# Using SSL with HAProxy for docker containers

**URL:** <https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307>\
**Category:** Help!\
**Created:** [May 24, 2016, 9:27pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307 "2016-05-24T21:27:22Z")\
**Posts on this page:** 14\
**Page:** 2

<div class="post-metadata">

**Author:** ![AstJ](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AstJ](https://discourse.haproxy.org/u/AstJ)\
**Post date:** [June 9, 2016, 11:46pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/21 "2016-06-09T23:46:52Z")

</div>

Thanks Lukas!

Unfortunately the script requires 1.6

> You need to be rolling HAProxy version 1.6.0 or later with Lua support enabled.

Mine is

> Package haproxy-1.5.14-3.el7.x86\_64 already installed and latest version

Should I try it anyway? Or look at this instead… [How To Secure HAProxy with Let's Encrypt on CentOS 7 | DigitalOcean](https://www.digitalocean.com/community/tutorials/how-to-secure-haproxy-with-let-s-encrypt-on-centos-7) ?

Btw, do you know how I can get version info on Centos? `haproxy -vv` does not work. Is `systemctl status haproxy` the equivalent?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [June 10, 2016, 7:55am UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/22 "2016-06-10T07:55:09Z")

</div>

I don’t know about docker or centos, but haproxy -vv should always work. The acme validation plugin needs haproxy 1.6 with Lua, there is no point in trying with 1.5.

---

<div class="post-metadata">

**Author:** ![AstJ](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AstJ](https://discourse.haproxy.org/u/AstJ)\
**Post date:** [June 14, 2016, 5:42pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/23 "2016-06-14T17:42:37Z")

</div>

Hey @lukastribus just coming back to report this has now all be set up - massive thanks for your help! 🙂 I have also edited the first post with a summary - hopefully it will help others without them having to read the whole thread.

Just one last question, what would be the best way to force https on my some of my sites? (Some of those defined under ‘Define hosts’ and some that use the default\_backed.)

Here is a reminder of what I have:

```auto
frontend http-in
        bind *:80
        default_backend main_apache_sites

        # Define hosts
	      redirect prefix http://discourse-forum-1.com code 301 if { hdr(host) -i www.discourse-forum-1.com }
        acl host_discourse hdr(host) -i discourse-forum-1.com
	      redirect prefix http://discourse-forum-2.com code 301 if { hdr(host) -i www.discourse-forum-2.com }
        acl host_discourse_2 hdr(host) -i discourse-forum-2.com		
	      redirect prefix http://discourse-forum-3.com code 301 if { hdr(host) -i www.discourse-forum-3.com }
        acl host_discourse_3 hdr(host) -i discourse-forum-3.com
		
        # which one to use
        use_backend discourse_docker if host_discourse
        use_backend discourse_docker_2 if host_discourse_2
        use_backend discourse_docker_3 if host_discourse_3	

backend main_apache_sites
    	server server1 127.0.0.1:8080 cookie A check
	    cookie JSESSIONID prefix nocache

backend discourse_docker
    	server server2 127.0.0.1:8888 cookie A check
	    cookie JSESSIONID prefix nocache

backend discourse_docker_2
    	server server2 127.0.0.1:8889 cookie A check
	    cookie JSESSIONID prefix nocache

backend discourse_docker_3
    	server server2 127.0.0.1:8890 cookie A check
	    cookie JSESSIONID prefix no cache

```

Do I just need lots of these?

```auto
redirect scheme https if { hdr(Host) -i www.mydomain.com } !{ ssl_fc }

```

(Where do they go? Under `Define hosts`?)

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [June 14, 2016, 8:28pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/24 "2016-06-14T20:28:43Z")

</div>

Yes, but in that case I would suggest to use a dedicated (named) ACL to define the list of hosts that need the HTTPS redirect, otherwise the configuration gets messy.

Note that there is no indentation in haproxy really. “redirect” and “acl” can start at the same place as can server and cookie in the backend.

---

<div class="post-metadata">

**Author:** ![AstJ](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AstJ](https://discourse.haproxy.org/u/AstJ)\
**Post date:** [June 14, 2016, 10:57pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/25 "2016-06-14T22:57:17Z")

</div>

Do you mean something like this?

```auto
# Define hosts
  redirect prefix http://myforum.com code 301 if { hdr(host) -i www.myforum.com }
  redirect scheme https if { hdr(Host) -i myforum.com } !{ ssl_fc }
  acl host_discourse_3 hdr(host) -i myforum.com

```

Or is there a better way?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [June 15, 2016, 6:57am UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/26 "2016-06-15T06:57:03Z")

</div>

Yes, but I would also use an ACL for this, so you only have to add a Host to the ssl\_redirect\_hosts ACL, not touch the actual redirect directive:

```
# Define hosts
redirect prefix http://myforum.com code 301 if { hdr(host) -i www.myforum.com }
acl host_discourse_3 hdr(host) -i myforum.com
acl ssl_redirect_hosts hdr(Host) -i myforum.com
acl ssl_redirect_hosts hdr(Host) -i myforum2.com
acl ssl_redirect_hosts hdr(Host) -i myforum3.com
redirect scheme https if ssl_redirect_hosts !{ ssl_fc }
```

---

<div class="post-metadata">

**Author:** ![AstJ](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AstJ](https://discourse.haproxy.org/u/AstJ)\
**Post date:** [June 16, 2016, 12:21pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/27 "2016-06-16T12:21:04Z")

</div>

Awesome, thanks Lukas!

Is there any way to do the same for removing the www’s? Or better still combine it all into one statement? No probs if not.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [June 16, 2016, 5:51pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/28 "2016-06-16T17:51:25Z")

</div>

I’m sure it is, you can find specifics in the documentation:  
[http://cbonte.github.io/haproxy-dconv/configuration-1.6.html#4-redirect](http://cbonte.github.io/haproxy-dconv/configuration-1.6.html#4-redirect)

---

<div class="post-metadata">

**Author:** ![AstJ](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AstJ](https://discourse.haproxy.org/u/AstJ)\
**Post date:** [October 21, 2016, 10:37pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/29 "2016-10-21T22:37:33Z")

</div>

Hi Lukas, sorry to bother you again, but would you know how I can enable secure cookies for the hosts we defined previously?

> [@lukastribus](#):
>
> # Define hosts
> 
> redirect prefix [http://myforum.com](http://myforum.com) code 301 if { hdr(host) -i [www.myforum.com](http://www.myforum.com) }  
> acl host\_discourse\_3 hdr(host) -i [myforum.com](http://myforum.com)  
> acl ssl\_redirect\_hosts hdr(Host) -i [myforum.com](http://myforum.com)  
> acl ssl\_redirect\_hosts hdr(Host) -i [myforum2.com](http://myforum2.com)  
> acl ssl\_redirect\_hosts hdr(Host) -i [myforum3.com](http://myforum3.com)  
> redirect scheme https if ssl\_redirect\_hosts !{ ssl\_fc }

Would I need to add this to the bottom?

> 

rspirep ^(set-cookie:.\*) \1;\ Secure if https !secured\_cookie

**Edit** : Just an update to say I seemed to have fixed my issue by simply adding the following to `frontend http-in`

> reqadd X-Forwarded-Proto:\ https if { ssl\_fc }

Does this look ok?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 23, 2016, 9:17am UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/30 "2016-10-23T09:17:55Z")

</div>

Yes, telling the application that the connection to the client is secured via X-Forwarded-Proto header is the proper thing to do in this case, instead of rewriting response headers at the proxy layer.

---

<div class="post-metadata">

**Author:** ![AstJ](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AstJ](https://discourse.haproxy.org/u/AstJ)\
**Post date:** [October 23, 2016, 2:41pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/31 "2016-10-23T14:41:07Z")

</div>

Thanks Lukas - you’re a ⭐ 🙂

---

<div class="post-metadata">

**Author:** ![Mike](https://avatars.discourse-cdn.com/v4/letter/m/58f4c7/32.png) [@Mike](https://discourse.haproxy.org/u/Mike)\
**Post date:** [December 2, 2016, 9:07pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/32 "2016-12-02T21:07:34Z")

</div>

Hi AstJ!

I’m working a very similar project right now. I was wondering if you could share your final config? 😃

thanks,  
Mike

---

<div class="post-metadata">

**Author:** ![AstJ](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AstJ](https://discourse.haproxy.org/u/AstJ)\
**Post date:** [December 4, 2016, 1:04am UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/33 "2016-12-04T01:04:00Z")

</div>

Hey @Mike, have you seen my guide on Discourse? It should have configs and further instruction 😃

> **[How to set up Discourse on a server with existing Apache sites](https://meta.discourse.org/t/how-to-set-up-discourse-on-a-server-with-existing-apache-sites/30013)**
>
> It’s not as daunting as it sounds! As you probably know, the only supported installs of Discourse are the Docker installs. While this may sound a bit intimidating at first, it’s really not all that bad. You basically need to do two things: ...

---

<div class="post-metadata">

**Author:** ![Mike](https://avatars.discourse-cdn.com/v4/letter/m/58f4c7/32.png) [@Mike](https://discourse.haproxy.org/u/Mike)\
**Post date:** [December 6, 2016, 5:09pm UTC](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307/34 "2016-12-06T17:09:37Z")

</div>

@AstJ  
🙂

Thanks!

[Previous page](https://discourse.haproxy.org/t/using-ssl-with-haproxy-for-docker-containers/307.md?page=1)
