You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HAproxy配置咨询:实现123.domain.com反向代理至api.domain.com

Solution for Transparent Reverse Proxy with HAProxy (No User Perception Change)

Hey there, let's work through this step by step to get your desired behavior without disrupting production traffic. First, let's clear up a key misconception: the redirect rules you were considering will cause browser address bar changes, which is exactly what you don't want. Instead, we need to set up a transparent reverse proxy—where HAproxy silently forwards requests to api.domain.com while keeping 123.domain.com in the user's address bar.


Step 1: Core Configuration (Frontend + Backend)

Here's the exact HAproxy config you'll need, integrated into your existing SSL frontend:

# Assume your existing HTTPS frontend is named https_frontend
frontend https_frontend
    bind *:443 ssl crt /path/to/your/ssl/certs/  # Keep your existing SSL setup
    # ... your existing ACLs and backend rules go here ...

    # New ACL to match requests to 123.domain.com
    acl host_subdomain_123 hdr(host) -i 123.domain.com
    # Route matching requests to our dedicated proxy backend
    use_backend api_proxy_backend if host_subdomain_123

# New backend to handle proxying to api.domain.com
backend api_proxy_backend
    # Point to your actual API server (adjust port if needed, e.g., 80 for HTTP)
    server api_target api.domain.com:443 ssl verify none  # Remove "verify none" if you want to validate the API's SSL cert
    # Rewrite the request Host header to match what api.domain.com expects
    reqirep ^Host: Host:\ api.domain.com
    # Critical: Rewrite any Location headers in responses to keep the subdomain
    # This prevents accidental redirects to api.domain.com from reaching the user
    rspirep ^Location:\ https?://api.domain.com/(.*) Location:\ https://123.domain.com/\1

What each part does:

  • reqirep: Modifies the incoming request's Host header to api.domain.com, so the backend API recognizes the request correctly.
  • rspirep: Scans responses for Location headers (common in 3xx redirects) and replaces api.domain.com with 123.domain.com, ensuring the user never sees the actual API domain.

Step 2: Safe Deployment (No Production Downtime)

To avoid breaking live traffic, follow these safe steps:

  1. Validate the config first: Run this command to check for syntax errors before applying:
    haproxy -c -f /path/to/your/haproxy.cfg
    
  2. Soft reload, don't restart: Use a reload instead of a full restart to keep existing connections alive:
    systemctl reload haproxy  # For systemd systems
    # OR
    service haproxy reload    # For init.d systems
    
  3. Test with limited traffic first: Add an ACL to restrict the proxy rule to only your IP address initially:
    acl my_test_ip src 192.168.1.100  # Replace with your IP
    use_backend api_proxy_backend if host_subdomain_123 my_test_ip
    
    Verify everything works as expected (no address bar changes, correct content loads) before removing the IP restriction.

Why Your Original Redirect Idea Won't Work

Redirect rules like redirect prefix http://123.domain.com tell the browser to send a new request to the target URL, which will update the address bar. This breaks your requirement of keeping the user on 123.domain.com without perception changes. Reverse proxying is the only way to achieve silent forwarding.

内容的提问来源于stack exchange,提问作者Pegasus1985

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 00:22:45