:13:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bmf7777](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/bmf7777/32/835_2.png) [@bmf7777](https://discourse.haproxy.org/u/bmf7777)\
**Post date:** [July 15, 2019, 7:13am UTC](https://discourse.haproxy.org/t/hitless-operation-with-chroot/4044/1 "2019-07-15T07:13:29Z")

</div>

i have haproxy configured with chroot operation and all is well (HA-Proxy version 2.0.1-1ppa1~bionic 2019/06/27 - [https://haproxy.org/](https://haproxy.org/)) … i’m interested in adding hitless operation …

i’ve added the following to my cfg file (`stats socket /var/run/haproxy.sock mode 600 expose-fd listeners level user`) …

do i need to specify or place (/var/run/haproxy.sock) in my chroot directory (/var/empty) or is my current configuration correct?

thanks in advance

```
global
	maxconn 100
	daemon
	tune.ssl.default-dh-param 2048
	chroot /var/empty
	user haproxy
	group haproxy
  	stats socket /var/run/haproxy.sock mode 600 expose-fd listeners level user
```

---

<div class="post-metadata">

**Author:** ![bmf7777](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/bmf7777/32/835_2.png) [@bmf7777](https://discourse.haproxy.org/u/bmf7777)\
**Post date:** [July 15, 2019, 8:39pm UTC](https://discourse.haproxy.org/t/hitless-operation-with-chroot/4044/2 "2019-07-15T20:39:52Z")

</div>

i believe using a port vs file system is simpler for chroot…

e.g. `stats socket 127.0.0.1:9002 expose-fd listeners level user` vs. /var/run/haproxy.sock which i would have to place in my chroot directory /var/empty

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [July 15, 2019, 8:55pm UTC](https://discourse.haproxy.org/t/hitless-operation-with-chroot/4044/3 "2019-07-15T20:55:17Z")

</div>

It needs to be a unix socket.

You don’t have to care about chroot, as the socket is opening before chrooting afaik.

---

<div class="post-metadata">

**Author:** ![bmf7777](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/bmf7777/32/835_2.png) [@bmf7777](https://discourse.haproxy.org/u/bmf7777)\
**Post date:** [July 15, 2019, 10:24pm UTC](https://discourse.haproxy.org/t/hitless-operation-with-chroot/4044/4 "2019-07-15T22:24:26Z")

</div>

thanks
