HAProxy后端配置疑问:如何连接Cloudflare后的远程SSL服务器并实现本地/远程节点轮询
Hey there! Let's break down your problem step by step—this is totally doable, so don't stress about feeling lost in that hosting config ocean 😊
First off, yes, you absolutely can set up HAProxy to balance traffic between local containers and remote SSL servers (even those behind Cloudflare). The main issue with your current setup is missing a critical detail for SSL handshakes with Cloudflare-backed hosts: SNI (Server Name Indication).
Why your current remote server config isn't working
Your log shows "SSL handshake failure" even with verify none because Cloudflare needs SNI to know which domain's backend to route your request to. Without specifying SNI, HAProxy doesn't send the domain name during the SSL handshake, so Cloudflare can't properly direct traffic to your remote server.
Fixed HAProxy Config for Remote SSL Backends
Let's adjust your backend bt2 section to include the necessary SNI setting, plus a few tweaks for reliability:
global maxconn 4000 daemon defaults mode http default-server init-addr last,libc,none option http-keep-alive option redispatch retries 3 timeout connect 15s # Extended a bit for remote connections timeout client 1m timeout server 1m option forwardfor resolvers mynameservers nameserver ns2 8.8.8.8:853 # DNS-over-TLS is fine, just ensure resolution works frontend stats bind *:8500 stats enable stats uri / stats refresh 10s frontend ft bind 0.0.0.0:443 ssl crt /usr/local/etc/haproxy/ha_trial.pem default_backend bt2 backend bt2 balance roundrobin http-send-name-header Host # Keeps Host header forwarding as you had # Local container servers server web1 web1:8080 check server web2 web2:8080 check server web3 web3:8080 check # Fixed remote server config with SNI server myback_remote myback.mysite.com:443 ssl verify none resolvers mynameservers sni str(myback.mysite.com) check
Key Changes Explained
sni str(myback.mysite.com): Forces HAProxy to send the correct domain name during the SSL handshake with Cloudflare. This is non-negotiable for Cloudflare-hosted domains, as it uses SNI to route to the right backend.- Extended
timeout connect: Remote connections can take longer than local ones, so adding a few extra seconds helps avoid premature timeouts. checkon the remote server: Enables HAProxy to actively monitor the remote server's status—this should fix the "Down for Maintenance" status once the handshake works.
Additional Tips to Ensure Success
- Verify DNS Resolution: Inside your HAProxy container, run
nslookup myback.mysite.comto confirm it resolves to Cloudflare's IPs. If not, double-check your resolver config. - Cloudflare SSL Mode: Make sure your remote server's Cloudflare SSL setting is set to "Flexible", "Full", or "Strict"—all of these work with HAProxy's
ssl verify none(if you want stricter security later, you can replaceverify nonewithverify requiredand add Cloudflare's root certificate to HAProxy). - Targeted Host Header Adjustments: If you need to force a specific Host header for the remote server (instead of forwarding the client's Host), add this to your
backend bt2:
This ensures the remote server (or its Nginx Proxy Manager) gets the correct domain name.http-request set-header Host myback.mysite.com if { server myback_remote }
Troubleshooting If It Still Fails
If you still see errors, check HAProxy's logs with docker logs <your-haproxy-container-name> to look for:
- DNS resolution failures (confirm your resolver is working)
- TLS version mismatches (add
ssl-min-ver TLSv1.2to the remote server line to enforce modern TLS)
With these changes, you should be able to get HAProxy balancing traffic smoothly between your local containers and the remote Cloudflare-backed server.
备注:内容来源于stack exchange,提问作者Nikolaos Hatzistelios

