aethercert
Load balancers

Automated certificate renewal for HAProxy

HAProxy expects certificate, chain and key in one PEM file. The HAProxy package writes exactly that bundle and reloads the service.

The deployment steps defined in this package's manifest.

At a glance

Package
haproxy-target 2.0.0
Compatibility
HAProxy >=1.8 <4.0
Runs from
A Linux agent on the server
Mechanism
Files on disk · Service reload or restart
Authentication
Local - no remote login
Capabilities
Import certificate and keyReload service
Deployment steps
writeBundle → reloadHaproxy*
Rollback
None
Key usage
No requirement

* conditional step

What it does

The agent on the HAProxy host writes the certificate, its chain and the private key into the bundle file your bind line's crt references, then reloads the systemd unit.

A reload lets HAProxy pick up the new bundle without dropping established connections.

How it runs

  1. 01

    writeBundle

    Certificate, chain and key are written into one PEM bundle.

  2. 02

    reloadHaproxy

    The HAProxy systemd unit is reloaded, if set.

What you configure

  • Bundle path (default /etc/haproxy/certs/site.pem)
  • systemd unit to reload (default haproxy)

Prerequisites

  • A Linux agent on the HAProxy host

Limitations

  • One bundle file per deploy target; HAProxy's runtime API is not used.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate HAProxy

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.