You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HAProxy后端配置疑问:如何连接Cloudflare后的远程SSL服务器并实现本地/远程节点轮询

HAProxy后端配置疑问:如何连接Cloudflare后的远程SSL服务器并实现本地/远程节点轮询

Hey there! Let's break down your problem step by step—this is totally doable, so don't stress about feeling lost in that hosting config ocean 😊

First off, yes, you absolutely can set up HAProxy to balance traffic between local containers and remote SSL servers (even those behind Cloudflare). The main issue with your current setup is missing a critical detail for SSL handshakes with Cloudflare-backed hosts: SNI (Server Name Indication).

Why your current remote server config isn't working

Your log shows "SSL handshake failure" even with verify none because Cloudflare needs SNI to know which domain's backend to route your request to. Without specifying SNI, HAProxy doesn't send the domain name during the SSL handshake, so Cloudflare can't properly direct traffic to your remote server.

Fixed HAProxy Config for Remote SSL Backends

Let's adjust your backend bt2 section to include the necessary SNI setting, plus a few tweaks for reliability:

global
    maxconn     4000
    daemon

defaults
    mode    http
    default-server init-addr last,libc,none
    option  http-keep-alive
    option  redispatch
    retries 3
    timeout connect 15s  # Extended a bit for remote connections
    timeout client  1m
    timeout server  1m
    option forwardfor

resolvers mynameservers
    nameserver ns2 8.8.8.8:853  # DNS-over-TLS is fine, just ensure resolution works

frontend stats
    bind *:8500
    stats enable
    stats uri /
    stats refresh 10s

frontend ft
    bind 0.0.0.0:443 ssl crt /usr/local/etc/haproxy/ha_trial.pem
    default_backend bt2

backend bt2
    balance roundrobin
    http-send-name-header Host  # Keeps Host header forwarding as you had

    # Local container servers
    server web1 web1:8080 check
    server web2 web2:8080 check
    server web3 web3:8080 check

    # Fixed remote server config with SNI
    server myback_remote myback.mysite.com:443 ssl verify none resolvers mynameservers sni str(myback.mysite.com) check

Key Changes Explained

  • sni str(myback.mysite.com): Forces HAProxy to send the correct domain name during the SSL handshake with Cloudflare. This is non-negotiable for Cloudflare-hosted domains, as it uses SNI to route to the right backend.
  • Extended timeout connect: Remote connections can take longer than local ones, so adding a few extra seconds helps avoid premature timeouts.
  • check on the remote server: Enables HAProxy to actively monitor the remote server's status—this should fix the "Down for Maintenance" status once the handshake works.

Additional Tips to Ensure Success

  • Verify DNS Resolution: Inside your HAProxy container, run nslookup myback.mysite.com to confirm it resolves to Cloudflare's IPs. If not, double-check your resolver config.
  • Cloudflare SSL Mode: Make sure your remote server's Cloudflare SSL setting is set to "Flexible", "Full", or "Strict"—all of these work with HAProxy's ssl verify none (if you want stricter security later, you can replace verify none with verify required and add Cloudflare's root certificate to HAProxy).
  • Targeted Host Header Adjustments: If you need to force a specific Host header for the remote server (instead of forwarding the client's Host), add this to your backend bt2:
    http-request set-header Host myback.mysite.com if { server myback_remote }
    
    This ensures the remote server (or its Nginx Proxy Manager) gets the correct domain name.

Troubleshooting If It Still Fails

If you still see errors, check HAProxy's logs with docker logs <your-haproxy-container-name> to look for:

  • DNS resolution failures (confirm your resolver is working)
  • TLS version mismatches (add ssl-min-ver TLSv1.2 to the remote server line to enforce modern TLS)

With these changes, you should be able to get HAProxy balancing traffic smoothly between your local containers and the remote Cloudflare-backed server.

备注:内容来源于stack exchange,提问作者Nikolaos Hatzistelios

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 14:04:50