Automated certificate renewal for HAProxy
HAProxy expects certificate, chain and key in one PEM file. The HAProxy package writes exactly that bundle and reloads the service.
package haproxy-target 2.0.0
writeBundlereloadHaproxywhen configured
At a glance
- Package
haproxy-target 2.0.0- Compatibility
HAProxy >=1.8 <4.0- Runs from
- A Linux agent on the server
- Mechanism
- Files on disk · Service reload or restart
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyReload service
- Deployment steps
- writeBundle → reloadHaproxy*
- Rollback
- None
- Key usage
- No requirement
* conditional step
What it does
The agent on the HAProxy host writes the certificate, its chain and the private key into the bundle file your bind line's crt references, then reloads the systemd unit.
A reload lets HAProxy pick up the new bundle without dropping established connections.
How it runs
- 01
writeBundle
Certificate, chain and key are written into one PEM bundle.
- 02
reloadHaproxy
The HAProxy systemd unit is reloaded, if set.
What you configure
- Bundle path (default /etc/haproxy/certs/site.pem)
- systemd unit to reload (default haproxy)
Prerequisites
- A Linux agent on the HAProxy host
Limitations
- One bundle file per deploy target; HAProxy's runtime API is not used.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Load balancers
Documentation
Automate HAProxy
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.