Logo
Explore Help
Register Sign In
cloud-hosting-platform/haproxy-manager-base
3
0
Fork 0
You've already forked haproxy-manager-base
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
615044fa14fb7ff03969865e3662b40d6ac46bde
haproxy-manager-base/templates/hap_security_tables.tpl

8 lines
170 B
Smarty
Raw Normal View History

Add rate limiting, connection limits, and timeout hardening Activate HAProxy's built-in attack prevention to stop floods that cause the container to become unresponsive: - Stick table tracks per-IP: conn_cur, conn_rate, http_req_rate, http_err_rate - Rate limit rules: deny at 50 req/s, tarpit at 20 req/s, connection rate limit at 60/10s, concurrent connection cap at 100, error rate tarpit at 20 errors/30s - Harden timeouts: http-request 300s→30s, connect 120s→10s, client 10m→5m, keep-alive 120s→30s - HTTP/2 Rapid Reset protection (CVE-2023-44487): stream and glitch limits - Stats frontend on localhost:8404 for monitoring - HEALTHCHECK now validates both port 80 (HAProxy) and 8000 (API) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-31 10:00:53 -07:00
# HAProxy Stats & Monitoring
frontend stats
bind 127.0.0.1:8404
stats enable
stats uri /stats
stats refresh 30s
stats show-legends
stats show-node
Reference in New Issue Copy Permalink
Powered by Gitea Version: 1.25.3 Page: 17ms Template: 0ms
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API