mirror of
https://github.com/ScuroNeko/mtg.git
synced 2026-08-31 22:24:02 +03:00
FILE / ScuroNeko/mtg
contrib/sni-router/haproxy.cfg
Исходный файл и его история в репозитории.
Add an ACL that routes /.well-known/acme-challenge/ requests on :80 to Caddy instead of redirecting to HTTPS, so Let's Encrypt certificate issuance works out of the box. Also simplify Caddyfile to use Caddy's http_port/https_port directives.
57 lines
1.5 KiB
INI
57 lines
1.5 KiB
INI
# HAProxy SNI router — Layer 4 (TCP mode)
|
|
#
|
|
# Inspects the SNI in the TLS ClientHello and routes traffic:
|
|
# - SNI matching the mtg secret domain -> mtg (FakeTLS / MTProto)
|
|
# - Everything else -> real web backend (Caddy)
|
|
#
|
|
# Because routing happens before TLS termination, each backend sees the
|
|
# raw ClientHello and handles TLS itself. The real web backend therefore
|
|
# presents a genuine certificate to any probe or browser.
|
|
|
|
global
|
|
log stdout format raw local0 info
|
|
maxconn 4096
|
|
|
|
defaults
|
|
log global
|
|
mode tcp
|
|
option tcplog
|
|
timeout connect 5s
|
|
timeout client 60s
|
|
timeout server 60s
|
|
|
|
# --- HTTP :80 — ACME challenges + redirect -----------------------------------
|
|
|
|
frontend http
|
|
bind *:80
|
|
mode http
|
|
|
|
# Let Caddy answer ACME HTTP-01 challenges for Let's Encrypt.
|
|
acl is_acme path_beg /.well-known/acme-challenge/
|
|
use_backend web_acme if is_acme
|
|
|
|
http-request redirect scheme https code 301
|
|
|
|
# --- TLS :443 — SNI-based routing -------------------------------------------
|
|
|
|
frontend tls
|
|
bind *:443
|
|
tcp-request inspect-delay 5s
|
|
tcp-request content accept if { req_ssl_hello_type 1 }
|
|
|
|
# Route Telegram clients to mtg.
|
|
# Replace "example.com" with the domain from your mtg secret.
|
|
use_backend mtg if { req_ssl_sni -i example.com }
|
|
|
|
default_backend web
|
|
|
|
backend mtg
|
|
server mtg mtg:3128
|
|
|
|
backend web
|
|
server web web:8443
|
|
|
|
backend web_acme
|
|
mode http
|
|
server web web:80
|