【问题标题】:X-Forwarded-Host header should not be overwritten by the HaProxy when it is already setX-Forwarded-Host 标头在已设置时不应被 HaProxy 覆盖
【发布时间】:2020-01-25 07:05:08
【问题描述】:
有人可以告诉如何在 openshift 3.11 中配置自定义 ha 代理路由器(haproxy-config.template),以避免 X-Forwarded-Host、X-Forwarded-Port 和 X-Forwarded-Proto 标头不应该被覆盖HaProxy 已经设置好了。不设置 header 时,应根据 HTTP 标准进行设置。
我尝试了https://access.redhat.com/solutions/3986281,但它不起作用。
谢谢,
桑托什
【问题讨论】:
标签:
openshift
router
haproxy
【解决方案1】:
以下代码对我有用:
旧配置:
http-request set-header X-Forwarded-Host %[req.hdr(host)]
http-request set-header X-Forwarded-Port %[dst_port]
http-request set-header X-Forwarded-Proto http if !{ ssl_fc }
http-request set-header X-Forwarded-Proto https if { ssl_fc }
改成新的:
acl h_xfh_exists req.hdr(X-Forwarded-Host) -m found
http-request set-header X-Forwarded-Host %[req.hdr(host)] unless h_xfh_exists
acl h_xfport_exists req.hdr(X-Forwarded-Port) -m found
http-request set-header X-Forwarded-Port %[dst_port] unless h_xfport_exists
acl h_xfproto_exists req.hdr(X-Forwarded-Proto) -m found
http-request set-header X-Forwarded-Proto http if !{ ssl_fc } !h_xfproto_exists
http-request set-header X-Forwarded-Proto https if { ssl_fc } !h_xfproto_exists