HAproxy配置咨询:实现123.domain.com反向代理至api.domain.com
Hey there, let's work through this step by step to get your desired behavior without disrupting production traffic. First, let's clear up a key misconception: the redirect rules you were considering will cause browser address bar changes, which is exactly what you don't want. Instead, we need to set up a transparent reverse proxy—where HAproxy silently forwards requests to api.domain.com while keeping 123.domain.com in the user's address bar.
Step 1: Core Configuration (Frontend + Backend)
Here's the exact HAproxy config you'll need, integrated into your existing SSL frontend:
# Assume your existing HTTPS frontend is named https_frontend frontend https_frontend bind *:443 ssl crt /path/to/your/ssl/certs/ # Keep your existing SSL setup # ... your existing ACLs and backend rules go here ... # New ACL to match requests to 123.domain.com acl host_subdomain_123 hdr(host) -i 123.domain.com # Route matching requests to our dedicated proxy backend use_backend api_proxy_backend if host_subdomain_123 # New backend to handle proxying to api.domain.com backend api_proxy_backend # Point to your actual API server (adjust port if needed, e.g., 80 for HTTP) server api_target api.domain.com:443 ssl verify none # Remove "verify none" if you want to validate the API's SSL cert # Rewrite the request Host header to match what api.domain.com expects reqirep ^Host: Host:\ api.domain.com # Critical: Rewrite any Location headers in responses to keep the subdomain # This prevents accidental redirects to api.domain.com from reaching the user rspirep ^Location:\ https?://api.domain.com/(.*) Location:\ https://123.domain.com/\1
What each part does:
reqirep: Modifies the incoming request'sHostheader toapi.domain.com, so the backend API recognizes the request correctly.rspirep: Scans responses forLocationheaders (common in 3xx redirects) and replacesapi.domain.comwith123.domain.com, ensuring the user never sees the actual API domain.
Step 2: Safe Deployment (No Production Downtime)
To avoid breaking live traffic, follow these safe steps:
- Validate the config first: Run this command to check for syntax errors before applying:
haproxy -c -f /path/to/your/haproxy.cfg - Soft reload, don't restart: Use a reload instead of a full restart to keep existing connections alive:
systemctl reload haproxy # For systemd systems # OR service haproxy reload # For init.d systems - Test with limited traffic first: Add an ACL to restrict the proxy rule to only your IP address initially:
Verify everything works as expected (no address bar changes, correct content loads) before removing the IP restriction.acl my_test_ip src 192.168.1.100 # Replace with your IP use_backend api_proxy_backend if host_subdomain_123 my_test_ip
Why Your Original Redirect Idea Won't Work
Redirect rules like redirect prefix http://123.domain.com tell the browser to send a new request to the target URL, which will update the address bar. This breaks your requirement of keeping the user on 123.domain.com without perception changes. Reverse proxying is the only way to achieve silent forwarding.
内容的提问来源于stack exchange,提问作者Pegasus1985

